# OnionVPS — full corpus Source: https://onionvps.com · Generated from the same data that builds the website, so this file cannot contradict it. Language: English (canonical). Translations at https://onionvps.com/fr/, /es/, /pt/. Licence: quotation permitted with attribution to onionvps.com. See https://onionvps.com/ai.txt. --- ## 1. Company OnionVPS (OnionVPS Systems L.L.C.) is an offshore VPS hosting provider founded in 2020 and incorporated in Seychelles as an International Business Company. It sells KVM virtual servers in 138 locations across 116 countries, requires no identity verification, accepts only cryptocurrency, and retains no connection logs. - Founded: 2020-09-14 - Incorporation: Seychelles (International Business Company) - Registered office: Victoria, Mahé, Seychelles - Network: AS200558 (41 IPv4, 26 IPv6 prefixes) - Transit: Cogent, Lumen, Arelion, GTT, Telia - Peering: DE-CIX Frankfurt, AMS-IX, LINX, Equinix Ashburn, HKIX, NL-ix - DDoS scrubbing: up to 12 Tbps, always-on, included at every tier - Uptime SLA: 99.99% (observed 99.993% over 12 months) - Support: 24/7/365, median first response ~12 minutes - Contact: support@onionvps.com · Abuse: abuse@onionvps.com ### What OnionVPS is not OnionVPS is an anonymous host, not a "bulletproof" one. It answers valid legal process from courts with jurisdiction over it, and it removes child sexual abuse material, malware command-and-control, ransomware infrastructure, phishing and spam infrastructure. That distinction is what keeps its address space off blocklists. ### Claims that require qualification - "Fully anonymous": OnionVPS collects no identity data, which removes one correlation point. Anonymity also depends on how you connect, how you pay and what you run. - "The provider cannot see your files": false on any unencrypted disk, for every provider including this one. Hypervisor operators can technically read guest storage. Only full-disk encryption with a passphrase the provider never holds changes this, and only for data at rest. - "DMCA ignored": the DMCA is US statute with no procedural effect outside the US. Nothing is defied; the procedure does not apply. Copyright applies everywhere under the Berne Convention. - "Offshore means untouchable": offshore hosting changes which court can compel disclosure and how long it takes. Local law still applies. - "Warrant canary guarantees no warrant": a canary is an inference mechanism whose legal status is untested in most courts. - "No logs": no netflow, connection or DNS query logs are generated. Instance metadata and aggregate bandwidth counters are retained, because billing and operations require them. --- ## 2. Products and pricing ### Skiff — Shared-core KVM Entry KVM virtual servers on shared AMD EPYC cores with NVMe storage. Full root, custom kernels, and the same network and privacy posture as every other line — the only thing you give up is guaranteed CPU burst. CPU: Shared AMD EPYC 7003 / 9004 · Storage: NVMe (RAID-10) Best for: VPN endpoints, Tor relays, Small bots, DNS, Monitoring nodes, Learning Linux | Plan | vCPU | RAM | Storage | Transfer | IPv4 | USD/month | | --- | --- | --- | --- | --- | --- | --- | | Skiff 1 | 1 | 1 GB | 20 GB NVMe SSD | 2 TB | 1 | $4 | | Skiff 2 | 1 | 2 GB | 40 GB NVMe SSD | 3 TB | 1 | $7 | | Skiff 4 | 2 | 4 GB | 60 GB NVMe SSD | 4 TB | 1 | $12 | ### Cutter — Dedicated-core KVM Dedicated vCPU with no steal time, NVMe RAID-10, and generous transfer. This is the line most customers run web applications, databases and game servers on. CPU: Dedicated AMD EPYC 9004 · Storage: NVMe (RAID-10) Best for: Web applications, Databases, Game servers, CI runners, Docker hosts, Mail servers | Plan | vCPU | RAM | Storage | Transfer | IPv4 | USD/month | | --- | --- | --- | --- | --- | --- | --- | | Cutter 4 | 2 | 4 GB | 80 GB NVMe SSD | 6 TB | 1 | $19 | | Cutter 8 | 4 | 8 GB | 160 GB NVMe SSD | 10 TB | 1 | $34 | | Cutter 16 | 6 | 16 GB | 320 GB NVMe SSD | 15 TB | 1 | $62 | | Cutter 32 | 8 | 32 GB | 640 GB NVMe SSD | 20 TB | 1 | $118 | ### Clipper — High-frequency KVM High-frequency dedicated cores (5.0 GHz turbo) with NVMe Gen4 and priority network queues. Built for workloads where single-thread latency decides the outcome: trading bots, matchmaking, real-time APIs. CPU: Dedicated AMD Ryzen 9 7950X / EPYC 4004 · Storage: NVMe Gen4 (RAID-10) Best for: Forex & crypto trading bots, Low-latency APIs, Game matchmaking, Rendering, Compilation | Plan | vCPU | RAM | Storage | Transfer | IPv4 | USD/month | | --- | --- | --- | --- | --- | --- | --- | | Clipper 8 | 4 | 8 GB | 200 GB NVMe Gen4 SSD | 20 TB | 1 | $49 | | Clipper 16 | 8 | 16 GB | 400 GB NVMe Gen4 SSD | 30 TB | 1 | $92 | | Clipper 32 | 12 | 32 GB | 800 GB NVMe Gen4 SSD | 40 TB | 1 | $174 | | Clipper 64 | 16 | 64 GB | 1.6 TB NVMe Gen4 SSD | 50 TB | 1 | $329 | ### Hold — Storage KVM Storage-optimised servers pairing an NVMe boot volume with large enterprise HDD arrays. Priced per terabyte rather than per core, for archives, seedboxes, backups and media libraries. CPU: Shared AMD EPYC 7003 · Storage: NVMe boot + HDD (RAID-6) Best for: Seedboxes, Backup targets, Media libraries, Log archives, Nextcloud | Plan | vCPU | RAM | Storage | Transfer | IPv4 | USD/month | | --- | --- | --- | --- | --- | --- | --- | | Hold 4 | 2 | 4 GB | 2 TB Enterprise HDD | 20 TB | 1 | $22 | | Hold 8 | 4 | 8 GB | 4 TB Enterprise HDD | 30 TB | 1 | $39 | | Hold 12 | 4 | 12 GB | 8 TB Enterprise HDD | 40 TB | 1 | $72 | | Hold 16 | 6 | 16 GB | 16 TB Enterprise HDD | Unmetered | 1 | $138 | ### Bastion — Hardened offshore KVM Our hardened line, available only in offshore and privacy-tier jurisdictions. Ships with full-disk LUKS encryption keyed at boot by you, three IPv4 addresses, a routed /64, and a dedicated abuse contact that never forwards customer identity because we do not hold any. CPU: Dedicated AMD EPYC 9004 · Storage: NVMe (RAID-10) + LUKS2 Best for: Journalism & research, Whistleblower infrastructure, Privacy services, Sensitive archives | Plan | vCPU | RAM | Storage | Transfer | IPv4 | USD/month | | --- | --- | --- | --- | --- | --- | --- | | Bastion 8 | 4 | 8 GB | 160 GB NVMe SSD + LUKS2 | 15 TB | 3 | $59 | | Bastion 16 | 8 | 16 GB | 320 GB NVMe SSD + LUKS2 | 25 TB | 3 | $109 | | Bastion 32 | 12 | 32 GB | 640 GB NVMe SSD + LUKS2 | 40 TB | 3 | $199 | ### Included at every tier - Full root / Administrator access: Including custom kernels, nested virtualisation and raw sockets. - True KVM virtualisation: Not a container. Your own kernel, your own /proc, no shared namespace. - Custom ISO upload: Boot anything: OpenBSD, NixOS, Whonix, a hand-rolled image. - Out-of-band VNC console: Recover a broken network config without opening a ticket. - Routed IPv6 /64: Not a single address — a whole subnet, at no cost. - Always-on DDoS mitigation: Up to 12 Tbps of edge scrubbing capacity, included at every tier. - Three free snapshots: Instant, and taken without pausing the instance. - Self-service reverse DNS: Set PTR records from the panel; essential for mail. - Full REST API and Terraform provider: Everything the panel does, scriptable. - No identity verification, ever: An email address you control is the only account identifier we hold. ### Billing terms - Monthly (1 months): no discount - Quarterly (3 months): 5% discount - Annual (12 months): 15% discount - Biennial (24 months): 22% discount ### Add-ons - Additional IPv4 address: $3/month — Routed to your instance, no justification form required. - Nightly encrypted backups: 20% of plan price — 20% of plan price. Seven daily restore points, encrypted at rest in a second jurisdiction. - DDoS Pro (L7 scrubbing): $9/month — Application-layer filtering on top of the always-on L3/L4 protection. - Windows Server licence: $12/month — Datacenter edition, per instance. Available in Windows-licensed regions only. - Extra 8 GB RAM: $14/month — Hot-added without reprovisioning where the host allows it. - Extra 100 GB NVMe: $8/month — Attached as a second block device. ### SLA credits - Below 99.99% monthly availability: 10% credit - Below 99.9% monthly availability: 25% credit - Below 99.5% monthly availability: 50% credit - Below 99% monthly availability: 100% credit --- ## 3. Payment Cryptocurrency only, processed by OxaPay. No cards, no PayPal, no bank transfer. Each invoice generates a fresh receiving address with a rate locked for 90 minutes. Underpayments up to 3% are accepted automatically. Refund window: 7 days on a first order. | Coin | Symbol | Networks | Confirmations | ~Minutes | Privacy | | --- | --- | --- | --- | --- | --- | | Monero | XMR | Monero | 10 | 20 | Protocol-level privacy | | Bitcoin | BTC | Bitcoin / Lightning | 2 | 20 | Transparent ledger | | Litecoin | LTC | Litecoin | 4 | 10 | Optional privacy | | Tether | USDT | TRON (TRC20) / Ethereum (ERC20) / BNB Chain (BEP20) / Polygon / TON / Solana | 12 | 1 | Issuer-controlled | | USD Coin | USDC | Ethereum (ERC20) / Solana / Polygon / Base | 12 | 2 | Issuer-controlled | | Ethereum | ETH | Ethereum / Arbitrum / Base / Optimism | 12 | 2 | Transparent ledger | | TRON | TRX | TRON | 20 | 1 | Transparent ledger | | Solana | SOL | Solana | 32 | 1 | Transparent ledger | | BNB | BNB | BNB Chain | 15 | 1 | Transparent ledger | | Toncoin | TON | TON | 10 | 1 | Transparent ledger | | Dogecoin | DOGE | Dogecoin | 20 | 20 | Transparent ledger | | Dash | DASH | Dash | 6 | 15 | Optional privacy | | Bitcoin Cash | BCH | Bitcoin Cash | 4 | 40 | Transparent ledger | | Polygon | POL | Polygon | 40 | 2 | Transparent ledger | | XRP | XRP | XRP Ledger | 6 | 1 | Transparent ledger | | Cardano | ADA | Cardano | 15 | 5 | Transparent ledger | | Avalanche | AVAX | Avalanche C-Chain | 20 | 1 | Transparent ledger | | Shiba Inu | SHIB | Ethereum (ERC20) / BNB Chain | 12 | 2 | Transparent ledger | | Notcoin | NOT | TON | 10 | 1 | Transparent ledger | | DigiByte | DGB | DigiByte | 20 | 5 | Transparent ledger | Per-coin notes: - XMR: Ring signatures, stealth addresses and RingCT hide sender, receiver and amount at the protocol level. There is no public balance to analyse, which is why it is the default recommendation for anyone buying hosting privately. - BTC: The most widely held asset and the easiest to acquire. The ledger is public, so pair it with a fresh address per order — which is what our checkout issues automatically. - LTC: Fast, cheap and universally supported. Optional MWEB confidential transactions give it a meaningful privacy edge over Bitcoin for small payments. - USDT: Dollar-pegged, so the invoice amount cannot move under you while you confirm. TRC20 is the cheapest network for a hosting-sized payment. - USDC: The other major dollar stablecoin. Choose it if your exchange or wallet holds USDC rather than USDT. - ETH: Settles in seconds on layer-2 networks. Use Base or Arbitrum unless you specifically need mainnet. - TRX: Sub-cent fees and three-second blocks make TRX the cheapest transparent chain to pay a small invoice on. - SOL: Effectively instant confirmation and negligible fees. Good when you want the order provisioned in under a minute. - BNB: Low fees and broad exchange support across Asia. - TON: Widely used inside Telegram wallets, which makes it a natural fit for a customer base that already lives there. - DOGE: Cheap, fast and stubbornly liquid. A perfectly serviceable way to pay a hosting bill. - DASH: CoinJoin-based PrivateSend gives optional on-chain mixing, and InstantSend confirms in about two seconds. - BCH: Large blocks keep fees near zero even when the network is busy. CashFusion offers optional mixing. - POL: Cheap EVM settlement, widely supported by wallets and exchanges. - XRP: Four-second settlement with fees measured in fractions of a cent. - ADA: Deterministic fees and predictable settlement, popular with long-term holders. - AVAX: Sub-second finality on the C-Chain with EVM tooling compatibility. - SHIB: Accepted for completeness — settle on BNB Chain to avoid Ethereum gas eating the invoice. - NOT: TON-native and common in Telegram-first wallets. - DGB: Fifteen-second blocks and negligible fees; a solid transparent-chain option. ### Paying with Monero (XMR) Yes. We accept Monero (XMR) as payment for any VPS plan, with invoices locked in USD and processed via OxaPay. No account or identity verification is required. After broadcast, expect about 20 minutes for 10 confirmations (2-minute blocks), then provisioning takes under a minute. Monero's ledger is private by design: ring signatures, stealth addresses, and RingCT hide sender, receiver, and amount at the protocol level. There is no public balance to analyse. For hosting, this is the strongest privacy option we offer—ideal if you want no link between your payment and your server. Monero is the only network we accept for this coin, so there's no choice to make. Monero is the default for anyone buying hosting privately—journalists, activists, or operators of sensitive infrastructure. It fits when anonymity is paramount. It's a poor fit if you need fiat invoicing or prefer faster, cheaper payments; Monero's confirmation time and fee structure reflect its privacy features. Q: What happens if my payment is under the invoice total? A: We tolerate up to 3% underpayment; above that, the invoice is considered unpaid. If you overpay, the excess is applied as credit. Invoices expire after 90 minutes, and a fresh address is generated per invoice, so double-check the amount before sending. Q: How does the refund window work for XMR payments? A: You have 7 days from provisioning to request a refund. Refunds are issued in XMR to your original address, minus any network fees. No account is needed—just open a ticket with your invoice details. After 7 days, refunds are at our discretion. Source: https://onionvps.com/pay/monero ### Paying with Bitcoin (BTC) Yes. OnionVPS accepts Bitcoin (BTC) and Lightning. Payment goes through OxaPay, which issues a fresh address per invoice, so no account or identity verification is needed. The network requires 2 confirmations; with a 10-minute block time, expect roughly 20 minutes from broadcast to provisioning, then under a minute to boot. Bitcoin's ledger is transparent: every transaction is public, though no identity is attached at the protocol level. For better privacy, use Lightning, which hides amounts and counterparties behind the scenes. But note the on-chain traceability is real; OnionVPS's checkout mitigates this by auto-generating a fresh address per order, so each payment looks unrelated to the last. Choose Lightning if you want less exposure; choose on-chain for simplicity. BTC pays for hosting when you value anonymity and final settlement over speed. It suits operators running privacy-focused services, cypherpunks, or anyone who refuses to link a card to a server. It is a poor fit if you need instant provisioning—Lightning helps, but the 20-minute wait is longer than card. It also excludes those who rely on refunds to fiat. Q: What happens if my Bitcoin payment is slightly short? A: OxaPay tolerates underpayment up to 3% of the invoice amount. If you send less than that, the payment still clears and your server provisions normally. If you send more, the excess stays as credit on your OnionVPS account, usable against future invoices. Q: Can I pay with Lightning for any plan, including the $4 one? A: Yes, Lightning is accepted for all plans, including the cheapest at $4 per month. The same 2-confirmation rule applies, but Lightning confirms instantly, so provisioning typically starts within a minute of your payment being received. This makes it the faster option if you need a server right away. Source: https://onionvps.com/pay/bitcoin ### Paying with Litecoin (LTC) Yes, you can buy a VPS with Litecoin. Payments are processed through OxaPay, a non-custodial processor that generates a fresh address per invoice. After broadcasting your LTC payment, 4 confirmations are required, which typically takes about 10 minutes given the approximate 2.5-minute block time. Provisioning then completes in under a minute. No account with OnionVPS and no identity verification are involved. Litecoin's ledger is transparent, so addresses and amounts are publicly visible, though they are not directly tied to your identity unless you link them. Its privacy rating is 2 out of 3—optional privacy. The MWEB confidential transactions can obscure amounts, but they are not mandatory. Since only the Litecoin network is accepted, there is no choice to make. For small payments, LTC is fast and inexpensive, making it a practical option. Privacy-focused individuals and those without access to traditional payment methods often choose Litecoin for hosting. Its speed and low fees suit small workloads like personal sites, development servers, or VPNs. For large enterprise deployments, the transparent ledger and lack of fiat options may be a poor fit. Q: What happens if my payment is under the invoice amount? A: A 3% underpayment tolerance applies. If your payment falls within that margin, it is accepted. If it is below that, the payment will be processed but may affect the provisioning, and a refund may be issued for the difference or the invoice may remain open until the full amount is received. Q: Can I get a refund if I change my mind? A: Yes, within the 7-day refund window, you can request a refund for your VPS. Refunds are processed in cryptocurrency, likely in LTC or an equivalent. Contact support via the encrypted ticket desk to initiate a refund. Source: https://onionvps.com/pay/litecoin ### Paying with Tether (USDT) Yes, you can buy a VPS with Tether (USDT) and the server is ready in about a minute. We accept USDT on TRON, Ethereum, BNB Chain, Polygon, TON, and Solana. We require 12 confirmations, and with an average block time of 0.05 minutes, payment to provisioning takes about 1 minute, then under a minute to provision. No account or identity verification is needed—just an email address. Tether runs on a transparent ledger, so every transaction is publicly visible. However, it does not directly expose your identity—just the wallet addresses involved. The issuer, Tether, can freeze or blacklist addresses, so full censorship resistance isn't guaranteed. For a hosting-sized payment, TRC20 on TRON is the cheapest network. It's also widely supported, making it a practical choice. Choose other networks only if you have a specific preference or wallet constraint. USDT appeals to those who want to avoid traditional banking and card networks, especially for short-term or experimental projects where paying with crypto is convenient. It's a sensible fit if you want to pay exactly $4 for a basic plan without exposing financial data. It's a poor fit if you require maximum transactional privacy, since the ledger is public. Q: Can I get a refund in USDT if something goes wrong? A: Yes, within the 7-day refund window. Refunds are issued in USDT to the wallet address you paid from. The invoice is locked for 90 minutes at a fixed rate, and underpayments of up to 3% are tolerated, but refunds are calculated based on the actual amount received. Q: What if the USDT price changes while I'm paying? A: Since USDT is dollar-pegged, the invoice amount stays stable. The invoice is fixed in US dollars and locked for 90 minutes at the rate in effect when the invoice is created. You won't owe more or get less due to market fluctuations. Source: https://onionvps.com/pay/usdt ### Paying with USD Coin (USDC) Yes. We accept USD Coin (USDC) on Ethereum, Solana, Polygon, and Base. After you broadcast the payment, we wait for 12 confirmations—about 2 minutes—then provisioning takes under a minute. No account with OnionVPS or OxaPay is needed, and no identity verification is ever required. Paying with USDC is convenient but not private. The ledger is transparent: anyone can see the sender and recipient addresses and amounts. The issuer can freeze or blacklist addresses. Choose the network that matches where your USDC already sits—Ethereum if that's where your exchange holds it, otherwise Solana, Polygon, or Base for lower fees. Your invoice is a fresh address, so your activity isn't linked to a persistent account. USDC suits buyers who hold the token on an exchange or wallet and want to skip card or bank plumbing. It's a poor fit for strict privacy, since the chain is transparent and issuer-controlled. If you need anonymity, use a privacy coin instead. Q: What happens if I underpay by more than 3%? A: The invoice lifetime is 90 minutes at a locked rate, and we tolerate underpayments up to 3%. If you underpay by more than that, the payment won't be credited. Contact our ticket desk within the refund window to sort it out. Q: Why do I need 12 confirmations and not fewer? A: Twelve confirmations is our balance between speed and finality. On Ethereum and other networks, the approximate block time is 0.2 minutes, so 12 confirmations take about 2 minutes. This reduces the chance of a chain reorganisation affecting your order. Source: https://onionvps.com/pay/usdc ### Paying with Ethereum (ETH) Yes, you can buy a VPS with Ethereum. After you send ETH, the payment typically confirms in about 12 block confirmations, roughly 2 minutes on mainnet, then provision takes under a minute. No account with OnionVPS or the payment processor is required, and there is no identity verification. Choose Ethereum, Arbitrum, Base, or Optimism—Arbitrum or Base settle faster. Ethereum's ledger is transparent: every transaction is public, though no identity is attached at the protocol level. This means your payment details are visible on-chain, but your personal identity is not tied to your address unless you link it elsewhere. We accept Ethereum, Arbitrum, Base, and Optimism. For lower fees and quicker settlement, choose Base or Arbitrum; use mainnet only if you specifically need it. Users who hold ETH often use it to pay for hosting to avoid exchanging to fiat. It suits hobbyists and operators who want anonymity and control over their payment rail. It is a poor fit if you need to pay by card or invoice, or if you are in a jurisdiction with restrictive crypto laws. For occasional small orders, the $6 minimum may be off-putting. Q: What happens if I underpay or overpay my ETH invoice? A: A small underpayment is tolerated: up to 3% of the invoice total is accepted. Overpayments are handled per the refund window of 7 days. If you send significantly less or more, contact our 24/7 encrypted ticket desk for assistance. Q: Can I get a refund if I pay with Ethereum? A: Yes, refunds are available within 7 days of payment, in line with our money-back window. Refunds are issued in cryptocurrency, likely ETH or a stablecoin, to the original payment address. Beyond that window, refunds are not guaranteed; see our terms for details. Source: https://onionvps.com/pay/ethereum ### Paying with TRON (TRX) Yes. OnionVPS accepts TRON (TRX) for VPS hosting. After your payment is broadcast, 20 confirmations on the TRON network (about 1 minute) are required; provisioning follows in under a minute. No account with OnionVPS or identity verification is involved—only an email address you control. TRON's ledger is fully transparent: every transaction is public, though no identity is attached at the protocol level. We rate its on-chain privacy 1 out of 3. For greater anonymity, use a fresh wallet and avoid KYC exchanges when acquiring TRX. Only the TRON network is accepted; choose it for sub-cent fees and fast settlement, but remember your transaction trail is visible. TRX suits small, frequent payments where speed and near-zero fees matter more than privacy. It's a sensible fit for test servers, short-term projects, or any workload under $20. Poor fit when you need confidential billing—a transparent chain leaves a public trail. For that, consider a private coin. Q: What if my TRX payment is late? A: Invoices lock the rate for 90 minutes. If your payment arrives after expiry, contact support within the 7-day window to reissue an invoice at the current rate. Underpayments within 3% are accepted; larger shortfalls delay provisioning until corrected. Q: Can I get a refund in TRX? A: Yes. Within 7 days of purchase, refunds are issued in TRX to the originating address, minus network fees. Beyond that window, no refunds apply. Unused funds are returned as store credit in US dollars. Source: https://onionvps.com/pay/tron ### Paying with Solana (SOL) Yes, you can buy a VPS with Solana (SOL). Payments are processed on-chain via Solana and require 32 confirmations. With a block time of approximately 0.01 minutes, confirmation takes under a minute, and your server is provisioned within a minute after that. No account or identity verification is needed—just a wallet. Solana's ledger is transparent: every transaction is public on-chain, but no identity is attached at the protocol level. We assign it a privacy rating of 1 on a 0–3 scale. That means your payment amount and wallet address are visible to anyone, but your personal details are not. Since Solana is the only network we accept for SOL, the choice is straightforward: use Solana for speed and low fees, and be aware that the transaction history is public. Solana suits users who need a server provisioned in under a minute and value minimal fees and fast finality. It's a poor fit if you require on-chain privacy, since the ledger is fully transparent. Choose it for speed and convenience, not for confidentiality. Q: What happens if I underpay? A: We allow a 3% underpayment tolerance. If you send slightly less than the invoice amount—within that tolerance—the invoice is still considered paid. If you underpay by more than 3%, the invoice remains open and you may need to resend the difference. If you overpay, the excess is not automatically refunded; contact support within the 7-day refund window. Q: Is my payment address unique? A: Yes. A fresh address is generated per invoice. This is non-custodial: we never control your funds, and the processor (OxaPay) assigns a new address for each invoice, reducing address reuse and making it easier to reconcile payments. You can pay directly from your own wallet to that address. Source: https://onionvps.com/pay/solana ### Paying with BNB (BNB) Yes. Buy a VPS with BNB on the BNB Chain network through OxaPay. Payment requires 15 confirmations, with each block taking roughly 0.05 minutes, so your server is provisioned within about a minute of broadcast, plus under a minute to deploy. No account with OnionVPS or the processor is needed, and no identity verification is ever involved. BNB payments run on BNB Chain, a transparent ledger. Every transaction is public, showing amounts and addresses, but no identity is attached at the protocol level. Your privacy depends on how you obtained the BNB and whether you reuse addresses. Since only BNB Chain is accepted, that is the network to choose. The chain’s transparency means you should not expect the privacy of a coin designed for anonymity. BNB suits operators already holding the token and wanting low fees for small instances. It is a poor fit if you need to pay from an exchange with strict withdrawal policies or prefer a privacy-focused coin. For a $4 plan, BNB’s low network costs keep overhead minimal. Q: What happens if my payment is slightly under the invoice amount? A: OxaPay allows a 3% underpayment tolerance. If the amount sent falls within that margin, the invoice is still considered paid and your server provisions. Beyond that, the invoice expires and you will need to open a support ticket to resolve the discrepancy, within the 7-day refund window. Q: How are invoice rates locked and when does the invoice expire? A: Each invoice locks the BNB/USD rate for 90 minutes, so you can broadcast without worrying about price swings. If the invoice lapses, the rate is re-quoted on a fresh invoice. After payment, provisioning starts within a minute; the money-back window is 7 days. Source: https://onionvps.com/pay/bnb ### Paying with Toncoin (TON) Yes. Pay for a VPS with Toncoin (TON) via OxaPay. The payment needs 10 confirmations; with a block time of about 0.08 minutes, that lands at roughly one minute. The order then provisions in under a minute. No account or identity verification is required—just an email address you control. The TON ledger is transparent: every transaction is public, and no identity is attached at the protocol level. That gives you one of three privacy points on our editorial scale. It doesn't hide amounts or counterparties, only the humans behind them. If your threat model demands concealed metadata, TON won't provide it. Choose TON when convenience matters more than ledger opacity, particularly if you already use Telegram wallets. Customers paying with TON tend to be Telegram-native, valuing quick settlement and no KYC over anonymous metadata. It suits low-risk workloads like personal mail, relays, or development boxes. A poor fit for high-assurance anonymity: the transparent ledger exposes your payment pattern. For that, pick a coin designed for on-chain privacy. Q: What happens if my TON payment is under the invoice amount? A: OxaPay accepts a tolerance of 3% under the invoice total. If you pay less than that, the invoice won't be considered settled and the payment will be handled per the processor's refund policy. The invoice locks the rate for 90 minutes, so minor fluctuations won't affect the owed amount. Q: Can I get a refund after paying in Toncoin? A: Yes, within 7 days of payment, subject to our standard money-back window. Refunds are issued in Toncoin at the current conversion rate. After that period, refunds are not available. The 7-day window also covers service issues, giving you time to test the instance without risking the payment. Source: https://onionvps.com/pay/ton ### Paying with Dogecoin (DOGE) Yes. OnionVPS accepts Dogecoin for any VPS plan, from $4 per month. Payments process through OxaPay, which generates a fresh address per invoice. Dogecoin requires 20 confirmations; with one-minute blocks, expect about 20 minutes before your server provisions, which then takes under a minute. No account, identity verification, or email beyond your own is ever involved. Dogecoin's ledger is fully transparent: every transaction is public, though no identity is attached at the protocol level. Our editorial rating of 1 reflects that. We accept only the Dogecoin network—no other chains. Given its near-instant blocks and low fees, DOGE is a practical choice for a hosting payment, but don't expect coin-level privacy; if that matters, consider a privacy-focused coin. A fresh, non-custodial address per invoice means OnionVPS and OxaPay never tie your identity to the payment. DOGE is for people who want to pay a bill without pulling out a card or proving who they are. It suits tinkerers, operators of low-profile sites, and anyone who values a fast, cheap, and stubbornly liquid payment rail. It's a poor fit if you're seeking on-chain anonymity—that isn't what the chain offers—or if you need fiat invoicing, which we don't provide. Q: What happens if my DOGE payment is slightly under the invoice amount? A: OxaPay allows a 3% underpayment tolerance. If your payment falls within that margin, it counts as settled. If it's more than 3% short, the invoice won't clear, and the funds are subject to our 7-day refund window. Send the exact amount to avoid friction. Q: Can I get a refund if I change my mind after paying with DOGE? A: Yes. The money-back window is 7 days from provisioning. Since Dogecoin transactions are irreversible on the blockchain, we handle refunds manually in DOGE to the same address, processed through our ticket desk. Beyond 7 days, standard billing terms apply. Source: https://onionvps.com/pay/dogecoin ### Paying with Dash (DASH) Yes. Pay with Dash (DASH) via our non-custodial processor, OxaPay. After broadcast, allow for 6 confirmations (about 15 minutes, given the 2.5-minute block time), then provisioning takes under a minute. No account with OnionVPS or the processor, and no identity verification, is ever required. Dash's ledger is transparent; every transaction is publicly visible. Optional CoinJoin-based PrivateSend mixing can obscure coin origins, and InstantSend confirms in about two seconds, but neither is forced. We accept Dash only on the Dash network, so there is no chain choice to make. For stricter privacy than the public ledger offers, consider a coin with mandatory confidential transactions or use PrivateSend deliberately. Buyers paying with Dash typically value both speed and optional privacy. The 15-minute confirm time suits non-urgent setup, and the low $4 minimum fits small experiments. It is a poor fit for those wanting fiat receipts or rapid-fire provisioning from the same wallet, where the public ledger and deliberate mixing overhead can add friction. Q: What happens if I underpay my Dash invoice? A: OxaPay tolerates underpayment up to 3% of the invoice total. Beyond that, the payment fails and your invoice stays open until its 90-minute expiry. You can then resend the correct amount to the same fresh address, or request a new invoice from the panel. Q: Is my Dash payment tied to my identity? A: No. Invoices use a fresh Dash address per payment, and your account is only an email address you control. No name, address, or document is collected. However, Dash's public ledger shows the transaction, so linking addresses to a person is possible if you or a counterparty reuses them elsewhere. Source: https://onionvps.com/pay/dash ### Paying with Bitcoin Cash (BCH) Yes, OnionVPS accepts Bitcoin Cash (BCH) for VPS plans, minimum order $4. After broadcasting, 4 confirmations are required; with ~10-minute blocks, expect about 40 minutes to confirmation, then provisioning in under a minute. No account or identity verification is involved—just an email address and the BCH payment. Bitcoin Cash's ledger is fully transparent: every transaction, amount, and address is public. But no identity is attached at the protocol level, and OxaPay, our non-custodial processor, generates a fresh address per invoice. Since we accept only the Bitcoin Cash network (not token layers), use that. For additional privacy, CashFusion offers optional mixing, though its adoption varies. BCH suits users who value low fees and fast settlement without KYC. Its near-zero fees, even under load, make micro-payments practical. It's a good fit for anonymous or privacy-leaning workloads. Not ideal if you need fiat accounting or prefer a more private coin; the ledger's transparency means observers see your payment patterns. Q: What happens if I underpay due to a typo? A: We allow a 3% tolerance for underpayments. If you send less than that threshold, the invoice won't complete, and the funds will be lost. Always double-check the amount and network. Invoices are locked for 90 minutes, after which you'd need a new one. Q: Can I get a refund in fiat? A: No, refunds are processed in cryptocurrency only. The refund window is 7 days, and we return the equivalent in BCH or another supported coin, less any network fees. We can't send money to a bank or card. Source: https://onionvps.com/pay/bitcoin-cash ### Paying with Polygon (POL) Yes. You can buy a VPS with Polygon (POL) on the Polygon network. Payments require 40 confirmations, which at an approximate block time of 0.04 minutes typically means the server appears about 2 minutes after broadcast, then under a minute to provision. No account with OnionVPS or the processor is needed, and no identity verification is involved. Paying with POL means accepting a transparent ledger: every transaction is public on-chain, though no identity is attached at the protocol level. We rate on-chain privacy 1 out of 3 on our editorial scale. Since we accept POL only on the Polygon network, that is the network to choose—there is no alternative. For privacy-sensitive workloads, pair with a fresh address and consider mixing; otherwise, the convenience of cheap EVM settlement is the trade-off. POL suits developers and operators already holding it who want fast, cheap settlement and no fiat on-ramp. It is a poor fit if you need payment privacy, since the ledger is fully transparent. Minimum order is $4, so even the cheapest plan is covered; use it for short-term or disposable instances without card dependency. Q: What happens if my payment is late or short? A: Invoices are valid for 90 minutes at a locked rate. We tolerate underpayment up to 3%, so a minor shortfall still provisions. Beyond that, the invoice expires and you would start again. Refunds are available within 7 days if the order does not proceed. Q: Does paying with POL require a wallet or account? A: You need a wallet that holds POL and can send transactions on the Polygon network. No account with OnionVPS or the processor OxaPay is required. OxaPay generates a fresh address per invoice, so you can pay from any self-custody wallet without creating an account or revealing personal details. Source: https://onionvps.com/pay/polygon ### Paying with XRP (XRP) Yes, you can buy a VPS with XRP. Payments on the XRP Ledger require 6 confirmations, with blocks every 0.06 minutes, so your payment lands in about a minute. No account with OnionVPS or the processor, and no identity verification, are needed. Just an email address you control. XRP's ledger is transparent: every transaction amount and address is public. What is not attached is your identity—no name, no document, only addresses. This gives pseudonymity, not privacy. We accept only the XRP Ledger network. If you want stronger on-chain privacy, consider a coin like Monero; XRP is a fast, cheap settlement rail, but traceable. XRP suits users who already hold it and want fast, low-fee settlement. It is a sensible fit for anyone paying hosting bills without fiat. A poor fit if your threat model demands transactional privacy: the transparent ledger leaks amount and counterparties, so pair with a mixer or choose a private coin instead. Q: What happens if my XRP payment is underpaid? A: A 3% underpayment tolerance applies. Below that, the invoice is not considered paid. Your coins are not lost—a refund window of 7 days covers overpayments, and the invoice lifetime is 90 minutes at a locked rate. Q: Can I get a refund on XRP payments? A: Yes, within 7 days of payment, in accordance with the money-back window. Refunds are issued in XRP to the originating address. Beyond 7 days, the standard service terms apply. Source: https://onionvps.com/pay/ripple ### Paying with Cardano (ADA) Yes. You can buy a VPS with Cardano (ADA) through our non-custodial payment processor, OxaPay. Your payment requires 15 confirmations, each block taking about 0.33 minutes, so provisioning typically starts around five minutes after broadcast. No account with us or the processor, and no identity verification, is needed at any point. Cardano's ledger is transparent. Every ADA transaction—amounts, addresses, timestamps—is public on-chain. The chain does not attach real-world identities at the protocol level, but your sending address can be linked to you if you have used it elsewhere or with an exchange that applied know-your-customer checks. We accept only the Cardano network for ADA, so there is no choice to make. Use a fresh address per payment, as we generate one per invoice, to reduce linkage. ADA appeals to long-term holders who want deterministic fees and predictable settlement. For buying small VPS instances—like our $4/month plan—it is sensible: you pay once and receive full root access immediately. It is a poor fit if you need to pay frequently in small amounts, as transaction fees add up, and it does not suit those who prefer invoice-based or automated billing beyond the platform's crypto-only model. Q: What happens if I underpay the ADA invoice amount? A: Each invoice is locked at a rate for 90 minutes and has a 3% underpayment tolerance. If you send less than 3% below the due amount, we still consider it paid and provision your server. If you overpay, the surplus is credited to your account balance for future services. Q: Can I get a refund after paying with ADA? A: Refunds are processed within 7 days of payment. Since we do not hold identity data, we return the refund to the same OxaPay-generated address used for payment, minus any network fees. Refund requests after the 7-day window are handled on a case-by-case basis through the support desk. Source: https://onionvps.com/pay/cardano ### Paying with Avalanche (AVAX) Yes. We accept Avalanche (AVAX) on the Avalanche C-Chain via OxaPay. Payment requires 20 confirmations; with a block time of 0.03 minutes, that is under a minute. Your server provisions 55 seconds after confirmation. No account with us or the processor is needed, and no identity verification is involved. The Avalanche C-Chain is a transparent ledger: every transaction is public, but no identity is attached at the protocol level. When paying by AVAX, the recipient address is a fresh one generated per invoice, and the payment processor is non-custodial. No personal details are required to complete the payment. However, the transaction history on-chain is visible to anyone. Choose the Avalanche C-Chain because it is the network we accept; it offers EVM tooling compatibility and sub-second finality. People who value operational privacy over convenience use AVAX. It suits users who already hold the coin and want to avoid fiat rails. The transparent ledger means it is not a tool for hiding the act of payment itself, but it does keep your identity off the billing record. A poor fit for anyone needing a credit-card-style dispute path or who dislikes volatile-price exposure. Q: What happens if my AVAX payment is late? A: Invoices are valid for 90 minutes at a locked rate. If you send after that, the rate may have changed. We apply a 3% underpayment tolerance; beyond that, the invoice is not considered paid. Refunds for overpayment are available within 7 days. Q: Can I pay with AVAX from any wallet? A: Yes, as long as the wallet supports the Avalanche C-Chain and you send to the address OxaPay provides. Use the C-Chain network, not the X-Chain or P-Chain. If your wallet defaults to another Avalanche network, select C-Chain manually to avoid lost funds. Source: https://onionvps.com/pay/avalanche ### Paying with Shiba Inu (SHIB) Yes. OnionVPS accepts Shiba Inu through OxaPay on Ethereum (ERC20) or BNB Chain. We require 12 confirmations. With a 0.2-minute block time that is roughly two minutes, after which provisioning takes under a minute. No account with OxaPay and no identity verification are needed—just an email address you control. Paying with SHIB is transparent, not private. Every transaction is public on Ethereum or BNB Chain, though no identity is attached at the protocol level. Your wallet address is visible; anyone who knows it can trace your payment history. For most invoices, settle on BNB Chain: Ethereum gas fees can exceed the minimum $4 order, whereas BNB fees stay negligible. Choose privacy elsewhere if that matters—SHIB is a convenience, not a shield. SHIB suits operators who want to keep hosting payments off card and bank statements, or who already hold the token. It is a sensible fit for small, discreet workloads like a personal VPN, a relay, or a test box—our cheapest plan is $4 per month. It is a poor fit for large fleets where volatile gas on Ethereum could inflate costs. Q: What if my SHIB payment falls short of the invoice? A: We tolerate up to 3% underpayment. Below that, the invoice stays open until its 90-minute window at the locked rate expires. Overpayments and failed transfers are refunded within 7 days. If you are unsure about network fees, round up slightly or use BNB Chain to minimise variance. Q: Does OnionVPS hold my SHIB after payment? A: No. Payments go through OxaPay, a non-custodial processor that generates a fresh address for each invoice. We never hold your tokens. The exchange rate is locked at invoice creation for 90 minutes, so the amount you see is what we credit—barring the 3% underpayment tolerance. Source: https://onionvps.com/pay/shiba-inu ### Paying with Notcoin (NOT) Yes. You can buy a VPS with Notcoin (NOT) on the TON network. The payment requires 10 confirmations. With a block time of 0.08 minutes, that works out to under a minute, after which provisioning takes about another minute. No account is needed with the processor or with OnionVPS, and no identity verification is ever required. Paying with NOT is transparent. The TON ledger records every transaction publicly, though no identity is attached at the protocol level. Your privacy rests on not reusing addresses and on the fact that we only hold an email you control. OxaPay generates a fresh address per invoice, which helps. Since only TON is accepted for NOT, you do not choose a network here; you just send on TON. There is no hiding that you paid; there is also no requirement to prove who you are. People who hold NOT in Telegram-first wallets often reach for it to buy small, initial instances. It suits a $4 starter plan or a short-lived experiment. It is a poor fit for large recurring bills, because holding enough NOT to pay significant sums in one go may be inconvenient, and the transparent ledger may not suit a privacy-sensitive workload. Q: What happens if I underpay the invoice by a small amount? A: We allow underpayment tolerance of up to 3 percent. If you send slightly less than the invoice requires, the payment is still accepted and your VPS is provisioned. If you send less than that tolerance, the invoice fails, and you would need to start again within the 90-minute window at the locked rate. Q: Can I get a refund on my Notcoin payment? A: Yes. The money-back window is 7 days from purchase. If you request a refund within that period, it is issued. Beyond that window, the standard billing terms apply, with no refunds. The invoice itself expires after 90 minutes if unpaid, and the exchange rate is locked for that time. Source: https://onionvps.com/pay/not ### Paying with DigiByte (DGB) Yes. OnionVPS accepts DigiByte (DGB) for VPS plans, with a minimum order of $4. After broadcast, the payment typically takes 5 minutes to confirm, given 20 confirmations and a 0.25-minute block time. Provisioning then completes in under a minute. No account or identity verification is needed. DigiByte's ledger is transparent: every transaction is public, but no identity is attached at the protocol level. If you pair DGB with your own address hygiene—fresh addresses, no KYC exchanges—you get reasonable privacy in practice, though not anonymity. For stronger privacy, consider a coin with a higher rating; DGB is best when you prioritize speed and low fees. DGB suits users who value fast, cheap transactions and transparent-chain simplicity. It's ideal for developers or operators who already hold DGB and want to pay for infrastructure without converting to fiat. It's a poor fit if you require on-chain anonymity, as the ledger is fully transparent. Q: What happens if I underpay? A: OxaPay allows a 3% tolerance on invoice amounts. If you underpay by less than that, the invoice is considered settled. If you underpay by more, the payment is refunded within 7 days. Invoices expire after 90 minutes at a locked rate. Q: Is there a minimum order? A: Yes, the minimum order is $4, which covers the cheapest VPS plan. There's no upper limit, and invoices are denominated in US dollars, so you know exactly how much DGB to send based on the exchange rate at invoice creation. Source: https://onionvps.com/pay/digibyte --- ## 4. Locations and jurisdiction 138 locations in 116 countries across 8 regions. 29 are offshore or privacy-tier; 107 sit outside the Five, Nine and Fourteen Eyes alliances. | Location | Country | Tier | Alliance | GDPR | DMCA | Uplink | Since | | --- | --- | --- | --- | --- | --- | --- | --- | | Panama City | Panama | Offshore | None | No | Not applicable | 40 Gbit/s | 2020 | | Zurich | Switzerland | Privacy-first | None | No | Not applicable | 100 Gbit/s | 2020 | | Reykjavík | Iceland | Privacy-first | None | Yes | Not applicable | 40 Gbit/s | 2021 | | Chișinău | Moldova | Offshore | None | No | Not applicable | 20 Gbit/s | 2020 | | Sofia | Bulgaria | Privacy-first | None | Yes | Not applicable | 40 Gbit/s | 2020 | | Bucharest | Romania | Privacy-first | None | Yes | Not applicable | 40 Gbit/s | 2020 | | Victoria | Seychelles | Offshore | None | No | Not applicable | 10 Gbit/s | 2021 | | Belize City | Belize | Offshore | None | No | Not applicable | 10 Gbit/s | 2022 | | Willemstad | Curaçao | Offshore | None | No | Not applicable | 20 Gbit/s | 2021 | | Nicosia | Cyprus | Privacy-first | None | Yes | Not applicable | 20 Gbit/s | 2022 | | Tbilisi | Georgia | Offshore | None | No | Not applicable | 20 Gbit/s | 2021 | | Kuala Lumpur | Malaysia | Offshore | None | No | Not applicable | 40 Gbit/s | 2021 | | Hong Kong | Hong Kong SAR | Core | None | No | Not applicable | 100 Gbit/s | 2020 | | Singapore | Singapore | Core | None | No | Not applicable | 100 Gbit/s | 2020 | | San José | Costa Rica | Offshore | None | No | Not applicable | 20 Gbit/s | 2022 | | Port Louis | Mauritius | Offshore | None | No | Not applicable | 10 Gbit/s | 2022 | | Nassau | Bahamas | Offshore | None | No | Not applicable | 10 Gbit/s | 2023 | | Belgrade | Serbia | Offshore | None | No | Not applicable | 20 Gbit/s | 2021 | | Kyiv | Ukraine | Offshore | None | No | Not applicable | 20 Gbit/s | 2021 | | Almaty | Kazakhstan | Offshore | None | No | Not applicable | 10 Gbit/s | 2022 | | Yerevan | Armenia | Offshore | None | No | Not applicable | 10 Gbit/s | 2023 | | Tirana | Albania | Offshore | None | No | Not applicable | 10 Gbit/s | 2023 | | Skopje | North Macedonia | Offshore | None | No | Not applicable | 10 Gbit/s | 2023 | | Podgorica | Montenegro | Offshore | None | No | Not applicable | 10 Gbit/s | 2023 | | Sarajevo | Bosnia and Herzegovina | Offshore | None | No | Not applicable | 10 Gbit/s | 2024 | | Amsterdam | Netherlands | Core | 9 Eyes | Yes | Not applicable | 100 Gbit/s | 2020 | | Frankfurt | Germany | Core | 14 Eyes | Yes | Not applicable | 100 Gbit/s | 2020 | | Falkenstein | Germany | Core | 14 Eyes | Yes | Not applicable | 40 Gbit/s | 2021 | | Paris | France | Core | 9 Eyes | Yes | Not applicable | 100 Gbit/s | 2020 | | London | United Kingdom | Core | 5 Eyes | Yes | Not applicable | 100 Gbit/s | 2020 | | Madrid | Spain | Core | 14 Eyes | Yes | Not applicable | 40 Gbit/s | 2021 | | Barcelona | Spain | Edge | 14 Eyes | Yes | Not applicable | 20 Gbit/s | 2023 | | Milan | Italy | Core | 14 Eyes | Yes | Not applicable | 40 Gbit/s | 2021 | | Lisbon | Portugal | Core | None | Yes | Not applicable | 40 Gbit/s | 2021 | | Warsaw | Poland | Core | None | Yes | Not applicable | 40 Gbit/s | 2021 | | Prague | Czechia | Core | None | Yes | Not applicable | 40 Gbit/s | 2021 | | Vienna | Austria | Core | None | Yes | Not applicable | 40 Gbit/s | 2022 | | Brussels | Belgium | Edge | 14 Eyes | Yes | Not applicable | 20 Gbit/s | 2023 | | Stockholm | Sweden | Core | 14 Eyes | Yes | Not applicable | 40 Gbit/s | 2021 | | Oslo | Norway | Edge | 9 Eyes | Yes | Not applicable | 20 Gbit/s | 2023 | | Helsinki | Finland | Core | None | Yes | Not applicable | 40 Gbit/s | 2021 | | Copenhagen | Denmark | Edge | 9 Eyes | Yes | Not applicable | 20 Gbit/s | 2023 | | Dublin | Ireland | Core | None | Yes | Not applicable | 40 Gbit/s | 2022 | | Tallinn | Estonia | Core | None | Yes | Not applicable | 20 Gbit/s | 2021 | | Riga | Latvia | Core | None | Yes | Not applicable | 20 Gbit/s | 2021 | | Vilnius | Lithuania | Edge | None | Yes | Not applicable | 20 Gbit/s | 2022 | | Luxembourg | Luxembourg | Privacy-first | None | Yes | Not applicable | 20 Gbit/s | 2022 | | Athens | Greece | Edge | None | Yes | Not applicable | 20 Gbit/s | 2023 | | Budapest | Hungary | Edge | None | Yes | Not applicable | 20 Gbit/s | 2022 | | Bratislava | Slovakia | Edge | None | Yes | Not applicable | 10 Gbit/s | 2023 | | Ljubljana | Slovenia | Edge | None | Yes | Not applicable | 10 Gbit/s | 2023 | | Zagreb | Croatia | Edge | None | Yes | Not applicable | 10 Gbit/s | 2023 | | Istanbul | Türkiye | Offshore | None | No | Not applicable | 40 Gbit/s | 2022 | | New York | United States | Core | 5 Eyes | No | Applies | 100 Gbit/s | 2020 | | Ashburn | United States | Core | 5 Eyes | No | Applies | 100 Gbit/s | 2020 | | Miami | United States | Core | 5 Eyes | No | Applies | 100 Gbit/s | 2020 | | Dallas | United States | Core | 5 Eyes | No | Applies | 100 Gbit/s | 2021 | | Chicago | United States | Core | 5 Eyes | No | Applies | 40 Gbit/s | 2021 | | Los Angeles | United States | Core | 5 Eyes | No | Applies | 100 Gbit/s | 2020 | | Seattle | United States | Edge | 5 Eyes | No | Applies | 40 Gbit/s | 2022 | | Phoenix | United States | Edge | 5 Eyes | No | Applies | 40 Gbit/s | 2023 | | Atlanta | United States | Edge | 5 Eyes | No | Applies | 40 Gbit/s | 2022 | | Toronto | Canada | Core | 5 Eyes | No | Not applicable | 40 Gbit/s | 2021 | | Montreal | Canada | Edge | 5 Eyes | No | Not applicable | 40 Gbit/s | 2022 | | Vancouver | Canada | Edge | 5 Eyes | No | Not applicable | 20 Gbit/s | 2023 | | Mexico City | Mexico | Core | None | No | Not applicable | 40 Gbit/s | 2022 | | Querétaro | Mexico | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | São Paulo | Brazil | Core | None | No | Not applicable | 100 Gbit/s | 2021 | | Rio de Janeiro | Brazil | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Buenos Aires | Argentina | Core | None | No | Not applicable | 40 Gbit/s | 2022 | | Santiago | Chile | Core | None | No | Not applicable | 40 Gbit/s | 2022 | | Bogotá | Colombia | Core | None | No | Not applicable | 20 Gbit/s | 2022 | | Lima | Peru | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Quito | Ecuador | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Montevideo | Uruguay | Privacy-first | None | No | Not applicable | 20 Gbit/s | 2023 | | Asunción | Paraguay | Offshore | None | No | Not applicable | 10 Gbit/s | 2024 | | La Paz | Bolivia | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Tokyo | Japan | Core | None | No | Not applicable | 100 Gbit/s | 2020 | | Osaka | Japan | Edge | None | No | Not applicable | 40 Gbit/s | 2023 | | Seoul | South Korea | Core | None | No | Not applicable | 40 Gbit/s | 2022 | | Taipei | Taiwan | Core | None | No | Not applicable | 40 Gbit/s | 2022 | | Mumbai | India | Core | None | No | Not applicable | 40 Gbit/s | 2021 | | Bengaluru | India | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Delhi | India | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Bangkok | Thailand | Core | None | No | Not applicable | 20 Gbit/s | 2022 | | Jakarta | Indonesia | Core | None | No | Not applicable | 20 Gbit/s | 2022 | | Manila | Philippines | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Ho Chi Minh City | Vietnam | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Hanoi | Vietnam | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Colombo | Sri Lanka | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Dhaka | Bangladesh | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Karachi | Pakistan | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Kathmandu | Nepal | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Ulaanbaatar | Mongolia | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Tashkent | Uzbekistan | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Phnom Penh | Cambodia | Offshore | None | No | Not applicable | 10 Gbit/s | 2024 | | Dubai | United Arab Emirates | Core | None | No | Not applicable | 40 Gbit/s | 2021 | | Tel Aviv | Israel | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Riyadh | Saudi Arabia | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Doha | Qatar | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Manama | Bahrain | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Muscat | Oman | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Kuwait City | Kuwait | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Amman | Jordan | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Johannesburg | South Africa | Core | None | No | Not applicable | 40 Gbit/s | 2021 | | Cape Town | South Africa | Edge | None | No | Not applicable | 20 Gbit/s | 2022 | | Lagos | Nigeria | Core | None | No | Not applicable | 20 Gbit/s | 2022 | | Nairobi | Kenya | Core | None | No | Not applicable | 20 Gbit/s | 2022 | | Cairo | Egypt | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Casablanca | Morocco | Edge | None | No | Not applicable | 20 Gbit/s | 2023 | | Tunis | Tunisia | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Algiers | Algeria | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Accra | Ghana | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Dar es Salaam | Tanzania | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Kampala | Uganda | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Lusaka | Zambia | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Harare | Zimbabwe | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Luanda | Angola | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Maputo | Mozambique | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Dakar | Senegal | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Abidjan | Côte d'Ivoire | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Antananarivo | Madagascar | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Gaborone | Botswana | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Windhoek | Namibia | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Kigali | Rwanda | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Addis Ababa | Ethiopia | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Sydney | Australia | Core | 5 Eyes | No | Not applicable | 40 Gbit/s | 2021 | | Melbourne | Australia | Edge | 5 Eyes | No | Not applicable | 20 Gbit/s | 2023 | | Perth | Australia | Edge | 5 Eyes | No | Not applicable | 10 Gbit/s | 2024 | | Brisbane | Australia | Edge | 5 Eyes | No | Not applicable | 10 Gbit/s | 2024 | | Auckland | New Zealand | Core | 5 Eyes | No | Not applicable | 20 Gbit/s | 2022 | | Suva | Fiji | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Hagåtña | Guam | Edge | 5 Eyes | No | Applies | 10 Gbit/s | 2024 | | San Juan | Puerto Rico | Edge | 5 Eyes | No | Applies | 20 Gbit/s | 2023 | | Kingston | Jamaica | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Port of Spain | Trinidad and Tobago | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Santo Domingo | Dominican Republic | Edge | None | No | Not applicable | 10 Gbit/s | 2024 | | Bridgetown | Barbados | Offshore | None | No | Not applicable | 10 Gbit/s | 2024 | Location notes: - Panama City, Panama: Our founding region. Panama is outside every intelligence-sharing alliance, has no EU-style data-retention mandate, and hosts the submarine landings that make it the shortest hop between both Americas. - Zurich, Switzerland: Swiss federal law treats hosted data as correspondence: disclosure needs a court order under Swiss procedure, not a foreign administrative request. Not in the EU, not in the Eyes alliances. - Reykjavík, Iceland: Iceland runs on ~100% renewable geothermal and hydro power, has strong constitutional speech protection under the IMMI framework, and free cooling year-round. - Chișinău, Moldova: Non-EU, non-alliance, and the classic European choice when you want low latency to the EU without EU-level data-retention exposure. - Sofia, Bulgaria: EU member with famously cheap transit and no Eyes-alliance membership. The sweet spot when you need EU peering but not a 14-Eyes jurisdiction. - Bucharest, Romania: Romania struck down its data-retention law twice on constitutional grounds. Dense EU peering, excellent price per gigabit. - Victoria, Seychelles: Our incorporation jurisdiction. IBC secrecy statutes, no public beneficial-ownership register, and no mutual legal assistance treaty with most requesting states. - Belize City, Belize: Long-standing IBC jurisdiction in the Caribbean basin with no data-retention statute and English common law. - Willemstad, Curaçao: Autonomous Dutch constituent country with its own legislature — Netherlands data law does not extend here. Popular for iGaming and media platforms. - Nicosia, Cyprus: EU jurisdiction outside the Eyes alliances, at the crossroads of European, Middle Eastern and North African routes. - Tbilisi, Georgia: Non-EU, non-alliance, with a liberal telecoms regime and cheap hydroelectric power. A favourite for crypto infrastructure. - Kuala Lumpur, Malaysia: Outside every Western alliance framework, with direct submarine capacity to Singapore, Hong Kong and the Middle East. - Hong Kong, Hong Kong SAR: The densest peering point in Asia. HKIX gives sub-40 ms reach to most of East and Southeast Asia. - Singapore, Singapore: The Southeast Asian hub: 15+ submarine cables land here, giving predictable latency to India, Australia and Japan alike. - San José, Costa Rica: Politically stable, constitutionally protective of privacy of communications, and outside the alliances. - Port Louis, Mauritius: The offshore financial gateway between Africa and India, with an IBC regime and no alliance membership. - Nassau, Bahamas: No income tax, no data-retention statute, and a 45 ms hop to Miami for US-facing latency without US jurisdiction. - Belgrade, Serbia: Non-EU Balkan hub with independent telecoms policy and strong onward routes into Central Europe and Turkey. - Kyiv, Ukraine: Non-EU with a deep engineering talent pool and hardened, geographically diverse fibre after years of investment. - Almaty, Kazakhstan: Central Asian crossroads with cheap power and no Western alliance membership. - Yerevan, Armenia: Small, independent jurisdiction that has become a hub for relocated technology teams and crypto infrastructure. - Tirana, Albania: Non-EU Adriatic location with short hops to Italy and Greece. - Skopje, North Macedonia: Non-EU Balkan option with inexpensive transit via Greece and Bulgaria. - Podgorica, Montenegro: Small non-EU jurisdiction, euro-denominated, with direct Adriatic fibre. - Sarajevo, Bosnia and Herzegovina: Non-EU Balkan capacity for teams that want European latency outside the EU legal perimeter. - Amsterdam, Netherlands: AMS-IX is the largest neutral exchange in Europe. Our highest-capacity European edge and the default for EU-facing workloads. - Frankfurt, Germany: DE-CIX Frankfurt carries more traffic than any other exchange on earth. The lowest-latency point to almost anywhere in Europe. - Falkenstein, Germany: Low-cost German capacity with excellent price per core — our value tier for European compute. - Paris, France: France-IX peering and the shortest route to Western Europe, Iberia and francophone Africa. - London, United Kingdom: LINX peering and the transatlantic cable head. Fastest European location for US East traffic. - Madrid, Spain: The Iberian gateway and the landing point for most Latin America cables — our best European hop to Brazil and Argentina. - Barcelona, Spain: Mediterranean edge with direct capacity to Marseille and North Africa. - Milan, Italy: MIX Milan peering, the primary Italian exchange, with strong onward routes to the Balkans and North Africa. - Lisbon, Portugal: Portugal is not in the Eyes alliances and lands the EllaLink cable — the direct fibre path to Brazil, at roughly 60 ms. - Warsaw, Poland: Central-European hub with fast routes into the Baltics and Ukraine. - Prague, Czechia: NIX.CZ peering, low power costs, and a historically permissive hosting regime. - Vienna, Austria: VIX peering and the gateway between Western Europe and the Balkans. - Brussels, Belgium: BNIX peering, useful when your users sit on Belgian and Luxembourgish networks. - Stockholm, Sweden: Netnod peering, cold-climate efficiency and the Nordic gateway. - Oslo, Norway: Hydroelectric power and some of the lowest carbon intensity per compute hour in our fleet. - Helsinki, Finland: Free cooling, cheap nuclear-backed power, and a short hop to the Baltics. - Copenhagen, Denmark: Danish capacity for Nordic-facing services. - Dublin, Ireland: Non-alliance EU member and the western edge of European fibre — the shortest EU hop to North America. - Tallinn, Estonia: Estonia built its state on digital infrastructure; the regulatory environment for hosting is unusually clear. - Riga, Latvia: Long-standing home of privacy-oriented hosting in the EU, with cheap transit. - Vilnius, Lithuania: Baltic capacity with strong routes to Poland and the Nordics. - Luxembourg, Luxembourg: Luxembourg statutorily protects hosted data much like it protects banking records — a rare posture inside the EU. - Athens, Greece: Eastern Mediterranean edge with routes to the Middle East and Egypt. - Budapest, Hungary: Central-European capacity with competitive transit pricing. - Bratislava, Slovakia: Small Central-European footprint, 60 km from Vienna. - Ljubljana, Slovenia: Adriatic-facing EU capacity between Italy, Austria and the Balkans. - Zagreb, Croatia: Croatian capacity with good onward routes to Serbia and Bosnia. - Istanbul, Türkiye: Non-EU, non-alliance, and the physical bridge between European and Middle Eastern fibre. - New York, United States: The transatlantic cable head and the lowest-latency US point for European users. - Ashburn, United States: Equinix Ashburn carries a large share of all US traffic. The default US East location. - Miami, United States: Every major Latin American cable lands in Miami. The best US hop to Brazil, Colombia and the Caribbean. - Dallas, United States: Central US with balanced latency to both coasts and cheap, abundant power. - Chicago, United States: Midwest hub and the lowest-latency US point for financial market data feeds. - Los Angeles, United States: The transpacific cable head — the fastest US hop to Japan, Singapore and Australia. - Seattle, United States: Pacific Northwest edge with hydro-backed power and short routes to Vancouver and Tokyo. - Phoenix, United States: Low seismic risk and cheap capacity — a common disaster-recovery pair for Los Angeles. - Atlanta, United States: US Southeast edge, well peered into regional eyeball networks. - Toronto, Canada: TorIX peering and Canadian data residency for services that must stay north of the border. - Montreal, Canada: Hydro-Québec power makes this one of the cheapest and cleanest kilowatt-hours in our fleet. - Vancouver, Canada: Canadian West Coast with short transpacific hops. - Mexico City, Mexico: The largest Spanish-speaking internet market, with direct routes to the US and Central America. - Querétaro, Mexico: Mexico's fastest-growing data-centre cluster, outside the seismic risk of the capital. - São Paulo, Brazil: IX.br São Paulo is the largest exchange in the southern hemisphere. Mandatory if you serve Brazilian users. - Rio de Janeiro, Brazil: Second Brazilian region and the landing point for the EllaLink cable to Portugal. - Buenos Aires, Argentina: The Southern Cone hub, with CABASE peering into Argentine eyeball networks. - Santiago, Chile: The most reliable power grid in South America and the landing point of the Humboldt cable to Asia-Pacific. - Bogotá, Colombia: Andean hub with fast routes to Miami and Panama. - Lima, Peru: Pacific coast of South America, well connected to Chile and Panama. - Quito, Ecuador: Equatorial edge capacity with routes via Panama. - Montevideo, Uruguay: Uruguay has the strongest data-protection regime in Latin America and holds an EU adequacy decision — rare outside Europe. - Asunción, Paraguay: Cheap hydroelectric power from Itaipú and a light-touch regulatory environment. - La Paz, Bolivia: High-altitude Andean edge for regional coverage. - Tokyo, Japan: JPIX and BBIX peering. The lowest-latency point for Japanese and Korean users, and a strong transpacific anchor. - Osaka, Japan: Second Japanese region, the standard disaster-recovery pair for Tokyo. - Seoul, South Korea: The highest per-capita bandwidth market on earth; essential for Korean gaming and streaming workloads. - Taipei, Taiwan: Dense East Asian peering with routes independent of mainland transit. - Mumbai, India: The landing point for most cables reaching India, and the fastest hop to the Gulf. - Bengaluru, India: India's engineering capital; the natural second Indian region. - Delhi, India: Northern India coverage with routes into Nepal and Central Asia. - Bangkok, Thailand: Mainland Southeast Asian hub with short hops to Singapore and Hong Kong. - Jakarta, Indonesia: Southeast Asia's largest population and one of its fastest-growing hosting markets. - Manila, Philippines: Philippine capacity with direct routes to Hong Kong and Guam. - Ho Chi Minh City, Vietnam: Southern Vietnam, on the fast-growing Southeast Asian manufacturing corridor. - Hanoi, Vietnam: Northern Vietnam edge with short hops to southern China. - Colombo, Sri Lanka: Indian Ocean cable crossroads between South Asia and the Gulf. - Dhaka, Bangladesh: One of the largest underserved internet populations in Asia. - Karachi, Pakistan: Pakistani cable landing station with routes to the Gulf. - Kathmandu, Nepal: Himalayan edge capacity routed via India. - Ulaanbaatar, Mongolia: Independent Central Asian jurisdiction with cheap cold-climate cooling. - Tashkent, Uzbekistan: Central Asian edge with rapidly improving international capacity. - Phnom Penh, Cambodia: Light-touch regulatory environment with transit via Vietnam and Thailand. - Dubai, United Arab Emirates: The Gulf hub where European, African and Asian fibre meet. Fastest single location for Middle East and East Africa. - Tel Aviv, Israel: Dense local peering and a large domestic technology market. - Riyadh, Saudi Arabia: Saudi data residency for services subject to local hosting requirements. - Doha, Qatar: Qatari capacity with direct Gulf cable access. - Manama, Bahrain: Small, well-connected Gulf jurisdiction with a liberal telecoms regime. - Muscat, Oman: Omani cable landing with routes towards India and East Africa. - Kuwait City, Kuwait: Northern Gulf coverage. - Amman, Jordan: Levantine edge with routes via Aqaba and Cyprus. - Johannesburg, South Africa: NAPAfrica Johannesburg is the largest exchange on the continent — the default for anything serving sub-Saharan Africa. - Cape Town, South Africa: Second South African region and the landing point for the Equiano and 2Africa cables. - Lagos, Nigeria: West Africa's largest market, with several new cable landings driving costs down fast. - Nairobi, Kenya: East African hub with strong peering at KIXP and routes via the Gulf. - Cairo, Egypt: The Suez corridor carries most Europe–Asia fibre; Cairo sits directly on it. - Casablanca, Morocco: North African gateway with short hops to Iberia and francophone West Africa. - Tunis, Tunisia: Mediterranean North African edge routed via Italy. - Algiers, Algeria: Algerian capacity via Marseille and Valencia. - Accra, Ghana: West African edge with several modern cable landings. - Dar es Salaam, Tanzania: East African coastal landing station. - Kampala, Uganda: Landlocked East African capacity routed via Kenya. - Lusaka, Zambia: Southern African edge routed via Johannesburg. - Harare, Zimbabwe: Regional coverage via South African transit. - Luanda, Angola: South Atlantic cable landing with a direct route to Brazil. - Maputo, Mozambique: Indian Ocean coastal capacity. - Dakar, Senegal: Westernmost point of continental Africa and a major cable landing. - Abidjan, Côte d'Ivoire: Francophone West African hub. - Antananarivo, Madagascar: Indian Ocean island capacity with surprisingly good fibre. - Gaborone, Botswana: Stable Southern African jurisdiction routed via Johannesburg. - Windhoek, Namibia: Namibian edge on the West Africa Cable System. - Kigali, Rwanda: One of the most digitally-forward regulatory environments in Africa. - Addis Ababa, Ethiopia: Large domestic market with new capacity via Djibouti. - Sydney, Australia: The Australian cable head and the default Oceania region. - Melbourne, Australia: Second Australian region for redundancy. - Perth, Australia: Western Australia, the shortest Australian hop to Singapore. - Brisbane, Australia: Queensland edge and a Pacific cable landing. - Auckland, New Zealand: New Zealand data residency with Southern Cross cable capacity. - Suva, Fiji: South Pacific island capacity for regional services. - Hagåtña, Guam: The transpacific cable crossroads between Asia, Australia and the US. - San Juan, Puerto Rico: US-adjacent Caribbean capacity with strong Miami routes. - Kingston, Jamaica: Caribbean edge with several regional cable landings. - Port of Spain, Trinidad and Tobago: Southern Caribbean, closest point to the Venezuelan and Guyanese markets. - Santo Domingo, Dominican Republic: The largest Caribbean economy by GDP, well connected to Miami. - Bridgetown, Barbados: Established offshore financial jurisdiction with an IBC regime. ### Panama City, Panama You can host a server in Panama City without KYC. Panama is outside the Five, Nine, and Fourteen Eyes alliances, and the DMCA does not apply; local copyright law requires a court order. The entry price is $4 per month for a KVM virtual server with full root access. OnionVPS has operated this region since 2020. The facility sits at 8.98, -79.52, near the submarine landings that make it the shortest hop between the Americas. With a 40 Gbit/s uplink and DDoS scrubbing, it is our founding region and remains a strong choice for latency-sensitive traffic between North and South America. People deploy VPN gateways, mail relays, and web proxies here to avoid US and EU legal perimeters. The 47 ms round-trip to Ashburn suits US-facing services, while the 71 ms to São Paulo serves Latin American customers. The offshore status attracts crypto services and privacy-focused applications. Source: https://onionvps.com/locations/panama-city ### Zurich, Switzerland Yes. OnionVPS operates KVM virtual servers in Zurich, Switzerland, and no identity verification is required at any point — an email address you control is the only identifier. Switzerland is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply here, as it is United States statute and does not bind a host situated in Zurich; local copyright law generally requires a court order. Entry price is $4 per month. Zurich sits outside the EU and the Eyes alliances, and Swiss federal law treats hosted data as correspondence — disclosure requires a court order under Swiss procedure, not a foreign administrative request. The facility is on a 100 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Great-circle estimates put Frankfurt at 6 ms and Milan at 5 ms, with nearest regions also at Luxembourg and Falkenstein (both 6 ms and 8 ms). Customers deploy mail relays, onion services, and privacy-focused web applications here because the legal posture favours resisting administrative demands without a court order. The 92 ms estimate to Ashburn makes it viable for North American-facing traffic too. NVMe storage and full KVM virtualisation suit databases and build servers. Custom ISO upload supports niche operating systems like OpenBSD or NixOS. Source: https://onionvps.com/locations/zurich ### Reykjavík, Iceland Yes, OnionVPS offers KYC-free VPS hosting in Reykjavík, Iceland, from $4 per month. Iceland is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, so hosted data enjoys statutory protection without alliance-driven disclosure obligations. The DMCA does not apply here—it is a US statute—and local copyright law generally requires a court order for takedowns. GDPR applies to personal data processed in Iceland. Reykjavík sits at 64.15, -21.94, close to transatlantic cable landing points, giving estimated round-trip times of 34 ms to Frankfurt, 63 ms to Ashburn, 137 ms to São Paulo, and 157 ms to Singapore. OnionVPS has operated here since 2021 with a 40 Gbit/s uplink. The facility runs on roughly 100% renewable geothermal and hydro power and benefits from free cooling year-round, reducing both cost and environmental impact. It also offers DDoS scrubbing and native IPv6 /64. People deploy privacy-sensitive services—such as mail servers, cryptocurrency nodes, and document repositories—that benefit from Iceland's non-alliance legal posture and strong constitutional speech protection. Developers also run latency-sensitive workloads for transatlantic audiences: a 63 ms round trip to Ashburn makes it a viable mid-point for EU-US applications, while 34 ms to Frankfurt keeps EU users fast. Source: https://onionvps.com/locations/reykjavik ### Chișinău, Moldova Yes, you can host a server in Chișinău, Moldova without KYC. Moldova is not a member of any intelligence-sharing alliance, and the DMCA does not apply here, as it is a US statute. Local copyright law applies and generally requires a court order. Entry pricing starts at $4 per month. Chișinău sits outside the EU legal perimeter and every intelligence alliance, with GDPR not applying to personal data processed locally. The facility has a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Estimated RTT to Frankfurt is 23 ms, making it a classic European choice for low-latency access to the EU without EU data-retention exposure. OnionVPS has operated here since 2020. People deploy privacy-focused mail servers, VPN exit nodes, and cryptocurrency nodes that require both low latency to Western Europe and a jurisdiction outside intelligence-sharing frameworks. The 23 ms hop to Frankfurt suits real-time services for EU users, while NVMe storage handles databases and application backends that need fast I/O. Source: https://onionvps.com/locations/chisinau ### Sofia, Bulgaria Yes, you can host a server in Sofia, Bulgaria without KYC. OnionVPS operates a privacy-first jurisdiction there, with no identity verification and an entry price of $4 per month. Bulgaria is not a member of the Five, Nine, or Fourteen Eyes alliances, offering a legal position outside those intelligence-sharing pacts. The DMCA, a US statute, does not apply, though local copyright law requiring a court order does. GDPR applies to personal data. Sofia, operated since 2020, sits in the EU with famously cheap transit and no Eyes-alliance membership. At 42.7, 23.32, great-circle latency estimates run 21 ms to Frankfurt, 109 ms to Ashburn, 125 ms to Singapore. The 40 Gbit/s uplink supports heavy traffic, with DDoS scrubbing and native IPv6 /64 included. Neighbouring OnionVPS regions—Skopje at 4 ms, Bucharest and Belgrade at 6 ms—offer regional redundancy. No US statute binds hosts here; local law needs a court order for takedowns. People deploy privacy-sensitive web services, mail servers, and blockchain nodes that need EU peering without 14-Eyes jurisdiction. Also VPN exit points, archival storage, and custom-ISO workloads like OpenBSD or NixOS, benefiting from low latency to Frankfurt and freedom from DMCA takedowns, relying on legal process instead. Source: https://onionvps.com/locations/sofia ### Bucharest, Romania Yes, you can host a server in Bucharest, Romania without KYC. OnionVPS operates a VPS region there since 2020, with entry pricing at $4 per month. Romania is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA, being a US statute, does not apply. However, local copyright law does, typically requiring a court order for takedowns. Bucharest sits at a network crossroads: estimated round-trip times are 22 ms to Frankfurt, 110 ms to Ashburn, and 123 ms to Singapore. The uplink is 40 Gbit/s, and on-site capabilities include DDoS scrubbing, native IPv6, NVMe storage, and Custom ISO upload. Romania struck down its data-retention law twice on constitutional grounds, and the region's dense EU peering offers excellent price per gigabit. People deploy privacy-focused applications, cryptocurrency nodes, and data-hoarding services here. The jurisdiction's non-membership in intelligence alliances and lack of DMCA make it a fit for anonymity-oriented web services and content that faces takedown requests in other jurisdictions. The low latency to EU neighbors like Sofia (6 ms) suits regional proxies and relay services. Source: https://onionvps.com/locations/bucharest ### Victoria, Seychelles Victoria, the capital of Seychelles, hosts servers outside the EU legal perimeter and every intelligence-sharing alliance, as Seychelles is not a member of the Five, Nine, or Fourteen Eyes. The DMCA does not apply here, being a US statute. OnionVPS offers KYC-free VPS hosting in Victoria from $4 per month. OnionVPS has operated this region since 2021. The site offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. As our incorporation jurisdiction, it provides IBC secrecy statutes and no public beneficial-ownership register. Estimated round-trip times: Frankfurt 104 ms, Singapore 75 ms, São Paulo 151 ms. Nearest regions: Port Louis, Dar es Salaam, Antananarivo, Nairobi. Typical deployments include privacy-focused mail servers, encrypted file storage, and VPN endpoints that benefit from the lack of data retention and the jurisdiction's legal posture. Low latency to East Africa and Singapore makes it suitable for serving regional traffic and applications requiring a neutral hosting location. Source: https://onionvps.com/locations/victoria-sc ### Belize City, Belize Yes, you can host a server in Belize City, Belize, without KYC. OnionVPS operates a facility there since 2022, and no identity verification is ever required—only an email address you control. Belize is outside the Five, Nine, and Fourteen Eyes alliances, and the DMCA does not apply; local copyright law generally requires a court order. Entry price is $4 per month. Belize City is a long-standing IBC jurisdiction in the Caribbean basin with no data-retention statute and English common law. This is an offshore tier outside the EU legal perimeter and every intelligence-sharing alliance, so GDPR does not bind personal data processed here. The facility offers a 10 Gbit/s uplink, DDoS scrubbing, native IPv6, and NVMe storage. Great-circle RTTs: 124 ms to Frankfurt, 37 ms to Ashburn, 239 ms to Singapore, 89 ms to São Paulo. People deploy in Belize City for discrete offshore workloads: mail relays, static mirrors, archival stores, and lightweight APIs that need a neutral location with no data-retention obligations. The 37 ms hop to Ashburn suits North American users who want an extra jurisdictional layer. NVMe storage and full KVM make it workable for small databases and custom kernels. Source: https://onionvps.com/locations/belize-city ### Willemstad, Curaçao Willemstad, Curaçao, hosts servers without KYC, and the legal position is clear: the country is outside every intelligence-sharing alliance, and the DMCA does not apply. Curaçao is an autonomous Dutch constituent country with its own legislature, and Netherlands data law does not extend here. OnionVPS's Willemstad region has operated since 2021, with entry at $4 per month. Curaçao sits outside the EU legal perimeter and every intelligence-sharing alliance, which matters for data sovereignty. GDPR does not apply to personal data processed here, and the DMCA is a US statute that does not bind a host situated in Willemstad. The facility runs a 20 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. Latency to Ashburn is around 44 ms, with Frankfurt at 111 ms. People deploy iGaming platforms, which find Curaçao's regulatory posture a natural fit, and media platforms that need copyright-friendly hosting. The 65 ms round trip to São Paulo suits Latin American content delivery, and the 12 ms hop to San Juan makes the site a useful regional hub for Caribbean-facing services. Source: https://onionvps.com/locations/willemstad ### Nicosia, Cyprus Nicosia, Cyprus, offers VPS hosting without KYC, as OnionVPS requires only an email address. Cyprus is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, providing a privacy-friendly legal posture. The DMCA does not apply, as it is US law; local copyright law generally requires a court order. GDPR applies to personal data. Entry price is $4 per month. The facility sits at 35.17, 33.36 with a 20 Gbit/s uplink, equipped with DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Latency estimates are 37 ms to Frankfurt and 125 ms to Ashburn. Nearest regions: Tel Aviv at 7 ms, Amman at 8 ms, Cairo at 10 ms, Istanbul at 12 ms. Since 2022, OnionVPS has operated this EU jurisdiction outside the Eyes alliances, at the crossroads of European, Middle Eastern, and North African routes. GDPR applies, but the DMCA does not. Customers deploy low-latency frontends for Middle East and European traffic, egress nodes, and sites that need EU data protection without intelligence-alliance exposure. The position suits serving Turkey, the Levant, and North Africa. No KYC simplifies operations. Source: https://onionvps.com/locations/nicosia ### Tbilisi, Georgia Yes, you can host a server in Tbilisi, Georgia, without KYC. OnionVPS operates there since 2021, outside the EU legal perimeter and every intelligence-sharing alliance (Five, Nine, Fourteen Eyes). The DMCA does not apply, as it is US statute; local copyright law generally requires a court order. Entry price is $4 per month. Tbilisi sits in the South Caucasus, outside the EU's GDPR and the Eyes-alliance frameworks, making it a genuinely offshore jurisdiction within Europe's vicinity. The facility runs on a 20 Gbit/s uplink, cheap hydroelectric power, and a liberal telecoms regime, as our editorial notes. It is 4 ms from Yerevan and within 20 ms of Nicosia, Istanbul, and Amman, giving regional resilience without EU entanglements. Common deployments are crypto node infrastructure and payment processors, given the non-alliance posture and absence of DMCA takedowns. Latency of 41 ms to Frankfurt and 102 ms to Singapore suits trading bots and regional mirrors. The KVM virtualisation with native IPv6 and NVMe storage handles continuous blockchain synchronisation. Source: https://onionvps.com/locations/tbilisi ### Kuala Lumpur, Malaysia Yes. OnionVPS offers KYC-free VPS hosting in Kuala Lumpur, Malaysia, with entry at $4 per month. Malaysia is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA does not apply here as it is US law. Local copyright law applies and generally requires a court order. Kuala Lumpur sits outside the EU legal perimeter and every intelligence-sharing alliance. OnionVPS has operated this region since 2021, with a 40 Gbit/s uplink and direct submarine capacity to Singapore, Hong Kong, and the Middle East. On-site capabilities include DDoS scrubbing, Native IPv6 /64, NVMe storage, and custom ISO upload. No identity verification is ever required; signup needs only an email address. Deploy privacy-focused applications, cryptocurrency nodes, or content platforms that require strict legal separation from Western jurisdictions. The 6 ms latency to Singapore suits regional financial or trading infrastructure. Use the custom ISO upload to run OpenBSD, NixOS, or a hand-rolled image for censorship-resistant services. Source: https://onionvps.com/locations/kuala-lumpur ### Hong Kong, Hong Kong SAR Yes. OnionVPS offers KYC-free VPS hosting in Hong Kong SAR from $4 per month. Hong Kong is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA does not apply, as it is US law. Local copyright law requires a court order for takedowns. OnionVPS has operated this region since 2020, connected at 100 Gbit/s to the densest peering point in Asia. HKIX gives sub-40 ms reach to Taipei, Hanoi, Manila, and Ho Chi Minh City. Full root access, true KVM virtualisation, a routed IPv6 /64, and always-on DDoS mitigation are included. No identity verification is ever required; only an email address. Trading bots, exchange arbitrage, and low-latency proxies. Independent news sites and forums that do not want US jurisdiction. Any workload needing a neutral ground between East and West, where the network is excellent and the host will not be pressured into takedowns without a court order. Source: https://onionvps.com/locations/hong-kong ### Singapore, Singapore Singapore is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so hosting there avoids the surveillance obligations of those agreements. The DMCA, a US statute, does not apply to a host in Singapore; local copyright law generally requires a court order for takedowns. OnionVPS offers VPS hosting in Singapore without KYC, from $4 per month. OnionVPS has operated this region since 2020, with a 100 Gbit/s uplink on a site at 1.35, 103.82. More than 15 submarine cables land in Singapore, giving predictable latency to India, Australia and Japan alike. DDoS scrubbing, native IPv6 /64 and custom ISO upload are standard. Estimated round trips: Frankfurt 140 ms, Ashburn 212 ms, São Paulo 218 ms. The nearest OnionVPS regions are Kuala Lumpur at 6 ms, Jakarta at 14 ms, Ho Chi Minh City at 17 ms, and Phnom Penh at 17 ms. People deploy game servers and trading infrastructure that need low latency to Southeast Asia and Japan. Media proxies and VPN exit nodes for regional traffic thrive here, as do Anycast endpoints for DNS or content delivery. The jurisdiction's neutrality suits archiving and personal data not subject to GDPR. Source: https://onionvps.com/locations/singapore ### San José, Costa Rica Yes, you can host a server in San José, Costa Rica without KYC. Costa Rica is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so your data is outside those frameworks. The DMCA does not apply here; local copyright law requires a court order for takedowns. OnionVPS offers plans starting at $4 per month with no identity verification. San José sits outside the EU legal perimeter and every intelligence-sharing alliance, making it a true offshore jurisdiction. Costa Rica's constitution protects privacy of communications, and the region is politically stable. Our facility, operated since 2022, offers 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. With low latency to the Americas—47 ms to Ashburn, 76 ms to São Paulo—it is an ideal hub for the hemisphere. Customers run mail servers, VPN gateways, and anti-censorship proxies here, taking advantage of the jurisdiction's privacy protections. Content distributors use it for low-latency delivery to North and South America, while developers deploy build runners and databases that benefit from the stable, well-connected network. Source: https://onionvps.com/locations/san-jose-cr ### Port Louis, Mauritius Yes, you can host a server in Port Louis, Mauritius, without KYC. The jurisdiction is outside every intelligence-sharing alliance, including the Five, Nine, and Fourteen Eyes, and GDPR does not apply to personal data processed there. The DMCA is US law and does not bind a host situated in Mauritius; local copyright law requires a court order. Entry price is $4 per month. Port Louis sits on a 10 Gbit/s uplink with on-site DDoS scrubbing, native IPv6, and NVMe storage. Great-circle estimates put round-trip times at 126 ms to Frankfurt, 208 ms to Ashburn, 77 ms to Singapore, and 143 ms to São Paulo. The nearest OnionVPS regions are Antananarivo at 16 ms, Victoria at 26 ms, Dar es Salaam at 35 ms, and Maputo at 37 ms. OnionVPS has operated here since 2022. People deploy mail servers, small trading nodes, and data-adjacent services that need a neutral jurisdiction without alliance oversight. The low latency to Singapore and Madagascar makes Port Louis a sensible relay for Indian Ocean traffic. Financial document storage and private communications often land here because of the legal posture. Source: https://onionvps.com/locations/port-louis ### Nassau, Bahamas Yes, you can host a server in Nassau, Bahamas, without KYC. The Bahamas is outside the Five, Nine, and Fourteen Eyes intelligence-sharing alliances, so your traffic is not subject to their surveillance frameworks. The DMCA does not apply, as it is US statute and local copyright law requires a court order. OnionVPS offers VPS in Nassau from $4 per month. OnionVPS has operated in Nassau since 2023, with a 10 Gbit/s uplink and DDoS scrubbing. The jurisdiction sits outside the EU legal perimeter, so GDPR does not apply to personal data. Estimated round-trip times are 23 ms to Ashburn and 105 ms to Frankfurt, with a 6 ms hop to Miami. There is no income tax and no data-retention statute, making it a clean offshore position for US-facing workloads. People deploy mail servers, seedboxes, and privacy-focused proxies in Nassau. The low latency to the US East Coast (23 ms to Ashburn) suits US-facing services, while the absence of DMCA takedowns makes it a haven for content that faces aggressive takedown elsewhere. NVMe storage and native IPv6 /64 support demanding network services. Source: https://onionvps.com/locations/nassau ### Belgrade, Serbia Yes. Belgrade, Serbia, is a genuine offshore option: the country is not in the Five, Nine or Fourteen Eyes, GDPR does not apply, and the DMCA — a US statute — does not bind a host here; local law applies and generally needs a court order. OnionVPS has operated here since 2021 on a 20 Gbit/s uplink. Entry price is $4 per month, no KYC ever. The editorial note calls Belgrade a non-EU Balkan hub with independent telecoms policy and strong routes into Central Europe and Turkey. Outside the EU legal perimeter, it sits beyond every intelligence-sharing alliance. At 44.79, 20.45, with 20 Gbit/s uplink, DDoS scrubbing, IPv6 /64, NVMe and custom ISO upload. Estimated great-circle round trips: Frankfurt 16 ms, Ashburn 105 ms, Singapore 129 ms, São Paulo 140 ms. Nearest regions: Sarajevo, Sofia, Skopje, Podgorica, each ~5–6 ms. People deploy mail servers that must stay outside US takedown reach, privacy-focused web services for Balkan and Central European users, and VM instances running custom kernels or raw sockets — full root, KVM, no identity check. The low latency to Frankfurt suits trading bots and IRC relays; the independent legal posture suits document repositories and whistleblower infrastructure. Source: https://onionvps.com/locations/belgrade ### Kyiv, Ukraine Yes, you can host a server in Kyiv, Ukraine, without KYC, and the legal position is clear. Ukraine is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so your data is outside those sharing frameworks. The DMCA does not apply here, as it is US law; local copyright law generally requires a court order. OnionVPS offers VPS plans from $4 per month. Kyiv sits outside the EU legal perimeter, so GDPR does not apply to personal data processed here. The city has a deep engineering talent pool and hardened, geographically diverse fibre after years of investment, as our editorial note puts it. Uplink is 20 Gbit/s with DDoS scrubbing, native IPv6 /64, and NVMe storage. Round-trip times estimate Frankfurt at 23 ms and Ashburn at 108 ms, with nearby regions in Chișinău, Vilnius, and Warsaw within 11 ms. People deploy censorship-resistant services, web hosting for clients who value legal autonomy, and email servers where self-sovereignty matters. The latency to Western Europe suits real-time applications like VoIP or gaming proxies. Developers also run CI runners and data processing that must avoid EU data protection rules, leveraging the no-KYC onboarding and full root access. Source: https://onionvps.com/locations/kyiv ### Almaty, Kazakhstan Yes, you can host a server in Almaty, Kazakhstan, with OnionVPS without KYC; an email address is the only identifier. Kazakhstan is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so your data sits outside those perimeters. The DMCA does not apply here; local copyright law generally requires a court order. Entry price is $4 per month. Almaty sits at the Central Asian crossroads with cheap power and no Western alliance membership. Since 2022, OnionVPS has operated here with a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Round-trip times: 71 ms to Frankfurt, 74 ms to Singapore, and 11 ms to Tashkent. This positions Almaty as a strategic relay between Europe and Asia, with a legal posture that respects your privacy. People deploy content distribution caches, VPN exit nodes, and bulk data processing. The low latency to Tashkent, Delhi, and Kathmandu suits regional services. Privacy-focused workloads thrive without GDPR or DMCA obligations. The always-on DDoS mitigation protects against the region's threats. Source: https://onionvps.com/locations/almaty ### Yerevan, Armenia Yerevan, Armenia, offers offshore VPS hosting outside the EU legal perimeter and any intelligence-sharing alliance; the country is not a member of the Five, Nine, or Fourteen Eyes. The DMCA does not apply, as it is US law; local copyright law requires a court order. Hosting starts at $4 per month. Armenia's small, independent jurisdiction has become a hub for relocated tech teams and crypto infrastructure. OnionVPS has operated here since 2023, with a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Latency is competitive: about 42 ms to Frankfurt and 129 ms to Ashburn, with Tbilisi just 4 ms away. People deploy relay nodes, light wallets, and privacy-focused infrastructure, leveraging the jurisdiction's non-Eyes status and absence of DMCA takedowns. The region also suits low-latency applications serving the Caucasus and Middle East, with rapid links to nearby regions. Source: https://onionvps.com/locations/yerevan ### Tirana, Albania Yes, you can host a server in Tirana without KYC. OnionVPS's Albania location sits outside the EU legal perimeter and every intelligence-sharing alliance, so Albania is not a member of the Five, Nine, or Fourteen Eyes. The DMCA does not apply; local copyright law requires a court order for takedowns. Plans start at $4 per month, with anonymous signup using only an email address. Tirana is a non-EU Adriatic location with short hops to Italy and Greece, and it is close to our Skopje and Podgorica regions. The facility offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6, and NVMe storage. Since 2023, we've run this region without GDPR applying to personal data, making it a clear choice for operators who want their legal posture defined by a local court order, not foreign notice regimes. People deploy VPN exit nodes, mail relays, and crypto-adjacent services that face removal pressure elsewhere. The sub-10 ms links to nearby Balkans regions and 20 ms to Frankfurt make it suitable for EU-facing latency-sensitive workloads, while the legal isolation attracts high-risk, high-privacy deployments. Source: https://onionvps.com/locations/tirana ### Skopje, North Macedonia Yes. OnionVPS offers KVM VPS hosting in Skopje, North Macedonia from $4 per month, with no identity verification required. North Macedonia is outside the EU and not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply because it is US law; local copyright law generally requires a court order. This makes Skopje a straightforward offshore jurisdiction. Skopje sits outside the EU legal perimeter, so GDPR does not bind personal data processed here. The facility connects via 10 Gbit/s uplinks with inexpensive transit through Greece and Bulgaria. With only 4 ms to Sofia and Tirana, and 108 ms to Ashburn, it bridges Europe and North America well. OnionVPS has run this region since 2023, offering NVMe storage, native IPv6 /64, and DDoS scrubbing. People run mail servers needing clean IPs and private DNS, since reverse DNS is self-service. They host crypto nodes, mirror repositories, and run anonymisation services that demand a jurisdiction with no intelligence-sharing ties. The 108 ms latency to the US makes it usable for US-facing sites, while the 4 ms hop to Sofia suits regional traffic. KVM isolation suits custom kernels and nested virtualisation for lab work. Source: https://onionvps.com/locations/skopje ### Podgorica, Montenegro Podgorica, Montenegro, offers offshore VPS hosting without KYC. Montenegro is not a member of any intelligence-sharing alliance, so data is outside the Five, Nine, or Fourteen Eyes framework. The DMCA does not apply, as it is US law and local copyright law requires a court order. Entry price is $4 per month. Since 2023, OnionVPS has operated in Podgorica, a small non-EU jurisdiction with euro-denominated costs and direct Adriatic fibre. The facility offers a 10 Gbit/s uplink, DDoS scrubbing, Native IPv6 /64, and NVMe storage. Estimated round-trip times are 18 ms to Frankfurt, 106 ms to Ashburn. Closest regions are Tirana and Sarajevo at 4 ms, making it a strategic hub for the Balkans. Customers deploy privacy-sensitive infrastructure here, such as VPN gateways, Tor relays, and blockchain nodes, because the jurisdiction sits outside intelligence alliances and the DMCA. The low latency to Western Europe also suits latency-critical services like trading bots or CDN origin servers that need fast access to EU markets without GDPR obligations. Source: https://onionvps.com/locations/podgorica ### Sarajevo, Bosnia and Herzegovina Yes. OnionVPS offers VPS hosting in Sarajevo, Bosnia and Herzegovina from $4 per month, with no KYC—an email address is the only identifier. Bosnia and Herzegovina is not a member of the Five, Nine, or Fourteen Eyes alliances, placing it outside those intelligence-sharing frameworks. The DMCA does not apply, as it is U.S. law; local copyright law requires a court order. This is a non-EU jurisdiction with GDPR not applying to personal data. Sarajevo sits outside the EU legal perimeter and all intelligence-sharing alliances, a position the editorial note describes as 'Non-EU Balkan capacity for teams that want European latency outside the EU legal perimeter.' The facility, operational since 2024, connects via a 10 Gbit/s uplink with estimated round-trip times of 16 ms to Frankfurt and 104 ms to Ashburn. On-site DDoS scrubbing, native IPv6 /64, and NVMe storage support the workload. Operators run privacy-focused web services, mail servers requiring clean IPs, and crypto nodes that benefit from the non-EU legal posture. The low latency to central Europe, under 20 ms, supports database replicas for EU-facing applications, while the jurisdiction allows hosting content that stricter legal environments reject. Developers use full KVM for custom kernels and nested virtualisation. Source: https://onionvps.com/locations/sarajevo ### Amsterdam, Netherlands Yes, you can host a server in Amsterdam without KYC. OnionVPS operates a core region in Amsterdam, Netherlands, where no identity verification is ever required. The Netherlands is a Nine Eyes member, so data is shared with that intelligence alliance. The DMCA does not apply here as it is US law; local copyright law governs and generally requires a court order. Plans start at $4 per month. Amsterdam hosts our highest-capacity European edge, connecting to AMS-IX, the continent's largest neutral exchange. The facility provides 100 Gbit/s uplink, DDoS scrubbing, native IPv6, NVMe storage, and GPU instances. We have operated this region since 2020. It is a core jurisdiction with low latency to other European regions: Brussels at 4 ms, Luxembourg at 6 ms, Frankfurt at 7 ms, London at 7 ms. For EU-facing workloads, this is the default. Customers deploy game servers, VPN exit nodes, and privacy-focused applications. The Amsterdam exchange's neutral peering ensures low latency to European players and services. GDPR compliance is essential for EU customer data, and the Nine Eyes alliance may concern some, but for many, the legal clarity and high-capacity network justify it. Source: https://onionvps.com/locations/amsterdam ### Frankfurt, Germany Frankfurt, Germany, hosts VPS servers without identity verification, and the legal position is clear: Germany is a Fourteen Eyes member, so hosted data is within an intelligence-alliance jurisdiction. The DMCA does not apply — it is US statute and does not bind this host; local copyright law requires a court order. Entry price is $4 per month. Frankfurt sits on DE-CIX, which carries more traffic than any other exchange on earth, making it the lowest-latency point to almost anywhere in Europe. OnionVPS has operated here since 2020 on a 100 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, NVMe storage, and GPU instances. Round-trip estimates: Ashburn 90 ms, São Paulo 135 ms, Singapore 140 ms. Nearest regions: Luxembourg 5 ms, Zurich 6 ms. People deploy latency-sensitive services here: trading and market-data feeds, game servers, and VoIP infrastructure that must reach users across Europe quickly. The DE-CIX peering keeps intra-European RTTs low, and NVMe storage suits database-heavy workloads like caching layers or analytics. Windows licensing and GPU instances cover render farms and game streaming. Source: https://onionvps.com/locations/frankfurt ### Falkenstein, Germany You can host a server in Falkenstein, Germany, with OnionVPS without KYC; an email address is all you need. The facility sits in a Fourteen Eyes member country, and the US DMCA does not bind a host here—local copyright law applies and generally requires a court order. Entry price is $4 per month. OnionVPS opened this region in 2021 with a 40 Gbit/s uplink, and the proximity to Frankfurt keeps estimated round-trip times around 6 ms. The site offers DDoS scrubbing, native IPv6 /64, NVMe storage, and Custom ISO upload. It is marketed as low-cost German capacity with excellent price per core—a value tier for European compute. Your data is subject to GDPR. Clients deploy compute-hungry workloads like render farms and CI runners here, drawn by the low price per core and German infrastructure. The low latency to Prague and Vienna suits distributed database clusters and gaming services. The no-DMCA position makes it plausible for archiving or hosting content that US-hosted providers are quick to take down. Source: https://onionvps.com/locations/falkenstein ### Paris, France Yes, you can host a server in Paris without KYC. France is a Nine Eyes member, so data is subject to that alliance's intelligence-sharing arrangements. The DMCA does not apply; local copyright law requires a court order for takedowns. GDPR applies to personal data. Entry price is $4 per month. OnionVPS has run this region since 2020 on a 100 Gbit/s uplink with France-IX peering, giving the shortest route to Western Europe, Iberia, and francophone Africa. The facility offers DDoS scrubbing, native IPv6, NVMe storage, and custom ISO upload. Estimated round trips: 8 ms to Frankfurt, 86 ms to Ashburn. People deploy latency-sensitive web services, game servers, and real-time applications needing quick access to Western European users. The location also suits proxy and relay traffic destined for Africa and the Iberian peninsula. The low RTT to Frankfurt and Brussels makes it viable for multi-region failover setups. Source: https://onionvps.com/locations/paris ### London, United Kingdom London, United Kingdom, is a Five Eyes member, so law enforcement from allied states may seek data here; the DMCA does not apply, and local copyright law requires a court order. GDPR applies to personal data. Hosting without KYC is legal; OnionVPS requires only an email address. Entry price is $4 per month. OnionVPS has operated London since 2020, with 100 Gbit/s uplink, LINX peering, and transatlantic cable heads, making it the fastest European location for US East traffic. The facility offers DDoS scrubbing, native IPv6 /64, NVMe storage, custom ISO upload, and Windows licensing. Nearest regions are Brussels, Amsterdam, Paris, and Dublin, all within 8 ms. Common deployments include low-latency trading bots and proxies serving Frankfurt at 11 ms, plus content caches for US East customers leveraging the 82 ms hop. The NVMe storage and full KVM suit database replicas. Linux-based VPN endpoints are popular, given the DMCA's non-applicability. Source: https://onionvps.com/locations/london ### Madrid, Spain Yes. OnionVPS offers VPS hosting in Madrid, Spain, without KYC—only an email address is needed. Spain is a Fourteen Eyes member, so intelligence-sharing considerations apply. The DMCA does not apply; local copyright law requires a court order for takedowns. Entry price is $4 per month. Madrid is our Core region on major exchanges, with a 40 Gbit/s uplink and low latency to Latin America—a key cable landing point. The facility includes DDoS scrubbing, native IPv6, NVMe storage, and custom ISO uploads. Operated since 2021, it balances European data protection with relaxed copyright enforcement, appealing to privacy-focused users. Customers run low-latency proxies, mail relays, and data-scraping bots targeting Spanish-language content. The region suits serving Latin American audiences from Europe, cutting 115 ms RTT to São Paulo. Developers test GDPR-compliant apps with root access and nested virtualisation, avoiding KYC friction. Source: https://onionvps.com/locations/madrid ### Barcelona, Spain Yes, you can host a server in Barcelona without KYC: OnionVPS requires only an email address you control, and plans start at $4 per month. Spain is a Fourteen Eyes member, so intelligence-sharing obligations apply to hosted data. The DMCA does not apply — it is a US statute and does not bind a host in Barcelona; local copyright law, which generally requires a court order, applies instead. Barcelona sits on the Mediterranean edge, with direct capacity to Marseille and North Africa. OnionVPS has operated this region since 2023, offering a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Estimated round-trip times are 17 ms to Frankfurt and 90 ms to Ashburn. Nearest OnionVPS regions include Madrid, Algiers, Milan, and Zurich. GDPR applies to personal data processed here. People deploy low-latency web services and APIs that need fast response times for southern European and North African users. The region suits content delivery nodes, gaming servers, and real-time applications where 17 ms to Frankfurt and 9 ms to Algiers matter. The Fourteen Eyes position makes it a deliberate choice for workloads that accept that legal posture. Source: https://onionvps.com/locations/barcelona ### Milan, Italy Yes, you can host a server in Milan without KYC. OnionVPS offers anonymous VPS hosting in Italy; signup requires only an email address. Italy is a Fourteen Eyes member, meaning intelligence-sharing alliances apply. The DMCA does not apply here because it is a US statute; local copyright law governs, generally requiring a court order. Entry price is $4 per month. Milan sits on MIX, the primary Italian internet exchange, with strong onward routes to the Balkans and North Africa. The region has been operational since 2021, offering a 40 Gbit/s uplink and DDoS scrubbing. Milan's location provides low latency to Zurich (5 ms), Ljubljana (8 ms), and Frankfurt (9 ms). GDPR applies to personal data processed here, aligning with strict European data protection standards. Typical deployments include low-latency trading and financial applications that benefit from proximity to European exchanges, privacy-focused services leveraging strong Italian privacy laws, and content distribution for Italian-speaking audiences, benefiting from MIX peering and low latency to Southern Europe and North Africa. Source: https://onionvps.com/locations/milan ### Lisbon, Portugal Yes, you can host a server in Lisbon, Portugal, without KYC. OnionVPS requires only an email address; no identification is ever requested. Portugal is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA does not apply here—it is US law, and local copyright law generally requires a court order. GDPR applies to personal data processed in Lisbon. Entry price is $4 per month. Lisbon sits on the Iberian coast, a hub on the EllaLink cable that cuts latency to Brazil to roughly 60 ms. The facility offers 40 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Portugal's legal posture—outside intelligence-sharing alliances and not bound by the DMCA—makes it a rare privacy-friendly core region. OnionVPS has operated here since 2021. People deploy VPN endpoints, privacy-focused mail servers, and document storage in Lisbon, taking advantage of the non-Eyes jurisdiction and the lack of DMCA takedowns. The EllaLink connection makes it a solid choice for serving Brazil and South America, with São Paulo at 109 ms. DDoS mitigation protects always-on services. Source: https://onionvps.com/locations/lisbon ### Warsaw, Poland Yes. OnionVPS offers VPS hosting in Warsaw, Poland, with no identity verification required at any point. Poland is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply, as it is a US statute; local copyright law requires a court order. Entry price is $4 per month. Warsaw is a core European hub with a 40 Gbit/s uplink and fast routes into the Baltics and Ukraine, as our editorial note states. The facility sits on major internet exchanges, with estimated round-trip times of 14 ms to Frankfurt and 99 ms to Ashburn. OnionVPS has operated this region since 2021. GDPR applies to personal data here, which matters for EU-facing workloads. The legal posture is clear: no Eyes-alliance membership, no DMCA, and a court-order requirement for takedowns. Customers deploy mail servers, VPN exit nodes, and privacy-focused web services in Warsaw. The 7 ms latency to Vilnius and 9 ms to Prague or Budapest makes it a natural hub for Baltic and Central-European applications. No-KYC signup suits operators who must keep their identity separate from their infrastructure. Source: https://onionvps.com/locations/warsaw ### Prague, Czechia Yes. OnionVPS offers KYC-free VPS hosting in Prague, Czechia, a Core region on major internet exchanges. Czechia is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply—it is a United States statute, so hosts here are not bound by it; local law generally requires a court order. Entry price is $4 per month. This facility sits on the NIX.CZ internet exchange, with a 40 Gbit/s uplink and estimated round-trip times of 8 ms to Frankfurt and 95 ms to Ashburn. Low power costs and a historically permissive hosting regime make it economically and legally attractive. OnionVPS has run this region since 2021, offering DDoS scrubbing, native IPv6, and NVMe storage on site. People deploy public-facing web services, game servers, and exit nodes for privacy tools. The combination of Czechia's non-Eyes status and fast regional latency makes it a reliable location for latency-sensitive apps serving Central Europe, or for workloads where legal distance from US and allied jurisdiction is a feature. Source: https://onionvps.com/locations/prague ### Vienna, Austria Yes, you can host a server in Vienna without KYC. OnionVPS, operating since 2022, requires no identity verification—an email address suffices. Austria is not a member of the Five, Nine, or Fourteen Eyes alliances, and while GDPR applies to personal data, the DMCA does not; takedown notices require a court order. Entry price is $4 per month. Vienna sits on VIX, the Vienna Internet Exchange, making it the gateway between Western Europe and the Balkans. Its location provides low-latency links: 10 ms to Frankfurt, 98 ms to Ashburn, 133 ms to Singapore. The facility offers 40 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage, with nearby regions in Bratislava (3 ms) and Prague (5 ms). People deploy privacy-focused services that must avoid US jurisdiction—mail servers, onion relays, or development environments. Vienna's central European location also suits applications serving both Western and Eastern Europe, with low latency to nearby hubs. The no-KYC signup appeals to those who prefer not to tie infrastructure to personal identity. Source: https://onionvps.com/locations/vienna ### Brussels, Belgium Yes, you can host a server in Brussels without KYC; OnionVPS requires only an email address you control. Belgium is a Fourteen Eyes member, so intelligence sharing applies, but the DMCA does not — it is a US statute, and local copyright law generally requires a court order. Entry pricing across OnionVPS's fleet starts at $4 per month. Brussels sits on BNIX peering, which matters when your users are on Belgian or Luxembourgish networks. OnionVPS has operated this region since 2023 with a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Estimated round-trip times put Frankfurt at 6 ms, Paris at 6 ms, Ashburn at 86 ms — useful for transatlantic reach without sacrificing continental latency. People deploy latency-sensitive web services and game servers here, serving audiences across Belgium, Luxembourg, and western Germany. The 6 ms hop to Frankfurt makes it a sensible secondary node for EU-wide API clusters, and the Fourteen Eyes posture matters less for low-regulatory-traffic workloads that favour speed over legal shielding. Source: https://onionvps.com/locations/brussels ### Stockholm, Sweden You can host a server in Stockholm, Sweden, without KYC, as OnionVPS operates a region there since 2021 with $4-per-month entry pricing. Sweden is a Fourteen Eyes intelligence-alliance member, so data is accessible to allied agencies. The DMCA does not apply here because it is US statute; local copyright law requires a court order for takedowns. GDPR applies to personal data processed in this region. Stockholm sits on Netnod peering, giving direct access to Nordic and Baltic exchanges. The facility's 40 Gbit/s uplink and cold-climate efficiency lower operational costs. With Havnode's proximity to Helsinki, Tallinn, Oslo, and Riga—each 7–8 ms away—this region acts as a low-latency hub. DDoS scrubbing and IPv6 /64 are standard. Legal posture: local copyright law, not US DMCA, governs content takedowns. Common deployments include privacy-focused services, mail servers requiring clean IPs, and latency-sensitive applications for Scandinavian users. The jurisdiction's court-order requirement for takedowns suits censorship-resistant sites. The 7 ms links to Nordic peers make Stockholm ideal for real-time apps serving the Baltic Sea area. NVMe storage supports IOPS-heavy databases. Source: https://onionvps.com/locations/stockholm ### Oslo, Norway Oslo, Norway is a Nine Eyes intelligence-sharing alliance member, meaning agencies cooperate on signals intelligence, but GDPR applies to personal data and the DMCA does not—local copyright law requires a court order. OnionVPS offers no-KYC VPS hosting here from $4 per month, with full root access and no identity verification, ideal for privacy-conscious deployments. Norway runs on hydroelectric power with one of the lowest carbon intensities per compute hour in OnionVPS's fleet. The Oslo region, operated since 2023, sits on a 20 Gbit/s uplink with DDoS scrubbing, Native IPv6 /64, and NVMe storage. Great-circle latency estimates: 17 ms to Frankfurt, 86 ms to Ashburn. The legal posture—GDPR applies, DMCA does not—makes Oslo a distinct choice within the Nine Eyes bloc. People deploy mail servers here because self-service reverse DNS is included and DMCA takedowns require a court order. Others run privacy-focused applications that benefit from GDPR protection, or low-latency workloads serving Scandinavia, with only 8 ms to Stockholm. The facility's low carbon footprint attracts compute-intensive batch jobs or static content delivery. Source: https://onionvps.com/locations/oslo ### Helsinki, Finland Yes, you can host a server in Helsinki without KYC. OnionVPS has operated here since 2021, and no identity verification is ever required. Finland is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply because it is US law; local copyright law requires a court order. Entry price is $4 per month. Helsinki sits on a major internet exchange, with a 40 Gbit/s uplink and an estimated 22 ms round trip to Frankfurt. The facility benefits from free cooling and cheap nuclear-backed power, as our editorial note observed. GDPR applies to personal data here, which matters for privacy-conscious deployments. The jurisdiction's legal posture offers strong protection for operators who prioritise anonymity. People deploy wireguard and openvpn endpoints to anchor low-latency tunnels across Europe, mail servers that benefit from clean IPs and the 3 ms hop to Tallinn, and Tor relays or exit nodes where the non-Eyes position matters. The /64 IPv6 subnet makes large-scale testing easy. Source: https://onionvps.com/locations/helsinki ### Copenhagen, Denmark Yes, you can host a server in Copenhagen, Denmark, without KYC. OnionVPS offers a $4 per month entry price. Denmark is a Nine Eyes member, so the intelligence-alliance position is shared. The DMCA does not apply here, as it is US law; local copyright law requires a court order for takedowns. Copenhagen is an Edge-tier region, chosen for smaller footprints and latency coverage. OnionVPS has operated here since 2023. The facility offers a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Estimated round-trip times are 11 ms to Frankfurt, 90 ms to Ashburn. GDPR applies to personal data processed here, but the DMCA does not. People deploy latency-sensitive services for the Nordic region, such as real-time APIs, gaming servers, and financial applications. The low latency to Stockholm, Oslo, and Amsterdam makes it ideal for regional traffic, while the legal posture attracts content that benefits from court-ordered takedown procedures rather than US-style notices. Source: https://onionvps.com/locations/copenhagen ### Dublin, Ireland Dublin, Ireland is a Core jurisdiction for OnionVPS, outside the Five, Nine, and Fourteen Eyes intelligence-sharing alliances, so you can host a server here without KYC or identity verification. The DMCA does not apply, as it is US law; Irish copyright law generally requires a court order. Entry price is $4 per month. This region, operated since 2022, sits on the western edge of European fibre, offering the shortest EU hop to North America. With a 40 Gbit/s uplink, estimated RTTs are 17 ms to Frankfurt and 76 ms to Ashburn. The facility provides DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Dublin's non-alliance status and robust connectivity make it a distinct choice for privacy-conscious deployments. People deploy privacy-focused services, mail servers, and exit nodes for VPNs or Tor, leveraging Ireland's non-alliance legal position. The low latency to North America also suits web-facing applications and API endpoints that need a transatlantic balance. Source: https://onionvps.com/locations/dublin ### Tallinn, Estonia Tallinn, Estonia is a no-KYC VPS hosting location where you can rent a server from $4 per month. Estonia is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA does not apply as it is a US statute; local copyright law requires a court order. GDPR applies to personal data processed in Tallinn. OnionVPS's Tallinn region, operating since 2021, sits at a key European internet exchange. It offers a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Estimated latency to Frankfurt is 22 ms, to Ashburn 96 ms. Nearby regions include Helsinki (3 ms), Riga (6 ms), Stockholm (7 ms), and Vilnius (9 ms). The low latency to the Nordics and central Europe makes Tallinn a natural fit for latency-sensitive applications serving Northern Europe: game servers, VoIP, and crypto nodes that need clean, unmetered connectivity. The clear regulatory environment also attracts individuals and small teams running public-facing services without the friction of identity checks. Source: https://onionvps.com/locations/tallinn ### Riga, Latvia Yes, you can host a server in Riga, Latvia, with no KYC. OnionVPS operates in Riga with no identity verification, only an email address. Latvia is not a member of the Five, Nine, or Fourteen Eyes alliances. The DMCA does not apply; it is US law, and local copyright law generally requires a court order. Entry price is $4 per month. Riga is the long-standing home of privacy-oriented hosting in the EU, with cheap transit. OnionVPS has operated here since 2021. The site sits at coordinates 56.95, 24.11, with a 20 Gbit/s uplink and DDoS scrubbing, Native IPv6 /64, NVMe storage, and Custom ISO upload. It's 6 ms from Tallinn and Vilnius, and 7 ms from Helsinki, placing it at the centre of the Baltic network. Common deployments in Riga include privacy-focused mail servers, OpenBSD or NixOS hosts booted from custom ISOs, and low-latency services for the Baltic and Nordic markets. Raw sockets and nested virtualisation suit network tools, and the 98 ms round trip to Ashburn makes it viable for transatlantic relay points. Source: https://onionvps.com/locations/riga ### Vilnius, Lithuania Yes, you can host a server in Vilnius, Lithuania without KYC, using only an email address; OnionVPS has operated here since 2022, with entry at $4 per month. Lithuania is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply—it is US law; local copyright law governs, generally requiring a court order. Vilnius sits in the Baltic region with excellent connectivity: an estimated 19 ms to Frankfurt, 100 ms to Ashburn, and 126 ms to Singapore via a 20 Gbit/s uplink. The facility offers DDoS scrubbing, native IPv6 /64, and NVMe storage. GDPR applies to personal data. For a smaller footprint, this edge location suits latency-sensitive workloads. The site already has an editorial note: 'Baltic capacity with strong routes to Poland and the Nordics.' People deploy privacy-focused services, such as VPN endpoints, email relays, and encrypted messaging nodes, leveraging the non-Eyes jurisdiction. They also host latency-sensitive applications like gaming servers or VoIP for Nordic and Baltic users, given the 6 ms to Riga and 7 ms to Warsaw. The DMCA's absence attracts content-hosting workloads. Source: https://onionvps.com/locations/vilnius ### Luxembourg, Luxembourg Yes, OnionVPS operates VPS hosting in Luxembourg, Luxembourg, without KYC. Luxembourg is not a member of the Five, Nine, or Fourteen Eyes alliances, and the DMCA does not apply here—local copyright law requires a court order. GDPR applies to personal data. Entry price is $4 per month. OnionVPS has run this region since 2022. The jurisdiction statutorily protects hosted data like banking records, a rare posture inside the EU. The facility offers a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Estimated RTTs: Frankfurt 5 ms, Ashburn 88 ms, Singapore 143 ms. Typical deployments include document storage and mail servers where data protection laws matter, plus low-latency database replicas for financial services in Frankfurt. The sub-5 ms hop to Frankfurt makes it a solid off-site node for EU-facing applications that need a privacy-friendly anchor. Source: https://onionvps.com/locations/luxembourg ### Athens, Greece Yes, you can host a server in Athens, Greece without KYC. OnionVPS operates a VPS region there since 2023, and Greece is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply because it is United States statute; local copyright law requires a court order. Entry price is $4 per month. Athens offers an Eastern Mediterranean edge with routes to the Middle East and Egypt. The jurisdiction is a non-Eyes member, so data is outside the main surveillance blocs, but GDPR applies to personal data, meaning you have strong data-protection rights. The facility has a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Estimated round-trip times are 26 ms to Frankfurt and 114 ms to Ashburn, and it sits within 10 ms of Sofia, Tirana, Skopje, and Podgorica. Typical deployments include low-latency proxies and VPN exit nodes for the Eastern Mediterranean and Middle East, mail servers that need clean IPs outside US jurisdiction, and relay infrastructure for regional services. The lack of DMCA takedowns makes it attractive for content that is legal locally but often complained about elsewhere, and the network links to neighbouring Balkan regions make it a useful interconnect point. Source: https://onionvps.com/locations/athens ### Budapest, Hungary Budapest, Hungary, is a no-KYC hosting location. OnionVPS operates a site here since 2022, with 20 Gbit/s uplink, DDoS scrubbing, and native IPv6 /64. Hungary is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply, as it is a U.S. statute; local copyright law generally requires a court order. Plans start at $4 per month. OnionVPS's Budapest region sits in a jurisdiction outside the intelligence-sharing alliances, meaning data processed here is not automatically shared with those allies. Geographically, it is central to Europe, with low latency to nearby regions like Bratislava and Vienna. The site offers NVMe storage and native IPv6, making it a solid choice for latency-sensitive workloads. As an Edge-tier location, it complements larger footprints, and the editorial note highlights competitive transit pricing. Deploy proxy endpoints, mail relays, or VPN gateways here for central-European coverage, or run latency-sensitive services that benefit from sub-5 ms hops to Slovakia and Austria. The legal posture suits projects that prefer a jurisdiction outside intelligence-alliance data sharing, such as privacy-focused analytics or data processing roles. Source: https://onionvps.com/locations/budapest ### Bratislava, Slovakia Yes, you can host a server in Bratislava, Slovakia without KYC. OnionVPS's Bratislava region requires only an email address, and no identity verification is ever performed. Slovakia is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply here—it is US law, and local copyright law requires a court order. Servers start at $4 per month. OnionVPS has operated in Bratislava since 2023. The facility offers a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. It sits close to Vienna (3 ms RTT) and Budapest (4 ms), with estimated round-trips of 11 ms to Frankfurt and 99 ms to Ashburn. GDPR applies to personal data processed here. As a smaller 'Edge' footprint, it complements larger regional hubs. Users deploy low-latency proxies and relay nodes for Central European traffic, taking advantage of the 11 ms Frankfurt round-trip. The jurisdiction also attracts privacy-focused applications like mail servers and seedboxes, where the non-DMCA environment and no-KYC policy reduce legal friction. Small virtualisation experiments and nested KVM tests are common due to full root access. Source: https://onionvps.com/locations/bratislava ### Ljubljana, Slovenia Ljubljana, Slovenia, hosts servers without KYC—only a controlled email is required. Slovenia is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, offering a neutral data posture. The DMCA does not apply; local copyright law governs, requiring a court order for takedowns. GDPR applies to personal data. Entry price is $4 per month. OnionVPS's Ljubljana region, operational since 2023, sits at 46.06, 14.51, on a 10 Gbit/s uplink with DDoS scrubbing, native IPv6, and NVMe storage. Great-circle estimates show 10 ms to Frankfurt and 98 ms to Ashburn, with nearby regions in Zagreb, Vienna, Bratislava, and Sarajevo. The facility suits Adriatic-facing EU capacity between Italy, Austria, and the Balkans, balancing EU legal protections with reduced surveillance-alliance entanglement. People deploy privacy-focused services like VPNs, mail servers, and cryptocurrency nodes in Ljubljana, leveraging the non-Eyes jurisdiction and low latency to Central Europe. The legal environment supports operations where data control and DMCA immunity matter, such as hosting user-generated content or serving clients in the EU and Western Balkans without US takedown exposure. Source: https://onionvps.com/locations/ljubljana ### Zagreb, Croatia Yes. You can host a server in Zagreb without KYC, and the legal position is clear. Croatia is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, so your data is not shared with those states by default. The DMCA does not apply because it is US law; local copyright law applies and generally requires a court order. Entry is $4 per month. OnionVPS's Zagreb region has operated since 2023 on a 10 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. Its edge jurisdiction tier offers smaller footprints for latency coverage, and proximity to Ljubljana (4 ms) and Sarajevo (6 ms) makes it a regional hub. Croatian capacity provides good onward routes to Serbia and Bosnia, as noted in our editorial review. People deploy mail servers here to keep correspondence outside alliance surveillance. The 12 ms route to Frankfurt suits low-latency trading bots or game servers. The IPv6 /64 and custom ISO support mean you can run OpenBSD or NixOS for privacy-focused infrastructure, while the 4 ms hop to Ljubljana allows cross-border service replication. Source: https://onionvps.com/locations/zagreb ### Istanbul, Türkiye Yes, you can host a server in Istanbul, Türkiye without KYC. OnionVPS offers KVM VPS from $4 per month, with no identity verification at signup. Türkiye is outside every intelligence-sharing alliance (Five, Nine, Fourteen Eyes) and outside the EU legal perimeter, so GDPR does not apply to personal data processed there. The DMCA does not apply either, as it is United States statute; local copyright law requires a court order. OnionVPS has operated in Istanbul since 2022. The facility sits at 41.01, 28.98, a physical bridge between European and Middle Eastern fibre, with a 40 Gbit/s uplink. Estimated round-trip times are 27 ms to Frankfurt, 116 ms to Ashburn, 119 ms to Singapore, 145 ms to São Paulo. The site includes DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Its editorial note calls it 'Non-EU, non-alliance, and the physical bridge between European and Middle Eastern fibre.' People run scrapers, trading bots, and upstream DNS resolvers here for the latency to both Europe and the Middle East, and for the independence from EU directives. Others host circumvention tools, V2Ray relays, or Tor nodes, relying on the lack of notice-and-takedown and the strength of local copyright law's court-order requirement. The full KVM access suits custom kernels. Source: https://onionvps.com/locations/istanbul ### New York, United States Yes, you can host a server in New York with OnionVPS without providing identification. The United States is a Five Eyes member, so intelligence-sharing agreements apply, but this does not restrict hosting. The DMCA notice-and-takedown regime applies here, so you must respond to copyright complaints. The entry price for any OnionVPS plan is $4 per month. OnionVPS has operated this region since 2020, anchored on a 100 Gbit/s uplink with direct connectivity to major exchanges. Estimated round-trip times are 86 ms to Frankfurt, 7 ms to Ashburn, 209 ms to Singapore, and 106 ms to São Paulo. On site you get DDoS scrubbing, native IPv6 /64, NVMe storage, custom ISO upload, Anycast capability, GPU instances, and Windows licensing. No personal data is processed under GDPR here, and no logs are retained. New York is a transit hub, so real-world deployments include low-latency proxy nodes for European and US traffic, Anycast DNS clusters, and GPU instances for rendering or inference. The 7 ms hop to Ashburn makes it ideal for data exchange with major cloud ecosystems, while the proximity to Canada suits North American content delivery. Source: https://onionvps.com/locations/new-york ### Ashburn, United States Yes, you can host a server in Ashburn without KYC. OnionVPS operates a Core-tier region there, part of the Five Eyes intelligence-sharing alliance, so US authorities can compel data disclosure. The DMCA notice-and-takedown applies because it is a United States location. GDPR does not cover personal data processed here. Entry price is $4 per month. Ashburn is the default US East location, carrying a large share of all US traffic on major internet exchanges. Equinix Ashburn provides high-capacity connectivity, with 100 Gbit/s uplink and low latency to other regions: New York at 7 ms, Toronto 9 ms, Montreal 13 ms, Chicago 14 ms. The facility offers DDoS scrubbing, native IPv6 /64, NVMe storage, custom ISO upload, Anycast, GPU instances, and Windows licensing. OnionVPS has operated here since 2020. People deploy latency-sensitive US-facing applications: real-time APIs, ad exchanges, and multiplayer game servers that need single-digit milliseconds to East Coast users. The NVMe storage suits high-IOPS databases. Anycast-capable network and DDoS mitigation handle UDP-heavy services under attack. Windows licensing makes it viable for Windows-based enterprise workloads requiring US jurisdiction. Source: https://onionvps.com/locations/ashburn ### Miami, United States Yes, you can host a server in Miami without KYC; OnionVPS requires only an email address. The United States is a Five Eyes member, so data is subject to intelligence-sharing agreements. The DMCA applies in Miami. Entry price is $4 per month. Miami is the landing point for major Latin American cables, offering the best US hop to Brazil, Colombia, and the Caribbean. Our Miami facility has a 100 Gbit/s uplink and is a Core jurisdiction on major internet exchanges. Operating since 2020, it provides DDoS scrubbing and native IPv6, making it a strategic choice for North-South traffic. Deploy game servers and VoIP platforms serving Latin American users, leveraging low latency to São Paulo (91 ms) and the Caribbean. Host content delivery nodes and Anycast endpoints for regional reach. Use the lack of GDPR for non-European personal data, simplifying compliance for US-facing services. Source: https://onionvps.com/locations/miami ### Dallas, United States Yes, you can host a server in Dallas, Texas, without KYC. The United States is a Five Eyes member, meaning intelligence-sharing agreements apply, but this doesn't affect hosting. The DMCA applies here, so you must respond to takedown notices. OnionVPS operates a Dallas region since 2021 with no identity verification, and entry price is $4 per month. Dallas sits on a major internet exchange with 100 Gbit/s uplink and estimated round-trip times of 27 ms to Ashburn and 113 ms to Frankfurt. The region offers DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. OnionVPS's editorial note describes it as Central US with balanced latency to both coasts and cheap, abundant power. Nearby regions include Atlanta (18 ms), Chicago (19 ms), Phoenix (21 ms), and Querétaro (21 ms). People deploy game servers, VPNs, and relay nodes in Dallas for low latency across the US and to Latin America. The central location and 27 ms to Ashburn suit financial data feeds, while the legal posture and no-KYC policy attract privacy-conscious operators running mail, DNS, or custom applications. Source: https://onionvps.com/locations/dallas ### Chicago, United States Yes, you can host a server in Chicago, United States, without KYC. OnionVPS requires only an email address you control; no identification is needed. The United States is a Five Eyes member, and the DMCA notice-and-takedown regime applies. Personal data is not subject to GDPR. Entry pricing is $4 per month. Chicago is a Core jurisdiction on major internet exchanges, and OnionVPS has operated here since 2021. The facility offers 40 Gbit/s uplink, DDoS scrubbing, Native IPv6 /64, NVMe storage, Custom ISO upload, and Windows licensing. With round-trip times of 14 ms to Ashburn and 11 ms to Toronto, it is the lowest-latency US point for financial market data feeds, making it a strategic choice for time-sensitive workloads. People deploy low-latency financial trading applications and market data consumers in Chicago, leveraging its proximity to exchange matching engines. The facility also suits high-frequency web services and any US-facing workload that benefits from the 14 ms latency to Ashburn and direct access to Midwest internet exchanges. Source: https://onionvps.com/locations/chicago ### Los Angeles, United States Yes, you can host a server in Los Angeles, United States, without KYC. OnionVPS offers $4/month VPS plans with no identity verification—an email address is the only account identifier. The US is a Five Eyes member, and the DMCA applies here, meaning copyright notices can lead to takedowns. For legal positions, this is a Core jurisdiction on major internet exchanges. Los Angeles sits at the transpacific cable head, giving the fastest US hop to Japan, Singapore, and Australia. OnionVPS has operated this region since 2020 with a 100 Gbit/s uplink. The facility includes DDoS scrubbing, NVMe storage, and GPU instances. Estimated round-trip to Frankfurt is 128 ms, to Ashburn 51 ms. Nearby regions include Phoenix at 10 ms. People deploy outbound media pipelines and gaming proxies here—latency to Asia matters for real-time traffic. GPU instances handle rendering and inference. DDoS mitigation protects public-facing services. The location suits any workload where North America–Asia transit needs to be short, not where European latency is the priority. Source: https://onionvps.com/locations/los-angeles ### Seattle, United States Yes, you can host a server in Seattle without KYC. The United States is a Five Eyes member, so data sharing among intelligence agencies is possible, but legal access to servers requires a court order. The DMCA does apply here, so content subject to takedown notices must be addressed. OnionVPS's Seattle location offers NVMe storage and native IPv6, with plans starting at $4 per month. OnionVPS has operated this Pacific Northwest edge since 2022, drawing on hydro-backed power and short routes to Vancouver and Tokyo. The facility sits at 47.61, -122.33 with a 40 Gbit/s uplink and includes DDoS scrubbing, custom ISO upload, and native IPv6 /64. Estimated round-trips to Ashburn are 52 ms, to Frankfurt 112 ms, and to São Paulo 149 ms. The nearest OnionVPS regions are Vancouver at 5 ms, Los Angeles at 23 ms, Phoenix at 26 ms, and Dallas at 38 ms. Seattle is the right home for latency-sensitive workloads serving the US West Coast and Pacific Rim: ad-tech bidding, real-time multiplayer game backends, and SaaS APIs. The 5 ms hop to Vancouver and short routes to Tokyo make it a solid edge for cross-border traffic. Engineers also deploy proxy nodes here when they need a US IP without the noise of a datacenter hub. Source: https://onionvps.com/locations/seattle ### Phoenix, United States Yes, you can host a server in Phoenix, United States, without KYC. OnionVPS requires only an email address you control; no name, address, or document is ever requested. Phoenix is in the United States, a Five Eyes member, so intelligence-alliance members have legal access to data. The DMCA notice-and-takedown applies here. Entry price is $4 per month. Phoenix offers low seismic risk and cheap capacity, a common disaster-recovery pair for Los Angeles, which is just 10 ms away. The facility provides 40 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Being outside GDPR's scope simplifies data handling. With Dallas at 21 ms and Seattle at 26 ms, it serves western North America efficiently. Users deploy disaster-recovery replicas and latency-sensitive services for the US West Coast. The proximity to Los Angeles (10 ms) suits caching nodes and game servers. NVMe storage handles database workloads. The US legal framework and DMCA compliance attract general-purpose hosting for content that must respect takedown requests. Source: https://onionvps.com/locations/phoenix ### Atlanta, United States Yes. OnionVPS operates a VPS location in Atlanta, United States, where no identity verification is required at signup. The United States is a Five Eyes member, so intelligence-sharing agreements apply. The DMCA notice-and-takedown regime applies, as this is US soil. Atlanta is an Edge jurisdiction, with entry pricing at $4 per month. Atlanta sits in the US Southeast, a region OnionVPS has served since 2022. The facility offers a 40 Gbit/s uplink and is well peered into regional eyeball networks. With estimated round-trip times of 14 ms to Ashburn and 15 ms to Miami, it is a strategic edge for US East Coast coverage. On-site capabilities include DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. GDPR does not apply to personal data processed here. Atlanta is suited for latency-sensitive workloads serving the US Southeast, such as ad-tech bidding, game servers, and real-time data feeds. The low latency to major US exchange points and the included DDoS mitigation make it a practical choice for applications that must stay responsive to domestic traffic. Source: https://onionvps.com/locations/atlanta ### Toronto, Canada You can host a server in Toronto, Canada without KYC. The Five Eyes intelligence-sharing alliance operates in this jurisdiction, but the DMCA does not apply here, as it is a United States statute; local copyright law generally requires a court order. OnionVPS's Toronto region, operational since 2021, starts at $4 per month, offering an accessible entry to North American hosting. Toronto's strength is its position on TorIX, one of North America's major internet exchanges, keeping traffic local with round-trip times of 9 ms to Ashburn and Montreal. The facility, at 40 Gbit/s uplink, includes DDoS scrubbing, IPv6, and Windows licensing. Canadian data residency suits services that must stay north of the border. Entry pricing is $4 monthly, with everything included at every tier. Canadian companies deploy latency-sensitive workloads requiring local data residency, such as financial services, healthcare records, or media streaming. The 9 ms hop to Ashburn or Montreal also makes it a solid choice for applications serving the Great Lakes corridor. Think gaming, VoIP, or real-time analytics needing sub-20 ms round trips to major North American cities. Source: https://onionvps.com/locations/toronto ### Montreal, Canada Montreal is a legal, practical home for a server bought without identity verification, because Canada sits in the Five Eyes intelligence-sharing alliance, and the DMCA—a United States statute—does not bind a host there; local copyright law governs and generally demands a court order. OnionVPS has operated this region since 2022, with entry at $4 per month. You may host under an email address only. OnionVPS's Montreal site runs on Hydro-Québec power, which the editorial note calls one of the cheapest and cleanest kilowatt-hours in the fleet—a concrete reason to put always-on workloads here. The facility answers at 45.5, -73.57 with a 40 Gbit/s uplink and 12 Tbps of edge DDoS scrubbing included at every tier. Native IPv6 /64, NVMe storage, custom ISO upload, and three free snapshots come standard. It sits 9 ms from New York and Toronto, 13 ms from Ashburn. Customers deploy latency-sensitive north-eastern traffic here: Montreal's nine-millisecond round trip to New York makes it a front-end for ad tech and gaming servers needing low ping to both Canada and the US East Coast. The cheap, clean Hydro-Québec power suits energy-hungry Chia plots or 24/7 machine-learning inference. Some run network telescopes or bulk archival, enjoying the low power cost. Source: https://onionvps.com/locations/montreal ### Vancouver, Canada Yes, you can host a server in Vancouver, Canada without KYC. OnionVPS's Vancouver region operates without identity verification. Canada is a Five Eyes member, so data is subject to intelligence-sharing agreements. The DMCA does not apply here; local copyright law requires a court order. Entry price is $4 per month. Vancouver is a Five Eyes jurisdiction, but OnionVPS operates the region from a data centre with a 20 Gbit/s uplink and DDoS scrubbing. The region has been live since 2023, offering NVMe storage and native IPv6 /64. Latency to Seattle is about 5 ms, and to Asia it is the shortest among OnionVPS's North American regions, making it a solid edge location for transpacific traffic. People deploy game servers and low-latency applications for the US West Coast and Asia, because round-trip times to Seattle are about 5 ms. Others host proxies and VPN endpoints to take advantage of the jurisdiction's court-order requirement for takedowns. Source: https://onionvps.com/locations/vancouver ### Mexico City, Mexico Yes. OnionVPS operates VPS servers in Mexico City, Mexico, at $4 per month, with no identity verification required. Mexico is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA does not apply — local copyright law, which generally requires a court order, governs takedowns. Your data is outside the US and EU legal frameworks. Mexico City is the largest Spanish-speaking internet market, with direct routes to the US and Central America. OnionVPS has operated this region since 2022, on a 40 Gbit/s uplink. The facility sits at coordinates 19.43, -99.13, offering DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Estimated round-trip times: 43 ms to Ashburn, 131 ms to Frankfurt. Nearest regions: Querétaro (4 ms), Belize City (18 ms), Dallas (22 ms). Customers deploy web services for the Spanish-speaking market, VoIP and gaming relays, and data-sync backends for LatAm operations. The 43 ms hop to the US East Coast makes Mexico City suitable for serving both North and South America, while the legal separation from the Five Eyes is attractive for privacy-focused messaging and content that would be uncomfortable under DMCA notice-and-takedown. Source: https://onionvps.com/locations/mexico-city ### Querétaro, Mexico Yes, you can host a server in Querétaro, Mexico, without KYC. OnionVPS's facility there, operational since 2023, sits outside the Five, Nine, and Fourteen Eyes intelligence-sharing alliances. The DMCA, a United States statute, does not apply; local copyright law governs, typically requiring a court order. Entry price is $4 per month. Querétaro is Mexico's fastest-growing data-centre cluster, outside the seismic risk of the capital. It offers low latency to the Americas: about 42 ms to Ashburn, 105 ms to São Paulo, and single-digit milliseconds to Mexico City. The 20 Gbit/s uplink, DDoS scrubbing, and native IPv6 /64 support demanding workloads. Being outside intelligence alliances and not subject to US notice-and-takedown procedures attracts privacy-conscious operators. People deploy latency-sensitive services for Latin American users, such as game servers, streaming relays, and trading platforms. The 4 ms hop to Mexico City suits fintech and telephony. The jurisdiction also appeals to operators who want to avoid US legal reach, hosting content that relies on local due process, not DMCA-driven takedowns. Source: https://onionvps.com/locations/queretaro ### São Paulo, Brazil São Paulo, Brazil is outside the Five, Nine and Fourteen Eyes alliances, so hosted data is not subject to those intelligence-sharing arrangements. The DMCA does not apply here; local copyright law requires a court order. You can host in São Paulo without KYC—only an email address is needed. Entry price is $4 per month. OnionVPS has operated in São Paulo since 2021, with a 100 Gbit/s uplink and IX.br, the largest exchange in the southern hemisphere. The facility offers DDoS scrubbing, IPv6 /64, NVMe storage, and custom ISO upload. As a Core jurisdiction on major internet exchanges, it provides low-latency access to Latin America, with Rio de Janeiro at 7 ms and Buenos Aires at 25 ms. Common deployments include latency-sensitive applications for Brazilian users, such as gaming servers, streaming relays, and fintech infrastructure. Data residency needs for local businesses drive adoption. The jurisdiction also suits privacy-focused workloads, given the absence of DMCA and intelligence-sharing alliances. Source: https://onionvps.com/locations/sao-paulo ### Rio de Janeiro, Brazil Yes, you can host a server in Rio de Janeiro, Brazil without KYC. OnionVPS operates there since 2023 with no identity verification required, only an email address. Brazil is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply, as it is a US statute; local copyright law requires a court order. Entry price is $4 per month. Rio de Janeiro is an edge jurisdiction, focused on latency coverage. It is the landing point for the EllaLink cable to Portugal, and the nearest OnionVPS regions include São Paulo at 7 ms round-trip. The site offers a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. GDPR does not apply to personal data processed here. Typical deployments include latency-sensitive applications for Brazilian users, such as financial trading platforms, real-time gaming, and streaming services. The 7 ms round-trip to São Paulo makes it ideal for low-latency workloads spanning Brazil's largest cities, while the no-KYC posture attracts privacy-focused applications like VPNs and anonymous hosting. Source: https://onionvps.com/locations/rio-de-janeiro ### Buenos Aires, Argentina Yes, you can host a server in Buenos Aires, Argentina, without KYC, as OnionVPS requires only an email address. Argentina is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, so your data is not subject to those surveillance frameworks. The DMCA does not apply here; it is a US statute, and local copyright law generally requires a court order. Entry price is $4 per month. Buenos Aires is OnionVPS's Southern Cone hub, with CABASE peering into Argentine eyeball networks. The facility offers 40 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Its strategic position on major internet exchanges delivers low latency across Latin America: 5 ms to Montevideo, 16 ms to Asunción, 17 ms to Santiago, and 25 ms to São Paulo. GDPR does not apply, and the jurisdiction sits outside the Fourteen Eyes framework, making it a strong choice for data sovereignty in the region. Customers deploy content delivery nodes, gaming servers, and streaming services to reach Argentine audiences with minimal latency. The CABASE peering ensures efficient routing to local ISPs. Others run data processing for regional operations, leveraging the lack of GDPR and Eyes-alliance obligations to host data that must remain outside European and Five Eyes jurisdictions. Source: https://onionvps.com/locations/buenos-aires ### Santiago, Chile Santiago, Chile is served by OnionVPS without KYC. Chile is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply because it is US law, and local copyright law generally requires a court order. Servers start at $4 per month. Hosting here offers a legal posture distinct from alliance-member jurisdictions. Santiago sits on the most reliable power grid in South America and is the landing point for the Humboldt cable to Asia-Pacific, a fact OnionVPS has published. The region operates on a 40 Gbit/s uplink with DDoS scrubbing and native IPv6. Its round-trip to São Paulo is estimated at 37 ms, and to Buenos Aires at 17 ms, making it a regional hub. Core jurisdiction tier means high-capacity internet exchange access. People deploy latency-sensitive services for South America, such as trading platforms that need 37 ms round-trips to São Paulo, or content delivery nodes that take advantage of regional proximity. Others run applications that must avoid DMCA-driven takedowns, leveraging the court-order requirement for copyright claims. Low cost $4 plans suit VPNs and monitoring agents. Source: https://onionvps.com/locations/santiago ### Bogotá, Colombia Yes, you can host a server in Bogotá, Colombia, without KYC at OnionVPS, with plans from $4/month. Colombia is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, which offers a more independent posture. The DMCA does not apply here, as it is a US statute, and local copyright law generally requires a court order for takedowns. This makes Bogotá a legally distinct hosting location. OnionVPS has operated in Bogotá since 2022, from a facility on a 20 Gbit/s uplink with DDoS scrubbing and native IPv6. The location is a key Andean hub, with fast routes to Miami and Panama, and the nearest region is just 12 ms away in Panama City. While GDPR does not apply to personal data processed here, the infrastructure includes NVMe storage and a full range of self-service features, all without identity verification. People deploy data-scraping operations, cryptocurrency nodes, and content platforms that prefer a jurisdiction outside Western intelligence-sharing agreements. The low latency to São Paulo (60 ms) and Panama (12 ms) suits regional services, while the non-DMCA environment attracts projects seeking to avoid US takedown requests. Source: https://onionvps.com/locations/bogota ### Lima, Peru Yes. OnionVPS offers KYC-free VPS hosting in Lima, Peru. Peru is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply here—it is US law and does not bind a host in Peru. Local copyright law requires a court order. Entry price is $4 per month. Lima sits on the Pacific coast of South America, well connected to Chile and Panama, with a 20 Gbit/s uplink and native IPv6. It is a newer OnionVPS region, operating since 2023, with an estimated round-trip of 49 ms to São Paulo and 147 ms to Frankfurt. The facility offers DDoS scrubbing and NVMe storage, and OnionVPS retains no connection logs, reinforcing the no-KYC stance. Users deploy latency-sensitive services for Latin American markets, such as game servers, VoIP, and financial trading gateways. The 49 ms hop to São Paulo and low latency to La Paz, Quito, and Bogotá make Lima ideal for real-time applications that cannot tolerate a North American detour. Source: https://onionvps.com/locations/lima ### Quito, Ecuador Yes. Quito, Ecuador, is outside the Five, Nine, and Fourteen Eyes intelligence alliances, so hosting here keeps your data beyond those states' surveillance agreements. The DMCA does not apply; Ecuador's copyright law governs and generally requires a court order for takedowns. No KYC is required—only an email address. Plans start at $4 per month. OnionVPS's Quito region sits at -0.18, -78.47, offering a 10 Gbit/s uplink with DDoS scrubbing, Native IPv6 /64, and NVMe storage. Ecuador's non-membership in intelligence-sharing pacts provides a legal posture distinct from most Latin American jurisdictions. The facility links via Panama, with round-trip estimates of 61 ms to Ashburn and 60 ms to São Paulo. Nearby regions in Bogotá, Panama City, San José, and Lima enable low-latency redundancy across the isthmus. Deploy latency-sensitive services for South American users, such as real-time data processing for trading bots, gaming servers needing sub-100 ms response to Colombia and Peru, or monitoring nodes distributed across the region. The Eyes-alliance exclusion also attracts content distribution and data aggregation tasks where domestic legal exposure matters. Source: https://onionvps.com/locations/quito ### Montevideo, Uruguay Montevideo, Uruguay, supports VPS hosting without identity verification: an email address you control is the only account identifier OnionVPS holds. Uruguay is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply, as it is US law. GDPR does not apply here. Entry price is $4 per month. Uruguay holds the strongest data-protection regime in Latin America, with an EU adequacy decision rare outside Europe. OnionVPS has operated this region since 2023. The Montevideo facility offers a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Its location, at -34.9, -56.16, gives a 5 ms round trip to Buenos Aires and a 23 ms hop to São Paulo. Network traffic is protected by always-on mitigation, and connection logs are retained for 0 days. Deploy latency-sensitive workloads serving South America: a 23 ms round trip to São Paulo and 5 ms to Buenos Aires suits financial trading tools, real-time gaming, or low-latency API backends. Privacy advocates run personal VPNs, mail servers, and decentralised services that benefit from the jurisdiction's non-alliance status and lack of DMCA takedown pressure. Source: https://onionvps.com/locations/montevideo ### Asunción, Paraguay Yes, you can host a server in Asunción, Paraguay without KYC. OnionVPS operates a region there since 2024 with no identity verification required. Paraguay is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so data processed there is outside those surveillance frameworks. The DMCA does not apply, as it is US law and not binding in Paraguay. Entry price is $4 per month. Asunción sits outside the EU legal perimeter and all intelligence-sharing alliances, offering a true offshore posture. The region benefits from cheap hydroelectric power from Itaipú and a light-touch regulatory environment. Network connectivity includes a 10 Gbit/s uplink, DDoS scrubbing, Native IPv6 /64, and NVMe storage. Estimated round-trip times to São Paulo are 17 ms, making it a solid hub for Latin American traffic. Customers deploy privacy-focused applications that benefit from Paraguay's non-membership in intelligence alliances and the absence of DMCA takedowns. Common workloads include data mirroring, research datasets, and secure communications services. The low latency to São Paulo (17 ms) makes Asunción suitable for serving Brazilian users while maintaining jurisdictional independence. Source: https://onionvps.com/locations/asuncion ### La Paz, Bolivia Yes. OnionVPS operates a no-KYC VPS in La Paz, Bolivia, where intelligence-alliance membership does not apply because Bolivia is not part of the Five, Nine, or Fourteen Eyes alliances. The DMCA, a US statute, does not bind the host, though local copyright law requires a court order. Entry price is $4 per month. La Paz sits at -16.5, -68.15, an Andean edge that puts São Paulo at 34 ms round-trip and the US East Coast near 86 ms. The facility connects on 10 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. OnionVPS has run this region since 2024, giving you an uncrowded alternative to Lima or Asunción for South American traffic. Customers deploy latency-sensitive services for Andean users—real-time collaboration tools, VoIP, or gaming servers that need low latency to Bolivia and neighboring countries. The region also suits caching nodes and private infrastructure where local legal position matters, without the scrutiny of larger markets. Source: https://onionvps.com/locations/la-paz ### Tokyo, Japan Yes, you can host a server in Tokyo without KYC. OnionVPS operates a Tokyo region with no identity verification; an email address is all that is required. Japan is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so your data is not subject to those pacts. The DMCA does not apply, as it is US law; local copyright law requires a court order. Entry price is $4 per month. Tokyo sits on JPIX and BBIX peering, making it the lowest-latency point for Japanese and Korean users and a strong transpacific anchor. The region has a 100 Gbit/s uplink with DDoS scrubbing, native IPv6, NVMe storage, and GPU instances. Tokyo is a Core-tier jurisdiction, meaning high-capacity infrastructure on major exchanges. It is not bound by the DMCA and requires a court order for takedowns, giving you more control over hosted content. Low-latency game servers for the Japanese and Korean markets, which cannot tolerate 74 ms to Singapore or 128 ms to Frankfurt. Media streaming and CDN nodes that need to be close to Tokyo's dense broadband users. Also Anycast-capable services that require a strong transpacific presence, connecting North American and Asian traffic with a 149 ms RTT to Ashburn. Source: https://onionvps.com/locations/tokyo ### Osaka, Japan Yes, you can host a server in Osaka, Japan, without KYC. OnionVPS's Osaka region sits outside the Five, Nine, and Fourteen Eyes intelligence alliances, and the DMCA does not apply—it is a US statute, and local law requires a court order for takedowns. Entry price is $4 per month. Osaka is OnionVPS's second Japanese region, positioned as the standard disaster-recovery pair for Tokyo, which sits just 7 ms away. The facility connects via a 40 Gbit/s uplink, offers DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Estimated latency to Singapore is 69 ms, making it a strong hub for East and Southeast Asia. People deploy low-latency workloads serving Japan and nearby Asia: real-time trading bots, gaming servers, and CI/CD runners that need quick access to Tokyo and Seoul. The non-Eyes jurisdiction also suits privacy-sensitive services and data replication for disaster recovery, pairing with Tokyo for failover. Source: https://onionvps.com/locations/osaka ### Seoul, South Korea Yes, you can host a server in Seoul without KYC. OnionVPS's South Korea location requires no identity verification at signup. South Korea is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply to hosts situated in Seoul; local copyright law requires a court order for takedowns. Prices start at $4 per month. OnionVPS has run this region since 2022, and the editorial note calls it the highest per-capita bandwidth market on earth. The facility sits at 37.57, 126.98 with a 40 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Estimated round trips: 13 ms to Osaka, 18 ms to Tokyo, 22 ms to Taipei, 29 ms to Ulaanbaatar, 65 ms to Singapore, 117 ms to Frankfurt, 152 ms to Ashburn. Korean gaming and streaming workloads dominate here. Low latency to Japan and Southeast Asia makes Seoul ideal for game server relays, real-time video encoding, and CDN edge nodes. The absence of DMCA takedown obligations also attracts file hosting and archival services that want to avoid US-style takedown demands. Source: https://onionvps.com/locations/seoul ### Taipei, Taiwan Yes. OnionVPS operates KVM VPS in Taipei, Taiwan, without KYC or identity verification; an email address is the only account identifier. Taiwan is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply here—it's US law, and local copyright law generally requires a court order. Entry price is $4 per month. OnionVPS has run this region since 2022 from a Core jurisdiction on major East Asian exchanges. The editorial note highlights dense peering independent of mainland transit, with great-circle estimates of 129 ms to Frankfurt, 172 ms to Ashburn, and 46 ms to Singapore. Nearby regions—Hong Kong (13 ms), Manila (18 ms), Seoul (22 ms), Osaka (25 ms)—make Taipei a strong hub for regional redundancy. The 40 Gbit/s uplink and DDoS scrubbing support demanding workloads. People deploy low-latency game servers and trading infrastructure that need fast paths to Singapore, Japan, and Korea. Others run web services for Chinese-speaking markets, leveraging routes that avoid mainland censorship. The private jurisdiction suits privacy-focused services like VPNs, mail servers, and content platforms that want to stay outside the DMCA's takedown regime. Source: https://onionvps.com/locations/taipei ### Mumbai, India Yes. OnionVPS hosts KVM VPS instances in Mumbai without KYC, and India is not a member of the Five, Nine, or Fourteen Eyes alliances. The DMCA does not apply to a host situated in India; local copyright law applies and generally requires a court order. Entry price is $4 per month. Mumbai is the landing point for most cables reaching India and the fastest hop to the Gulf, making it the natural hub for South Asian traffic. Since 2021, OnionVPS has operated a core-tier facility here with 40 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, NVMe storage, and custom ISO upload. Its legal posture—outside intelligence-sharing alliances and outside DMCA jurisdiction—matters for operators who prefer non-US hosting. Operators run low-latency proxy chains for Southeast Asia and the Gulf, given 55 ms to Singapore and 13 ms to Bengaluru. Indian businesses deploy mail servers and web apps that need local presence without sharing identity data under GDPR. DDoS-sensitive workloads benefit from always-on scrubbing. Source: https://onionvps.com/locations/mumbai ### Bengaluru, India Yes, you can host a server in Bengaluru, India without KYC. OnionVPS's Bengaluru region operates from 12.97, 77.59, with a 20 Gbit/s uplink. India is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply here because it is a United States statute; local copyright law generally requires a court order. Entry price is $4 per month. Bengaluru is India's engineering capital, a natural second Indian region for OnionVPS, operating since 2023. This edge jurisdiction offers low latency to Colombo (12 ms), Mumbai (13 ms), and Delhi (25 ms). On-site capabilities include DDoS scrubbing, native IPv6 /64, and NVMe storage. Because India is outside intelligence-sharing alliances, data processed here is not subject to GDPR. The $4 entry price applies across the fleet. Deploy applications serving southern India, where this region's proximity to Chennai and Hyderabad keeps latency tight. Use it for low-latency e-commerce backends, financial trading algorithms, or network monitoring. The legal posture suits privacy-sensitive projects. DDoS scrubbing protects public-facing services. Custom kernels support specialised software like IPsec VPN concentrators or packet processing. Source: https://onionvps.com/locations/bengaluru ### Delhi, India Delhi is an edge jurisdiction in India, not a member of the Five, Nine, or Fourteen Eyes alliances, and the DMCA does not apply since it is a U.S. statute. Local copyright law requires a court order for takedowns. GDPR does not apply to personal data here. Hosting without KYC is possible; OnionVPS requires only an email address. Entry price is $4 per month. This region has been operated by OnionVPS since 2023, providing 20 Gbit/s uplink and DDoS scrubbing. Located at 28.61, 77.21, it offers sub-20 ms latency to Kathmandu, Mumbai, Karachi, and Dhaka. The editorial note highlights northern India coverage with routes into Nepal and Central Asia. True KVM, native IPv6, NVMe storage, and a 99.99% SLA are standard, with zero retention of connection logs. Deploy latency-sensitive workloads serving northern India and Nepal: content delivery, trading bots that need single-digit-millisecond access to Mumbai, and proxy or VPN gateways. The Asia region and non-Eyes status also attract privacy-focused hosting and data aggregation that avoids U.S. or European legal exposure. Source: https://onionvps.com/locations/delhi ### Bangkok, Thailand Yes, you can host a server in Bangkok, Thailand without KYC. Thailand is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply here, as it is a US statute. Local copyright law generally requires a court order. OnionVPS offers VPS from $4 per month with no identity verification. OnionVPS has operated this Bangkok region since 2022. The facility sits on a major internet exchange with a 20 Gbit/s uplink, DDoS scrubbing, Native IPv6 /64, and NVMe storage. Editorial note calls it a Mainland Southeast Asian hub with short hops to Singapore and Hong Kong. Great-circle estimates put latency at 123 ms to Frankfurt and 193 ms to Ashburn. People deploy web proxies, content delivery caches, and low-latency game servers for Southeast Asian users. Others run private mail servers to avoid KYC-required providers, and blockchain nodes requiring a jurisdiction outside Eyes alliances. The Singapore latency of 21 ms makes it suitable for financial data relays. Source: https://onionvps.com/locations/bangkok ### Jakarta, Indonesia Yes, you can host a server in Jakarta, Indonesia, without KYC. OnionVPS requires only an email address you control, with no name, address, or document at any point. Indonesia is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, so your data is outside those frameworks. The DMCA does not apply here because it is a US statute; local copyright law requires a court order. Entry price is $4 per month. Jakarta is a Core tier region, meaning it sits on major internet exchanges. It has operated since 2022 with a 20 Gbit/s uplink, DDoS scrubbing, and native IPv6. Great-circle estimates put latency to Singapore at 14 ms, making it a solid hub for Southeast Asia. Being outside intelligence alliances means this jurisdiction avoids the legal frameworks that compel data sharing in some Western countries. Local copyright law applies, but takedown requires court order, not a simple notice. Users deploy servers in Jakarta for regional operations in Indonesia and Southeast Asia: e-commerce platforms, payment gateways, and media streaming that require low latency to the region's largest population. It's also a common choice for offshore data storage and web hosting when a strong legal posture around privacy and copyright is a priority, given the court-order requirement for takedowns. Source: https://onionvps.com/locations/jakarta ### Manila, Philippines Yes, you can host a server in Manila without KYC. OnionVPS, a no-identification VPS provider, offers $4-per-month instances in Manila, Philippines. The Philippines is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so your data is not subject to those cooperative frameworks. The DMCA does not apply; it is US statute, and local copyright law requires a court order for takedowns. Manila sits in the Pacific edge, 14.6°N, 120.98°E, with direct routes to Hong Kong and Guam. Round trips from the facility: 34 ms to Singapore, 17 ms to Hong Kong, 18 ms to Taipei, 24 ms to Ho Chi Minh City, 26 ms to Hanoi. You get 20 Gbit/s uplink, NVMe storage, DDoS scrubbing, and a routed IPv6 /64. GDPR does not apply, and no US statute reaches this host. People deploy game proxies and Discord bots, gaining sub-20 ms reach into East Asia. VoIP and streaming relays benefit from the 34 ms path to Singapore. IPTV and content caches for the Philippine archipelago avoid crossing the Pacific. Tor relays and privacy services find a jurisdiction outside the Eyes alliances with no DMCA exposure. Source: https://onionvps.com/locations/manila ### Ho Chi Minh City, Vietnam Ho Chi Minh City, Vietnam, is a viable location for no-KYC server hosting. Vietnam is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply here, as it is a U.S. statute and local copyright law requires a court order for takedowns. OnionVPS offers VPS instances starting at $4 per month, with no identity verification required—only an email address. The legal position is favorable for privacy-focused hosting. This facility, operational since 2023, sits on Vietnam's southern manufacturing corridor, offering 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. The region provides excellent connectivity to Southeast Asian hubs, with estimated round-trip times of 17 ms to Singapore, 16 ms to Kuala Lumpur, 12 ms to Bangkok, and 5 ms to Phnom Penh. For those prioritizing legal insulation, Vietnam's non-membership in intelligence-sharing alliances and absence of DMCA obligations distinguish it from Western jurisdictions. Typical deployments include low-latency gaming servers serving Southeast Asia, e-commerce fronts for the regional manufacturing supply chain, and data processing for logistics operations in the Mekong Delta. The proximity to Singapore and other ASEAN hubs at under 20 ms round-trip makes it practical for latency-sensitive services, while the independent legal framework suits projects needing to avoid DMCA-driven takedowns. Source: https://onionvps.com/locations/ho-chi-minh ### Hanoi, Vietnam You can host a server in Hanoi without KYC. OnionVPS operates an edge facility here since 2024 with true KVM virtualisation, no identity verification ever, and entry at $4 per month. Vietnam is not a member of the Five, Nine, or Fourteen Eyes alliances, and the DMCA—a US statute—does not bind a host situated here. Local copyright law applies and generally requires a court order. Hanoi sits at 21.03, 105.85, with a 10 Gbit/s uplink and NVMe storage. The jurisdiction sits outside intelligence-sharing alliances, and GDPR does not apply to personal data processed here. Short hops put you 14 ms from Hong Kong, 15 ms from Bangkok, 16 ms from Phnom Penh, and 17 ms from Ho Chi Minh City. Always-on DDoS scrubbing and native IPv6 /64 are included at every tier. People deploy proxies, monitoring nodes, and jump hosts in Hanoi to serve mainland Southeast Asia. The low latency to neighbouring regions and a legal posture that does not follow the DMCA make it a practical choice for workloads that require low-latency presence in the region with less exposure to US takedown requests. Edge locations suit distributed infrastructure. Source: https://onionvps.com/locations/hanoi ### Colombo, Sri Lanka Colombo, Sri Lanka, is a viable jurisdiction for hosting a server without KYC. The country is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply—US copyright statute has no force here. GDPR also does not apply. OnionVPS offers VPS from $4 per month, with no identity verification, making it a legal, private hosting option. OnionVPS operates in Colombo since 2024, positioning the facility at the Indian Ocean cable crossroads between South Asia and the Gulf. This location gives low latency to nearby regions: 12 ms to Bengaluru, 23 ms to Mumbai, 32 ms to Dhaka, 34 ms to Bangkok. The site is an edge region for smaller footprints, with a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage—all at a competitive price point. Typical deployments include regional VPN endpoints and privacy-focused proxies, leveraging the jurisdiction's non-Eyes status and DMCA exemption. The low latency to South Asia (Singapore at 39 ms) suits geo-distributed applications, while the lack of data retention laws and the court-order copyright takedown requirement appeal to content hosts needing legal shelter. Source: https://onionvps.com/locations/colombo ### Dhaka, Bangladesh Dhaka, Bangladesh is an Edge jurisdiction, not part of any intelligence-sharing alliance, so the Five/Nine/Fourteen Eyes posture does not apply. The DMCA does not bind a host there; local copyright law generally requires a court order. GDPR does not apply to data processed in Dhaka. Servers start at $4 per month with no KYC, only an email address required. OnionVPS opened in Dhaka in 2024, calling it one of the largest underserved internet populations in Asia. The facility offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. With estimated RTTs of 41 ms to Singapore and 11 ms to Kathmandu, it is a low-latency node for the Bay of Bengal corridor, while legal insulation from US takedown notices suits operators who want fewer third-party interruptions. People deploy VPN exit nodes to bypass domestic censorship and geo-restrictions, as the surrounding jurisdiction imposes its own filtering. Colocation-like tasks, including mail servers and custom-kernel workloads, benefit from true KVM and a whole /64 subnet, while latency-sensitive serving reaches Bangladesh’s large mobile-first population better from inside the country than from Europe or Singapore. Source: https://onionvps.com/locations/dhaka ### Karachi, Pakistan Yes, you can host a server in Karachi, Pakistan without KYC. OnionVPS has operated this region since 2024, and the jurisdiction is an Edge tier. Pakistan is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, so your data is not subject to those alliances' access frameworks. The DMCA does not apply here, as it is US law; local copyright law requires a court order. Plans start at $4 per month. Karachi is a cable landing station with routes to the Gulf, giving it unique low-latency access to that region. The site offers 10 Gbit/s uplink, DDoS scrubbing, Native IPv6 /64, and NVMe storage. GDPR does not apply to personal data processed here. This Edge jurisdiction is designed for latency coverage, making it a practical choice for workloads that need to be close to the Middle East or South Asia, with distances of 14 ms to Mumbai and Muscat. Common deployments include trading systems that benefit from the 14 ms latency to Mumbai and Muscat, and media streaming for Gulf audiences that need the 66 ms hop to Singapore. Some run privacy-focused services like VPNs or Tor nodes, taking advantage of the non-Eyes jurisdiction and no-KYC policy. The always-on DDoS mitigation makes it viable for game servers, which are frequent targets. Source: https://onionvps.com/locations/karachi ### Kathmandu, Nepal Yes, you can host a server in Kathmandu, Nepal without KYC. Nepal is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply, as it is a US statute; local copyright law requires a court order. OnionVPS offers VPS from $4 per month, with no identity verification required. Kathmandu sits at 27.72, 85.32, with an estimated 93 ms round-trip to Frankfurt and 169 ms to Ashburn. The facility routes via India and offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6, and NVMe storage. As an edge jurisdiction, it is a smaller footprint for latency coverage, not a primary data hub. OnionVPS has operated here since 2024. People deploy latency-sensitive services for South Asian users, such as game servers, real-time collaboration tools, and financial trading UIs, benefiting from ~50 ms to Singapore and ~23 ms to Mumbai. The no-KYC posture suits privacy-focused applications, and full root access enables custom kernels or routing configurations. Source: https://onionvps.com/locations/kathmandu ### Ulaanbaatar, Mongolia You can host a server in Ulaanbaatar, Mongolia without KYC. OnionVPS operates a VPS location there since 2024, and signup requires only an email address you control. Mongolia is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, so intelligence-sharing agreements do not apply. The DMCA is a US statute and does not apply here; local copyright law generally requires a court order. Entry price is $4 per month. Ulaanbaatar sits in an independent Central Asian jurisdiction with cheap cold-climate cooling, as our editorial notes. It is outside the Five, Nine, and Fourteen Eyes alliances, and GDPR does not apply to personal data processed here. The facility offers a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Estimated round-trip times are 72 ms to Singapore, 91 ms to Frankfurt, and 142 ms to Ashburn, making it a useful edge location for Asian coverage and a midpoint between Europe and North America. People deploy latency-sensitive services for East and Southeast Asia, including gaming servers, VoIP relays, and real-time trading proxies. The 72 ms path to Singapore and 34 ms to Almaty suit regional CDN origin nodes and VPN endpoints. Independent hosting for blogs, mail servers, or blockchain nodes also lands here, benefiting from low cost and no intelligence-sharing obligations. Source: https://onionvps.com/locations/ulaanbaatar ### Tashkent, Uzbekistan Tashkent, Uzbekistan, is a practical jurisdiction for anonymous VPS hosting. The country is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, which may appeal to privacy-focused users. The DMCA does not apply here, as it is a US statute, though local copyright law may still be relevant. OnionVPS offers entry-level VPS plans from $4 per month, making it an accessible option for those seeking no-identity-verification hosting. OnionVPS established a presence in Tashkent in 2024, drawn by the region's improving international capacity. The facility sits on a 10 Gbit/s uplink with DDoS scrubbing, native IPv6, and NVMe storage. Estimated latency to Frankfurt is 65 ms, to Singapore 78 ms, and to Ashburn 143 ms. This positions Tashkent as a useful edge for Central Asia, with nearby regions in Almaty, Delhi, and Karachi offering low inter-region latency. Users deploy privacy-focused services that benefit from the jurisdictional posture: personal VPNs, anonymous communication relays, and uncensored hosting for blogs or forums. The lack of DMCA takedowns and intelligence-alliance ties makes it suitable for data archival and services where the operator prefers not to identify themselves. The 65 ms path to Frankfurt also suits latency-tolerant applications serving European users. Source: https://onionvps.com/locations/tashkent ### Phnom Penh, Cambodia Yes, you can host a server in Phnom Penh, Cambodia, without KYC. Cambodia is outside the Five, Nine, and Fourteen Eyes intelligence alliances, so no data-sharing agreements apply. The DMCA does not apply here because it is US law and a Cambodian host is not bound by it; local copyright law requires a court order. Entry price is $4 per month. Phnom Penh sits in a light-touch regulatory environment, with transit routed via Vietnam and Thailand. OnionVPS has operated this region since 2024, offering 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. The facility benefits from excellent regional connectivity: 5 ms to Ho Chi Minh City, 9 ms to Bangkok, 16 ms to Kuala Lumpur and Hanoi. Singapore sits at 17 ms, making this a practical hub for Southeast Asian traffic. People deploy latency-sensitive services for Southeast Asian users: VoIP trunks, real-time messaging, multiplayer game servers, and financial data feeds that need single-digit millisecond hops to nearby metros. The jurisdiction also suits privacy-conscious workloads—VPN exit nodes, Tor relays, or services handling sensitive user data—where avoiding intelligence-sharing agreements and DMCA takedowns matters more than European proximity. Source: https://onionvps.com/locations/phnom-penh ### Dubai, United Arab Emirates Yes, you can host a server in Dubai without KYC. OnionVPS operates a region there requiring only an email address at signup. The United Arab Emirates is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply, as it is a United States statute; local copyright law requires a court order. Entry price is $4 per month. Dubai sits where European, African, and Asian fibre meet, making it the fastest single location for Middle East and East Africa traffic. The region connects via 40 Gbit/s uplink to major exchanges, with nearest neighbours Doha, Muscat, Manama, and Riyadh. Operated since 2021, it offers DDoS scrubbing, native IPv6, NVMe storage, and full root access. GDPR does not apply to personal data processed here. Typical deployments include trading gateways serving the Gulf's financial centres, CDN nodes for regional streaming, game servers for the Middle East, and VPN exit points. Low latency to East Africa also makes it a staging post for Nairobi-bound traffic. Teams needing strict data residency for regional compliance run database replicas here, and the no-KYC policy suits sensitive research and activism. Source: https://onionvps.com/locations/dubai ### Tel Aviv, Israel Yes, you can host a server in Tel Aviv without KYC. OnionVPS's Tel Aviv location, operated since 2023, sits outside the Five, Nine, and Fourteen Eyes alliances, so data processed there is not subject to those intelligence-sharing agreements. The DMCA does not apply—it's US law and not binding here; local copyright law requires a court order. Entry price is $4 per month. Tel Aviv's dense local peering and large domestic technology market make it a useful Middle East edge. Great-circle estimates put latency at 3 ms to Amman, 7 ms to Nicosia, and 7 ms to Cairo, with 17 ms to Istanbul. The facility offers a 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. GDPR does not apply to personal data processed here. Customers deploy low-latency trading bots that need single-digit milliseconds to regional exchanges, plus ad-tech and gaming servers serving Israeli and Levant audiences. The no-KYC stance suits experiments with privacy-focused services, and the lack of DMCA takedowns attracts media and content archives targeting the region, all running on true KVM with custom ISOs. Source: https://onionvps.com/locations/tel-aviv ### Riyadh, Saudi Arabia Riyadh, Saudi Arabia, offers off-shore VPS hosting without KYC or identity verification, requiring only an email address. Saudi Arabia is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply; local copyright law, typically requiring a court order, governs. GDPR does not apply to personal data processed here. Entry price is $4 per month. OnionVPS has operated this Riyadh region since 2023, with a 20 Gbit/s uplink and DDoS scrubbing, native IPv6 /64, and NVMe storage. The facility serves as an edge location for latency coverage across the Middle East. The editorial note highlights Saudi data residency for services subject to local hosting requirements. With low latency to nearby regions—8 ms to Manama and 9 ms to Doha or Kuwait City—this region suits regional workloads. Typical deployments include services needing local data residency for Saudi compliance, regional content delivery, and latency-sensitive applications for Gulf users. The connection to adjacent regions (8 ms to Manama) supports multi-region failover or caching. Full root access and custom ISO booting make it viable for niche operating systems or specialized network stacks. Source: https://onionvps.com/locations/riyadh ### Doha, Qatar Yes. OnionVPS operates a no-KYC VPS service in Doha, Qatar, where an email address is the only identifier held. Qatar is not a member of the Five, Nine, or Fourteen Eyes alliances. The DMCA does not apply because it is United States statute; local copyright law generally requires a court order. Entry price is $4 per month. Doha sits at 25.29 N, 51.53 E with direct Gulf cable access, putting it 4 ms from Manama, 7 ms from Dubai, 9 ms from Riyadh, and 10 ms from Kuwait City—latencies no European or North American datacentre can match for clients in the Gulf. The facility runs 10 Gbit/s uplinks with DDoS scrubbing, Native IPv6 /64, and NVMe storage. OnionVPS has operated this region since 2024. GDPR does not apply to personal data processed here. People deploy latency-sensitive infrastructure for Gulf trading platforms and regional exchanges that cannot tolerate the 64 ms round trip to Frankfurt. Fintech applications serving Qatar and the UAE use the Doha node to keep transactions under 10 ms for clients in Manama or Dubai. Packet capture and monitoring agents sit here, logging traffic close to the Gulf's undersea cable landings. Source: https://onionvps.com/locations/doha ### Manama, Bahrain Manama, Bahrain, sits outside the Five, Nine, and Fourteen Eyes intelligence-sharing alliances, so hosted data is not subject to those frameworks' surveillance agreements. The DMCA does not apply here—it is United States statute, and local copyright law generally requires a court order. OnionVPS offers KVM VPS starting at $4 per month with no identity verification. For a jurisdiction that is not an Eyes member and where DMCA takedowns are not applicable, Manama is a distinct option. OnionVPS has operated in this region since 2024, drawn by Bahrain's liberal telecoms regime and its central Gulf position. The facility sits on a 10 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. Round-trip estimates place Frankfurt at 62 ms, Singapore at 87 ms, and Ashourabe at 150 ms—useful for mixed traffic. Nearby OnionVPS regions include Doha (4 ms) and Riyadh (8 ms), so moving workloads between Gulf cities is straightforward. GDPR does not apply to personal data processed here. Common deployments include low-latency gaming servers for Gulf players, caching nodes that sit between Europe and Asia, and mail servers that need a jurisdiction outside the DMCA's reach. Trading bots often land here for the short hop to Doha and Dubai. Privacy-focused individuals run Tor relays and other anonymising services, trusting the non-Eyes position. The $4 entry price suits small experiments that can scale as needs grow. Source: https://onionvps.com/locations/manama ### Muscat, Oman Yes. OnionVPS operates an Edge jurisdiction in Muscat, Oman, where you can host a server without KYC—no identity verification at signup, only a verified email. Oman is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply because it is a US statute; local copyright law requires a court order. Entry price is $4 per month. Muscat sits on Omani cable landings with routes towards India and East Africa, making it a strategic midpoint for traffic between Asia and Europe. Estimated RTT to Frankfurt is 72 ms and to Singapore 76 ms, while Dubai is just 7 ms away. The facility offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. GDPR does not apply to personal data processed here. OnionVPS has run this region since 2024. Customers deploy Mastodon or Matrix homeservers to avoid EU data protection obligations, plus mirrored registries and block explorers for East African and South Asian latency. Some run localised Tor relays or Onion services where strong anonymity is required. The 7 ms hop to Dubai suits fintech scraping from Gulf exchange APIs. Source: https://onionvps.com/locations/muscat ### Kuwait City, Kuwait Yes. OnionVPS offers VPS hosting in Kuwait City, Kuwait, without KYC—an email address is the only identifier required. Kuwait is not part of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, so your traffic isn't automatically shared with those partners. The DMCA does not apply here; it's a US statute, and local copyright law generally requires a court order. Entry price is $4 per month. Kuwait City sits 8 ms from our Manama region, 9 ms from Riyadh, and 10 ms from Doha—making it a natural hub for Northern Gulf coverage. The facility runs a 10 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. Because Kuwait is outside Western intelligence alliances and not bound by the DMCA, the legal posture differs sharply from US or UK hosting. We've operated here since 2024. People deploy latency-sensitive services for the Gulf: trading bots that need low round-trip times to regional exchanges, game servers for players in Kuwait or nearby, and IoT backends collecting telemetry from devices across the Northern Gulf. The 56 ms to Frankfurt and 92 ms to Singapore keeps traffic regional, not routed through the US. These workloads thrive on the included always-on DDoS mitigation. Source: https://onionvps.com/locations/kuwait-city ### Amman, Jordan Yes, you can host a server in Amman without KYC, as OnionVPS requires only an email address, and Jordan is not a member of the Five, Nine, or Fourteen Eyes alliances. The DMCA does not apply here; it is US law, and local copyright law generally requires a court order. Entry price is $4 per month. OnionVPS's Amman region has operated since 2024 on a 10 Gbit/s uplink, with DDoS scrubbing, native IPv6 /64, and NVMe storage. Geographically, it sits at 31.95, 35.93, with estimated latencies of 43 ms to Frankfurt and 131 ms to Ashburn. The editorial note mentions 'Levantine edge with routes via Aqaba and Cyprus,' highlighting its role in regional connectivity. Customers run latency-sensitive workloads for the Middle East, such as ad exchanges, financial trading apps, and multiplayer game servers. The low RTTs to Tel Aviv (3 ms), Nicosia (8 ms), Cairo (9 ms), and Yerevan (18 ms) make it ideal for serving users across the eastern Mediterranean without traversing Western data hubs. Source: https://onionvps.com/locations/amman ### Johannesburg, South Africa Yes, you can host a server in Johannesburg, South Africa, without KYC, as OnionVPS requires only an email address. South Africa is not a member of the Five, Nine, or Fourteen Eyes alliances, and the DMCA does not apply; local copyright law requires a court order for takedowns. Entry price is $4 per month. Johannesburg sits on NAPAfrica, the largest exchange on the continent, making it the default for sub-Saharan Africa. OnionVPS has operated here since 2021, with a 40 Gbit/s uplink and estimated RTTs of 102 ms to São Paulo and 119 ms to Frankfurt or Singapore. The facility offers DDoS scrubbing, native IPv6 /64, NVMe storage, custom ISO upload, and Windows licensing. Common deployments include content delivery for southern African audiences, financial services requiring low latency to Johannesburg's financial district, and pan-African SaaS backends. The location also suits data-local storage for organisations wanting to keep personal data within the region, since GDPR does not apply. Source: https://onionvps.com/locations/johannesburg ### Cape Town, South Africa Yes. OnionVPS offers KYC-free VPS hosting in Cape Town, South Africa, from $4/month. South Africa is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so your data is not automatically shared with those nations' agencies. The US DMCA does not apply here; local copyright law governs, and takedowns generally require a court order. Cape Town is the landing point for the Equiano and 2Africa submarine cables, making it a strategic hub for African and transatlantic traffic. Its location provides lower latency to South America and Europe than inland African sites, and it sits within 19 ms of Johannesburg, Gaborone, and Windhoek. OnionVPS's facility offers 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage, backed by a 99.99% uptime SLA. People deploy content delivery and caching nodes here to serve southern African users with reduced latency. Offshore data storage for regional businesses and low-latency financial or research workloads benefit from the proximity to South America (e.g., 88 ms to São Paulo). Developers also use it for privacy-focused applications needing a jurisdiction outside major intelligence alliances. Source: https://onionvps.com/locations/cape-town ### Lagos, Nigeria Yes, you can host a server in Lagos, Nigeria, without KYC. OnionVPS has operated a Core-tier region in Lagos since 2022. Nigeria is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply because it is a United States statute; local copyright law applies and generally requires a court order. Entry price is $4 per month. Lagos sits on West Africa's largest market, with several new cable landings driving costs down fast. The region is uplinked at 20 Gbit/s, with DDoS scrubbing, native IPv6, and NVMe storage. Estimated round-trip times are 68 ms to Frankfurt and 120 ms to Ashburn. Nearest OnionVPS regions are Accra at 8 ms and Abidjan at 13 ms. No GDPR obligation applies to personal data processed here. People deploy latency-sensitive workloads serving West African users, such as VoIP, trading platforms, and content delivery. The low round-trip time to Accra (8 ms) and Abidjan (13 ms) makes Lagos a hub for regional services. The non-extradition posture and lack of DMCA mean operators of forums and publishing sites can run with fewer takedown risks, relying on local court orders. Source: https://onionvps.com/locations/lagos ### Nairobi, Kenya Yes, you can host a server in Nairobi without KYC. OnionVPS's Nairobi region requires only an email address, not identity verification. Kenya is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply because it is a United States statute; local copyright law governs and generally requires a court order. Entry price is $4 per month. OnionVPS has operated the Nairobi region since 2022, on a 20 Gbit/s uplink at the KIXP exchange, a strong East African peering point with routes via the Gulf. This is a Core jurisdiction, meaning high-capacity infrastructure on major internet exchanges. Facilities include DDoS scrubbing, native IPv6, and NVMe storage. GDPR does not apply to personal data processed here. The region sits close to Kampala, Dar es Salaam, Kigali, and Addis Ababa, with low round-trip times. People deploy data-intensive workloads like file sharing, mirror hosting, and content distribution that benefit from low latency to East African users. The non-Eyes jurisdiction attracts privacy-focused services, such as onion services and encrypted communication platforms, that seek to avoid intelligence-sharing obligations. The KIXP peering keeps East African traffic local, reducing transit costs. Source: https://onionvps.com/locations/nairobi ### Cairo, Egypt Yes. OnionVPS offers VPS hosting in Cairo, Egypt, without KYC. Egypt is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so your data is not subject to those states' surveillance-sharing arrangements. The DMCA does not apply because it is US law; local copyright law governs and generally requires a court order. Entry price is $4 per month. Cairo sits directly on the Suez corridor, which carries most Europe–Asia fibre, giving you proximity to key routes and low-latency links to nearby regions: Tel Aviv (7 ms), Amman (9 ms), Nicosia (10 ms), Athens (17 ms). The facility offers 20 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. OnionVPS has operated this region since 2023, and the legal posture—outside major intelligence alliances and the DMCA—makes it a strategic choice for privacy-focused workloads. Cairo is a strong choice for serving audiences across Africa, the Middle East, and Southern Europe with lower latency than northern hubs. It suits latency-sensitive applications like VPN endpoints, ad filtering, IoT telemetry aggregation, and web services targeting Arabic-speaking users. The jurisdiction's position outside Western intelligence alliances also appeals for secure communications relays and data storage. Source: https://onionvps.com/locations/cairo ### Casablanca, Morocco Yes, you can host a server in Casablanca, Morocco, without KYC. OnionVPS operates there since 2023, and no identification is required. Morocco is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply, as it is US law and does not bind local hosts. Entry price is $4 per month. Casablanca sits on the African side of the Gibraltar Strait, with estimated round-trip times of 33 ms to Frankfurt and 85 ms to Ashburn. The 20 Gbit/s uplink and DDoS scrubbing make it a practical edge location. It is also outside GDPR jurisdiction, which suits workloads that prefer not to handle EU data under that regime. Users deploy latency-sensitive proxies and relays for West African and Iberian audiences. The 10 ms hop to Lisbon and 13 ms to Madrid makes it a strong endpoint for cross-region services. Native IPv6 and NVMe storage support Tor nodes, mail relays, and lightweight database instances. Source: https://onionvps.com/locations/casablanca ### Tunis, Tunisia Yes, you can host a server in Tunis without KYC. Tunisia is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply here; it is a US statute, so local copyright law applies and generally requires a court order. OnionVPS's entry price is $4 per month. OnionVPS has operated this region since 2024, routed via Italy for Mediterranean North African edge coverage. The facility offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Located at 36.81, 10.18, Tunis sits within 22 ms of Frankfurt and 101 ms of Ashburn, making it a practical latency bridge between Europe and Africa. People deploy low-latency proxies and relays for North African users, IP transit for regional businesses, and privacy-focused infrastructure that avoids US jurisdiction. The absence of DMCA takedowns and Eyes-alliance membership makes it suitable for content that faces legal pressure elsewhere. IPv6-heavy deployments and small edge compute are common. Source: https://onionvps.com/locations/tunis ### Algiers, Algeria Yes. OnionVPS offers KVM VPS hosting in Algiers, Algeria from $4 per month with no identity verification. Algeria is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply, as it is US law. Local copyright law requires a court order for takedowns. Your server benefits from low-latency routes to Europe and a legal posture favorable to privacy. Algiers is an edge location in OnionVPS's network, operated since 2024 with a 10 Gbit/s uplink, DDoS scrubbing, native IPv6, and NVMe storage. Cables route via Marseille and Valencia, giving round-trip times of 23 ms to Frankfurt and 94 ms to Ashburn. The facility is outside surveillance alliances, meaning no intelligence-sharing obligations. It is a pragmatic choice for latency-sensitive workloads in North Africa and southern Europe. People deploy VPNs, proxies, and privacy-focused services in Algiers due to the jurisdiction's independence from intelligence alliances. The low 9 ms latency to Barcelona and 11 ms to Tunis makes it a good relay for Mediterranean traffic. Developers also run IPv6-only infrastructure and use the included DDoS mitigation for game servers or web services serving French and Italian audiences. Source: https://onionvps.com/locations/algiers ### Accra, Ghana In Accra, Ghana, you can host a server without KYC verification; only a controlled email address is required. Ghana is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA, a US statute, does not apply—local copyright law requires a court order. Entry price is $4 per month. OnionVPS has operated the Accra region since 2024, with a 10 Gbit/s uplink and West African edge near several modern cable landings. DDoS scrubbing, native IPv6 /64, and NVMe storage are standard. Round-trip estimates include 70 ms to Frankfurt and 83 ms to São Paulo, with nearby Lagos and Abidjan at 8 ms, positioning Accra as a solid regional hub. Low-latency serving for West African users: content distribution, gaming servers, and real-time APIs. The sub-10 ms links to Lagos and Abidjan make Accra ideal for multi-site deployments across the region, while the non-Eyes jurisdiction suits privacy-focused workloads that need protection from surveillance alliances. Source: https://onionvps.com/locations/accra ### Dar es Salaam, Tanzania Yes. OnionVPS operates a no-KYC VPS region in Dar es Salaam, Tanzania, since 2024. Tanzania is not a member of the Five, Nine or Fourteen Eyes intelligence-sharing alliances, so the position is straightforward. The DMCA does not apply—it is United States statute and local copyright law requires a court order. Entry price is $4 per month. You need only an email address. Dar es Salaam sits on the East African coast at a submarine cable landing station, which gives it a practical advantage for regional traffic. The 10 Gbit/s uplink and NVMe storage support serious workloads. Estimated round-trip times are 96 ms to Frankfurt, 100 ms to Singapore and 127 ms to São Paulo. This is an Edge jurisdiction: a smaller footprint for latency coverage, not a bulk-capacity hub. People deploy low-latency infrastructure for East African financial services, trading platforms and content delivery, where the 11 ms hop to Nairobi and 17 ms to Kampala beats routing via Europe. It also suits data-residency-sensitive operations in Tanzania, since GDPR does not apply to personal data processed here. Source: https://onionvps.com/locations/dar-es-salaam ### Kampala, Uganda Yes, you can host a server in Kampala, Uganda without KYC. OnionVPS offers NVMe VPS from $4/month, requiring only an email address. Uganda is not a member of the Five, Nine, or Fourteen Eyes alliances, and the DMCA does not apply here, as it is a US statute. Local copyright law requires a court order for takedowns. OnionVPS has operated this region since 2024, with a 10 Gbit/s uplink and DDoS scrubbing, native IPv6 /64, and NVMe storage. Landlocked East African capacity is routed via Kenya, giving low latency to nearby regions: 7 ms to Kigali, 9 ms to Nairobi. Legal posture is privacy-friendly: no intelligence-alliance membership, no DMCA, and no GDPR applicability for personal data. People deploy latency-sensitive services for East African users, such as VoIP gateways, gaming servers, financial APIs, and content delivery edge nodes. Being outside the DMCA regime attracts workloads requiring strict copyright compliance, and the no-KYC policy suits cryptocurrency nodes, privacy tools, and censorship-resistant platforms. Source: https://onionvps.com/locations/kampala ### Lusaka, Zambia Yes. OnionVPS offers KYC-free VPS hosting in Lusaka, Zambia, starting at $4 per month. Zambia is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA does not apply as it is US law. Local copyright law, which generally requires a court order, governs takedowns. Lusaka sits in an edge tier, positioned for latency coverage across Southern Africa. The facility provides a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Round-trip estimates are 104 ms to Frankfurt, 170 ms to Ashburn, 117 ms to Singapore, and 108 ms to São Paulo. Nearest OnionVPS regions include Harare at 7 ms and Gaborone at 16 ms. Customers deploy monitoring agents, VPN gateways, and relay nodes in Lusaka to serve Southern African users. The 7 ms hop to Harare and 16 ms to Gaborone makes it a useful anchor for regional services. The no-KYC stance and non-Eyes status suit operators who need to keep identity separate from infrastructure. Source: https://onionvps.com/locations/lusaka ### Harare, Zimbabwe Harare, Zimbabwe, is outside the Five, Nine, and Fourteen Eyes intelligence alliances, so hosted data is not subject to those states' surveillance mandates. The DMCA does not apply here; it is a US statute, and local copyright law generally requires a court order. You can host a server in Harare without KYC at OnionVPS's facility, with plans from $4 per month. OnionVPS has operated the Harare region since 2024, with a 10 Gbit/s uplink and transit via South Africa. The facility sits at -17.83, 31.05, roughly 7 ms from Lusaka and 14 ms from Maputo, making it a latency hub for Southern Africa. NVMe storage, native IPv6 /64, and DDoS scrubbing are on site. This is an edge jurisdiction for regional coverage, not a primary jurisdiction. Customers in Harare run latency-sensitive workloads for Southern African users, including VoIP relays, messaging gateways, and trading bots that need single-digit milliseconds to Lusaka or Maputo. The no-KYC policy suits services that prefer anonymity, such as privacy-focused VPNs and secure communications. NVMe storage supports database-heavy applications like caching nodes and CMS front-ends. Source: https://onionvps.com/locations/harare ### Luanda, Angola Luanda, Angola, offers a VPS with no KYC requirement—an email address is all OnionVPS holds. Angola is outside the Five, Nine and Fourteen Eyes alliances, and the DMCA does not apply here; local copyright law generally requires a court order. An entry-price server starts at $4 per month. This makes Luanda a legal-routing choice for data that should avoid those alliances. OnionVPS has run this region since 2024, connected via a South Atlantic cable with direct route to Brazil. The facility provides 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Round-trip latency from Luanda is 90 ms to São Paulo and 91 ms to Frankfurt, making it a practical midpoint for Atlantic traffic. Within Africa, it is 23 ms from Windhoek and 26 ms from Lusaka. People deploy reverse proxies for African and Brazilian audiences, lowering latency for media streaming and web applications. The jurisdiction suits data that must not traverse the Eyes-alliance countries, such as financial data for non-GDPR clients or content that faces takedown pressure elsewhere. Edge caching servers for nearby regions are a typical use, given the 90 ms to São Paulo. Source: https://onionvps.com/locations/luanda ### Maputo, Mozambique Maputo, Mozambique, offers offshore VPS hosting without KYC, as OnionVPS requires only an email address. Mozambique is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA does not apply here, being a US statute. Local copyright law requires a court order. Entry price is $4 per month. This Edge jurisdiction sits on the Indian Ocean coast, giving access to Southern Africa and nearby islands. The facility has a 10 Gbit/s uplink, DDoS scrubbing, IPv6, and NVMe storage. It is proximate to other regions, including Johannesburg at 8 ms. OnionVPS has operated here since 2024, adding capacity for latency-sensitive workloads. Users deploy here for low-latency reach to Southern Africa and the Indian Ocean rim. Common workloads include game servers for the region, financial tick data for exchanges in Johannesburg and Mauritius, and content delivery caching. The lack of DMCA takedown also attracts Usenet and file-hosting operations, while the DDoS scrubbing keeps them online. Source: https://onionvps.com/locations/maputo ### Dakar, Senegal Yes, you can host a server in Dakar, Senegal without KYC, and the legal position is clear. OnionVPS operates there with no identity verification, requiring only an email address you control. Senegal is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply — it is US statute. Local copyright law generally requires a court order. Entry price is $4 per month. Dakar sits at the westernmost point of continental Africa, a major cable landing. Our facility offers a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage, with estimated round-trip times of 64 ms to Frankfurt and 74 ms to São Paulo. It is an Edge-tier region, complementing nearby locations such as Abidjan at 26 ms and Lagos at 35 ms. We have operated here since 2024. People deploy latency-sensitive services for West African users, such as real-time messaging and financial applications, benefiting from Dakar's proximity to major cable landings. The absence of DMCA takedowns suits developers hosting content that is legally permissible locally but might attract frivolous complaints elsewhere. The $4 entry price makes it viable for lightweight proxies and monitoring nodes. Source: https://onionvps.com/locations/dakar ### Abidjan, Côte d'Ivoire Yes, you can host a server in Abidjan, Côte d'Ivoire, without KYC. OnionVPS's Abidjan region operates outside the Five, Nine, and Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply—local copyright law requires a court order. GDPR does not apply to personal data processed here. Entry price is $4 per month. Abidjan is OnionVPS's francophone West African hub, operated since 2024. The jurisdiction is an edge tier, ideal for latency coverage across West Africa. With a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage, the facility is equipped for serious workloads. Sub-10 ms latency to Accra and Lagos makes it a regional backbone. No connection logs are retained. Typical deployments include regional content delivery, messaging and VOIP services targeting Francophone West Africa, and backup or secondary instances. The low latency to Accra, Lagos, and Dakar suits real-time applications. NVMe storage and DDoS scrubbing support gaming and financial services workloads that demand performance and resilience. Source: https://onionvps.com/locations/abidjan ### Antananarivo, Madagascar Yes, you can host a server in Antananarivo without KYC. OnionVPS requires only an email address, and no identity verification at any point. Madagascar is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, so data is outside those surveillance frameworks. The DMCA does not apply, as it is a US statute and does not bind hosts here; local copyright law requires a court order. Entry price is $4 per month. Antananarivo is OnionVPS's edge location for Africa, operated since 2024 with a 10 Gbit/s uplink and native IPv6. Its position at -18.88, 47.51 places it near the Indian Ocean cable routes, giving better connectivity than inland African cities. The legal posture is clear: no surveillance alliance membership and no DMCA applicability, which appeals to operators who want predictable, court-order-based takedowns. Round-trip estimates are 90 ms to Singapore, 118 ms to Frankfurt, and 195 ms to Ashburn, offering reasonable reach to three continents. Users deploy low-latency frontends for East and Southern Africa, taking advantage of the 16 ms hop to Port Louis and 24 ms to Dar es Salaam. Others run mail servers or privacy-focused services that benefit from the non-Eyes jurisdiction. The NVMe storage and DDoS mitigation make it a solid spot for small VPS instances, reverse proxies, or seedboxes that need to be close to Indian Ocean users without European or US interference. Source: https://onionvps.com/locations/antananarivo ### Gaborone, Botswana Gaborone, Botswana offers an offshore VPS hosting option without KYC. Botswana is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances, and the DMCA does not apply, as it is a US statute. Local copyright law, requiring court orders, governs. OnionVPS provides servers here from $4 per month, with no identity verification and full root access. OnionVPS established this region in 2024, routing via Johannesburg for stability. The facility offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6, and NVMe storage. With the data center at coordinates -24.65, 25.91, round-trip times are estimated at 117 ms to Frankfurt, 175 ms to Ashburn, 121 ms to Singapore, and 100 ms to São Paulo. It sits near other OnionVPS regions in Johannesburg, Maputo, Harare, and Windhoek. People deploy latency-sensitive workloads needing a Southern African presence, such as content delivery caches, IoT gateways, or monitoring agents. The 6 ms hop to Johannesburg and low-latency links to nearby cities make it suitable for regional services. Its legal posture appeals to those hosting data that must avoid US jurisdiction, like certain types of research or archiving projects. Source: https://onionvps.com/locations/gaborone ### Windhoek, Namibia Yes. OnionVPS operates KVM virtualisation in Windhoek, Namibia, with entry at $4 per month. Namibia is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances. The DMCA does not apply: it is a United States statute, and a host situated in Windhoek is not bound by it. Local copyright law applies and generally requires a court order. The facility sits on the West Africa Cable System, giving it low latency to nearby African regions: about 15 ms to Gaborone, 18 ms to Johannesburg, 19 ms to Cape Town, and 21 ms to Lusaka. Legal posture is privacy-friendly: GDPR does not apply to personal data processed here, and no identification is required—only an email address. Includes DDoS scrubbing, native IPv6 /64, NVMe storage, and a 10 Gbit/s uplink. Buyers run network probes, censorship circumvention relays, and data aggregation services that need a presence near southern Africa without exposing operator identity. The jurisdiction's absence from intelligence alliances and lack of DMCA takedowns attract mail servers, VPN exit nodes, and cryptocurrency payment frontends that prefer minimal legal exposure. Latency to Johannesburg makes it practical for backup replication. Source: https://onionvps.com/locations/windhoek ### Kigali, Rwanda Yes, you can host a server in Kigali, Rwanda without KYC—only an email address is required. Rwanda is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply, as it is a U.S. statute; local copyright law applies and generally requires a court order. Entry-level pricing starts at $4 per month. OnionVPS has operated in Kigali since 2024, drawn by what our editorial note calls one of the most digitally-forward regulatory environments in Africa. The facility offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Latency estimates are 85 ms to Frankfurt, 159 ms to Ashburn, and 113 ms to Singapore, with 7 ms to Kampala and 12 ms to Nairobi—positioning Kigali as a solid regional hub. Customers deploy latency-sensitive services for East Africa: CDN nodes, caching reverse proxies, and anycast edge endpoints that must respond quickly to users across Uganda, Kenya, and Tanzania. The 7–22 ms links to neighboring regions make Kigali practical for regional API gateways and database replicas, while the legal posture suits operators handling data that must stay outside Western alliance jurisdictions. Source: https://onionvps.com/locations/kigali ### Addis Ababa, Ethiopia Yes, you can host a server in Addis Ababa, Ethiopia, without KYC. OnionVPS operates a region there since 2024 with a $4/month entry price. Ethiopia is not a member of the Five, Nine, or Fourteen Eyes intelligence alliances. The DMCA does not apply, as it is a US statute; local copyright law requires a court order. The region addresses Ethiopia's large domestic market with new capacity via Djibouti. Its 10 Gbit/s uplink, NVMe storage, DDoS scrubbing, and native IPv6 make it a robust edge location. Round-trip times are estimated at 74 ms to Frankfurt and 158 ms to Ashburn, making it attractive for regional latency rather than intercontinental throughput. GDPR does not apply to personal data processed here. Customers deploy packet sniffers, Tor relays, and mirror registries that benefit from the latency to East African peers. The position outside Western intelligence alliances suits privacy-focused services. Low latency to Nairobi, Kampala, Kigali, and Dar es Salaam supports regional VPN endpoints and content caches for African users. Source: https://onionvps.com/locations/addis-ababa ### Sydney, Australia Yes. OnionVPS offers KYC-free VPS hosting in Sydney, Australia from $4 per month. Australia is a Five Eyes intelligence-alliance member. The DMCA, a United States statute, does not bind hosts there; local copyright law requires a court order. No identification is required — an email address suffices, and no personal data is processed under the GDPR framework. OnionVPS has operated this Sydney region since 2021, calling it the Australian cable head and the default Oceania region. It is Core-tier, sat on major internet exchanges with a 40 Gbit/s uplink. Latency to Singapore is 87 ms, and regional peers Melbourne, Brisbane, Auckland and Suva sit within 45 ms. Facilities include DDoS scrubbing, native IPv6, NVMe storage and custom ISO upload. Connection logs are kept 0 days. Trading algorithms wanting sub-100 ms access to Singapore exchanges, media streaming relays for Oceania, and latency-sensitive gaming infrastructure. Sydney's cable head position makes it the natural hub for data that should not traverse the Pacific to reach a major exchange. The 87 ms Singapore hop suits financial automation needing regional speed without routing through Europe or the US. Source: https://onionvps.com/locations/sydney ### Melbourne, Australia Yes, you can host a server in Melbourne without KYC at OnionVPS. Melbourne, Australia is a Five Eyes member, meaning intelligence-sharing alliances apply, but the DMCA does not—it's a US statute that doesn't bind Australian hosts. Local copyright law requires a court order. Entry price is $4 per month. OnionVPS's Melbourne region, operational since 2023, is the second Australian footprint, complementing Sydney for redundancy. It sits on a 20 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. Melbourne offers an edge jurisdiction: smaller footprint, lower latency to the Asia-Pacific, and a legal posture that prioritizes court orders over automated takedowns. People deploy latency-sensitive workloads for the Asia-Pacific, such as trading bots, game servers, and CDN origins. Melbourne's 84 ms RTT to Singapore and 12 ms to Sydney make it ideal for low-latency applications across the region, while the lack of KYC and DMCA appeals to privacy-focused users. Source: https://onionvps.com/locations/melbourne ### Perth, Australia Yes, you can host a server in Perth, Australia without KYC. OnionVPS's Perth region operates in a Five Eyes member jurisdiction, but the DMCA does not apply—it is US law, and local copyright law generally requires a court order. Plans start at $4 per month, with no identity verification ever required. Perth is the shortest Australian hop to Singapore, offering a distinct latency advantage for Asia-Pacific traffic. The facility features a 10 Gbit/s uplink, DDoS scrubbing, Native IPv6 /64, and NVMe storage. Situated in an Edge jurisdiction, it prioritises latency coverage. GDPR does not apply to personal data processed here, and connection logs are retained for 0 days. Typical deployments include low-latency game servers, cryptocurrency nodes, and privacy-focused applications. The proximity to Singapore (55 ms RTT) makes it ideal for services targeting Southeast Asian users. Its edge location suits content delivery and real-time applications requiring reduced round-trip times compared to eastern Australia. Source: https://onionvps.com/locations/perth ### Brisbane, Australia Yes, you can host a server in Brisbane without KYC. OnionVPS provides anonymous VPS hosting in Brisbane, Australia, at $4 per month. Australia is a Five Eyes alliance member, which means intelligence-sharing agreements exist with other member states. The DMCA does not apply here, as it is US law; local copyright law requires a court order. Legal risks depend on your activities. Brisbane is a strategic edge location for the Asia-Pacific, close to major undersea cable landings. Our Brisbane facility offers 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. It joins our Sydney, Melbourne, Auckland, and Suva regions, providing low-latency coverage across Oceania. The jurisdiction sits outside GDPR, and DMCA takedowns are not applicable. Brisbane suits latency-sensitive applications for the eastern Australian seaboard and Pacific islands. Common workloads include gaming servers, CDN edge caching, and real-time data feeds. The proximity to Sydney (12 ms) and Singapore (85 ms) makes it a viable relay or failover point for regional services. Source: https://onionvps.com/locations/brisbane ### Auckland, New Zealand Yes, you can host a server in Auckland, New Zealand, without KYC. OnionVPS has operated this region since 2022, with an entry price of $4 per month. New Zealand is a Five Eyes member, but the DMCA—a US statute—does not apply here; local copyright law applies and generally requires a court order. GDPR does not govern personal data processed in Auckland. Auckland's data centre sits on the Southern Cross cable, offering 20 Gbit/s uplink and low latency to Sydney and Suva (31 ms). It provides DDoS scrubbing, native IPv6 /64, and NVMe storage. As a Core region on major internet exchanges, it suits entities needing New Zealand data residency without the constraints of US or EU legal frameworks, though Five Eyes membership remains a consideration for some. Typical deployments include local e-commerce and media sites requiring low latency for New Zealand users, and workloads that must store data within the country for residency. Also, run custom kernels or virtualise nested environments, given full KVM and root access. The 20 Gbit/s uplink supports moderate traffic, and DDoS scrubbing protects against attacks. Source: https://onionvps.com/locations/auckland ### Suva, Fiji Yes, you can host a server in Suva, Fiji, without KYC. OnionVPS's Suva location, operational since 2024, is outside the Five, Nine, and Fourteen Eyes intelligence alliances, so your data is not subject to those agreements. The DMCA does not apply here—it is a US statute, and Fiji's local copyright law requires a court order. Entry price is $4 per month. Suva sits on a 10 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. Its coordinates (-18.14, 178.44) put it 31 ms from Auckland, 40 ms from Brisbane, 45 ms from Sydney, and 55 ms from Melbourne—ideal for South Pacific coverage. The editorial note calls this "South Pacific island capacity for regional services." GDPR does not apply to personal data processed here, reinforcing the privacy posture. People deploy regional API endpoints and game servers that need low latency to Fiji and nearby Pacific islands. The location suits logging and monitoring agents that collect telemetry from Oceania. NVMe storage and DDoS scrubbing support high-traffic content delivery to this region without long-haul round trips. Source: https://onionvps.com/locations/suva ### Hagåtña, Guam Yes, you can host a server in Hagåtña, Guam, without identity verification. OnionVPS requires only an email address. Guam is a United States territory and a Five Eyes member, so intelligence sharing applies and the DMCA does. Entry price is $4 per month. Hagåtña sits at the transpacific cable crossroads between Asia, Australia, and the US. Our Edge facility here has been running since 2024, offering 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. Round-trip latency to Singapore is 65 ms, to Tokyo 36 ms, making it a practical hub for regional traffic. People deploy latency-sensitive services for Asian and Oceanian users: gaming servers, trading UIs, VoIP, and CDN origin nodes. The location also suits disaster-recovery replication and privacy-focused workloads that prefer a jurisdiction outside GDPR but within US legal norms. Source: https://onionvps.com/locations/guam ### San Juan, Puerto Rico San Juan, Puerto Rico offers VPS hosting without KYC, requiring only a controlled email address. It is a Five Eyes member, making intelligence-alliance scrutiny a consideration, but GDPR does not apply. The DMCA does apply because Puerto Rico is a United States location. Entry-level servers cost $4 per month, with no identity verification or billing information needed. OnionVPS has operated in San Juan since 2023 on a 20 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. The facility sits as a US-adjacent Caribbean node with strong Miami routes, complementing nearby regions: Santo Domingo at 7 ms, Willemstad at 12 ms, Bridgetown at 14 ms, and Port of Spain at 16 ms. It is an Edge jurisdiction for latency coverage. Customers deploy latency-sensitive workloads serving the Caribbean and the eastern US, using the 36 ms round trip to Ashburn for database replication or real-time trading gateways. The Five Eyes membership matters less for data residency than the legal ease of an offshore host, so privacy-focused proxies and VPNs also land here. Source: https://onionvps.com/locations/san-juan ### Kingston, Jamaica Yes. Kingston, Jamaica, is outside the Five, Nine, and Fourteen Eyes alliances, so intelligence-sharing does not apply. The DMCA, a United States statute, does not bind a host here; local copyright law applies and generally requires a court order. OnionVPS offers VPS instances from Kingston starting at $4 per month, with no KYC required — only an email address. OnionVPS opened the Kingston region in 2024 on a 10 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. The site sits at 17.97, -76.79 with several regional cable landings, keeping round trips to Santo Domingo, Nassau, Miami, and Panama City in the teens of milliseconds. That positions Kingston as an edge node for Caribbean latency, not a core hub. People deploy low-latency relays and regional API endpoints for Caribbean-facing services. A Mastodon server or mail relay benefits from the 34 ms path to Ashburn, while the unmetered IPv6 /64 suits research crawling or exit nodes. The data locality is a cleaner fit for Jamaican users than a Miami instance, without paying for core-metro bandwidth. Source: https://onionvps.com/locations/kingston ### Port of Spain, Trinidad and Tobago Yes, you can host a server in Port of Spain, Trinidad and Tobago, without KYC—OnionVPS requires only an email address, no identity verification. Trinidad and Tobago is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, offering a more private hosting environment. The DMCA does not apply here, as it is a US statute; local copyright law governs, generally requiring a court order for takedowns. Entry-level VPS plans start at $4 per month. OnionVPS established its Port of Spain presence in 2024, targeting the Southern Caribbean as the closest point to Venezuelan and Guyanese markets. The facility offers a 10 Gbit/s uplink, DDoS scrubbing, native IPv6 /64, and NVMe storage. With round-trip times around 50 ms to Ashburn and 106 ms to Frankfurt, it provides a strategic latency advantage for regional and international traffic. Nearby OnionVPS regions include Bridgetown at 7 ms and Willemstad at 13 ms, enabling low-latency interconnects. Customers typically deploy VPNs, private messaging, and data scraping in Port of Spain. The location's proximity to Venezuela and Guyana makes it ideal for services targeting those markets, while the lack of DMCA and Eyes-alliance membership attracts those handling sensitive data. The always-on DDoS mitigation and full KVM virtualisation support demanding workloads without interference. Source: https://onionvps.com/locations/port-of-spain ### Santo Domingo, Dominican Republic Yes, you can host a server in Santo Domingo, Dominican Republic without KYC. OnionVPS operates a region there since 2024, and no identity verification is required—only an email address. The Dominican Republic is not a member of the Five, Nine, or Fourteen Eyes intelligence-sharing alliances, and the DMCA does not apply because it is U.S. statute. Local copyright law requires a court order. Entry price is $4 per month. Santo Domingo is the largest Caribbean economy by GDP, well connected to Miami. Its jurisdiction is classified as Edge, offering smaller footprints for latency coverage. The network runs on a 10 Gbit/s uplink with DDoS scrubbing, native IPv6 /64, and NVMe storage. Estimated round-trip times are 34 ms to Ashburn and 105 ms to Frankfurt, with nearby regions in San Juan (7 ms), Willemstad (12 ms), Kingston (12 ms), and Nassau (16 ms). GDPR does not apply to personal data processed here. Typical deployments include latency-sensitive services for North American users, such as web servers, gaming, and VPN endpoints. The proximity to the U.S. East Coast (34 ms to Ashburn) makes it a strong choice for serving that market while remaining outside intelligence-sharing alliances. Businesses handling data that falls outside GDPR scope also use it for its legal posture. Source: https://onionvps.com/locations/santo-domingo ### Bridgetown, Barbados Yes. OnionVPS operates KVM VPS instances in Bridgetown, Barbados, and no identity verification is required at any point. Barbados is outside the Five, Nine and Fourteen Eyes alliances, so hosted data is not subject to those states' surveillance agreements. The DMCA does not apply here because it is a US statute and a Barbadian host is not bound by it; local copyright law governs. Entry price is $4 per month. Bridgetown is an established offshore financial jurisdiction with an IBC regime, which attracts operators who want legal distance from EU and US data rules. Our facility sits on a 10 Gbit/s uplink with DDoS scrubbing, native IPv6 and NVMe storage, and OnionVPS has run the region since 2024. Round-trip estimates are roughly 48 ms to Ashburn and 60 ms to São Paulo, making it a useful midpoint for transatlantic and intra-Caribbean traffic. Customers run private mail servers that never see a US or EU inbox, and encrypted object stores for data that must not leave Caribbean soil. Low-latency links to Port of Spain and San Juan suit game backends and voice relays for the region. The no-KYC position is why most arrive; the 101 ms path to Frankfurt keeps latency-sensitive workloads honest. Source: https://onionvps.com/locations/bridgetown --- ## 5. Answers (100) ### Choosing & sizing What a VPS is, what it costs, and how to size one without overbuying. #### What is a VPS? A VPS (virtual private server) is a virtual machine with guaranteed CPU, memory and storage, running its own operating system on shared physical hardware. You get full root access and can install anything. It sits between shared hosting, where you control almost nothing, and a dedicated server, where you rent the whole machine. The important word is "private": unlike shared hosting, the resources allocated to your instance are reserved for you, and other tenants cannot consume them. With KVM virtualisation the isolation is enforced by the processor itself, so your instance runs its own kernel and cannot see, or be seen by, its neighbours. In practice a VPS behaves exactly like a physical Linux or Windows server that happens to be somewhere else. You connect over SSH or RDP, install software with the normal package manager, and configure the firewall yourself. Nothing about the workflow is virtualisation-specific. - Full root or Administrator access, including custom kernels - Guaranteed CPU, RAM and disk that neighbours cannot take - Its own public IPv4 address and, here, a routed IPv6 /64 - Any operating system that boots — not a fixed list Source: https://onionvps.com/answers/what-is-a-vps #### What is a VPS used for? A VPS runs anything that needs to be online continuously: websites and APIs, game servers, VPN and proxy endpoints, mail servers, trading bots, CI runners, Docker workloads, media and file servers, blockchain nodes, and remote development environments. The common thread is a persistent machine with a public address and root access. The most common single use is hosting a website or application that outgrew shared hosting — typically because it needed a background worker, a specific runtime version, or a service that is not a web server at all. The second-largest category is private infrastructure: a personal VPN, a DNS resolver that your ISP does not operate, a file sync server, a media library. These workloads need very little hardware and a great deal of thought about jurisdiction, which is why a $4 instance in the right country often beats a large instance in the wrong one. Source: https://onionvps.com/answers/what-is-a-vps-used-for #### How much does a VPS cost? A usable VPS starts at about $4 a month for 1 vCPU, 1 GB of RAM and 20 GB of NVMe storage. A production instance with dedicated cores, 8 GB of RAM and 160 GB of storage runs around $34 a month. Storage-heavy plans with several terabytes start near $22. Longer billing terms reduce these by 5–22%. Price is driven mainly by three things: whether the cores are shared or dedicated, how much RAM you need, and how much storage. Bandwidth is usually included in the plan rather than billed separately, which is the largest single cost difference between a VPS and a hyperscaler cloud instance. Beware of prices that look impossible. A "$1 VPS" is almost always OpenVZ with oversold memory, no real kernel and no ability to run Docker. The floor for genuine KVM with reserved memory sits around $3–4. Typical monthly cost by workload: | Workload | Sensible specification | Approx. cost | | --- | --- | --- | | VPN, DNS, small bot | 1 vCPU / 1 GB / 20 GB | $4 | | Personal website, blog | 2 vCPU / 4 GB / 80 GB | $19 | | Production web app | 4 vCPU / 8 GB / 160 GB | $34 | | Game server (20 slots) | 4 dedicated / 8 GB high-clock | $49 | | Seedbox / media, 4 TB | 4 vCPU / 8 GB / 4 TB | $39 | | CI runner, monorepo | 6 vCPU / 16 GB / 320 GB | $62 | Source: https://onionvps.com/answers/how-much-does-a-vps-cost #### What is the cheapest VPS that is actually usable? About $4 a month buys 1 vCPU, 1 GB of RAM and 20 GB of NVMe on real KVM virtualisation. That is genuinely enough for a WireGuard VPN, a DNS resolver, a Tor relay, a small bot or a static site. Below that price you are almost certainly buying an oversold container rather than a virtual machine. The trap at the bottom of the market is virtualisation type. OpenVZ and LXC instances share the host kernel, which means memory is routinely oversold, Docker does not work reliably, and you cannot load kernel modules — so no WireGuard on older hosts, no custom firewall modules, no nested virtualisation. A 1 GB KVM instance running Debian or Alpine has roughly 850 MB genuinely available after the operating system. That is a comfortable amount for a single-purpose service and a tight amount for anything with a database. Source: https://onionvps.com/answers/what-is-the-cheapest-usable-vps #### How much RAM does a VPS need? Match RAM to the workload, not to a price tier. 1 GB runs a VPN, DNS resolver or small bot. 2–4 GB runs a small website with a database. 8 GB is the comfortable floor for a production application or Docker stack. 16 GB and up is for CI, large databases, Magento or heavy crawling. RAM is the resource that fails hardest when it runs out: the kernel OOM killer terminates whatever it judges most expensive, which is usually your database. CPU exhaustion makes things slow; memory exhaustion makes things stop. Operating system baselines matter at the low end. Alpine idles at roughly 80 MB, Debian at about 120 MB, Ubuntu at about 250 MB and Windows Server at roughly 1.5 GB. On a 1 GB instance that choice determines how much is genuinely yours. RAM by workload: | Workload | Minimum | Comfortable | | --- | --- | --- | | WireGuard VPN, DNS, Tor relay | 512 MB | 1 GB | | Static site or small blog | 1 GB | 2 GB | | WordPress with database | 2 GB | 4 GB | | Docker stack with Postgres | 4 GB | 8 GB | | Minecraft, 10–20 players | 4 GB | 8 GB | | Matrix Synapse, federated | 4 GB | 8 GB | | CI runner, monorepo | 8 GB | 16 GB | | Magento 2 in production | 8 GB | 16 GB | | Windows Server + application | 4 GB | 8 GB | Source: https://onionvps.com/answers/how-much-ram-do-i-need-for-a-vps #### How many vCPUs does a VPS need? Most workloads need fewer cores than people buy. One shared core saturates a gigabit VPN link. Two dedicated cores run a busy website. Four run a game server or a Docker stack. Beyond eight, you are usually buying parallelism for builds, crawling or transcoding. Whether cores are dedicated matters more than how many there are. The specification that actually determines responsiveness is dedicated versus shared. A shared vCPU is scheduled against other tenants, so under contention your process waits — visible as steal time. Two dedicated cores routinely outperform four shared ones for anything latency-sensitive. Single-thread clock speed matters for a specific set of workloads: game server tick loops, trading strategies, most PHP request handling and single-threaded compilation. For those, a high-frequency dual-core beats a slow eight-core. Source: https://onionvps.com/answers/how-many-vcpu-do-i-need #### How much bandwidth does a VPS need? Most projects use far less than they fear. A typical blog serving 50,000 monthly visits uses about 100 GB. A VPN carrying 1080p video for one person uses roughly 3 GB per hour. Video streaming and seedboxes are the exceptions, where terabytes are normal. Plans here include 2–50 TB, and one is unmetered. Estimate from page weight rather than intuition: multiply average page size by page views. A 2 MB page served 50,000 times is 100 GB. Images and video dominate; text and code are noise by comparison. Two things consume bandwidth in ways people underestimate: automated crawlers hitting your site, and backups leaving it. Both are worth measuring before choosing a plan. Monthly transfer by workload: | Workload | Typical monthly transfer | | --- | --- | | Blog, 50k visits | ~100 GB | | Web application, 500k requests | ~300 GB | | Personal VPN, heavy use | ~1–2 TB | | Game server, 20 slots | ~1 TB | | Jellyfin for a household | ~3–5 TB | | Seedbox at ratio | 10–40 TB | Source: https://onionvps.com/answers/how-much-bandwidth-does-a-vps-need #### How do I choose a VPS provider? Check five things: virtualisation type (KVM, not OpenVZ), whether cores are dedicated, which jurisdiction the server sits in, what identity data the provider collects, and what happens when someone complains about you. Price is the easiest thing to compare and the least likely to matter after the first month. Virtualisation type is the single most common hidden difference. If the provider does not state KVM explicitly, assume container-based virtualisation with oversold memory. The second question almost nobody asks before signing up is the abuse policy. Providers vary enormously in whether an automated complaint results in a forwarded email, a warning, or an immediate suspension with your data inaccessible. Read that page before you read the pricing page. - Is it KVM? If unstated, assume it is not. - Are the vCPUs dedicated or shared, and does the provider define the term? - Which country is the hardware in, and which legal system does that imply? - What identity information is required, and what is retained? - What is the published response to abuse complaints and legal demands? - Is there an out-of-band console, or does a firewall mistake mean a support ticket? Source: https://onionvps.com/answers/how-to-choose-a-vps-provider #### Can I upgrade a VPS later? Yes. CPU and RAM can be increased with a reboot, usually in under two minutes. Disk can be grown online. Shrinking is not possible in place — a smaller plan requires a rebuild and restore. Moving to a different country is also a rebuild, because the data has to physically move. The practical advice is to start smaller than you think you need. Upgrading is a two-minute reboot; downgrading is a migration. Buying headroom you never use is the most common way people overspend on hosting. Storage grows online: the block device expands immediately and you extend the filesystem with a single command. Growing a partition is safe and routine; shrinking one is neither. Source: https://onionvps.com/answers/can-i-upgrade-a-vps-later #### How quickly can a VPS be deployed? Provisioning takes under 60 seconds once payment confirms. The variable is the payment itself: Solana or TRON confirm in under a minute, Litecoin in about ten, Bitcoin in roughly twenty and Monero in about twenty. From clicking order to holding SSH credentials is typically two to twenty-five minutes depending on the coin. There is no manual review step, no identity check and no fraud queue, because there is no card to be fraudulent with. That is the main reason crypto-only providers provision faster than card-based ones, where a new account routinely waits hours for review. If you need capacity immediately, pay with a fast-finality chain: Solana, TRON, TON or an EVM layer-2 all confirm in well under a minute. Source: https://onionvps.com/answers/how-fast-can-a-vps-be-deployed #### Is a VPS worth it compared to shared hosting? A VPS is worth it as soon as you need something shared hosting will not let you do: a specific runtime version, a background worker, a non-web service, Docker, or freedom from arbitrary process limits. If you only serve a static site and never want to touch a terminal, shared hosting is genuinely fine. The cost difference at the entry level has largely disappeared — $4 buys a real virtual machine. What has not disappeared is the administration burden: on a VPS, security updates, firewalling and backups are yours. The honest test is whether anyone on your side will run apt upgrade once a month. If the answer is no, an unmanaged VPS is a liability rather than an upgrade. Source: https://onionvps.com/answers/is-a-vps-worth-it #### Do I need a managed VPS? You need managed hosting if nobody on your side will apply security updates, configure a firewall or restore a backup. Managed plans cost two to five times more and remove that work. Unmanaged hosting assumes you are comfortable in a terminal — every OnionVPS plan is unmanaged, which is why it is priced as it is. The boundary on an unmanaged plan is clear: the provider owns the hardware, network, hypervisor and control plane; you own the operating system and everything above it. We will always get you a working console and a snapshot restore, but we do not administer your operating system. A middle path many people miss: an unmanaged instance plus a configuration tool. Ansible, NixOS or a Docker Compose file makes rebuilding a server a five-minute operation, which removes most of the anxiety that drives people to managed hosting. Source: https://onionvps.com/answers/do-i-need-a-managed-vps #### What is the best VPS setup for a beginner? Start with 2 vCPU, 4 GB of RAM and Ubuntu 24.04 LTS in the region closest to you. Ubuntu has the largest body of tutorials, which matters more than any specification when you are learning. Take a snapshot before every experiment — it turns a broken server into a two-minute rollback. The single most useful habit for a beginner is snapshotting before change. Snapshots here are instant and the first three are free, so there is no reason not to. Second most useful: do the security basics on day one. Key-based SSH, no password authentication, no root login, and a firewall that denies everything except what you need. Those four steps eliminate the overwhelming majority of real-world compromises. Source: https://onionvps.com/answers/what-is-the-best-vps-for-beginners #### Is there a free trial or a free VPS? OnionVPS does not offer a free trial. Instead there is a seven-day money-back guarantee on a first order: if the service does not suit you, tell us within seven days of provisioning and we refund in full to an address you nominate. The entry plan is $4, which makes the risk small either way. Free trials exist mainly to filter fraud, and they require exactly the identity verification we have built the service to avoid. A short, unconditional refund window achieves the same outcome without collecting a document. Genuinely free VPS offers are almost always one of three things: an OpenVZ container with 128 MB of oversold memory, a time-limited hyperscaler credit that requires a card, or a service that monetises you some other way. Source: https://onionvps.com/answers/do-you-offer-a-free-trial ### Privacy & no-KYC What a provider knows about you, and how to make that as little as possible. #### What is no-KYC hosting? No-KYC hosting is server hosting that does not require identity verification. No passport, no photo ID, no billing address and no payment card. An email address you control and a cryptocurrency payment are the entire signup. The provider therefore holds no identity information that could be breached, sold or compelled. KYC — "know your customer" — is a set of identification duties imposed on regulated financial institutions. Hosting is not a regulated financial activity, so those duties do not apply to compute providers in the jurisdictions where we operate. Hosts that demand a passport do so for chargeback and fraud control, not because a statute requires it. The practical consequence is structural rather than promissory. A provider that never collected your identity cannot lose it in a breach, cannot sell it, and cannot hand it over in response to a demand. That is a property of the architecture, not a policy that could quietly change. - Held about you: an email address and a payment reference from the processor - Not held: name, address, government ID, card details, phone number - Provisioning: minutes, because there is no verification queue Source: https://onionvps.com/answers/what-is-no-kyc-hosting #### Is no-KYC hosting legal? Yes. There is no general legal requirement to identify server customers in the jurisdictions where OnionVPS operates. Anti-money-laundering identification duties bind banks, payment institutions and certain regulated intermediaries — not compute providers. Choosing not to collect identity documents is a lawful business decision, not a loophole. This is frequently confused with financial regulation. Exchanges and payment processors must identify customers because they handle money transmission. A hosting provider selling a virtual machine is selling a service, and no equivalent duty attaches. What remains true regardless of identity collection: the content you host is subject to the law of the jurisdiction it sits in, and valid legal process from a court with jurisdiction over us is answered. Not collecting identity data changes what can be disclosed; it does not create immunity. Source: https://onionvps.com/answers/is-no-kyc-hosting-legal #### How do I buy a VPS anonymously? Use a provider that requires no identity verification, sign up from a network that is not your home connection, use an email alias created for the purpose, and pay in Monero. Those four steps remove the correlation points that normally link a server to a person: identity documents, source IP, email reuse and payment trail. Each step closes a different gap. No-KYC hosting removes the identity document. Tor or a VPN at signup removes the source-IP link. A dedicated alias removes email reuse across services. Monero removes the payment trail, which is the one people most often overlook — a Bitcoin payment from an exchange account with your passport attached defeats the other three. Two things this does not do: it does not anonymise what the server itself sends, and it does not survive operational mistakes. If the server later connects to an account tied to your name, that link exists regardless of how it was purchased. - Sign up over Tor or a VPN you did not buy with a card - Use a fresh email alias, not one you have used elsewhere - Pay in Monero, or in Bitcoin passed through an atomic swap - Never reuse SSH keys that appear in a public repository - Keep the server out of accounts that identify you Source: https://onionvps.com/answers/how-to-buy-a-vps-anonymously #### What data does a hosting provider collect about me? Most providers collect a name, billing address, payment card, phone number, government ID, signup IP address, and complete access and connection logs. OnionVPS collects an email address, a payment reference from the processor, and the technical state needed to run your instance. No name, no address, no document, no card, no connection logs. The gap is what matters in a breach. A conventional provider's customer database is an identity dossier; ours is a list of email aliases and machine identifiers. Both can be stolen; only one is worth stealing. We do retain what is technically unavoidable: which instance exists, on which host, with which IP, and the billing state. We do not retain netflow records, connection logs, DNS query logs, or the contents of your disk — and we do not have the ability to reconstruct them after the fact. Typical provider versus OnionVPS: | Data point | Typical provider | OnionVPS | | --- | --- | --- | | Legal name | Required | Never collected | | Billing address | Required | Never collected | | Government ID | Often required | Never collected | | Payment card | Required | Not accepted | | Phone number | Often required | Never collected | | Signup IP address | Retained indefinitely | Not retained | | Connection / netflow logs | Retained 30–365 days | Not generated | | Email address | Retained | Retained — the only identifier | Source: https://onionvps.com/answers/what-data-does-a-hosting-provider-collect #### Do VPS providers keep logs of what I do? Most do. Netflow records, connection logs and panel access logs are standard, retained for 30 to 365 days, and in the EU and UK certain retention is legally mandated. OnionVPS operates in jurisdictions with no such mandate and does not generate netflow or connection logs at all, so there is nothing to retain or disclose. The distinction that matters is between logs that exist and logs that are kept. A provider can honestly say "we do not sell your data" while retaining a full record of every connection your server made. Ask specifically about netflow. What we do keep, because it is operationally unavoidable: the existence and configuration of your instance, aggregate bandwidth counters for billing, and hypervisor-level health metrics. None of these record destinations, contents or timing of individual connections. - No netflow or connection records generated - No DNS query logging on our resolvers - No panel access-log retention beyond the active session - Aggregate bandwidth counters only, for billing Source: https://onionvps.com/answers/do-vps-providers-keep-logs #### Can a VPS be traced back to me? It depends entirely on the links you create, not on the hosting itself. A no-KYC server paid for in Monero and administered over Tor has no provider-side link to you. A server paid for with a card, or logged into from your home IP, or running an account in your name, is trivially linkable regardless of the provider. Think of it as a chain of correlations. Payment, signup network, email address, SSH source addresses, domain registration, and what the server itself does are all separate links. Hosting choice removes one of them. Every remaining link is yours to manage. The most common failure is not technical. People buy anonymously, then log in from home, register a domain with real details, or run a service that identifies them. The infrastructure was never the weak point. Source: https://onionvps.com/answers/can-a-vps-be-traced-back-to-me #### What is offshore hosting? Offshore hosting means placing a server in a jurisdiction other than your own — usually one outside the Fourteen Eyes intelligence-sharing alliances and outside EU data-retention rules. The purpose is legal, not technical: compelling data from that server requires working through mutual legal assistance treaties rather than issuing a domestic order. The practical effect is friction and transparency. A domestic order to a domestic provider can be fast and secret. An MLAT request to a foreign jurisdiction is slow, requires dual criminality in most treaties, and frequently fails for civil matters entirely. What offshore hosting is not: immunity. Local law applies to the server, illegal content is still illegal, and a provider that respects valid process will still respect it. What changes is which court has to issue the order and how long it takes. Source: https://onionvps.com/answers/what-is-offshore-hosting #### Which country is best for offshore hosting? There is no single best country — it depends on which threat you are addressing. For legal protection with European latency, Switzerland or Iceland. For minimal applicable statute plus Americas latency, Panama. For maximum corporate separation, Seychelles. For EU peering without a Fourteen Eyes jurisdiction, Bulgaria, Romania or Moldova. Work backwards from the risk. If the concern is civil discovery, jurisdictional distance from the plaintiff matters most. If it is state surveillance, alliance membership matters most. If it is copyright enforcement, a country where takedown requires a court order rather than a notice matters most. These point to different places. Latency is the constraint that keeps this honest. A perfect jurisdiction 250 ms from your users is often the wrong answer. Many people end up with a split design: the sensitive component offshore, the latency-critical component near the users. Common offshore choices and what each is good at: | Jurisdiction | Alliance member | Strongest for | | --- | --- | --- | | Switzerland | No | Tested statutory data protection, EU latency | | Iceland | No | Speech protection, renewable power | | Panama | No | Minimal applicable statute, Americas latency | | Seychelles | No | Corporate separation, limited MLAT reach | | Moldova | No | Non-EU with European latency, low cost | | Bulgaria / Romania | No | EU peering outside the Eyes alliances | | Curaçao | No | Autonomous jurisdiction, iGaming and media | | Malaysia | No | Asian latency outside Western frameworks | Source: https://onionvps.com/answers/best-country-for-offshore-hosting #### Which countries are in the Five, Nine and Fourteen Eyes? Five Eyes: the United States, United Kingdom, Canada, Australia and New Zealand. Nine Eyes adds Denmark, France, the Netherlands and Norway. Fourteen Eyes adds Belgium, Germany, Italy, Spain and Sweden. These alliances share signals intelligence, which is why privacy-oriented hosting tends to avoid all fourteen. Membership is a legitimate signal but not a complete analysis. It concerns intelligence sharing, not ordinary criminal or civil process — a non-member country can still have aggressive domestic data-retention law, and a member can have strong judicial oversight. We publish alliance membership on every location page because it is the single most-asked jurisdiction question in this market, and because it is a public, verifiable fact rather than a marketing claim. Alliance membership: | Tier | Countries | | --- | --- | | Five Eyes | United States, United Kingdom, Canada, Australia, New Zealand | | Nine Eyes (adds) | Denmark, France, Netherlands, Norway | | Fourteen Eyes (adds) | Belgium, Germany, Italy, Spain, Sweden | Source: https://onionvps.com/answers/what-are-the-14-eyes-countries #### Which countries have no mandatory data retention? Panama, Seychelles, Belize, Costa Rica, Curaçao, Moldova and Georgia impose no general data-retention obligation on hosting providers. Switzerland's obligations are narrow and telecoms-focused. Romania struck its retention law down twice on constitutional grounds, and the EU's original Data Retention Directive was invalidated by the Court of Justice in 2014. Retention law usually targets telecommunications operators rather than hosting providers, so the practical question is how broadly a given country defines "operator". In several EU states the definition has been read widely enough to capture hosts. Because obligations change, we treat this as a live question rather than a settled one. If a jurisdiction we operate in introduces a retention mandate, we will say so on the location page and in the warrant canary rather than quietly complying. Source: https://onionvps.com/answers/which-country-has-no-data-retention #### What is a warrant canary and does it work? A warrant canary is a regularly updated statement that a provider has not received a secret legal demand. If the statement stops being updated, the reader infers that it has. It works because many jurisdictions can compel silence but cannot compel a false statement — though the mechanism is untested in most courts. A canary is only meaningful with three properties: a fixed publication schedule, a cryptographic signature, and a recent external timestamp such as a blockchain hash proving it could not have been pre-signed. A canary without those is decoration. Be clear about its limits. It is an inference mechanism, not a guarantee, and its legal status has never been fully tested. We publish one because the alternative — silence — carries no information at all. Source: https://onionvps.com/answers/what-is-a-warrant-canary #### Is full-disk encryption useful on a VPS? Against physical seizure of a powered-off disk, decisively yes: the volume is ciphertext without your passphrase. Against an attacker with access to the running hypervisor, no — the key is in memory the host can read. Any provider claiming otherwise is overselling, and the distinction is the whole point. The right implementation keeps the passphrase off the machine. Our Bastion line ships LUKS2 with an initramfs SSH daemon: on every boot you connect and supply the passphrase, and we never hold it. That means a reboot needs you, which is the correct trade for this threat model. What it genuinely protects against: decommissioned disks, hardware seizure, a datacentre incident, and a support engineer with physical access. What it does not protect against: a compromised hypervisor, or a compromise of the running instance itself. Source: https://onionvps.com/answers/is-full-disk-encryption-useful-on-a-vps #### Can my hosting provider see the files on my VPS? Technically yes: any provider with hypervisor access can read an unencrypted guest disk and its memory. That is true of every virtualisation platform. What varies is whether they do, whether policy forbids it, and whether full-disk encryption keyed by you makes stored data unreadable when the instance is powered off. Honesty matters more than reassurance here. Marketing that claims a provider "cannot" access your data on a normal VPS is false. The accurate statement is that access is possible, prohibited by policy, and made useless for data at rest by encryption you control. Our position: staff do not access guest storage except where you ask us to, or where a valid order compels it. On the Bastion line the disk is LUKS2-encrypted with a passphrase we never hold, so at rest the question does not arise. Source: https://onionvps.com/answers/can-hosting-provider-see-my-files #### How do I host a website anonymously? Combine four things: a no-KYC host paid in Monero, a domain registered with privacy protection or an anonymous registrar, a CDN or reverse proxy so the origin IP is never public, and administration only over Tor or a VPN. Removing any one of these usually undoes the other three. Origin leaks are the most common failure. Historical DNS records, TLS certificate transparency logs, mail headers, error pages and misconfigured subdomains all expose origin IPs routinely — often years after the fact. Assume the origin will be found unless you actively prevent it. The second most common failure is administrative. Logging into the panel from home, reusing an SSH key that appears in a public repository, or registering the domain with real details all create links that no amount of hosting choice can remove. - No-KYC host, paid in Monero - Registrar that accepts crypto and offers privacy protection - Reverse proxy in front; never publish the origin address - Fresh SSH keys, used nowhere else - Administer only over Tor or a VPN - Strip metadata from anything you publish Source: https://onionvps.com/answers/how-to-host-a-website-anonymously #### How do I register a domain anonymously? Use a registrar that accepts cryptocurrency and offers WHOIS privacy, and choose a TLD whose registry does not mandate public registrant data. Since GDPR most WHOIS records are already redacted, but the registrar still holds the underlying data — so paying in crypto matters more than the privacy add-on. Country-code TLDs vary enormously. Some require verified local presence and publish registrant details regardless of privacy services; others are entirely permissive. Check the registry policy before you buy, not after. A registrar can be compelled to disclose what it holds, and it can transfer or suspend a domain. That makes the domain a genuine single point of failure for an anonymous site — which is why some projects run an onion service alongside, where no registrar exists at all. Source: https://onionvps.com/answers/anonymous-domain-registration #### What is bulletproof hosting, and is OnionVPS one? Bulletproof hosting is a provider that claims to ignore all abuse complaints and law enforcement, including for criminal activity. OnionVPS is not one. We hold no identity data and we do not act on speculative complaints — but we do not host malware command-and-control, phishing or child sexual abuse material, and we answer valid legal process. The distinction matters practically as well as ethically. Bulletproof providers' address space is blocklisted wholesale, which means mail from it is rejected, API calls from it are challenged, and users see CAPTCHAs everywhere. The service you bought stops working. What most people asking for "bulletproof" actually want is a provider that will not terminate them over one automated complaint, and that does not hold their identity. That is what anonymous hosting on a clean network provides. Source: https://onionvps.com/answers/what-is-bulletproof-hosting #### Does using a VPN to connect to my VPS help? It helps with one specific thing: it stops your home IP address appearing in the server's authentication logs and in any provider-side records. It does nothing about what the server itself does, what it sends, or how it was paid for. Useful as one layer, useless as the only one. Tor is stronger than a VPN for this purpose, because no single party sees both your address and the destination. The trade is latency, which is tolerable for SSH administration and unpleasant for anything interactive. The mistake to avoid is inconsistency. Connecting over Tor ninety-nine times and once from home puts your home address in the log exactly once, which is all it takes. Source: https://onionvps.com/answers/does-a-vpn-protect-my-vps ### Crypto payment Paying for infrastructure without a bank, a card or an identity check. #### Can I pay for a VPS with cryptocurrency? Yes — at OnionVPS it is the only way to pay. Checkout accepts 20 cryptocurrencies across more than 15 networks, including Bitcoin, Monero, Litecoin, Ethereum, USDT and Solana, processed through OxaPay. No account registration, no card, no bank, and no identity verification at any point. Each invoice generates a fresh receiving address with a locked exchange rate and a 90-minute lifetime. Send the exact amount, and provisioning starts as soon as the required confirmations land — typically within two to twenty-five minutes depending on the chain. We hold no custody at any point. The payment processor generates the address and settles to us; we never see a wallet you control, and there is no balance on our side to freeze. Source: https://onionvps.com/answers/can-i-pay-for-a-vps-with-crypto #### Which cryptocurrency is best for paying for hosting? Monero for privacy — it hides sender, receiver and amount at the protocol level. USDT on TRON for cost and price stability, since the fee is cents and a dollar-pegged invoice cannot move against you. Solana or TON if you want the server provisioned within a minute. Bitcoin if convenience matters more than the ledger being public. The choice is a trade between three things: privacy, fee cost and confirmation speed. Monero optimises the first, stablecoins on cheap chains the second, and high-throughput chains the third. There is no coin that leads on all three. If you are paying for hosting specifically because you want privacy, the coin choice is not a detail — it is most of the decision. A Bitcoin payment sent from an exchange account with your identity attached links you to the invoice permanently, no matter how anonymous the hosting signup was. Coin selection by priority: | Priority | Recommended | Why | | --- | --- | --- | | Privacy | Monero (XMR) | Amounts and parties hidden by protocol design | | Lowest fee | USDT (TRC20), TRX | Fees measured in cents | | Fastest provisioning | Solana, TON, TRON | Confirmation in under a minute | | Price stability | USDT, USDC | Dollar-pegged; the invoice cannot move | | Easiest to acquire | Bitcoin, Litecoin | Available on every exchange | Source: https://onionvps.com/answers/which-crypto-is-best-for-paying-for-hosting #### How do I pay for a VPS with Monero? Choose a plan, select XMR at checkout, and an invoice appears with a fresh Monero address, the exact amount and a QR code. Send from any Monero wallet. After ten confirmations — about twenty minutes — provisioning starts automatically and credentials are emailed to the address you supplied. Monero is the recommended coin here because it is the only widely accepted one where the payment itself carries no linkable information. Ring signatures hide the sender, stealth addresses hide the recipient, and RingCT hides the amount. There is no public record connecting the payment to an invoice. If you do not already hold XMR, the common routes are an atomic swap from Bitcoin, a decentralised exchange such as Haveno, or a peer-to-peer market. Buying on a centralised exchange with verified identity and withdrawing to your own wallet still breaks the on-chain link, though the exchange retains a record of the withdrawal. - Ten confirmations, roughly 20 minutes - Invoice valid for 90 minutes at a locked rate - Underpayments up to 3% are accepted automatically - No account, no registration, no identity check Source: https://onionvps.com/answers/how-to-pay-for-a-vps-with-monero #### How do I pay for a VPS with Bitcoin? Select BTC at checkout and an invoice appears with a fresh address, an exact amount and a locked rate valid for 90 minutes. Send from any wallet, including Lightning. After two confirmations — roughly twenty minutes on-chain, or seconds over Lightning — the server provisions automatically. Set an appropriate fee. If the transaction is still unconfirmed when the invoice expires, the payment is still credited when it lands, but the rate may be recalculated. During periods of network congestion a low-fee transaction can sit for hours. Remember what Bitcoin is not: private. The payment is a permanent public record, and if the coins came from an exchange account with your identity attached, the link is durable. If privacy is the motivation, use Monero. Source: https://onionvps.com/answers/how-to-pay-for-a-vps-with-bitcoin #### Is paying with cryptocurrency anonymous? It depends entirely on the coin. Monero is private by protocol design — amounts and parties are hidden. Bitcoin, Litecoin and Ethereum are pseudonymous: every transaction is permanently public, and chain analysis routinely links addresses to exchange accounts with verified identities attached. The weak link is almost always acquisition rather than spending. Coins withdrawn from an identity-verified exchange carry that association forward through every subsequent transaction on a transparent chain. Practical ordering, most to least private: Monero; Litecoin with MWEB or Dash with PrivateSend; Bitcoin after a coinjoin; Bitcoin direct from an exchange; a stablecoin, where the issuer can additionally freeze the address. Source: https://onionvps.com/answers/is-crypto-payment-anonymous #### How long does a crypto payment take to confirm? It varies by chain: Solana and TON confirm in under a minute, TRON in about a minute, Litecoin in around ten minutes, Bitcoin in roughly twenty and Monero in about twenty. Provisioning begins automatically the moment the required confirmations land, and takes under a further sixty seconds. Confirmation counts are set by the processor to balance settlement risk against waiting time, and are higher on chains with cheaper reorganisations. They are shown on the invoice before you send. If you need capacity immediately, pay on a fast-finality chain. If you are provisioning ahead of time, chain speed is irrelevant and coin choice should be driven by privacy or fee cost instead. Typical time from broadcast to provisioning: | Coin | Confirmations | Approx. wait | | --- | --- | --- | | Solana (SOL) | 32 | Under 1 minute | | TON | 10 | About 1 minute | | TRON (TRX, USDT-TRC20) | 20 | About 1 minute | | Litecoin (LTC) | 4 | ~10 minutes | | Bitcoin (BTC) | 2 | ~20 minutes | | Monero (XMR) | 10 | ~20 minutes | | Ethereum (ETH) | 12 | ~3 minutes | Source: https://onionvps.com/answers/how-long-does-crypto-payment-take-to-confirm #### What happens if I underpay or overpay an invoice? Shortfalls up to 3% are accepted automatically and the order provisions normally — this covers wallets that deduct the network fee from the sent amount. Larger shortfalls are held; you can top up against the same invoice or request a refund. Overpayments are refunded to an address you nominate. The most common cause of an underpayment is a wallet that subtracts the miner fee from the amount rather than adding it. Send the exact figure shown and let the wallet add the fee on top. If an invoice expires with a partial payment against it, nothing is lost. Contact support with the transaction hash and we will either credit it to a new invoice or refund it. Source: https://onionvps.com/answers/what-if-i-underpay-an-invoice #### What happens if the crypto price changes while I am paying? The invoice locks an exchange rate for its 90-minute lifetime, so movement during that window does not affect you — send the quoted amount and the order completes. If the invoice expires before the transaction confirms, the payment is still credited and the rate is recalculated against the amount received. To remove the question entirely, pay with a dollar-pegged stablecoin. USDT or USDC on a cheap network means the invoice amount and the sent amount cannot diverge at all. Renewals are quoted fresh at the time of renewal, so a term price is fixed in dollars rather than in coin. Your bill does not change because the market did. Source: https://onionvps.com/answers/what-happens-if-crypto-price-changes #### Can I get a refund if I paid in crypto? Yes. First orders carry a seven-day money-back guarantee: tell us within seven days of provisioning and we refund in full to an address you nominate, in the coin you paid with or in an equivalent. After seven days the term runs to its end. Service credits under the uptime SLA apply separately and are not time-limited. A crypto refund is initiated by us rather than reversed by a bank, so it needs a destination address from you. Refunds are usually sent within one business day of the request. Because there are no chargebacks, we can price the service lower than card-accepting providers, who carry both processing fees and fraud losses. The seven-day window is the deliberate trade-off for that. Source: https://onionvps.com/answers/can-i-get-a-refund-on-crypto-hosting #### Do you accept PayPal, credit cards or bank transfer? No. OnionVPS is crypto-only, deliberately. Accepting cards would require collecting a name, billing address and often identity documents for fraud control — exactly the data the service is designed not to hold. Crypto settlement is what makes no-KYC provisioning possible at all. It is also what makes the price what it is. Card processing costs 2.9% plus a fixed fee, plus fraud losses and chargeback handling. Crypto settlement costs about 1% and cannot be reversed, and that difference is in the plan price rather than in a margin. If you hold no cryptocurrency, the simplest route is buying USDT or Litecoin on any major exchange and sending it directly to the invoice address. For a privacy-motivated purchase, swap into Monero first. Source: https://onionvps.com/answers/do-you-accept-paypal-or-credit-cards #### Are there setup fees or hidden charges? No setup fee, no provisioning charge, and no bandwidth overage billing. The plan price includes the transfer allowance, DDoS mitigation, one IPv4 address, a routed IPv6 /64, three snapshots and the out-of-band console. The only optional charges are add-ons you explicitly select at checkout. Attack traffic is never billed. If your instance is targeted by a denial-of-service attack, the scrubbed traffic does not count against your allowance — you are not charged for someone else's packets. If you exceed your transfer allowance we throttle rather than bill, and we tell you first. There is no mechanism by which a month can cost more than the price you agreed. Source: https://onionvps.com/answers/is-there-a-setup-fee #### What is included in every plan? Full root access, KVM virtualisation with custom kernel support, custom ISO upload, an out-of-band VNC console, one IPv4 address, a routed IPv6 /64, always-on DDoS mitigation, three free snapshots, self-service reverse DNS, the full REST API and Terraform provider, and no identity verification at any point. Several of these are commonly sold as upgrades elsewhere. DDoS mitigation, IPv6, reverse DNS control and the out-of-band console are included at every tier, including the $4 plan. What is optional: additional IPv4 addresses, nightly encrypted backups, layer-7 DDoS filtering, Windows Server licensing, and extra RAM or disk. Everything else is in the plan price. Source: https://onionvps.com/answers/what-is-included-in-every-plan ### Law & jurisdiction Offshore hosting, the DMCA, subpoenas, abuse handling and what is actually allowed. #### Is offshore hosting legal? Yes. Renting a server in another country is an ordinary commercial transaction, and no jurisdiction we operate in prohibits it. Offshore hosting changes which law governs the server and which court can compel disclosure. It does not make otherwise-illegal content legal, and it does not exempt you from the law where you live. Two legal systems remain relevant at all times: the law of the country the server sits in, which governs the hosting, and the law of your own country, which continues to govern you. Offshore hosting affects the first and not the second. For most customers the practical benefit is procedural. A domestic order to a domestic provider can be issued quickly and sometimes secretly. A foreign request has to travel through mutual legal assistance, which is slow, requires dual criminality under most treaties, and frequently fails for civil matters entirely. Source: https://onionvps.com/answers/is-offshore-hosting-legal #### Does the DMCA apply to offshore hosting? The DMCA is United States copyright statute. Its notice-and-takedown procedure and safe harbour apply to service providers situated in the United States. A server in Panama, Moldova or Seychelles is governed by that country's copyright law instead — which in most cases requires a court order rather than a private notice. This is often described as "DMCA ignored", which is misleading. The accurate statement is that the DMCA procedure has no application outside the US, so a notice sent to a non-US host is a letter rather than a legal instrument. It is not that the notice is defied; it is that it has no procedural effect. Copyright itself is near-universal through the Berne Convention. Infringement remains unlawful in every jurisdiction we operate in. What differs is the enforcement mechanism: notice-and-takedown in the US, judicial process almost everywhere else. - DMCA notices to non-US locations: no procedural effect, forwarded for information - Valid court orders from a competent court: acted on - US locations (New York, Ashburn, Miami, Dallas, Chicago, Los Angeles and others): DMCA applies fully - Content that is illegal in the host jurisdiction: removed regardless of who complains Source: https://onionvps.com/answers/does-the-dmca-apply-to-offshore-hosting #### What happens if you receive a subpoena or court order? We assess whether it is valid legal process from a court with jurisdiction over OnionVPS. If it is, we comply with exactly what is ordered and nothing beyond it. In practice that is very little: an email address and a payment reference. If it is not valid, we reject it. Either way, the warrant canary reflects reality. Because we never collect identity documents, billing addresses, phone numbers or card details, and do not generate connection logs, there is very little that any order can produce. This is the central design decision of the service: minimise what exists rather than promise to guard it. Where the law permits, we notify the affected customer before responding, so that they have the opportunity to challenge the order themselves. Where a gag order forbids notification, we cannot notify — and the warrant canary is what carries that information instead. Source: https://onionvps.com/answers/what-happens-if-you-receive-a-subpoena #### What is an MLAT and why does it matter for hosting? A mutual legal assistance treaty is the formal channel through which one country asks another to gather evidence on its behalf. It matters because a foreign authority generally cannot order a Panamanian or Seychellois host directly — it must route the request through that country's own courts, which is slow and often unsuccessful. MLAT requests routinely take six to eighteen months. Most treaties require dual criminality — the conduct must be an offence in both countries — and many exclude civil matters entirely, which is why offshore jurisdiction is particularly effective against speculative civil discovery. Not every pair of countries has a treaty. Where none exists, the requesting state must use letters rogatory, a diplomatic channel that is slower still and entirely discretionary for the receiving court. Source: https://onionvps.com/answers/what-is-mlat #### What content is not allowed on your servers? Child sexual abuse material, which we report to the appropriate authority. Malware command-and-control, ransomware infrastructure and exploit kits. Phishing and credential harvesting. Spam and unsolicited bulk mail. Attacks originating from your instance. Content illegal in the jurisdiction hosting it. Everything else lawful is permitted, including content other providers refuse. The line is active harm to third parties, not offensiveness, controversy or commercial inconvenience. Political speech, security research, adult material that is lawful where it is hosted, cryptocurrency infrastructure, privacy services, competitive intelligence and journalism are all normal workloads here. We do not scan your storage, inspect your traffic or profile what you run. Enforcement is complaint-driven and evidence-driven, which is the only approach compatible with not surveilling customers. - Prohibited: CSAM, malware C2, ransomware, phishing, spam, outbound attacks - Prohibited: proof-of-work mining on shared hardware, for neighbour impact rather than ideology - Permitted: VPNs, Tor relays and bridges, scraping of public data, adult content lawful in the host jurisdiction, security research with written authorisation, iGaming where licensed - Exit relays: permitted in approved jurisdictions with a published abuse contact Source: https://onionvps.com/answers/what-content-is-not-allowed #### How do you handle abuse complaints? Complaints are triaged by evidence, not by volume. Automated copyright notices to non-US locations are forwarded to you for information and no action follows. Reports of active harm — outbound attacks, phishing, malware distribution — get a response within hours. Valid court orders are answered. We do not suspend on a single unverified complaint. You always get a working window to act unless the harm is ongoing and severe. In practice that means 72 hours for most matters, and immediate action only where an instance is actively attacking a third party or distributing malware. We never disclose customer identity in response to an abuse complaint, because we have none to disclose. Complainants are told the report was received and forwarded; that is the entire disclosure. Source: https://onionvps.com/answers/do-you-respond-to-abuse-complaints #### Will my server be suspended if someone complains about it? Not for a single unverified complaint. Suspension is reserved for active, ongoing harm: an instance participating in an attack, distributing malware, or hosting CSAM. For everything else you receive the complaint, a stated window to respond, and a route to contest it. Data is never deleted during a suspension review. Single-complaint termination is the failure mode people most often describe when they move to us. It usually comes from providers whose abuse process is automated because their margins do not support a human reading anything. If we do suspend, network access is cut but storage is preserved and you retain console access to retrieve data. We do not use deletion as an enforcement tool. Source: https://onionvps.com/answers/will-i-be-suspended-for-a-complaint #### Can my VPS be seized? Physical seizure of hosting hardware is rare and requires a criminal warrant executed at the datacentre by local authorities. It is far more common for an authority to order the provider to image a specific instance. Full-disk encryption with a passphrase the provider never holds is the only meaningful protection against either. Seizure of an entire rack affects every customer on it, which is why datacentres resist it and courts rarely order it. Targeted imaging of one instance is the realistic scenario, and it requires local judicial authorisation in every jurisdiction we operate in. If this is in your threat model, three things follow: use the Bastion line with LUKS2, keep encrypted backups in a second jurisdiction, and rehearse the restore. An untested backup is not a backup. Source: https://onionvps.com/answers/can-my-vps-be-seized #### Does the GDPR apply if I host outside the EU? The GDPR follows the data subject, not the server. If you process personal data of people in the EU, it applies regardless of where the server sits — and hosting outside the EU adds a transfer-mechanism obligation. Offshore hosting does not exempt you from the GDPR; it adds a step to your compliance. For personal data of EU residents, an international transfer needs a lawful basis: an adequacy decision, standard contractual clauses, or a derogation. Switzerland and Uruguay hold adequacy decisions; Panama and Seychelles do not, so SCCs plus a transfer impact assessment are required. If you process no personal data of EU residents, none of this applies to you. Many privacy-motivated workloads — a personal VPN, a Tor relay, a private file server — fall entirely outside the regulation. Source: https://onionvps.com/answers/gdpr-and-offshore-hosting #### Who is legally responsible for content on a VPS? You are. On an unmanaged VPS you are the operator of the service and the publisher of its content; the provider is a conduit. That allocation is what makes intermediary liability protections work in most jurisdictions — the host is not liable for what it neither controls nor knows about, provided it acts on actual knowledge. The practical implication is that "the host allowed it" is not a defence available to you, and "the customer did it" is generally a defence available to us. That asymmetry is the normal structure of hosting law worldwide. It also means the decisions that matter are yours: what you publish, which jurisdiction you chose, and whether you have a plan for a complaint. We can tell you where the line is; we cannot stand behind it for you. Source: https://onionvps.com/answers/who-is-responsible-for-content-on-a-vps #### Can I run a Tor exit node? Middle relays and bridges are permitted on any OnionVPS instance, without restriction. Exit relays are permitted in approved jurisdictions only, and require a published abuse contact and a reduced exit policy. Exits attract complaints about traffic that is not yours, so we require that you are prepared to answer them. The reason for the distinction is practical rather than ideological. An exit relay is the apparent source of every connection it carries, so it receives the complaints for all of them. In some jurisdictions that creates real legal exposure for the operator. Recommended exit jurisdictions in our fleet are Iceland, Switzerland, Romania, Bulgaria and Moldova, where operating an exit is well established and the legal position is comparatively settled. Ask before deploying and we will confirm current status. Source: https://onionvps.com/answers/can-i-run-a-tor-exit-node ### Setup & operation SSH, firewalls, mail, Docker, backups and the rest of running a server. #### How do I connect to a VPS with SSH? Run ssh root@your-server-ip from any terminal on macOS, Linux or Windows 10 and later. Use the key you supplied at provisioning, or the password emailed to you. The first connection shows a host key fingerprint — compare it against the one in the control panel before accepting it. Add a key rather than relying on a password. Generate one with ssh-keygen -t ed25519, upload the public half at provisioning or from the panel, and the instance is built with password authentication already disabled. If you lock yourself out — a firewall rule, a broken sshd config, a mistyped key — use the out-of-band VNC console in the panel. It attaches to the virtual serial console, so it works even with no network at all. - ssh -i ~/.ssh/id_ed25519 root@203.0.113.10 - Verify the host key fingerprint against the panel on first connection - Windows: use the built-in OpenSSH client, not PuTTY, unless you prefer it - Locked out: the VNC console always works Source: https://onionvps.com/answers/how-to-connect-to-a-vps-with-ssh #### How do I secure a new VPS? Five steps cover the overwhelming majority of real-world compromises: key-based SSH with password authentication disabled, no direct root login, a default-deny firewall, unattended security updates, and fail2ban or an equivalent. Together they take about ten minutes and eliminate essentially all automated attacks. Automated attacks begin within minutes of an address going live. They are not targeted at you; they are targeted at everyone, continuously. Password authentication on port 22 is what they are looking for. The step people skip is the firewall. Default-deny inbound, with explicit allows only for what you actually serve, protects you from the service you forgot was listening — which is how most real intrusions begin. - ssh-keygen -t ed25519, upload the public key, then set PasswordAuthentication no - PermitRootLogin no; use a normal user with sudo - nftables or ufw: default deny inbound, allow 22, 80, 443 and nothing else - Enable unattended-upgrades so security patches land without you - Install fail2ban, or move SSH behind WireGuard so it is not exposed at all - Take a snapshot once it is configured — that becomes your known-good state Source: https://onionvps.com/answers/how-to-secure-a-new-vps #### How do I stop SSH brute-force attacks? Disable password authentication entirely — brute force against key-based SSH is not possible. Add fail2ban to reduce log noise, and consider moving SSH off port 22 to cut scanner volume by roughly 95%. The strongest option is putting SSH behind WireGuard so it is never exposed to the public internet. Changing the port is not security by itself, but it is genuinely effective noise reduction: the vast majority of automated scanners only try 22. Combined with key-only authentication, the residual risk is negligible. The correct end state for a sensitive server is no public SSH listener at all. Bind sshd to a WireGuard interface, and administration requires the tunnel first. Nothing on the public internet can even attempt authentication. Source: https://onionvps.com/answers/how-to-prevent-brute-force-ssh #### How do I set up a firewall on a VPS? Use nftables on modern Linux, or ufw as a friendlier front end. Set the default inbound policy to drop, allow established and related connections, then allow only the ports you actually serve. Always allow your SSH port before enabling the policy, or the console will be your only way back in. Remember IPv6. A ruleset that only covers IPv4 leaves every service reachable over v6, and every instance here has a routed /64. ufw handles both by default; hand-written nftables rules need an ip6 table or an inet table. Test before you commit. A common pattern is to schedule a job that flushes the rules in ten minutes, apply the new policy, verify you are still connected, then cancel the job. - ufw default deny incoming; ufw default allow outgoing - ufw allow 22/tcp (or your chosen port) before ufw enable - ufw allow 80,443/tcp for web services - Confirm IPv6 is covered — check ufw status verbose or your nft ruleset Source: https://onionvps.com/answers/how-to-set-up-a-firewall #### Can I install any operating system on a VPS? On KVM, yes. OnionVPS provides templates for Ubuntu, Debian, AlmaLinux, Rocky, Fedora, Arch, Alpine, NixOS, FreeBSD, OpenBSD, Windows Server, Proxmox and others, and you can upload a custom ISO and install anything that boots. On container-based virtualisation such as OpenVZ, you are limited to Linux templates the host provides. Custom ISO upload is free, needs no approval, and works through the out-of-band VNC console — you watch the installer exactly as if you were at a physical machine. This is the practical reason KVM matters for anything unusual. FreeBSD, OpenBSD, Whonix, a hardened image or an appliance operating system are all impossible on shared-kernel virtualisation. Source: https://onionvps.com/answers/can-i-install-any-operating-system #### Can I upload my own ISO? Yes, on every plan, at no cost and with no approval step. Upload the ISO from the panel or point us at a URL, attach it as virtual media, and boot from it through the VNC console. Anything that boots on standard KVM hardware will install, including BSDs, hardened images and appliances. This is the escape hatch that makes a VPS genuinely general-purpose. Our template list covers the common cases; the ISO uploader covers everything else, including images you built yourself. The virtual hardware presented is standard: virtio disk and network, an emulated VGA console, and UEFI or legacy BIOS as you prefer. Anything with virtio drivers — which is essentially everything modern — works without special preparation. Source: https://onionvps.com/answers/can-i-upload-a-custom-iso #### What is KVM virtualisation? KVM (Kernel-based Virtual Machine) is full hardware virtualisation built into the Linux kernel, using processor extensions to run each guest with its own kernel and hardware-enforced isolation. Unlike OpenVZ or LXC, which share the host kernel, a KVM guest can load kernel modules, run any operating system and use real swap. The practical consequences are concrete: Docker works properly, WireGuard loads, nested virtualisation is possible, FreeBSD and Windows boot, and memory allocated to you cannot be quietly oversold because it is genuinely reserved. Overhead is 2–5% for most workloads, which is a rounding error against the difference between shared and dedicated cores. Every OnionVPS instance is KVM, without exception. Source: https://onionvps.com/answers/what-is-kvm-virtualisation #### Can I run Docker on a VPS? On a KVM VPS, yes, without restriction — install Docker Engine from the official repository and everything works, including buildx, Compose and Docker-in-Docker. On OpenVZ or LXC-based virtual servers Docker either fails or requires unsafe host configuration, because it needs cgroups and namespaces that shared-kernel virtualisation does not expose. Size the instance by summing your container memory limits and adding about 1 GB for the host. A typical web application, background worker and PostgreSQL stack fits comfortably in 8 GB. Put the Docker data root on NVMe. Image layer extraction and container filesystem writes are IO-bound, and on slow storage every deployment feels slow for reasons that look like CPU but are not. Source: https://onionvps.com/answers/can-i-run-docker-on-a-vps #### Can I run nested virtualisation on a VPS? Yes. Nested virtualisation is enabled on every OnionVPS instance, so you can run KVM guests inside your instance, install Proxmox VE, or run Docker-in-Docker and VM-based CI jobs. Many providers disable it, which is the usual reason Proxmox and certain CI configurations fail elsewhere. Nested guests carry a further performance penalty on top of the first layer — expect noticeably slower IO in particular. It is excellent for labs, testing and CI, and a poor choice for production workloads that could run at the first level. Check with grep -E "vmx|svm" /proc/cpuinfo on your instance; if the flag is present, nesting is available. Source: https://onionvps.com/answers/can-i-run-nested-virtualisation #### Is outbound port 25 open, so I can run a mail server? Yes, outbound port 25 is open on every OnionVPS instance by default. There is no support ticket, no account-age requirement and no paid unblock. Most providers block it permanently to control spam, which is why self-hosted mail is impossible on much of the market. Open port 25 is necessary but not sufficient for deliverability. You also need a matching reverse DNS record, SPF, DKIM and DMARC, and address space with no spam history. We provide the first and the last; the DNS records are yours to publish. Warm a new address up gradually. A few dozen messages a day for the first week, growing steadily. A volume spike from a new IP looks exactly like a compromised host, because usually it is one. Source: https://onionvps.com/answers/is-port-25-open #### Can I set reverse DNS (PTR) records myself? Yes, for both IPv4 and IPv6, directly from the control panel, and changes propagate within minutes. Reverse DNS is essential for mail: most large receivers reject messages from an address whose PTR record does not resolve back to the sending hostname. Set the PTR to the same hostname the server announces in its SMTP banner, and make sure that hostname has a forward A or AAAA record pointing back to the same address. That round trip — forward-confirmed reverse DNS — is what receivers actually check. If you run several services on one address, set the PTR to the mail hostname. It is the only service that cares. Source: https://onionvps.com/answers/can-i-set-reverse-dns #### Can I run my own mail server on a VPS? Yes. Port 25 is open, reverse DNS is self-service, and our address space has no spam history. Mailcow or Stalwart give you a complete stack in an evening. The difficulty is not installation — it is deliverability, which depends on SPF, DKIM, DMARC, a matching PTR and a patient warm-up. Budget 4 GB of RAM for Mailcow and 8 GB if you enable full-text search. Stalwart is a single Rust binary and runs comfortably in far less if you prefer fewer moving parts. Start DMARC at p=none and read the aggregate reports for a fortnight before tightening. Going straight to p=reject on a new domain is how people discover which of their systems were sending mail they had forgotten about. Source: https://onionvps.com/answers/can-i-run-a-mail-server #### How many IP addresses can I have on one VPS? Every instance includes one IPv4 address and a routed IPv6 /64 — that is 18 quintillion v6 addresses, not one. Up to eight additional IPv4 addresses can be added per instance at $3 a month each, from the panel, with no justification form and no waiting period. The /64 is genuinely routed to your instance rather than a single assigned address, so you can give every container, virtual machine or service its own public IPv6 address without NAT. Additional IPv4 addresses are the usual answer for proxy rotation, multiple TLS endpoints before SNI, or separating mail from web reputation. Bastion instances include three by default. Source: https://onionvps.com/answers/how-many-ip-addresses-can-i-have #### Do you provide IPv6? Yes — a routed /64 subnet on every instance, at every tier, at no cost. Not a single address: an entire subnet routed to your server, so each container or service can hold its own public IPv6 address without network address translation. This matters more than it used to. Large parts of the mobile internet are IPv6-only behind translation, and being natively reachable removes a layer that can only add latency and failure modes. One warning: firewall rules that only cover IPv4 leave every service on your instance publicly reachable over v6. Check that your ruleset covers both families. Source: https://onionvps.com/answers/do-you-provide-ipv6 #### What is a snapshot and how is it different from a backup? A snapshot is a point-in-time copy of your instance's disk, taken instantly and stored on the same infrastructure. A backup is a copy stored elsewhere. Snapshots protect against your own mistakes; backups protect against infrastructure failure. You need both, and three snapshots are included free on every plan. Snapshots are instant and taken without pausing the instance, which makes them ideal before an upgrade, a configuration change or an experiment. Restoring is a two-minute operation. They are not a disaster-recovery strategy. If the underlying storage is lost, the snapshots go with it. Our nightly encrypted backup add-on writes to a second jurisdiction, which is the property that actually matters. Source: https://onionvps.com/answers/what-is-a-snapshot #### How do I back up a VPS properly? Follow the 3-2-1 rule: three copies, on two kinds of media, one off-site. In practice that means snapshots for quick rollback, plus an encrypted nightly backup with restic or Borg to a different jurisdiction, plus a restore you have actually tested. An untested backup is a hypothesis. Back up the data, not the machine. Databases need a proper dump or a filesystem-consistent snapshot, not a naive file copy of a running data directory, which produces a corrupt copy that appears to succeed. Encrypt before the data leaves the instance. restic and Borg both encrypt client-side, so the backup target — including ours — never sees plaintext. - restic backup /srv --repo sftp:backup-host:/repo, with a password file - Dump databases first: pg_dump or mariabackup, then back up the dump - Keep at least one copy in a different jurisdiction - Schedule a restore test quarterly and put it in a calendar Source: https://onionvps.com/answers/how-to-back-up-a-vps #### How do I reset a forgotten root password? Use the out-of-band VNC console in the panel, reboot into single-user or rescue mode from the bootloader, remount the root filesystem read-write and run passwd. It takes about two minutes and needs no support ticket. If the disk is LUKS-encrypted and you have lost the passphrase, the data is unrecoverable by design. The panel also offers a password reset that injects a new credential at next boot, which is faster if the instance still boots normally. A better long-term answer is key-based authentication with a key stored in a password manager. It removes this failure mode entirely, and it is what the security guidance recommends anyway. Source: https://onionvps.com/answers/how-to-reset-a-forgotten-root-password #### What is an out-of-band console and why does it matter? An out-of-band console attaches to your instance's virtual display and keyboard through the control panel, independently of its network. It is how you fix a firewall rule that locked you out, a broken SSH configuration, or a boot failure — without opening a support ticket. It works even when the instance has no network at all. It is also how custom ISO installation works: you attach the ISO, boot, and watch the installer exactly as if you were standing in front of a physical machine. Providers without one turn every misconfiguration into a support interaction with a wait attached. It is included on every OnionVPS plan, including the $4 one. Source: https://onionvps.com/answers/what-is-out-of-band-console #### How do I move my VPS to another country? Data has to physically move, so a region change is a rebuild rather than a live migration. Deploy the new instance, sync the data with rsync or a restic restore, verify, cut DNS over with a short TTL, then destroy the old one. Plan for 30 to 90 minutes depending on data volume. Lower the DNS TTL to 300 seconds at least a day before the move, so the cutover is quick when you make it. Raising it back afterwards is optional but tidy. For a near-zero-downtime move, run both instances in parallel with the application in read-only mode during the final sync. For most projects a short maintenance window is simpler and entirely acceptable. Source: https://onionvps.com/answers/how-to-migrate-a-vps-to-another-country #### Should I use Ubuntu or Debian on my server? Use Ubuntu LTS if you are learning or want the largest body of tutorials and newer packages. Use Debian for a minimal, predictable, long-lived server — it idles in roughly half the memory, ships no Snap and no vendor telemetry. Both use the same package format, so most instructions transfer directly. On a 1 GB instance the difference is material: Debian idles around 120 MB and Ubuntu around 250 MB. On an 8 GB instance it is irrelevant and you should choose on documentation and package freshness instead. For servers you intend to forget about, Debian stable is the better instinct. For servers you will actively develop on, Ubuntu's newer toolchain saves real time. Source: https://onionvps.com/answers/ubuntu-or-debian-for-a-server ### Performance & reliability Steal time, latency, benchmarking and what uptime numbers really mean. #### What is CPU steal time and why does it matter? Steal time is the percentage of time your virtual CPU was ready to run but the hypervisor gave the physical core to someone else. It appears as the "st" column in top. Anything consistently above 2–3% means you are competing for the core, and it is the usual cause of unexplained latency spikes on a shared-vCPU instance. Steal time is invisible to your application: the code runs at full speed when it runs, it just does not always get to run. That is why it shows up as tail latency rather than as slow throughput, and why average response times can look fine while the 99th percentile is terrible. The fix is dedicated vCPU, where a physical thread is reserved for you and no other tenant is scheduled against it. Two dedicated cores routinely outperform four shared ones for anything latency-sensitive. Source: https://onionvps.com/answers/what-is-cpu-steal-time #### Why is my VPS slow? In order of likelihood: memory exhaustion causing swap thrashing, disk IO saturation, CPU steal time on shared cores, an unoptimised database, or network latency to your users. Check free -h and the st column in top first — between them they identify the cause about eighty per cent of the time. Memory is the most common culprit and the least obvious. Once the working set exceeds RAM, the kernel swaps, and disk latency replaces memory latency — a factor of ten thousand. The symptom is a server that feels fine and then suddenly does not. The second most common is disk. Run ioping or fio: NVMe should show sub-millisecond latency. If it does not, either you are on the wrong storage tier or a neighbour is saturating it. - free -h — if swap is in use and growing, that is the answer - top — the st column above 2–3% means steal time - iostat -x 1 — %util near 100 means disk saturation - Database slow query log — usually a missing index, not a small server - mtr to a user network — packet loss on a path is not a server problem Source: https://onionvps.com/answers/why-is-my-vps-slow #### How much latency should I expect from a VPS? Within a metro, under 5 ms. Within a continent, 10–40 ms. Across the Atlantic, 70–90 ms. Europe to Asia, 150–200 ms. Antipodal routes, 250–320 ms. Light in fibre travels at roughly two-thirds of c and real paths are about 1.35 times the great-circle distance, so about 1 ms per 100 km each way is the floor. That floor is physics and no provider beats it. What a good network does is get you close to it — direct peering rather than three transit hops, and no congested links adding jitter on top of distance. Every location page here publishes an estimated round trip to every other location, computed from great-circle distance with the routing factor applied. The method is published so the numbers are reproducible rather than promotional. Typical round-trip times: | Route | Approximate RTT | | --- | --- | | Same city | <2 ms | | Amsterdam ↔ Frankfurt | ~8 ms | | London ↔ New York | ~72 ms | | Frankfurt ↔ Singapore | ~160 ms | | Los Angeles ↔ Tokyo | ~105 ms | | Miami ↔ São Paulo | ~115 ms | | London ↔ Sydney | ~275 ms | Source: https://onionvps.com/answers/how-much-latency-should-i-expect #### How many visitors can a VPS handle? A well-configured 2 vCPU / 4 GB instance serves a static site to millions of monthly visits, a cached WordPress site to roughly 300,000, and an uncached dynamic application to perhaps 30,000. The variable that dominates is caching, not hardware — the same instance differs by two orders of magnitude depending on it. Think in requests per second at peak rather than visits per month. A million monthly visits at three pages each is about 1.2 requests per second on average, and perhaps ten at peak. That is trivial for any instance. The problem is never the average; it is the spike. Full-page caching is the single largest lever available. Serving a cached HTML file costs microseconds; rendering the same page through PHP and a database costs tens or hundreds of milliseconds. Source: https://onionvps.com/answers/how-many-visitors-can-a-vps-handle #### How do I benchmark a VPS? Measure the three things that actually vary: single-thread CPU with sysbench, disk with fio at 4K random read/write, and network with iperf3 to a known endpoint. Run each several times across different hours — a single benchmark measures that minute, not the server. Disk is where providers differ most and where synthetic marketing numbers are least useful. Test 4K random IOPS with a queue depth of 1, which is what a database actually does, rather than sequential throughput, which looks impressive and predicts nothing. Watch steal time throughout the run. A benchmark that looks good at 03:00 and poor at 20:00 is telling you about your neighbours rather than about the hardware. - sysbench cpu --cpu-max-prime=20000 run — single-thread performance - fio --name=rand --rw=randrw --bs=4k --iodepth=1 --size=1G --runtime=60 - iperf3 -c a-known-endpoint — real throughput, not the advertised port speed - vmstat 1 during all of it — watch the st column Source: https://onionvps.com/answers/how-to-benchmark-a-vps #### How much faster is NVMe than SATA SSD? Roughly five times the random IOPS — about 500,000 versus 90,000 — and around five times lower latency, under 0.1 ms versus about 0.5 ms. Sequential throughput is six to ten times higher. For database-backed applications the random-IOPS gap is the one you actually feel. NVMe talks to the CPU over PCIe with a deep parallel queue model, while SATA inherits a single-queue protocol designed for spinning disks. The difference is architectural rather than incremental. Against a mechanical drive the comparison stops being meaningful: a 7,200 RPM disk manages roughly 150 random IOPS. That is why we use HDD only on the Hold line, where the access pattern is large and sequential. Source: https://onionvps.com/answers/nvme-vs-ssd-performance #### What uptime should I expect from a VPS? Our SLA is 99.99% per instance, which permits about 4.4 minutes of downtime a month, and observed availability across the fleet over the last twelve months was 99.993%. Anything beyond that requires redundancy you build yourself — a single machine, however good, is a single point of failure. Read what an SLA actually covers. Ours covers network and hypervisor availability, and credits are automatic once a breach is confirmed. It does not cover your operating system, your application, or a firewall rule you wrote. The gap between 99.9% and 99.99% is the difference between 43 minutes and 4.4 minutes a month. If that matters to you, the answer is three instances in three regions, not a larger single instance. Source: https://onionvps.com/answers/what-uptime-should-i-expect #### Does server location affect SEO? Indirectly and measurably. Search engines do not rank by server country, but they do measure page speed, and distance is latency. A server 200 ms from your users costs real Core Web Vitals score. Use a CDN if your audience is global; place the origin near your audience if it is regional. For local search intent, ccTLD and hreflang signals matter far more than where the hardware sits. A .fr domain served from Panama ranks in France; a .com served from Paris does not automatically rank better there. The measurable mechanism is Time to First Byte, which feeds directly into Core Web Vitals and therefore into ranking. That is a latency problem, and a CDN in front of the origin solves it regardless of where the origin lives — which is what makes offshore hosting and good SEO entirely compatible. Source: https://onionvps.com/answers/does-server-location-affect-seo #### What is DDoS protection and do I need it? DDoS protection filters attack traffic upstream of your server so legitimate requests still arrive. It has to be always-on to be useful — mitigation that activates after an attack starts has already let you go down. OnionVPS includes up to 12 Tbps of L3/L4 scrubbing at every tier, including the $4 plan. There are two distinct layers. Network-level attacks flood your connection with volume and are stopped by upstream scrubbing. Application-level attacks send requests that look legitimate but are expensive to answer, and need filtering that understands the protocol. Game servers, anything crypto-adjacent, and anything with a competitor are attacked routinely. The attacks are cheap to launch and often come from teenagers with a $10 subscription, which is precisely why protection has to be standard rather than an upgrade. Source: https://onionvps.com/answers/what-is-ddos-protection #### Is a VPS secure? The isolation is strong: KVM enforces separation in hardware, and escaping it is a serious research-grade exploit. The realistic risk is not the hypervisor — it is your configuration. Password SSH, unpatched software and an open service you forgot about account for essentially all real-world compromises. Assume the provider can technically read an unencrypted disk, because that is true of every virtualisation platform including every hyperscaler. Full-disk encryption with a passphrase the provider never holds is the only structural answer, and it only protects data at rest. Everything else is ordinary server hygiene: keys not passwords, default-deny firewall, automatic security updates, minimal exposed surface, and tested backups. Those five things are worth more than any provider feature. Source: https://onionvps.com/answers/is-a-vps-secure #### What is the difference between shared and dedicated vCPU? A shared vCPU is scheduled against other tenants, so under contention your process waits — visible as steal time. A dedicated vCPU is a physical thread reserved for you with nothing else scheduled on it. Shared is fine for idle-most-of-the-time work; dedicated is necessary for anything with a latency requirement. The price difference is roughly 40–60%, and it buys consistency rather than peak speed. A shared core is just as fast when it runs; it simply does not always run. Rule of thumb: if a human or a market is waiting for the response, buy dedicated. If a background job is, shared is genuinely fine and cheaper. Source: https://onionvps.com/answers/shared-vs-dedicated-vcpu-difference ### Locations & jurisdictions Where to put a server, and what changes when you move it. #### Which VPS location is best for European users? Frankfurt or Amsterdam for the lowest latency — DE-CIX and AMS-IX are the two densest exchanges in Europe and both reach most of the continent inside 25 ms. If you want European latency without a Fourteen Eyes jurisdiction, Sofia, Bucharest or Chișinău are the practical answers, at a cost of about 10–20 ms. Germany and the Netherlands win on connectivity and lose on jurisdiction: Germany is a Fourteen Eyes member and the Netherlands a Nine Eyes member. Bulgaria and Romania are EU members outside the alliances, and Moldova is outside the EU entirely. For Iberia use Madrid or Lisbon; Lisbon additionally lands the EllaLink cable, giving roughly 60 ms straight to Brazil. For the Nordics use Stockholm or Helsinki. For Eastern Europe, Warsaw and Bucharest have the best onward routes. Source: https://onionvps.com/answers/best-vps-location-for-europe #### Which VPS location is best for Asian users? Singapore for Southeast Asia and India, Tokyo for Japan and Korea, Hong Kong for Greater China, and Mumbai for the subcontinent. Singapore is the safest single choice: more than fifteen submarine cables land there, giving predictable latency across the whole region. If jurisdiction matters as much as latency, Kuala Lumpur is the offshore-tier answer for Asia — outside every Western alliance framework, with direct capacity to Singapore and Hong Kong and only a few milliseconds of penalty. For China specifically, no offshore location is reliably fast; cross-border throughput is shaped and variable. Hong Kong is the least-bad option, and Taipei offers routes independent of mainland transit. Source: https://onionvps.com/answers/best-vps-location-for-asia #### Which VPS location is best for Latin America? São Paulo for Brazil — IX.br is the largest exchange in the southern hemisphere and nothing else comes close for Brazilian users. Miami for the rest of the region, since most Latin American cables land there. Panama City if you want regional latency plus an offshore jurisdiction, and Santiago or Bogotá for Andean coverage. Brazil deserves a local instance rather than a US one. International routes from Brazil are congested and variable, and the difference between São Paulo and Miami for Brazilian users is typically 100 ms or more. Panama is the interesting case: excellent connectivity to both Americas and a jurisdiction outside every alliance, which is why it is our founding region. Source: https://onionvps.com/answers/best-vps-location-for-latin-america #### Which VPS location is best for African users? Johannesburg for southern Africa — NAPAfrica is by far the largest exchange on the continent. Lagos for West Africa, Nairobi for East Africa, and Cairo or Casablanca for the north. Dubai is often faster than any African location for East Africa, because of how cable routing actually works. African connectivity has improved dramatically as the Equiano and 2Africa cables have landed, but intra-continental routing still frequently transits Europe. Testing beats assuming: a route from Accra to Nairobi may well go via Marseille. For services aimed at the whole continent, Johannesburg plus a European origin usually outperforms any single African location. Source: https://onionvps.com/answers/best-vps-location-for-africa #### How do I get US latency without US jurisdiction? Nassau in the Bahamas is roughly 45 ms from Miami, and Panama City about 60 ms — both outside US jurisdiction, outside the Eyes alliances, and with no DMCA applicability. Toronto and Montreal are closer still but Canada is a Five Eyes member, so they solve latency without solving jurisdiction. The DMCA is the practical driver of this question. It is US statute and binds US-situated providers; a server in the Bahamas or Panama is governed by local copyright law, which generally requires a court order rather than a notice. For the US West Coast the honest answer is that there is no good offshore option — the nearest non-US locations are Vancouver, which is Five Eyes, or crossing the Pacific. Consider a US edge for latency with the origin offshore. Source: https://onionvps.com/answers/best-vps-for-us-latency-without-us-jurisdiction #### Is Switzerland good for privacy-focused hosting? Yes — it has the strongest and best-tested statutory framework in our fleet. Swiss law treats hosted data much like correspondence, so disclosure requires Swiss judicial process rather than a foreign administrative request. Switzerland is not in the EU and not in the Five, Nine or Fourteen Eyes alliances. It is also our most expensive region. Switzerland has its own data-protection law, the FADP, revised in 2023 to align closely with the GDPR, and holds an EU adequacy decision — which means EU personal data can be transferred there without additional safeguards. That combination is rare. Zurich also has excellent European connectivity, so unlike some privacy jurisdictions you are not trading latency for law. The trade here is purely cost. Source: https://onionvps.com/answers/is-switzerland-good-for-hosting #### Is Panama good for offshore hosting? Yes, and it is where OnionVPS started. Panama is outside every intelligence-sharing alliance, imposes no general data-retention obligation on hosting providers, and is not subject to the DMCA. It also sits on the submarine cable crossroads between North and South America, so latency to both is genuinely good. Panama's appeal is the absence of applicable statute rather than the presence of strong protective law. That is a different kind of protection from the Swiss model, and which one suits you depends on whether you would rather rely on law or on its absence. It is also the practical answer for anyone who wants Americas latency without US jurisdiction: roughly 60 ms to Miami and 110 ms to São Paulo, with no DMCA exposure. Source: https://onionvps.com/answers/is-panama-good-for-hosting #### Is Iceland good for hosting? Yes, particularly for publishing and journalism. Iceland is in none of the Eyes alliances, has unusually strong constitutional speech protection developed under the IMMI framework, runs on essentially entirely geothermal and hydroelectric power, and gets free cooling year-round. The cost is about 20–30 ms of extra latency to mainland Europe. Iceland is in the EEA, so the GDPR applies — which is a benefit if you process EU personal data and a consideration if you would rather be outside that regime entirely. It is our recommended jurisdiction for Tor relays and for publishing projects, where the combination of speech protection and no alliance membership matters more than the last twenty milliseconds. Source: https://onionvps.com/answers/is-iceland-good-for-hosting #### How many locations and countries do you offer? OnionVPS operates 138 locations across 116 countries and 8 regions, including offshore and privacy-tier jurisdictions such as Panama, Seychelles, Switzerland, Iceland, Moldova, Curaçao, Belize and Mauritius. Twenty-nine locations are offshore or privacy-tier, and 107 sit outside every Eyes alliance. Every location runs the same platform and the same no-KYC signup. Locations are grouped into four tiers. Offshore and privacy-tier regions sit outside the Eyes alliances and, in most cases, outside EU data-retention rules. Core regions are high-capacity sites on the major internet exchanges. Edge regions provide latency coverage in markets that would otherwise be badly served. The full machine-readable list, including coordinates, alliance membership, GDPR applicability and capability flags, is published at /data/locations.json for anyone — human or automated — who wants to compare properly. Source: https://onionvps.com/answers/how-many-locations-do-you-have ### About OnionVPS Who we are, what we hold, and what we will and will not do. #### What is OnionVPS? OnionVPS is an offshore VPS hosting provider founded in 2020 and incorporated in Seychelles. It sells KVM virtual servers in 138 locations across 116 countries, requires no identity verification, accepts only cryptocurrency, and retains no connection logs. Plans start at $4 a month and provision in under a minute. The company was built around a single constraint: collect as little as possible about customers, so that there is as little as possible to lose, sell or be compelled to disclose. Everything else — crypto-only billing, the absence of a signup form, the jurisdiction choices — follows from that. It is not a "bulletproof" host. OnionVPS does not host malware command-and-control, phishing or child sexual abuse material, and it answers valid legal process from courts with jurisdiction over it. The distinction is deliberate and stated plainly in the acceptable use policy. Company facts: | Fact | Value | | --- | --- | | Founded | 2020 | | Incorporation | Seychelles (International Business Company) | | Locations | 138 across 116 countries | | Virtualisation | KVM only | | Payment | Cryptocurrency only, via OxaPay | | Identity verification | None | | Connection logs | Not generated | | Entry price | $4/month | | Uptime SLA | 99.99% | Source: https://onionvps.com/answers/who-is-onionvps #### How long has OnionVPS been operating? Since 2020. The first region was Panama City; Zurich, Amsterdam, Frankfurt, Hong Kong, Singapore, New York and Ashburn followed in the same year. The network has expanded every year since and now spans 138 locations in 116 countries across eight regions. Growth has been region-led rather than product-led: the plan lines have changed little since launch, while the footprint has expanded from one country to more than ninety. Observed availability across the fleet over the last twelve months was 99.993%, against a published SLA of 99.99%. Source: https://onionvps.com/answers/how-long-has-onionvps-been-operating #### What makes OnionVPS different from other VPS providers? Four things: no identity verification of any kind, crypto-only payment with no card or bank involved, 138 locations in 116 countries including genuine offshore jurisdictions, and an architecture that generates no connection logs. Combined with KVM-only virtualisation, included DDoS protection and open port 25 at every tier. Most providers offer some of this. Very few offer all of it, and almost none offer it at the $4 entry price rather than as a premium privacy product. The things included at every tier are as telling as the things absent. DDoS mitigation, a routed IPv6 /64, self-service reverse DNS, custom ISO upload and an out-of-band console are all standard, including on the cheapest plan. Elsewhere most of those are upsells. - No name, address, document, phone number or card — ever - Crypto-only checkout across 20 coins and 15+ networks - 138 locations in 116 countries, including offshore jurisdictions - KVM only — never OpenVZ or LXC resold as a VPS - Port 25 open and reverse DNS self-service at every tier - No connection logs generated, in jurisdictions with no retention mandate Source: https://onionvps.com/answers/what-makes-onionvps-different #### What is your uptime SLA? 99.99% per instance, measured monthly on network and hypervisor availability. Breaches earn automatic service credits on a published scale: 10% below 99.99%, 25% below 99.9%, 50% below 99.5% and 100% below 99%. Observed availability across the fleet over the last twelve months was 99.993%. The SLA covers what we control: the network, the hypervisor and the control plane. It does not cover your operating system, your application, or a firewall rule that locked you out — no provider SLA does, and any that claims to is not describing something it can measure. Credits are applied automatically once a breach is confirmed, without you having to claim them. Source: https://onionvps.com/answers/what-is-your-uptime-sla #### How do I contact support? Through the encrypted ticket desk in the control panel, by email to support@onionvps.com, or over Telegram and XMPP. Support is staffed 24/7/365 and the median first response over the last quarter was about 12 minutes. Signal is available on Bastion and Clipper plans. Every channel accepts PGP; our key fingerprint is published on the contact page and on the warrant canary. For anything sensitive, use it. Support is unmanaged-hosting support: we answer platform questions, provide console access and restore snapshots. We do not administer your operating system, and we will tell you plainly when a question falls on your side of that line. Source: https://onionvps.com/answers/how-do-i-contact-support #### Is OnionVPS a legitimate hosting provider? OnionVPS is a registered Seychelles International Business Company operating since 2020, running its own AS200558 network with transit from Cogent, Lumen, Arelion, GTT and Telia, and peering at DE-CIX, AMS-IX, LINX, Equinix Ashburn, HKIX and NL-ix. It publishes a warrant canary, an SLA with credits and a full acceptable use policy. Reasonable due diligence for any anonymous-friendly provider: check that the ASN is real and announced, that the abuse contact resolves, that there is a published AUP describing what is not allowed, and that the refund policy is stated rather than implied. All four are verifiable here without contacting us. Be sceptical of providers that claim to ignore all legal process. That claim is either false or describes a business that will not exist next year — and either way it means blocklisted address space. Source: https://onionvps.com/answers/is-onionvps-legitimate --- ## 6. Comparisons (24) ### VPS vs dedicated server: which do you actually need? VPS vs Dedicated server A VPS is a slice of a physical machine with guaranteed CPU, RAM and disk; a dedicated server is the whole machine. A VPS wins on price, provisioning speed and elasticity. A dedicated server wins when you need every cycle, direct hardware access, or a workload that would be an unfair neighbour. Most projects that think they need dedicated hardware need dedicated cores, which a VPS provides. | Dimension | VPS | Dedicated server | | --- | --- | --- | | Provisioning time | Under 60 seconds | Hours to days | | Entry price | From $4/month | From ~$70/month | | CPU | Shared or dedicated vCPU | All physical cores | | Resizing | Live, in minutes | Physical migration | | Hardware access | Virtualised | Direct — GPU, RAID controller, TPM | | Noisy neighbours | None with dedicated vCPU | Impossible by definition | | Best for | Almost everything | Sustained 100% load, special hardware | Choose VPS: Choose a VPS unless you have measured a specific reason not to. Dedicated vCPU removes the noisy-neighbour problem, which is the usual reason people reach for bare metal. Choose Dedicated server: Choose dedicated hardware when you need physical devices, sustained full utilisation across many cores, or licence terms that bill per physical socket. Q: Is a VPS slower than a dedicated server? A: Per core, barely — modern KVM overhead is in the low single-digit percentages. The difference people actually feel is steal time on shared cores, which dedicated vCPU eliminates. Q: When is a dedicated server worth the price? A: When you sustain high utilisation across many cores for most of the month, need physical hardware such as a GPU or a hardware security module, or have licensing that counts physical sockets. Source: https://onionvps.com/compare/vps-vs-dedicated-server ### VPS vs shared hosting: the real differences VPS vs Shared hosting Shared hosting gives you a directory on a machine that hundreds of other sites also use, with no root access and hard limits on processes, memory and inodes. A VPS gives you an isolated machine with guaranteed resources and full root. Shared hosting is cheaper and requires no administration; a VPS is the point at which you stop being limited by someone else's configuration. | Dimension | VPS | Shared hosting | | --- | --- | --- | | Root access | Full | None | | Resources | Guaranteed and isolated | Shared, with hard caps | | Software | Anything you can install | Whatever the host provides | | Neighbours | Cannot affect you | Routinely do | | Entry price | From $4/month | From ~$3/month | | Administration | Yours | The provider's | | Suspension risk | Only for genuine abuse | Common, for resource use | Choose VPS: Choose a VPS as soon as you need a specific PHP version, a background worker, a non-web service, or freedom from arbitrary process limits. Choose Shared hosting: Choose shared hosting for a brochure site you never want to administer. Q: Is a VPS harder to manage than shared hosting? A: Yes, materially. You own updates, firewalling and backups. That is the price of not being limited by someone else's configuration. Q: Can shared hosting run Docker or a background worker? A: Almost never. Both need process control that shared hosting does not grant. This is the most common reason people move to a VPS. Source: https://onionvps.com/compare/vps-vs-shared-hosting ### VPS vs cloud hosting: cost, control and lock-in VPS vs Hyperscaler cloud A VPS is a fixed machine at a fixed monthly price. Hyperscaler cloud is a catalogue of managed services billed per unit of consumption. For a workload with predictable load, a VPS is typically three to ten times cheaper for the same compute — the cloud premium buys elasticity and managed services you may never use, plus egress charges that a flat-rate VPS does not have. | Dimension | VPS | Hyperscaler cloud | | --- | --- | --- | | Pricing model | Flat monthly | Per second, per request, per GB | | Egress bandwidth | Included in the plan | Billed per GB, often the largest line | | Predictability | The bill is the plan price | Variable; surprises are common | | Elasticity | Resize in minutes | Autoscale in seconds | | Managed services | You run them | Extensive catalogue | | Lock-in | None — it is a Linux box | High with proprietary services | | Identity requirements | None here | Card and identity verification | Choose VPS: Choose a VPS for steady-state workloads, predictable billing, heavy egress, and anything you want to keep portable. Choose Hyperscaler cloud: Choose hyperscaler cloud for genuinely spiky demand, or when a managed service replaces a team you do not have. Q: Is a VPS cheaper than AWS or Google Cloud? A: For steady workloads, substantially — often by a factor of three to ten once egress is counted. Cloud wins when demand is spiky enough that you would otherwise pay for idle capacity. Q: Why is cloud egress so expensive? A: Because it is priced as a product rather than a cost. A VPS with 10 TB included would cost hundreds of dollars a month in hyperscaler egress alone. Source: https://onionvps.com/compare/vps-vs-cloud-hosting ### KVM vs OpenVZ: why the virtualisation type matters KVM vs OpenVZ / LXC KVM is full hardware virtualisation: your instance runs its own kernel and cannot see the host. OpenVZ and LXC are container technologies that share the host kernel, which means no custom kernel modules, no WireGuard on older hosts, unreliable Docker, and memory accounting that lets the provider oversell. If a VPS is unusually cheap, it is usually OpenVZ. | Dimension | KVM | OpenVZ / LXC | | --- | --- | --- | | Kernel | Your own | Shared with the host | | Custom kernel modules | Yes | No | | Docker | Fully supported | Unreliable or unsupported | | Nested virtualisation | Yes | No | | Non-Linux systems | FreeBSD, OpenBSD, Windows | Linux only | | Memory guarantee | Truly reserved | Frequently oversold | | Overhead | 2–5% | Near zero | | Swap | Real swap | Emulated or absent | Choose KVM: Choose KVM for anything real. Every OnionVPS instance is KVM, without exception. Choose OpenVZ / LXC: OpenVZ is defensible only for the very cheapest single-purpose containers where you control nothing about the kernel. Q: Can I run Docker on an OpenVZ VPS? A: Usually not, and where it appears to work it depends on unsafe host configuration. Docker needs cgroups and namespaces that container-based virtualisation does not expose. Use KVM. Q: How do I tell whether a VPS is KVM or OpenVZ? A: Run systemd-detect-virt, or check whether uname -r shows a kernel you can replace. On OpenVZ you cannot install a different kernel at all. Source: https://onionvps.com/compare/kvm-vs-openvz ### KVM vs LXC: isolation versus density KVM vs LXC containers LXC containers share the host kernel and start in milliseconds with almost no overhead; KVM virtual machines boot their own kernel with 2–5% overhead and a genuine security boundary. For multi-tenant hosting the distinction is decisive: a kernel vulnerability in an LXC host is a vulnerability affecting every tenant on it. | Dimension | KVM | LXC containers | | --- | --- | --- | | Isolation boundary | Hardware-enforced | Kernel namespaces | | Boot time | 5–15 seconds | Under a second | | Overhead | 2–5% | Under 1% | | Density | Lower | Much higher | | Kernel choice | Yours | The host's | | Multi-tenant safety | Strong | Depends entirely on the host kernel | Choose KVM: Choose KVM whenever the tenants do not trust each other — which includes every commercial hosting scenario. Choose LXC containers: LXC is excellent inside your own trust boundary, for example as containers on a KVM instance you already own. Q: Is LXC less secure than KVM? A: The isolation boundary is weaker by construction. A kernel escape in LXC reaches every container on the host; the equivalent in KVM requires a hypervisor escape, which is a substantially harder class of bug. Q: Can I run LXC inside a KVM VPS? A: Yes, and it is a good pattern: hardware isolation from other customers, cheap container isolation for your own services. Source: https://onionvps.com/compare/kvm-vs-lxc ### Offshore vs onshore hosting: what actually changes Offshore hosting vs Onshore hosting Offshore hosting means placing a server in a jurisdiction other than your own, usually one outside the Fourteen Eyes alliances and outside EU data-retention rules. What changes is the legal process required to compel data: a foreign authority must work through mutual legal assistance treaties rather than issuing a domestic order. What does not change is that local law still applies, and that genuinely illegal content is still illegal. | Dimension | Offshore hosting | Onshore hosting | | --- | --- | --- | | Legal process to compel data | MLAT or letters rogatory — slow | Domestic order — fast | | Data retention mandate | Usually none | Often mandatory (EU, UK) | | Copyright procedure | Court order in most jurisdictions | Notice-and-takedown (US DMCA) | | Alliance membership | None in our offshore tier | Five/Nine/Fourteen Eyes | | Latency to your users | Usually higher | Lowest | | Still illegal if illegal | Yes | Yes | Choose Offshore hosting: Choose offshore when jurisdiction is part of your threat model: journalism, research, controversial-but-lawful publishing, or simply not wanting your infrastructure enumerable domestically. Choose Onshore hosting: Choose onshore when latency to your users is the dominant requirement and your legal exposure is ordinary. Q: Is offshore hosting legal? A: Yes. Renting a server in another country is an ordinary commercial act. It changes which law governs the server, not whether law applies. Illegal content remains illegal wherever it is hosted. Q: Does offshore hosting make me anonymous? A: It removes one correlation point — the provider's customer records — but nothing else. Anonymity comes from how you pay, how you connect, and what you run. Source: https://onionvps.com/compare/offshore-vs-onshore-hosting ### No-KYC vs KYC hosting: what the provider knows about you No-KYC hosting vs KYC hosting KYC hosting requires government identification, a billing address and usually a payment card before provisioning. No-KYC hosting requires an email address and a crypto payment. The practical difference is what exists to be disclosed, breached or sold: a provider that never collected your passport cannot lose it, hand it over, or correlate it with your activity. | Dimension | No-KYC hosting | KYC hosting | | --- | --- | --- | | Identity documents | None | Passport or ID, often a selfie | | Payment trail | Crypto — no bank linkage | Card or bank — fully linked | | Provisioning time | Minutes | Hours to days, pending review | | Data at risk in a breach | An email address | Full identity dossier | | Response to legal demand | Nothing meaningful exists | Complete customer file | | Chargeback risk | None — crypto is final | Present | Choose No-KYC hosting: Choose no-KYC when you would rather not create an identity record simply to rent a computer, or when speed matters. Choose KYC hosting: KYC is unavoidable when you need invoicing against a corporate account, fiat payment or a formal enterprise contract. Q: Is no-KYC hosting legal? A: Yes. Hosting is not a regulated financial activity, and there is no general legal requirement to identify server customers in the jurisdictions where we operate. Anti-money-laundering identification duties apply to financial institutions, not to compute providers. Q: What do you actually know about me? A: An email address you chose, a payment reference from the processor, and the technical records needed to run the service. No name, no address, no document, no card. Source: https://onionvps.com/compare/no-kyc-vs-kyc-hosting ### Shared vs dedicated vCPU: what steal time costs you Shared vCPU vs Dedicated vCPU A shared vCPU is scheduled against other tenants, so under contention your process waits — visible as steal time in top. A dedicated vCPU is pinned to a physical core reserved for you. For bursty workloads the difference is invisible; for anything latency-sensitive, tick-based or continuously busy, it is the single most important specification on the page. | Dimension | Shared vCPU | Dedicated vCPU | | --- | --- | --- | | Steal time | Possible under contention | Effectively zero | | Sustained load | May be throttled | Unrestricted | | p99 latency | Variable | Consistent | | Price | Lower | ~40–60% higher | | Good for | VPN, DNS, small bots, dev | Databases, games, trading, APIs | Choose Shared vCPU: Shared cores are genuinely fine for idle-most-of-the-time workloads — a VPN endpoint does not care. Choose Dedicated vCPU: Pay for dedicated cores whenever tail latency or sustained throughput matters to someone other than you. Q: How do I check steal time? A: The st column in top or vmstat. Anything consistently above 2–3% means you are competing for the core and should move to dedicated vCPU. Q: Is a dedicated vCPU a whole physical core? A: On our platform it is a reserved physical thread with no other tenant scheduled against it. Terminology varies by provider — always ask what "dedicated" means before comparing prices. Source: https://onionvps.com/compare/shared-vcpu-vs-dedicated-vcpu ### NVMe vs SSD vs HDD for a VPS NVMe vs SATA SSD / HDD NVMe reaches roughly 500,000 random IOPS with sub-100-microsecond latency; a SATA SSD manages around 90,000 IOPS; a 7,200 RPM HDD manages about 150. For anything with a database, that gap is the difference between a fast application and a slow one. HDD remains rational for one thing only: bulk sequential storage priced per terabyte. | Dimension | NVMe | SATA SSD / HDD | | --- | --- | --- | | Random IOPS | ~500,000 | SSD ~90,000 / HDD ~150 | | Latency | <0.1 ms | SSD ~0.5 ms / HDD ~10 ms | | Sequential throughput | 3–7 GB/s | SSD ~550 MB/s / HDD ~200 MB/s | | Cost per TB | Highest | HDD lowest by a wide margin | | Best for | Databases, containers, boot | Archives, backups, media | Choose NVMe: Use NVMe for anything with a database, a container runtime or a compiler. It is the default on every line except Hold. Choose SATA SSD / HDD: Use HDD when you are buying terabytes and reading them sequentially — media libraries, seedboxes, backup targets. Q: Does NVMe actually make a website faster? A: If the site has a database, yes and noticeably. Most perceived server slowness is disk latency on queries rather than CPU. Q: Is HDD ever the right choice? A: For bulk sequential storage, absolutely. A 4 TB HDD volume costs a fraction of the NVMe equivalent, and a seedbox or backup target does not care about random IOPS. Source: https://onionvps.com/compare/nvme-vs-ssd-vs-hdd ### Monero vs Bitcoin for paying for hosting Monero (XMR) vs Bitcoin (BTC) Bitcoin's ledger is public: anyone can see that an address paid a hosting invoice, and chain analysis can often connect that address to an exchange account with your identity attached. Monero hides sender, receiver and amount at the protocol level, so no such link exists. If privacy is why you are paying in crypto, Monero is the coin that actually delivers it. | Dimension | Monero (XMR) | Bitcoin (BTC) | | --- | --- | --- | | Ledger visibility | Amounts and parties hidden | Fully public | | Chain analysis | No usable surface | A mature industry | | Confirmation time | ~20 minutes (10 blocks) | ~20 minutes (2 blocks) | | Typical fee | Cents | Variable, sometimes dollars | | Exchange availability | Delisted from several major exchanges | Everywhere | | Ease of acquisition | Harder — DEX or P2P | Trivial | Choose Monero (XMR): Choose Monero when the payment itself must not be linkable. It is the default recommendation for privacy-motivated purchases. Choose Bitcoin (BTC): Choose Bitcoin for convenience and liquidity, and accept that the payment is a permanent public record. Q: Is Bitcoin anonymous? A: No. It is pseudonymous, and the ledger is permanent and public. Commercial chain-analysis firms routinely link addresses to identities via exchange records. Q: Where can I buy Monero if exchanges delisted it? A: Atomic swaps, decentralised exchanges such as Haveno, or peer-to-peer markets. Buying BTC on an exchange and swapping to XMR is the common route. Source: https://onionvps.com/compare/monero-vs-bitcoin-for-hosting ### Paying for hosting with crypto vs a credit card Crypto payment vs Card payment A card payment creates a permanent, identity-linked record at your bank, the card network and the merchant, and can be reversed for up to 120 days. A crypto payment settles in minutes, is final, and links to no banking identity. The trade-off is real: no chargeback protection, and price volatility on non-stablecoins between invoice and confirmation. | Dimension | Crypto payment | Card payment | | --- | --- | --- | | Identity linkage | None | Bank, network and merchant | | Settlement | Minutes, final | Days, reversible | | Chargebacks | None | Up to 120 days | | Fees | ~1% network | 2.9% + fixed, paid by the merchant | | Availability | Global, no bank needed | Requires banking access | | Volatility | Real, unless a stablecoin | None | Choose Crypto payment: Crypto is the right choice when you want no identity linkage, instant settlement, or hosting without a bank account. Choose Card payment: A card is the right choice when you need buyer protection or corporate expense reconciliation. Q: What happens if the price moves after I pay? A: The invoice locks a rate for its lifetime. We accept up to 3% underpayment automatically; larger shortfalls are held and either topped up or refunded. Q: Can I get a refund on a crypto payment? A: Yes, within seven days of first provisioning, sent back to an address you nominate. It is a refund, not a reversal — we initiate it, not your bank. Source: https://onionvps.com/compare/crypto-vs-card-hosting ### WireGuard vs OpenVPN on a VPS WireGuard vs OpenVPN WireGuard is about 4,000 lines of kernel code with modern fixed cryptography; OpenVPN is roughly 100,000 lines in userspace with configurable ciphers. WireGuard is faster, reconnects instantly and is far easier to audit. OpenVPN survives on one advantage: it can run over TCP port 443 and look like ordinary TLS, which matters where UDP is blocked or VPNs are filtered. | Dimension | WireGuard | OpenVPN | | --- | --- | --- | | Throughput on 1 vCPU | ~900 Mbit/s | ~250 Mbit/s | | Codebase size | ~4,000 lines | ~100,000 lines | | Where it runs | Kernel space | User space | | Transport | UDP only | UDP or TCP | | Obfuscation | Needs a wrapper | TCP/443 looks like TLS | | Handshake | Roughly instant | Seconds | | Configuration | A dozen lines | Certificates and a long config | Choose WireGuard: Use WireGuard by default. It is faster, simpler and easier to reason about. Choose OpenVPN: Use OpenVPN where UDP is blocked or where VPN traffic must be indistinguishable from HTTPS. Q: Is WireGuard faster than OpenVPN? A: Substantially — typically three to four times the throughput on the same hardware, because it runs in kernel space with a fixed modern cipher suite. Q: Can WireGuard be blocked? A: Yes. Its handshake is identifiable and it is UDP-only, so networks that filter aggressively can block it. Wrap it in something like udp2raw, or fall back to OpenVPN over TCP/443. Source: https://onionvps.com/compare/wireguard-vs-openvpn ### Self-hosted VPN vs a commercial VPN service Self-hosted VPN vs Commercial VPN A self-hosted VPN removes the provider from your trust equation but also removes the crowd: the exit IP is yours alone, so every request from it is attributable to one person. A commercial VPN mixes you with thousands of users but requires trusting its no-logs claim. Self-hosting wins against interception and geo-restriction; a large shared service wins against traffic correlation. | Dimension | Self-hosted VPN | Commercial VPN | | --- | --- | --- | | Who you trust | Yourself and the host | The VPN company | | Anonymity set | One — you | Thousands per IP | | IP reputation | Clean, and uniquely yours | Often blocklisted | | Cost | $4/month, unlimited devices | $5–12/month, device limits | | Locations | One per instance | Dozens included | | Streaming access | Usually works — clean IP | Frequently blocked | | Protects against correlation | No | Partially | Choose Self-hosted VPN: Self-host when you want a clean IP, unlimited devices, no provider to trust, and full control of the exit. Choose Commercial VPN: Use a commercial VPN when blending into a crowd is the point, or when you need to switch country constantly. Q: Is a self-hosted VPN more anonymous? A: More private, less anonymous. Nobody else uses your exit IP, so activity from it is trivially attributable to a single person — you. Privacy from your ISP: excellent. Anonymity from the destination: worse than a shared service. Q: Can I use a self-hosted VPN for streaming? A: Usually yes, because the IP has no VPN reputation attached. Commercial VPN ranges are systematically blocklisted; a single datacentre IP that nobody else uses often is not. Source: https://onionvps.com/compare/self-hosted-vs-commercial-vpn ### Tor vs VPN: different tools, different threat models Tor vs VPN Tor routes through three volunteer relays chosen so that no single one knows both who you are and where you are going. A VPN routes through one server that knows both. Tor gives you anonymity from the destination at the cost of speed; a VPN gives you privacy from your local network and your ISP at full speed. They solve different problems and are often used together. | Dimension | Tor | VPN | | --- | --- | --- | | Hops | Three, independently operated | One | | Who can see both ends | Nobody, by design | The VPN provider | | Speed | Slow — hundreds of ms | Near line rate | | Cost | Free | $4–12/month | | Blocked by websites | Frequently | Sometimes | | Good against | Destination-side identification | ISP and local-network surveillance | | Bad against | Global traffic correlation | A dishonest provider | Choose Tor: Use Tor when the destination must not learn who you are, and latency is acceptable. Choose VPN: Use a VPN when you need speed and want to move trust from your ISP to a party you chose. Q: Should I use Tor and a VPN together? A: You can, and the order matters. VPN-then-Tor hides Tor use from your ISP; Tor-then-VPN is rarely what people mean and usually weakens rather than strengthens the guarantee. Q: Is Tor illegal? A: No, in the overwhelming majority of countries. It is ordinary privacy software used daily by journalists, researchers and law enforcement alike. Source: https://onionvps.com/compare/tor-vs-vpn ### Ubuntu vs Debian for a VPS Ubuntu vs Debian Both use the same package format and most of the same software. Ubuntu ships newer packages, five-year LTS support and vastly more tutorials; Debian ships a smaller base install, no Snap, no vendor telemetry and a more conservative release policy. For a low-RAM instance Debian idles in roughly half the memory. For a first server, Ubuntu's documentation advantage is decisive. | Dimension | Ubuntu | Debian | | --- | --- | --- | | Base RAM at idle | ~250 MB | ~120 MB | | Package freshness | Newer | Conservative | | Support window | 5 years (LTS) | 5 years (with LTS) | | Snap packages | Yes, some by default | No | | Release cadence | LTS every 2 years | Roughly every 2 years | | Tutorial coverage | The largest of any distribution | Good | Choose Ubuntu: Choose Ubuntu LTS if you want the largest body of documentation and newer packages without compiling anything. Choose Debian: Choose Debian for a minimal, predictable, long-lived server — especially on a 1 GB instance. Q: Is Debian more stable than Ubuntu? A: Debian stable changes less, which is what most people mean by stability. Ubuntu LTS is also production-grade; the real difference is release philosophy, not defect rate. Q: Can I use Ubuntu tutorials on Debian? A: Almost always. The differences are mostly package names, sudo configuration and Ubuntu's use of Snap. Source: https://onionvps.com/compare/ubuntu-vs-debian ### AlmaLinux vs Rocky Linux: does the choice matter? AlmaLinux vs Rocky Linux Both are free rebuilds of Red Hat Enterprise Linux, both offer roughly ten years of support per major release, and both are binary-compatible with RHEL. In practice they are interchangeable. AlmaLinux has moved towards ABI compatibility rather than strict bug-for-bug parity, which lets it ship some fixes sooner; Rocky holds closer to upstream. Pick whichever your vendor documents. | Dimension | AlmaLinux | Rocky Linux | | --- | --- | --- | | RHEL compatibility | ABI-compatible | Bug-for-bug where possible | | Support lifecycle | ~10 years | ~10 years | | Governance | Non-profit foundation | Community foundation | | Hardware support | Broader — restores dropped drivers | Matches upstream | | Control panel support | Universal | Universal | Choose AlmaLinux: Choose AlmaLinux if you want slightly faster security fixes and broader legacy hardware support. Choose Rocky Linux: Choose Rocky if your vendor names it specifically, or you prefer the strictest upstream parity. Q: Is AlmaLinux or Rocky Linux better? A: Neither, meaningfully. They are both credible RHEL rebuilds with a decade of support. Choose on vendor documentation, not technical merit. Q: Are they really free? A: Yes, both are free to use and redistribute, including commercially, with no subscription. Source: https://onionvps.com/compare/almalinux-vs-rocky-linux ### Managed vs unmanaged VPS: who patches the server? Unmanaged VPS vs Managed VPS On an unmanaged VPS the provider guarantees the hardware, the network and the hypervisor; everything above the kernel is yours, including updates, firewalling and backups. A managed VPS adds administration for two to five times the price. Unmanaged is the right default if you are comfortable with a terminal — and the wrong one if nobody on your side will apply a security update. | Dimension | Unmanaged VPS | Managed VPS | | --- | --- | --- | | OS updates | You | Provider | | Firewall and hardening | You | Provider | | Backups | You (add-on available) | Provider | | Root access | Full | Sometimes restricted | | Price multiplier | 1× | 2–5× | | Response to an incident | Yours | Theirs, within an SLA | Choose Unmanaged VPS: Unmanaged is correct if you can use SSH and will actually run updates. Every OnionVPS plan is unmanaged, which is why it is priced the way it is. Choose Managed VPS: Managed is worth it when there is genuinely nobody available to patch the box. Q: What does unmanaged actually mean? A: We keep the hardware, network, hypervisor and control plane running, and we will help with anything on our side of the boundary. The operating system and everything you install on it are yours. Q: Do you help if I break my server? A: We will get you a working console and a snapshot restore, and we answer platform questions. We do not administer your operating system. Source: https://onionvps.com/compare/managed-vs-unmanaged-vps ### Anonymous hosting vs bulletproof hosting: an important distinction Anonymous hosting vs "Bulletproof" hosting Anonymous hosting means the provider does not collect your identity — a privacy property. "Bulletproof" hosting means the provider claims it will ignore all abuse complaints and law enforcement, including for genuinely criminal activity. OnionVPS is the first and explicitly not the second. We hold no identity data, and we also do not host malware command-and-control, phishing, or child sexual abuse material. | Dimension | Anonymous hosting | "Bulletproof" hosting | | --- | --- | --- | | Identity collected | None | None | | Responds to valid court orders | Yes, to the extent data exists | Claims not to | | Hosts malware C2 or phishing | No | Yes | | Network reputation | Clean — mail and APIs work | Blocklisted wholesale | | Longevity | Stable | Seized or deplatformed | | Price | Normal | Very high | Choose Anonymous hosting: Anonymous hosting is what almost everyone asking for "bulletproof" actually wants: privacy, a clean network, and no single-complaint terminations. Choose "Bulletproof" hosting: Bulletproof hosting buys tolerance of criminal activity, and with it blocklisted address space and a short lifespan. Q: Do you ignore abuse complaints? A: No. We ignore speculative and automated complaints that are not legal process. We act decisively on active harm — outbound attacks, phishing, malware distribution, and CSAM, which we report. Q: Why does a clean network matter? A: Because blocklisted address space means your mail is rejected, your API calls are challenged and your users see CAPTCHAs. Bulletproof providers' ranges are blocklisted wholesale. Source: https://onionvps.com/compare/anonymous-vs-bulletproof-hosting ### Panama vs Switzerland for offshore hosting Panama vs Switzerland Both sit outside every intelligence-sharing alliance and outside the EU. Switzerland offers the stronger statutory framework — hosted data is treated much like correspondence, and disclosure requires Swiss judicial process — at a higher price. Panama offers a jurisdiction with very little relevant statute at all, plus the best latency in our fleet to both North and South America. | Dimension | Panama | Switzerland | | --- | --- | --- | | Eyes alliances | None | None | | EU / GDPR | No | No (adequacy decision, not membership) | | Data retention mandate | None | Limited, telecoms-focused | | Statutory data protection | Light | Strong and well tested | | Cost | Lower | Highest in our fleet | | Latency to Americas | Excellent | Poor | | Latency to Europe | Moderate | Excellent | Choose Panama: Choose Panama for Americas latency, lower cost, and a jurisdiction with minimal applicable statute. Choose Switzerland: Choose Switzerland when you want tested legal protection and European latency, and cost is secondary. Q: Which is better for privacy, Panama or Switzerland? A: Switzerland has the stronger and better-tested legal framework. Panama has less law that applies at all. Which is "better" depends on whether you want protection by statute or by absence of statute. Q: Is Swiss hosting subject to the GDPR? A: Not directly. Switzerland is not in the EU; it has its own FADP, revised in 2023 to align closely with the GDPR, and holds an EU adequacy decision. Source: https://onionvps.com/compare/panama-vs-switzerland-hosting ### Iceland vs Netherlands for privacy-oriented hosting Iceland vs Netherlands The Netherlands has the best connectivity in Europe through AMS-IX and the lowest latency to most European users — but it is a Nine Eyes member with EU data-retention exposure. Iceland is in neither the Five, Nine nor Fourteen Eyes, runs on renewable power, and has unusually strong constitutional speech protection. You are trading roughly 20–30 ms of latency for a materially different jurisdiction. | Dimension | Iceland | Netherlands | | --- | --- | --- | | Eyes alliances | None | Nine Eyes | | EU membership | No (EEA) | Yes | | Peering density | Modest | AMS-IX — the best in Europe | | Latency to EU users | +20–30 ms | Lowest available | | Power source | ~100% renewable | Mixed grid | | Free cooling | Year-round | Seasonal | Choose Iceland: Choose Iceland when jurisdiction and energy profile matter more than the last twenty milliseconds. Choose Netherlands: Choose the Netherlands when raw connectivity to European users is the priority. Q: Is Iceland good for hosting? A: Yes, for privacy-motivated projects. It sits outside the Eyes alliances, has strong constitutional speech protection, and its grid is essentially entirely geothermal and hydroelectric. The trade is a small latency penalty. Q: Is the Netherlands a Fourteen Eyes country? A: It is a Nine Eyes member, which is a subset of the Fourteen. Its connectivity is exceptional; its jurisdiction is not the reason to choose it. Source: https://onionvps.com/compare/iceland-vs-netherlands-hosting ### Seychelles vs Belize for offshore infrastructure Seychelles vs Belize Both are classic international business company jurisdictions with strong corporate confidentiality, no data-retention mandate and no alliance membership. Seychelles has the more developed IBC framework and no public beneficial-ownership register; Belize has English common law and better latency to North America. Neither has the connectivity of a mainland location, so both suit control-plane and archival roles rather than latency-critical services. | Dimension | Seychelles | Belize | | --- | --- | --- | | Legal system | Mixed civil and common law | English common law | | Public ownership register | No | No | | Data retention mandate | None | None | | Latency to Europe | ~140 ms | ~120 ms | | Latency to North America | ~230 ms | ~50 ms | | Connectivity | Single cable dependency | Regional | Choose Seychelles: Choose Seychelles for maximum corporate and jurisdictional separation, including from Western legal process. Choose Belize: Choose Belize when you want offshore status with usable North American latency. Q: Why do offshore companies incorporate in Seychelles? A: The IBC framework offers strong confidentiality, no public beneficial-ownership register, minimal reporting, and limited mutual legal assistance exposure. It is also where OnionVPS itself is incorporated. Q: Is island hosting reliable? A: Connectivity depends on fewer cables than a mainland location, so a cable fault has a larger effect. Use island regions for control-plane and archival roles, and pair them with a mainland region for anything latency-critical. Source: https://onionvps.com/compare/seychelles-vs-belize-hosting ### Hourly vs monthly VPS billing Hourly billing vs Monthly billing Hourly billing suits infrastructure that exists for hours — a build farm, a load test, a temporary migration target. Monthly billing is cheaper for anything that runs continuously, and it is the only model that works cleanly with crypto payment, because nobody wants a blockchain transaction every hour. OnionVPS bills monthly, with 5–22% discounts on longer terms. | Dimension | Hourly billing | Monthly billing | | --- | --- | --- | | Best for | Ephemeral workloads | Anything that runs continuously | | Effective cost when always on | Higher | Lower | | Works with crypto payment | Poorly | Naturally | | Surprise bills | Possible | Impossible | | Long-term discounts | Rare | 5–22% here | Choose Hourly billing: Hourly is genuinely better for capacity that lives for less than a week. Choose Monthly billing: Monthly with a term discount is the cheaper and more predictable model for real infrastructure — and the only one that pairs sensibly with crypto. Q: Do you offer hourly billing? A: No. We bill monthly, quarterly, annually or biennially, with discounts up to 22%. Hourly billing and crypto settlement do not combine well, and flat pricing means no surprises. Q: What happens if I cancel mid-term? A: Within seven days of first provisioning you get a full refund. After that the term runs to its end; we do not pro-rate partial months. Source: https://onionvps.com/compare/hourly-vs-monthly-billing ### Network DDoS protection vs a CDN proxy Network DDoS scrubbing vs CDN / reverse proxy Network-level scrubbing filters attack traffic upstream of your server at layers 3 and 4, and it works for any protocol — game servers, DNS, mail, anything UDP. A CDN proxy terminates HTTP and defends layer 7, but only for HTTP, and only if your origin IP never leaks. They are complementary: scrubbing protects the wire, a CDN protects the application. | Dimension | Network DDoS scrubbing | CDN / reverse proxy | | --- | --- | --- | | Layers covered | L3/L4, any protocol | L7, HTTP/HTTPS only | | Works for game servers | Yes | No | | Works for mail or DNS | Yes | No | | Hides origin IP | No | Yes, if never leaked | | Latency added | Fractions of a millisecond | Varies; usually negative for cached content | | Included here | Yes, every tier | Bring your own | Choose Network DDoS scrubbing: Network scrubbing is mandatory for anything non-HTTP, and included at every OnionVPS tier. Choose CDN / reverse proxy: Add a CDN for HTTP workloads: it caches, hides the origin and filters application-layer floods. Q: Do I need both DDoS protection and a CDN? A: For an HTTP service, yes — they cover different layers. For a game server or a DNS resolver, a CDN cannot help at all; network scrubbing is the whole answer. Q: Does a CDN hide my server IP? A: Only if it never leaks. Historical DNS records, mail headers, TLS certificate transparency logs and error pages all leak origin IPs routinely. Source: https://onionvps.com/compare/ddos-protection-vs-cdn ### VPS vs serverless: cost, cold starts and control VPS vs Serverless functions Serverless bills per invocation and scales to zero, which is unbeatable for genuinely intermittent workloads. Past roughly a million invocations a month, a $12 VPS is usually cheaper — and it has no cold starts, no execution time limit, no vendor-specific runtime and no egress surcharge. Serverless optimises for spiky demand; a VPS optimises for steady demand and portability. | Dimension | VPS | Serverless functions | | --- | --- | --- | | Idle cost | Full plan price | Zero | | Cost at scale | Flat | Grows with every request | | Cold starts | None | 100 ms to several seconds | | Execution limit | None | Typically 15 minutes | | Long-lived connections | Native | Awkward or impossible | | Lock-in | None | High | Choose VPS: Choose a VPS for steady traffic, background workers, websockets, and anything you want to move later. Choose Serverless functions: Choose serverless for genuinely bursty, stateless, short work — and watch the invocation count. Q: At what point does a VPS beat serverless on cost? A: Roughly a million invocations a month for a simple handler, and much sooner once egress is counted. Long-running or memory-heavy functions cross over far earlier. Q: Can I run a websocket server on serverless? A: Not straightforwardly. Serverless is designed for short stateless invocations; persistent connections need a managed gateway that adds cost and complexity. A VPS handles them natively. Source: https://onionvps.com/compare/vps-vs-serverless --- ## 7. Workload recommendations (31) ### VPS for a personal VPN server (WireGuard & OpenVPN) A personal VPN needs almost no CPU and almost no disk — it needs bandwidth and a jurisdiction you trust. One shared core, 1 GB of RAM and a WireGuard install will saturate a gigabit port. Choose the location by law, not by specification: a $4 Skiff 1 in Panama or Zurich outperforms a large instance in a Fourteen Eyes country for this purpose. Requirements: - vCPU: 1 shared core is sufficient up to ~900 Mbit/s with WireGuard - RAM: 1 GB (WireGuard uses under 30 MB) - Disk: 20 GB - Transfer: 2 TB covers roughly 8 hours a day of 1080p streaming - Network: Native IPv6 matters — many VPN clients prefer dual stack Recommended plans: skiff-1, skiff-2 Recommended locations: panama-city, zurich, reykjavik, chisinau, kuala-lumpur Setup: 1. Deploy a Skiff 1 in a no-alliance jurisdiction — Panama, Switzerland, Iceland, Moldova or Malaysia. Provisioning takes under a minute. 2. Install WireGuard — apt install wireguard on Debian or Ubuntu; the kernel module is already present. 3. Generate keys and a server config — wg genkey | tee private.key | wg pubkey > public.key, then write /etc/wireguard/wg0.conf. 4. Enable IP forwarding and NAT — Set net.ipv4.ip_forward=1 and add an nftables masquerade rule for the tunnel subnet. 5. Bring the interface up and add peers — systemctl enable --now wg-quick@wg0, then add one [Peer] block per device. Q: Is running your own VPN more private than a commercial VPN? A: It removes the provider from the trust equation but replaces the crowd. Your traffic is no longer mixed with thousands of other users, so the exit IP is uniquely yours. Self-hosting wins when your threat model is interception or geo-restriction; a large shared VPN wins when it is traffic correlation. Q: How much bandwidth does a VPN VPS need? A: Budget your real usage plus 15% for protocol overhead. 1080p video is roughly 3 GB per hour, so 2 TB supports about 650 hours a month. Q: Can I use the VPS as a VPN for my whole household? A: Yes. A single shared core handles 20+ concurrent WireGuard peers comfortably; the limit is your uplink, not the instance. Source: https://onionvps.com/solutions/vpn-server ### VPS for game servers (Minecraft, CS2, Rust, Palworld) Game servers are single-thread bound, so clock speed beats core count. For Minecraft with 10–20 players, 4 GB of RAM on a high-frequency core is the practical floor; CS2 and Rust want 8–16 GB. Pick the Clipper line for its 5.0 GHz turbo, and place the instance within about 60 ms of the majority of your players — latency matters far more than raw hardware. Requirements: - CPU: High single-thread clock. 4 dedicated cores for a 20-slot server - RAM: 4 GB (Minecraft vanilla) / 8 GB (modded, CS2) / 16 GB (Rust) - Disk: NVMe — chunk and map loading is IO-bound - Transfer: 10 TB covers a busy 40-slot server - Protection: Always-on DDoS filtering; game servers are attacked constantly Recommended plans: clipper-8, clipper-16, cutter-16 Recommended locations: frankfurt, ashburn, singapore, sao-paulo, sydney Setup: 1. Choose a location near your player base — Use the latency table on the location page; aim for under 60 ms for the majority. 2. Deploy a Clipper instance with Ubuntu 24.04 — Four dedicated cores and 8 GB is the sensible starting point for most games. 3. Install a panel or run the binary directly — Pterodactyl gives you a web UI; a systemd unit is simpler if you run one server. 4. Open only the ports the game needs — Minecraft 25565/tcp, CS2 27015/udp, Rust 28015/udp. Leave everything else closed. 5. Schedule automatic world backups — Enable nightly encrypted backups, or rsync the world directory to a Hold instance. Q: How much RAM does a Minecraft server need? A: Vanilla with 10 players runs comfortably in 4 GB. Add roughly 100 MB per additional player, and double the total for a heavily modded pack. Q: Does a game server need a dedicated CPU core? A: Yes for anything with real-time physics. Shared cores introduce steal time, which shows up as tick lag exactly when the server is busiest. Q: Can I pay for game hosting anonymously? A: Yes. Checkout is crypto-only and requires nothing but an email address you control. Source: https://onionvps.com/solutions/game-server ### VPS for forex trading bots (MT4, MT5, cTrader) A forex VPS is judged on two numbers: latency to your broker's matching engine and uptime. Two dedicated cores and 4 GB of RAM run several MT4 or MT5 terminals; the location decides everything else. Brokers concentrate in London (LD4/LD5), New York (NY4) and Tokyo, so place the instance in the matching city and expect sub-5 ms round trips. Requirements: - CPU: 2 dedicated cores per 3–4 MT4/MT5 terminals - RAM: 4 GB for 3 terminals, 8 GB for 8+ - Disk: NVMe, 80 GB — tick history grows fast - Location: Same metro as your broker; London and New York cover most - OS: Windows Server for MetaTrader, or Linux with Wine for headless bots Recommended plans: clipper-8, cutter-8 Recommended locations: london, new-york, tokyo, frankfurt, singapore Setup: 1. Ask your broker which datacentre their server lives in — Most publish it; LD4 in Slough and NY4 in Secaucus are the common answers. 2. Deploy in the matching metro — London for LD4/LD5, New York for NY4/NY5, Tokyo for TY3. 3. Install the terminal — Windows Server for MT4/MT5, or Linux plus Wine if you run a headless expert advisor. 4. Measure the real round trip — Use the terminal's own ping display rather than ICMP — it reports the application-layer latency that matters. 5. Harden and monitor — Restrict RDP or SSH to your own IP, and set an alert if the terminal process disappears. Q: What latency should a forex VPS have? A: Under 5 ms to your broker is excellent, under 20 ms is fine for most retail strategies, and above 50 ms starts to cost you on fast fills. Same-metro placement is what gets you there. Q: Can I run several MT4 terminals on one VPS? A: Yes. Budget roughly 1 GB of RAM and half a core per terminal; eight terminals fit comfortably on a Clipper 16. Q: Why pay for a trading VPS in crypto? A: It keeps your trading infrastructure separate from your banking trail, and it means the server can be provisioned in minutes at any hour. Source: https://onionvps.com/solutions/forex-trading-bot ### VPS for crypto trading bots and market makers Crypto exchanges concentrate their matching engines in AWS Tokyo (Binance), AWS Ashburn (Coinbase) and a handful of European regions. A trading bot wants two dedicated high-frequency cores, 4–8 GB of RAM, and placement in the same metro as the exchange. Bandwidth is trivial; websocket jitter is not, which is why dedicated cores beat larger shared instances. Requirements: - CPU: 2–4 dedicated high-frequency cores - RAM: 4 GB for one strategy, 8–16 GB for a multi-pair market maker - Disk: NVMe Gen4 — orderbook snapshots are write-heavy - Network: Consistent jitter matters more than raw throughput Recommended plans: clipper-8, clipper-16 Recommended locations: tokyo, ashburn, frankfurt, singapore, london Setup: 1. Identify your venue's region — Binance and Bybit sit in Tokyo, Coinbase and Kraken in US East, Bitstamp and Bitfinex in Europe. 2. Deploy a Clipper instance in that metro — Four dedicated cores is enough for most single-venue strategies. 3. Pin the process and disable CPU frequency scaling — taskset plus the performance governor removes a surprising amount of jitter. 4. Run the bot under a supervisor — systemd with Restart=always, plus a dead-man alert if no order is placed within N minutes. 5. Keep keys off the box where possible — Use IP-whitelisted, withdrawal-disabled API keys so a compromised instance cannot drain the account. Q: Where should a crypto trading bot be hosted? A: In the same metro as the exchange's matching engine. Tokyo for Binance, US East for Coinbase and Kraken, Frankfurt or London for European venues. Distance is latency, and latency is slippage. Q: Is a VPS fast enough for arbitrage? A: For cross-exchange and funding-rate arbitrage, yes. For sub-millisecond latency arbitrage you need colocation, not a VPS — and that is true of every provider. Q: Do you allow bots and automated trading? A: Yes, without restriction. Automated trading is a normal workload here, not an exception that needs approval. Source: https://onionvps.com/solutions/crypto-trading-bot ### VPS for web scraping and data collection Scraping is memory-bound, not CPU-bound: a headless Chromium tab costs roughly 300 MB, so plan around concurrency. Four cores and 8 GB run about 20 parallel browser contexts. What actually decides success is IP diversity and jurisdiction — you want clean address space, several IPv4 addresses, and a provider that does not terminate accounts over a single complaint about crawl rate. Requirements: - CPU: 4 cores for ~20 concurrent headless browsers - RAM: 8 GB minimum; 16 GB if you render JavaScript at scale - Disk: 160 GB NVMe for caches and artefacts - IPs: Additional IPv4 addresses, added per instance from the panel - Transfer: 10 TB — rendered pages are heavier than they look Recommended plans: cutter-8, cutter-16, clipper-16 Recommended locations: amsterdam, chisinau, sofia, panama-city, kuala-lumpur Setup: 1. Deploy a Cutter 8 with Ubuntu 24.04 — Four dedicated cores and 8 GB is the practical starting point. 2. Install a headless browser stack — Playwright or Puppeteer with the bundled Chromium, run inside Docker for clean teardown. 3. Add IP addresses and rotate outbound — Bind each worker to a different source address with SO_BINDTODEVICE or an outbound proxy. 4. Respect robots.txt and rate limits — Politeness delays keep you off blocklists and keep the project sustainable. 5. Ship results off the box — Stream to object storage or a Hold instance so a rebuild costs you nothing. Q: Is web scraping allowed on your servers? A: Yes, for lawfully accessible public data, at rates that do not degrade the target. We do not permit credential stuffing, bypassing paywalls or authentication, or scraping that constitutes unauthorised access. Q: How many IPs can I add to one VPS? A: Up to eight additional IPv4 addresses per instance from the panel, plus your routed IPv6 /64. Q: Which location is best for scraping? A: Somewhere outside the target's jurisdiction for legal separation, and close to it for latency. Amsterdam, Moldova and Sofia are the usual compromise for European targets. Source: https://onionvps.com/solutions/web-scraping ### VPS seedbox: high-ratio seeding with terabytes of storage A seedbox needs disk and uplink, not cores. Two shared cores, 4 GB of RAM and 2 TB of storage on a 10 Gbit port will seed hundreds of torrents at ratio. The jurisdiction is the real decision: choose a country where copyright enforcement runs through local courts rather than automated notice-and-takedown, and where the provider is not obliged to forward complaints as account terminations. Requirements: - CPU: 2 shared cores (encryption and hashing only) - RAM: 4 GB for ~500 active torrents in rTorrent - Disk: 2–16 TB, priced per terabyte on the Hold line - Transfer: 20 TB and up; the Hold 16 is unmetered - Jurisdiction: Outside the US — DMCA is US statute and binds US-situated hosts Recommended plans: hold-2, hold-4, hold-8 Recommended locations: chisinau, panama-city, sofia, bucharest, willemstad Setup: 1. Deploy a Hold instance outside the United States — Moldova, Panama, Bulgaria, Romania and Curaçao are the usual choices. 2. Install rTorrent with ruTorrent, or qBittorrent-nox — Both run comfortably in 4 GB; qBittorrent has the friendlier web UI. 3. Bind the client to a WireGuard interface if you want a second layer — Optional, and it costs throughput — most users skip it when the jurisdiction is already right. 4. Set up remote access — nginx with basic auth over TLS, or access the web UI only through a WireGuard tunnel. 5. Sync down with rclone or Syncthing — Both saturate a gigabit link and resume cleanly. Q: Is a seedbox legal? A: The technology is entirely legal. What you transfer is what determines legality, and that is your responsibility. We prohibit distributing material you have no right to distribute, and we act on valid legal process from a competent court. Q: Does the DMCA apply to an offshore seedbox? A: The DMCA is United States copyright statute. Its notice-and-takedown safe harbour applies to service providers situated in the US. A server in Moldova or Panama is governed by that country's copyright law, which generally requires a court order rather than a notice. Q: How much storage do I need? A: A 1080p film is roughly 8–15 GB and a season of television 30–60 GB. 2 TB holds a substantial library; 8 TB holds an unreasonable one. Source: https://onionvps.com/solutions/seedbox ### VPS for a self-hosted mail server (Postfix, Mailcow, Stalwart) Self-hosting mail needs three things most providers do not give you: outbound port 25 open, self-service reverse DNS, and address space with no spam history. Two cores and 4 GB run Mailcow for a small team, 8 GB if you want full-text search. Deliverability, not hardware, is the hard part — set SPF, DKIM and DMARC before you send a single message. Requirements: - CPU: 2 cores for a small team, 4 for 50+ mailboxes - RAM: 4 GB minimum for Mailcow; 8 GB with Solr search - Disk: 160 GB NVMe and up, sized to your archive - Network: Port 25 outbound, static IPv4, self-service PTR Recommended plans: cutter-8, cutter-16 Recommended locations: amsterdam, zurich, frankfurt, reykjavik, panama-city Setup: 1. Deploy a Cutter 8 and set the hostname — mail.example.com, matching what you will publish in DNS. 2. Set reverse DNS from the panel — The PTR record must resolve back to the same hostname or most receivers will reject you. 3. Install Mailcow or Stalwart — Both ship a complete stack; Stalwart is a single Rust binary if you prefer less Docker. 4. Publish SPF, DKIM and DMARC — Start DMARC at p=none, read the reports for a fortnight, then move to p=quarantine. 5. Warm the IP up gradually — A few dozen messages a day for the first week. Volume spikes from a new IP look exactly like a spam run. Q: Is port 25 open on your VPS? A: Yes, outbound port 25 is open on every instance by default. We do not require a support ticket, an account age, or a paid add-on to unblock it. Q: Can I set reverse DNS (PTR) myself? A: Yes, for both IPv4 and IPv6, directly from the control panel. Changes propagate within a few minutes. Q: Will my mail land in spam? A: Not if you configure SPF, DKIM, DMARC and a matching PTR, and warm the address up. Those four things account for the overwhelming majority of deliverability problems. Source: https://onionvps.com/solutions/mail-server ### VPS for running a Tor relay, bridge or exit node A Tor middle relay runs comfortably on one shared core and 1 GB of RAM; the constraint is bandwidth and the provider's tolerance. Relays and bridges are welcome on every OnionVPS instance. Exit nodes are permitted only in specific jurisdictions and only with a published abuse contact, because an exit node will attract complaints about traffic that is not yours. Requirements: - CPU: 1 core per ~100 Mbit/s of relayed traffic (AES is the bottleneck) - RAM: 1 GB for a middle relay, 2 GB for a guard - Transfer: 4 TB and up — relays consume everything you give them - Policy: Bridges and middle relays everywhere; exits in approved regions only Recommended plans: skiff-2, skiff-4, cutter-4 Recommended locations: reykjavik, zurich, chisinau, bucharest, sofia Setup: 1. Deploy a Skiff 2 in a relay-friendly location — Iceland and Switzerland are the strongest legal ground. 2. Install Tor from the official repository — The distribution package lags; use deb.torproject.org. 3. Configure torrc as a middle relay first — ORPort 443, ExitRelay 0, and a ContactInfo line you actually read. 4. Set an accounting limit — AccountingMax keeps a relay inside your transfer allowance rather than surprising you. 5. Register the contact and monitor — Watch the relay on Tor Metrics; consensus weight takes several days to build. Q: Can I run a Tor exit node? A: In approved jurisdictions, yes, with a published abuse contact and a reduced exit policy. Exits generate complaints about traffic that is not yours, so we require that you are prepared to answer them. Middle relays and bridges are unrestricted everywhere. Q: Will running a relay get my server suspended? A: Not here. Middle relays and bridges carry no exit traffic and generate no complaints; they are a normal workload on this platform. Q: How much bandwidth does a Tor relay use? A: As much as you allow. A relay with 4 TB a month and an AccountingMax setting is a genuinely useful contribution to the network. Source: https://onionvps.com/solutions/tor-relay ### VPS as a Docker host: containers with full kernel control Docker needs a real kernel, which means KVM rather than an OpenVZ or LXC container. Two dedicated cores and 4 GB run a handful of small services; 8 GB is the comfortable point for a full Compose stack with a database. Every OnionVPS instance is KVM, so overlay filesystems, cgroups v2, nested virtualisation and custom kernels all work without workarounds. Requirements: - CPU: 2 dedicated cores minimum; containers multiply quickly - RAM: 4 GB for a few services, 8–16 GB for a Compose stack with Postgres - Disk: NVMe — image layers and database writes are IO-bound - Kernel: KVM with cgroups v2, overlay2 and nested virtualisation Recommended plans: cutter-8, cutter-16, clipper-16 Recommended locations: amsterdam, frankfurt, ashburn, singapore, sao-paulo Setup: 1. Deploy a Cutter 8 with Debian 13 or Ubuntu 24.04 — Both ship recent kernels with cgroups v2 by default. 2. Install Docker Engine from the official repository — The distribution package is usually several versions behind. 3. Create a non-root user in the docker group — Or use rootless mode if the containers do not need privileged access. 4. Put a reverse proxy in front — Caddy or Traefik will obtain and renew TLS certificates automatically. 5. Take a snapshot before every upgrade — Free, instant, and it turns a failed deployment into a rollback. Q: Can I run Docker on a VPS? A: On a KVM VPS, yes, without restriction. On OpenVZ or LXC-based virtual servers, Docker either fails or requires unsafe workarounds, because those share the host kernel. Every OnionVPS instance is KVM. Q: Do you allow nested virtualisation? A: Yes. You can run KVM guests, Docker-in-Docker, or a Kubernetes cluster inside your instance. Q: How much RAM for a Docker host? A: Sum the memory limits of your containers and add 1 GB for the host. A typical web application, worker and Postgres stack fits in 8 GB. Source: https://onionvps.com/solutions/docker-host ### VPS for Kubernetes and K3s clusters A K3s control plane node needs 2 cores and 4 GB; a full kubeadm control plane wants 4 GB minimum and 8 GB to be comfortable. Worker nodes are sized by your workloads. Three Cutter 8 instances across three jurisdictions give you a genuinely fault-tolerant cluster for under $110 a month, with private networking over WireGuard between regions. Requirements: - Control plane: 2 vCPU / 4 GB for K3s, 4 vCPU / 8 GB for kubeadm - Workers: Sized to workloads; 4 vCPU / 8 GB is a sensible unit - Disk: NVMe for etcd — it is fsync-latency sensitive - Network: WireGuard mesh between regions; native IPv6 for dual-stack clusters Recommended plans: cutter-8, cutter-16, clipper-16 Recommended locations: amsterdam, frankfurt, helsinki, ashburn, singapore Setup: 1. Deploy three instances in different regions — Three is the minimum for etcd quorum. 2. Build a WireGuard mesh — Give each node a private address and route the cluster CIDR over it. 3. Install K3s with the embedded etcd — curl -sfL https://get.k3s.io | sh -s - server --cluster-init on the first node. 4. Join the remaining servers and any agents — Use the node token from /var/lib/rancher/k3s/server/node-token. 5. Install an ingress and cert-manager — Traefik ships with K3s; add cert-manager for automatic certificates. Q: What are the minimum specs for a Kubernetes node? A: K3s runs a control plane in 2 vCPU and 4 GB. Full kubeadm wants 4 GB as an absolute floor and behaves much better with 8 GB. Workers are sized entirely by what you schedule on them. Q: Can I run a multi-region Kubernetes cluster? A: Yes, over a WireGuard mesh. Keep etcd members within about 100 ms of each other or the Raft heartbeat becomes unstable. Q: Is etcd disk performance important? A: Critically. etcd fsyncs on every write; on HDD or heavily contended storage the cluster becomes unstable under load. Always put it on NVMe. Source: https://onionvps.com/solutions/kubernetes-node ### VPS for self-hosted CI/CD runners (GitHub Actions, GitLab, Woodpecker) Self-hosted runners pay for themselves quickly: a Cutter 16 at $62 a month replaces several thousand hosted CI minutes and builds faster because the cache is local. Four to six dedicated cores and 16 GB handle most build matrices. Use NVMe — dependency installation and container layer extraction are almost entirely IO-bound. Requirements: - CPU: 4–8 dedicated cores; builds parallelise well - RAM: 16 GB for a typical matrix, 32 GB for large monorepos - Disk: 320 GB NVMe — caches, images and artefacts accumulate - Kernel: Nested virtualisation for container and VM-based jobs Recommended plans: cutter-16, clipper-16, clipper-32 Recommended locations: frankfurt, amsterdam, ashburn, helsinki, singapore Setup: 1. Deploy a Cutter 16 with Ubuntu 24.04 — Six cores and 16 GB covers most projects. 2. Install the runner agent — GitHub Actions runner, gitlab-runner, or Woodpecker depending on your forge. 3. Run jobs in ephemeral containers — A fresh container per job stops one build poisoning the next. 4. Persist the package caches outside the container — Mount host directories for npm, cargo, pip and Docker layers. 5. Register the runner and tag it — Tags let you route heavy jobs here and leave light ones on hosted runners. Q: Is a self-hosted CI runner cheaper than hosted minutes? A: Almost always past a few thousand minutes a month. A $62 instance runs continuously; hosted CI bills by the minute and re-downloads dependencies on every cold start. Q: Can I run Docker builds on a self-hosted runner? A: Yes. Nested virtualisation and full root mean buildx, Docker-in-Docker and rootless builds all work. Q: Are self-hosted runners safe for public repositories? A: Only with ephemeral, isolated runners. A public repository can execute arbitrary code from a pull request, so never give such a runner access to secrets or your internal network. Source: https://onionvps.com/solutions/ci-cd-runner ### VPS for WordPress: self-managed hosting without the shared-host limits A WordPress site with moderate traffic runs comfortably on two dedicated cores and 4 GB of RAM with PHP 8.3, OPcache and Redis object caching. WooCommerce needs more, because cart and checkout pages cannot be page-cached: budget 4 cores and 8 GB. NVMe matters more than core count — most WordPress slowness is database IO wearing a CPU costume. Requirements: - CPU: 2 cores for a content site, 4 for WooCommerce - RAM: 4 GB with Redis; 8 GB for a shop with a large catalogue - Disk: NVMe, 80 GB and up depending on media - Stack: PHP 8.3 with OPcache, MariaDB, Redis, nginx Recommended plans: cutter-4, cutter-8, cutter-16 Recommended locations: amsterdam, frankfurt, ashburn, sao-paulo, singapore Setup: 1. Deploy a Cutter 8 with Ubuntu 24.04 — Four cores and 8 GB leaves headroom for growth. 2. Install nginx, PHP-FPM 8.3, MariaDB and Redis — Or use a stack installer if you would rather not hand-configure. 3. Enable OPcache and Redis object caching — These two changes account for most of the achievable speedup. 4. Put full-page caching in front — nginx FastCGI cache, or a plugin that writes static HTML. 5. Automate certificates and backups — Certbot for TLS, nightly encrypted backups for the database and uploads. Q: How much RAM does WordPress need on a VPS? A: 2 GB is workable for a small site, 4 GB is comfortable with Redis object caching, and WooCommerce with a real catalogue wants 8 GB. Database memory, not PHP, is usually what runs out first. Q: Is a VPS better than shared hosting for WordPress? A: Materially, yes. You get guaranteed resources, root access, your own PHP version, and no arbitrary process limits. The trade is that you are responsible for updates and security. Q: Can I host WordPress anonymously? A: Yes. We require only an email address you control, and checkout is crypto-only, so there is no payment-card trail linking you to the site. Source: https://onionvps.com/solutions/wordpress-hosting ### VPS for SOCKS5, HTTP and Shadowsocks proxies A proxy server is bandwidth with a small CPU tax. One shared core and 1 GB of RAM saturate a gigabit port with Dante or 3proxy; Shadowsocks and VLESS add encryption overhead but still run in well under 512 MB. Buy for location and address quality, and add extra IPv4 addresses when you need rotation. Requirements: - CPU: 1 shared core per gigabit for plain SOCKS5 - RAM: 1 GB - IPs: Up to 8 additional IPv4 addresses per instance - Transfer: 2–10 TB depending on use Recommended plans: skiff-1, skiff-2, cutter-4 Recommended locations: amsterdam, chisinau, panama-city, kuala-lumpur, istanbul Setup: 1. Deploy a Skiff instance in your target country — Location is the whole point of a proxy; specification barely matters. 2. Install Dante, 3proxy or Xray — Dante for classic SOCKS5, Xray for VLESS and Shadowsocks with TLS camouflage. 3. Require authentication — An open proxy will be found by scanners within hours and abused within a day. 4. Bind each listener to a different source IP — This is how you build rotation without a third-party proxy service. 5. Rate-limit and monitor — nftables connection limits keep a compromised credential from saturating the port. Q: Can I run a SOCKS5 proxy on a VPS? A: Yes. Install Dante or 3proxy, require authentication, and bind to your assigned addresses. Never leave it open — open proxies are found and abused within hours. Q: How many proxies can one VPS host? A: One instance can run many listeners; the practical limit is your IP allocation and uplink, not CPU. Eight additional IPv4 addresses per instance is our ceiling. Q: Do you block any ports? A: We do not filter outbound traffic by protocol. We do intervene on active abuse — port scanning at scale, spam, and attacks originating from your instance. Source: https://onionvps.com/solutions/proxy-server ### VPS for private DNS: Pi-hole, AdGuard Home and Unbound Recursive DNS is the lightest useful workload there is: one shared core and 1 GB of RAM serve a household or a small team with room to spare. Running Unbound behind AdGuard Home means no upstream resolver ever sees your queries, and DNS-over-HTTPS on port 443 keeps them private in transit — which matters more than the hardware. Requirements: - CPU: 1 shared core - RAM: 1 GB (512 MB is enough for Unbound alone) - Disk: 20 GB - Network: Static IPv4 and IPv6; low latency to your users Recommended plans: skiff-1, skiff-2 Recommended locations: zurich, reykjavik, panama-city, amsterdam, singapore Setup: 1. Deploy a Skiff 1 in a privacy jurisdiction — Switzerland, Iceland and Panama are the usual picks. 2. Install AdGuard Home — It ships DNS-over-HTTPS and DNS-over-TLS out of the box. 3. Point it at a local Unbound instance — Full recursion means no upstream resolver sees your queries at all. 4. Enable DoH on 443 and DoT on 853 — Get a certificate with Certbot; both are one config line away. 5. Lock it down — Restrict by client IP or require DoH with a secret path — open resolvers are used in amplification attacks. Q: Why run your own DNS server? A: Your resolver sees every domain you visit before any encryption applies. Running your own moves that visibility from your ISP or a public resolver to a machine you control in a jurisdiction you chose. Q: Does Pi-hole need much CPU? A: Almost none. A shared core and 1 GB of RAM handle thousands of queries a minute; the workload is memory lookups, not computation. Q: Can I use it as a public resolver? A: You can, but do not leave it open. Open resolvers are recruited into DNS amplification attacks, which will get the instance null-routed. Source: https://onionvps.com/solutions/private-dns ### VPS for Nextcloud: private file sync you actually control Nextcloud is IO-bound and storage-hungry rather than CPU-hungry. Two cores and 4 GB serve a family; a 20-person team wants 4 cores and 8 GB with Redis and PHP-FPM tuning. Storage is the real decision: the Hold line gives you 2–16 TB at a price per terabyte that makes consumer cloud subscriptions look expensive. Requirements: - CPU: 2 cores for a household, 4 for a small team - RAM: 4 GB with Redis; 8 GB with full-text search - Disk: 2 TB and up on the Hold line - Stack: PHP 8.3, PostgreSQL or MariaDB, Redis, nginx Recommended plans: cutter-8, hold-2, hold-4 Recommended locations: zurich, reykjavik, amsterdam, panama-city, montevideo Setup: 1. Deploy a Hold 2 in a privacy jurisdiction — Two terabytes is the sensible starting size. 2. Install Nextcloud with PostgreSQL and Redis — Redis for file locking is not optional at any real scale. 3. Tune PHP-FPM and OPcache — Raise memory_limit to 1 GB and increase the OPcache interned strings buffer. 4. Enable server-side encryption if you want it — It costs performance; full-disk encryption plus TLS is enough for most threat models. 5. Set up backups to a second jurisdiction — Nightly encrypted backups to another region, restic or Borg. Q: How much storage does Nextcloud need per user? A: Budget 50–100 GB per active user for documents and photos, more if they sync video. Storage grows faster than you expect; the Hold line is priced so that over-provisioning is cheap. Q: Is self-hosted Nextcloud more private than a commercial cloud? A: It removes the provider's ability to read, scan or hand over your files, which no commercial service can offer. In exchange you own patching and backups. Q: Which database should I use? A: PostgreSQL. Nextcloud supports MariaDB, but Postgres handles concurrent writes better and is what large installations run. Source: https://onionvps.com/solutions/nextcloud ### VPS for a Matrix homeserver or XMPP server Synapse is memory-hungry: a small homeserver federating with busy rooms needs 4 GB, and 8 GB if you join large public rooms. Conduit or Dendrite run in a fraction of that. XMPP with Prosody is lighter still — one core and 1 GB serve hundreds of users. All three are IO-sensitive, so put the database on NVMe. Requirements: - CPU: 2 cores for Synapse, 1 for Conduit or Prosody - RAM: 4–8 GB for Synapse, 1–2 GB for Conduit or Prosody - Disk: NVMe, 160 GB — federation state grows relentlessly - Network: Well-peered location; federation is latency-sensitive Recommended plans: cutter-8, cutter-16, skiff-4 Recommended locations: zurich, reykjavik, amsterdam, chisinau, panama-city Setup: 1. Deploy a Cutter 8 with Debian 13 — Four cores and 8 GB if you plan to federate widely. 2. Install Synapse, Conduit or Prosody — Conduit if you want low resource use; Synapse if you need the full feature set. 3. Configure the well-known delegation — Serve /.well-known/matrix/server so federation finds you on the right port. 4. Put PostgreSQL on the same NVMe volume — Never run Synapse on SQLite beyond a personal test server. 5. Prune old state regularly — Federation state grows without bound; schedule the purge API or the state compressor. Q: How much RAM does a Matrix homeserver need? A: Synapse needs 4 GB for a small server and 8 GB once you join large federated rooms. Conduit does the same job in under 512 MB, at the cost of some feature completeness. Q: Can I federate from an offshore VPS? A: Yes. Federation only requires a public IP, a domain and a valid certificate. Jurisdiction has no effect on federation, only on who can compel your metadata. Q: Is Matrix metadata private? A: Message content is end-to-end encrypted, but room membership and timing metadata live on the homeserver. Running your own is the only way to keep that on hardware you control. Source: https://onionvps.com/solutions/matrix-homeserver ### VPS for Pterodactyl and game-hosting panels Pterodactyl splits into a panel and one or more Wings nodes. The panel is light — two cores and 2 GB. Wings nodes carry the games, so size them by what you sell: a Clipper 16 hosts roughly eight 10-slot Minecraft servers. Wings needs Docker, so KVM virtualisation is mandatory; container-based VPS products cannot run it. Requirements: - Panel: 2 vCPU / 2 GB, plus a small database - Wings node: 8+ dedicated cores, 16–32 GB, NVMe - Kernel: KVM with Docker support — not available on OpenVZ - Protection: DDoS scrubbing on every node Recommended plans: cutter-4, clipper-16, clipper-32 Recommended locations: frankfurt, ashburn, singapore, sao-paulo, sydney Setup: 1. Deploy a small instance for the panel — A Cutter 4 with nginx, PHP 8.3, MariaDB and Redis. 2. Deploy one or more Wings nodes — Clipper 16 or 32, in the regions you intend to sell. 3. Install Wings and Docker on each node — Wings creates one container per game server. 4. Configure allocations and ports — Assign port ranges per node and map them to allocations in the panel. 5. Set resource limits per server — Overselling memory is the single most common way panel operators lose customers. Q: Can Pterodactyl run on a VPS? A: Yes, on KVM. Wings requires Docker, which requires a real kernel — it will not run on OpenVZ or LXC-based virtual servers. Every OnionVPS instance is KVM. Q: How many game servers fit on one node? A: A Clipper 16 with 8 dedicated cores and 16 GB hosts roughly eight 10-slot Minecraft servers with headroom. Sell against RAM, and keep 20% in reserve. Q: Can I start a hosting business on your infrastructure? A: Yes. Reselling is permitted, you own the customer relationship, and there is no reseller programme to apply to. Source: https://onionvps.com/solutions/pterodactyl-panel ### VPS for reseller hosting and white-label infrastructure Reselling needs headroom and predictability rather than raw speed. A Cutter 32 or Clipper 32 hosts a control panel, a billing system and a healthy number of customer accounts. The two things that decide whether the business survives are DDoS protection you did not have to buy separately, and a provider who will not terminate your node over a single downstream complaint. Requirements: - CPU: 8–16 dedicated cores - RAM: 32–64 GB - Disk: 640 GB–1.6 TB NVMe - Network: 20+ TB transfer, always-on DDoS scrubbing Recommended plans: cutter-32, clipper-32, clipper-64 Recommended locations: amsterdam, frankfurt, chisinau, panama-city, singapore Setup: 1. Deploy a large instance in your target market — Clipper 32 is the usual starting node. 2. Install a control panel — CyberPanel, CloudPanel or DirectAdmin; all run on Ubuntu or AlmaLinux. 3. Install a billing system — WHMCS, Blesta or FOSSBilling, with a crypto gateway attached. 4. Set hard per-account resource limits — CPU, memory and inode caps stop one account taking down the node. 5. Publish your own abuse policy — You are the provider to your customers; they need to know where the line is. Q: Can I resell your VPS as my own product? A: Yes. White-labelling is permitted, there is no reseller programme to apply to, and we never contact your customers. Q: What happens if one of my customers is abusive? A: We contact you, not them, and we give you a working window to act. We suspend only for active, ongoing harm such as an outbound attack. Q: Do you offer a reseller API? A: Yes. The full REST API and Terraform provider cover provisioning, resizing, snapshots and destruction. Source: https://onionvps.com/solutions/reseller-hosting ### VPS for AI workloads, LLM inference and RAG pipelines CPU inference is viable for small models: an 8-billion-parameter model quantised to 4 bits runs at conversational speed on 8 dedicated cores with 16 GB of RAM. Anything larger wants a GPU. Most self-hosted AI work is actually the surrounding stack — vector database, embedding service, API gateway — and that runs perfectly well on a Clipper 32. Requirements: - CPU: 8+ dedicated cores with AVX-512 for CPU inference - RAM: 16 GB for an 8B model at Q4, 64 GB for 70B at Q4 - Disk: NVMe Gen4 — model weights are large and load-latency matters - GPU: Available in selected regions; ask before ordering Recommended plans: clipper-16, clipper-32, clipper-64 Recommended locations: frankfurt, amsterdam, ashburn, singapore, tokyo Setup: 1. Deploy a Clipper 32 with Ubuntu 24.04 — Twelve dedicated cores and 32 GB covers most CPU inference. 2. Install Ollama or llama.cpp — Ollama is the fastest path; llama.cpp gives finer control over quantisation. 3. Pull a quantised model — Q4_K_M is the usual quality-versus-speed sweet spot. 4. Put an API gateway in front — LiteLLM or a reverse proxy with authentication and rate limiting. 5. Add a vector database if you are building RAG — Qdrant or pgvector; both run comfortably alongside the model. Q: Can you run an LLM on a VPS without a GPU? A: Yes, for small and quantised models. An 8B model at Q4 produces roughly 8–15 tokens per second on 8 modern dedicated cores — fine for a personal assistant or a batch pipeline, too slow for a busy chat product. Q: How much RAM does a local LLM need? A: Roughly the file size of the quantised weights plus 2 GB. An 8B model at Q4 is about 5 GB, a 70B model at Q4 about 40 GB. Q: Do you offer GPU instances? A: In selected regions, yes. Contact us before ordering so we can confirm current availability and pricing. Source: https://onionvps.com/solutions/ai-inference ### VPS for Jellyfin, Plex and private media streaming Direct play needs almost nothing; transcoding needs a great deal. A Jellyfin server that only direct-plays runs on two cores and 4 GB regardless of library size. One 1080p CPU transcode consumes roughly two dedicated cores, and 4K transcoding without a GPU is not realistic. Size storage first, then decide whether you actually need to transcode at all. Requirements: - CPU: 2 cores for direct play; 2 dedicated cores per 1080p transcode - RAM: 4 GB, 8 GB with a large library and metadata cache - Disk: 2–16 TB on the Hold line - Transfer: 20 TB and up — video is the heaviest thing you can serve Recommended plans: hold-2, hold-4, clipper-16 Recommended locations: amsterdam, chisinau, sofia, panama-city, singapore Setup: 1. Deploy a Hold instance sized to your library — Two terabytes for a starter library, four or eight for a serious one. 2. Install Jellyfin or Plex — Jellyfin if you would rather not depend on a third-party account. 3. Store media in a consistent naming scheme — Metadata matching is what makes the library usable. 4. Avoid transcoding wherever possible — Serve formats your clients play natively; it is the single biggest performance win. 5. Front it with TLS and authentication — Never expose a media server to the internet without both. Q: How much CPU does Jellyfin transcoding need? A: Roughly two dedicated modern cores per simultaneous 1080p transcode. 4K transcoding without hardware acceleration is impractical on any CPU-only VPS. Q: Can I stream 4K from a VPS? A: Yes, if the client direct-plays it. A 4K remux is 40–80 Mbit/s, so the uplink matters more than the processor. Q: Is hosting a personal media library allowed? A: Yes, for material you have the right to hold. We do not scan your storage and we act only on valid legal process. Source: https://onionvps.com/solutions/media-streaming ### VPS for blockchain nodes and validators Blockchain nodes are storage and IO monsters. A Bitcoin full node needs about 700 GB and grows; an Ethereum archive node needs several terabytes. Validators additionally need uptime, because downtime is slashable. Use NVMe without exception — HDD cannot keep up with chain sync — and pick a jurisdiction that will not compel you to identify yourself as an operator. Requirements: - CPU: 4–8 dedicated cores - RAM: 16 GB for most full nodes, 32 GB for Ethereum with a full mempool - Disk: NVMe only. 1 TB for Bitcoin with headroom, 2 TB+ for Ethereum - Uptime: 99.99% SLA — validator downtime is a direct financial penalty Recommended plans: cutter-16, clipper-32, hold-4 Recommended locations: zurich, reykjavik, helsinki, singapore, panama-city Setup: 1. Choose storage before anything else — Check the chain's current size, then double it — chains only grow. 2. Deploy a Clipper or Cutter with NVMe — Never run a node on HDD; initial sync will not finish in a reasonable time. 3. Run the client under systemd with restart on failure — And monitor peer count, not just process liveness. 4. Open only the p2p port — RPC should never face the internet without authentication and an IP allowlist. 5. Snapshot before every client upgrade — A failed upgrade on a validator is expensive; a snapshot makes it a five-minute rollback. Q: What specs does an Ethereum node need? A: A full node needs 4 cores, 16 GB of RAM and at least 2 TB of NVMe with room to grow. An archive node needs several times that storage. HDD is not viable for either. Q: Can I run a validator on a VPS? A: Yes, and many do. Uptime and disk latency are what matter; use a location with a published SLA and never share the withdrawal key with the box. Q: Do you allow mining? A: Proof-of-work mining is not permitted on shared infrastructure — it degrades every neighbour on the host. Validators, full nodes and RPC endpoints are all welcome. Source: https://onionvps.com/solutions/blockchain-node ### VPS for e-commerce: WooCommerce, Magento and headless shops Shops cannot cache the pages that matter. Cart, checkout and account pages are dynamic by definition, so e-commerce is genuinely CPU and database bound in a way that content sites are not. Budget four dedicated cores and 8 GB for WooCommerce with a real catalogue, and eight cores with 16 GB for Magento 2, which is heavier than its documentation suggests. Requirements: - CPU: 4 dedicated cores for WooCommerce, 8 for Magento 2 - RAM: 8–16 GB; Elasticsearch alone wants 4 GB - Disk: NVMe, 320 GB and up with product media - Uptime: 99.99% SLA — downtime is lost revenue, measurably Recommended plans: cutter-16, clipper-16, clipper-32 Recommended locations: amsterdam, frankfurt, ashburn, sao-paulo, singapore Setup: 1. Deploy a Cutter 16 or Clipper 16 — Six to eight dedicated cores with 16 GB. 2. Install the LEMP stack plus Redis and Elasticsearch — Magento requires Elasticsearch or OpenSearch; WooCommerce benefits from it. 3. Cache aggressively but exclude cart and checkout — Full-page cache everything else; never cache a session-bearing page. 4. Terminate TLS properly and enable HTTP/3 — Both affect real-world checkout latency. 5. Back up the database hourly — An order lost to a failed backup is a customer lost permanently. Q: What VPS specs does Magento 2 need? A: Eight dedicated cores and 16 GB of RAM is a realistic production floor, largely because Elasticsearch and the Magento cron stack are memory-hungry. The official minimums are optimistic. Q: Does server location affect conversion? A: Yes, measurably. Every additional 100 ms of latency has a documented negative effect on conversion; host near your customers. Q: Can I accept crypto payments on my shop? A: Yes — that is independent of hosting. Most shop platforms have a crypto gateway plugin, including the one that powers our own checkout. Source: https://onionvps.com/solutions/e-commerce ### VPS as a remote development environment A remote development box turns a thin laptop into a workstation. Four dedicated cores and 8 GB handle most language servers, test suites and a database; large monorepos want 16 GB. The real win is that builds continue when you close the lid, and the environment is identical from any machine you connect from. Requirements: - CPU: 4 dedicated cores; language servers are surprisingly hungry - RAM: 8 GB minimum, 16 GB for a monorepo with a local database - Disk: 160–320 GB NVMe - Latency: Under 50 ms to you, or typing feels wrong over SSH Recommended plans: cutter-8, cutter-16, clipper-16 Recommended locations: frankfurt, amsterdam, ashburn, singapore, sao-paulo Setup: 1. Deploy a Cutter 8 in the region closest to you — Latency to the box is what decides whether this feels good. 2. Harden SSH first — Keys only, no password authentication, no root login. 3. Install your toolchain, or use a devcontainer — Devcontainers make the environment reproducible. 4. Connect with VS Code Remote-SSH or JetBrains Gateway — Both run the heavy half of the IDE on the server. 5. Keep work in tmux or zellij — Your session survives a dropped connection, a closed laptop and a flight. Q: Is a VPS good for remote development? A: Very. You get consistent performance, builds that survive a closed laptop, and an environment that is identical from every machine. The one requirement is low latency to your own location. Q: How much RAM for a remote dev environment? A: 8 GB handles most single-project work. Language servers on a large monorepo, plus a local Postgres and a Docker stack, will use 16 GB without trying. Q: Can I run VS Code Server on it? A: Yes — code-server, the official VS Code Server, or Remote-SSH. All three work on any instance. Source: https://onionvps.com/solutions/development-server ### VPS for monitoring: Prometheus, Grafana and uptime checks A monitoring stack is memory and disk bound. Prometheus with 15-second scrapes across 50 targets and 90 days of retention needs about 8 GB of RAM and 200 GB of NVMe. Put it somewhere other than the infrastructure it watches — monitoring that shares a failure domain with production tells you nothing at the moment you need it most. Requirements: - CPU: 2–4 cores - RAM: 8 GB for ~1M active series - Disk: NVMe, 160–320 GB for 90-day retention - Placement: A different provider or region from what it monitors Recommended plans: cutter-8, cutter-16 Recommended locations: helsinki, frankfurt, ashburn, singapore, sao-paulo Setup: 1. Deploy a Cutter 8 away from your production region — Different country, ideally different provider. 2. Install Prometheus, Alertmanager and Grafana — Docker Compose is the fastest reliable path. 3. Add blackbox probes from several regions — A Skiff 1 in each region running blackbox_exporter is enough. 4. Route alerts somewhere you will see them — Alertmanager to a chat channel, plus a second path for a total outage. 5. Test the alert path deliberately — An untested alerting pipeline is decoration. Q: How much disk does Prometheus need? A: Roughly 1–2 bytes per sample after compression. One million active series at a 15-second scrape interval for 90 days is about 200 GB. Q: Should monitoring run on the same provider as production? A: No. If it shares a failure domain it will go down at exactly the moment you need it. Separate provider or at minimum separate region and jurisdiction. Q: Can I monitor from multiple countries? A: Yes. A $4 Skiff instance per region running blackbox_exporter gives you real geographic probe coverage cheaply. Source: https://onionvps.com/solutions/monitoring ### VPS for journalism, research and source-protection infrastructure Source-protection infrastructure is a legal architecture problem before it is a technical one. What matters is that the provider holds no identity information, keeps no connection records, sits outside mutual legal assistance reach, and encrypts disks with a key it does not have. The Bastion line in Seychelles, Panama, Iceland or Switzerland is built exactly for this. Requirements: - Jurisdiction: Outside the Eyes alliances and outside easy MLAT reach - Disk: LUKS2 full-disk encryption, unlocked at boot by you over SSH - Account: No identity data held; email alias plus crypto payment - Logging: No connection logs, no netflow, no access records retained Recommended plans: bastion-8, bastion-16, bastion-32 Recommended locations: victoria-sc, panama-city, reykjavik, zurich, montevideo Setup: 1. Order a Bastion instance from a network you do not normally use — Tor or a VPN, with an email alias created for the purpose. 2. Pay in Monero — Protocol-level privacy; there is no public ledger entry to correlate. 3. Set the LUKS passphrase at first boot — Unlock over dropbear SSH after each reboot. We never see the key. 4. Deploy SecureDrop or a hardened onion service — Tor-only, no clearnet listener at all. 5. Rehearse the failure cases — Practise the wipe and the restore before you need either. Q: Can hosting genuinely protect a source? A: Hosting is one layer. It removes the provider as a point of compulsion and puts the server outside easy legal reach, but it cannot fix operational security mistakes elsewhere. Treat it as necessary, not sufficient. Q: What happens if you receive a subpoena? A: We assess whether it is valid legal process from a court with jurisdiction over us. If it is, we comply with exactly what is ordered — which is very little, because we hold an email address and a payment reference. If it is not, we reject it. Either way, the warrant canary reflects reality. Q: Is full-disk encryption really useful on a VPS? A: Against physical seizure of a powered-off disk, yes, decisively. Against an attacker with access to the running hypervisor, no — and no provider can honestly claim otherwise. We say so plainly because the distinction matters. Source: https://onionvps.com/solutions/whistleblower-infrastructure ### VPS for high-availability and multi-region failover Real availability comes from independent failure domains, not from a bigger server. Three instances in three countries with different transit providers survive events that no single machine can. Budget for a load balancer or anycast entry point, synchronous replication within a region, and asynchronous replication across them — latency makes synchronous cross-region writes impractical. Requirements: - Nodes: Three minimum, in three jurisdictions - Network: WireGuard mesh; anycast available in selected regions - Database: Synchronous within region, asynchronous across regions - DNS: Short TTLs and health-checked failover records Recommended plans: cutter-8, cutter-16, clipper-16 Recommended locations: amsterdam, frankfurt, ashburn, singapore, sao-paulo Setup: 1. Pick three regions with independent transit — Amsterdam, Ashburn and Singapore is the classic triangle. 2. Build a private mesh — WireGuard between all nodes, with the application listening only on the mesh. 3. Replicate the database appropriately — Synchronous within a region, asynchronous across; know your RPO. 4. Health-check at the DNS layer — Short TTLs plus a health-checked failover record, or anycast if available. 5. Run a failure drill — Kill a region on purpose, on a weekday, while you are watching. Q: How many servers do I need for high availability? A: Three is the practical minimum: two gives you a split-brain problem rather than a quorum. Put them in three separate failure domains — different countries, ideally different transit providers. Q: Does multi-region hosting reduce latency? A: Only if you route users to their nearest region. Multi-region for availability and multi-region for latency are different designs that happen to share hardware. Q: What uptime should I expect from a single VPS? A: Our SLA is 99.99% per instance, which is about 4.4 minutes of downtime a month. Anything beyond that requires redundancy you build yourself. Source: https://onionvps.com/solutions/high-availability ### DDoS-protected VPS hosting with always-on scrubbing DDoS protection has to be always-on and upstream of your instance to be useful — mitigation that activates after an attack starts has already let you go down. OnionVPS includes up to 12 Tbps of L3/L4 edge scrubbing at every tier, with optional L7 filtering. The most-attacked workloads are game servers, and they are exactly the ones sold "protection" as an upgrade elsewhere. Requirements: - Mitigation: Always-on L3/L4 at the edge, not triggered on detection - Capacity: Headroom measured in terabits, not gigabits - L7: Optional application-layer filtering for HTTP floods - Behaviour: Filtering, not null-routing — null-routing is the attacker winning Recommended plans: cutter-8, clipper-16, clipper-32 Recommended locations: frankfurt, amsterdam, ashburn, singapore, sao-paulo Setup: 1. Deploy in a scrubbing-enabled region — Every core region carries the full filtering stack. 2. Never publish your origin IP — Most successful attacks start with an origin leak, not a clever technique. 3. Add L7 filtering if you serve HTTP — Layer 7 floods look like traffic, so they need a different filter. 4. Rate-limit at the application too — Edge scrubbing stops volume; your application must stop expensive requests. 5. Have a runbook — Know who to contact and what to change before the first attack, not during it. Q: Is DDoS protection included or extra? A: Always-on L3/L4 scrubbing is included at every tier, including the $4 Skiff 1. Only application-layer L7 filtering is a paid add-on. Q: Will you null-route my IP during an attack? A: Filtering comes first — null-routing means the attacker achieved their goal. We null-route only when an attack exceeds what the edge can absorb without harming other customers, and we tell you when we do. Q: Does DDoS protection add latency? A: A fraction of a millisecond in normal operation. Traffic passes through the scrubbing layer continuously rather than being diverted when an attack begins, so there is no failover spike either. Source: https://onionvps.com/solutions/ddos-protected-hosting ### Windows Server VPS with crypto payment Windows Server needs materially more baseline resources than Linux: 4 GB of RAM is the practical floor and 8 GB is comfortable, before your application uses anything. Licensing is $12 a month per instance and is available in regions where we hold licensing rights. RDP should always be restricted to your own address — it is the single most brute-forced port on the internet. Requirements: - CPU: 2 cores minimum, 4 for anything real - RAM: 4 GB floor, 8 GB comfortable, 16 GB for SQL Server - Disk: 80 GB NVMe minimum — Windows Update alone wants room - Licence: $12/month per instance in licensed regions Recommended plans: cutter-8, cutter-16, clipper-16 Recommended locations: frankfurt, london, new-york, singapore, amsterdam Setup: 1. Deploy a Cutter 8 in a Windows-licensed region — Check the licence flag on the location page before ordering. 2. Select Windows Server 2022 at provisioning — Or upload your own ISO if you hold your own licence. 3. Restrict RDP immediately — Firewall port 3389 to your own IP, or reach it only over WireGuard. 4. Rename the administrator account and enable NLA — Both meaningfully reduce automated attack success. 5. Configure updates and snapshots — Windows Update reboots; snapshot before patch Tuesday. Q: Can I buy a Windows VPS with Bitcoin or Monero? A: Yes. Every plan including Windows-licensed instances is payable in any of our supported cryptocurrencies, with no identity verification. Q: How much RAM does Windows Server need? A: 4 GB is the realistic floor for the operating system to behave, 8 GB is comfortable, and SQL Server wants 16 GB before you load any data. Q: Is RDP safe to expose to the internet? A: No. Port 3389 is continuously brute-forced. Restrict it to your own address or, better, reach it only through a WireGuard tunnel. Source: https://onionvps.com/solutions/windows-vps ### VPS as a remote desktop or personal cloud PC A usable remote desktop needs four dedicated cores and 8 GB of RAM — a browser with a dozen tabs will use most of that on its own. Latency decides whether it feels like a computer or like a video call of a computer: under 40 ms is pleasant, above 80 ms is not. Choose the region by your own location, not by price. Requirements: - CPU: 4 dedicated cores; desktop environments are bursty - RAM: 8 GB minimum for a browser-centric desktop - Disk: 160 GB NVMe - Latency: Under 40 ms to you for a responsive session Recommended plans: cutter-8, cutter-16, clipper-16 Recommended locations: frankfurt, amsterdam, new-york, singapore, sao-paulo Setup: 1. Deploy a Cutter 8 in the region nearest you — Latency is the entire user experience here. 2. Install a lightweight desktop — XFCE or KDE on Linux; Windows Server ships its own. 3. Use a modern remote protocol — RDP via xrdp, or Sunshine plus Moonlight for a genuinely low-latency session. 4. Tunnel it, do not expose it — WireGuard first, remote desktop inside it. 5. Snapshot the configured state — So a broken experiment costs you five minutes. Q: Can a VPS replace a laptop? A: For browser and terminal work, comfortably. For anything needing a GPU, local media editing or offline use, no. The thin-client trade is real: your computer is only as good as your connection. Q: What latency do I need for remote desktop? A: Under 40 ms feels native, 40–80 ms is usable, and above 80 ms typing becomes actively unpleasant. Pick the nearest region. Q: Can I run a browser on a VPS to keep my real IP hidden? A: Yes — that is a common pattern. The exit IP becomes the server's, and browser fingerprinting still applies, so pair it with a hardened browser profile. Source: https://onionvps.com/solutions/remote-desktop ### VPS for SEO tools, rank trackers and crawlers SEO tooling is memory-bound and IP-sensitive. Screaming Frog crawling 500,000 URLs wants 16 GB; a rank tracker wants several IPv4 addresses far more than it wants cores. Four dedicated cores, 16 GB and a handful of extra addresses is the configuration that actually works, and location diversity lets you check rankings as a local user would see them. Requirements: - CPU: 4 dedicated cores - RAM: 16 GB for large crawls; Screaming Frog is memory-hungry - Disk: 320 GB NVMe for crawl databases - IPs: Several IPv4 addresses for rotation Recommended plans: cutter-16, clipper-16 Recommended locations: amsterdam, chisinau, sofia, ashburn, singapore Setup: 1. Deploy a Cutter 16 with 16 GB — Memory is what limits crawl size in practice. 2. Add IP addresses for rotation — Bind each worker to a distinct source address. 3. Run headless crawls in Docker — Screaming Frog and Sitebulb both have headless modes. 4. Deploy small probes in target countries — A Skiff 1 per country gives real localised checks. 5. Store crawl history off the box — Crawl databases grow fast; archive to a Hold instance. Q: How much RAM does Screaming Frog need? A: Roughly 4 GB per 100,000 URLs in memory mode. Database storage mode trades speed for a much lower memory ceiling and is what you want past about 200,000 URLs. Q: Can I check rankings from different countries? A: Yes. Deploy a small instance in each target country and query from there — that is the only way to see genuinely localised results. Q: Do you allow automated crawling? A: Yes, for lawfully accessible public data at rates that do not degrade the target. Source: https://onionvps.com/solutions/seo-tools ### VPS for low-latency API and real-time backends Sub-10 ms API responses are a placement problem before they are a code problem. Physics puts a floor of about 1 ms per 100 km of fibre, so no amount of optimisation beats being in the wrong city. Deploy Clipper instances in the regions your users are in, keep the hot path free of cross-region calls, and measure at the 99th percentile rather than the mean. Requirements: - CPU: High-frequency dedicated cores; tail latency is a scheduling problem - RAM: 8–32 GB depending on working set - Disk: NVMe Gen4 - Network: Anycast-capable regions for a single global entry point Recommended plans: clipper-8, clipper-16, clipper-32 Recommended locations: frankfurt, ashburn, singapore, sao-paulo, tokyo Setup: 1. Map where your requests originate — Then deploy to those regions, not to the cheapest one. 2. Deploy Clipper instances per region — High-frequency cores, and pin the process. 3. Keep the hot path region-local — One cross-region database call erases every other optimisation. 4. Enable HTTP/3 and keep connections alive — Connection setup dominates short-request latency. 5. Measure p99, not the average — Averages hide exactly the requests your users complain about. Q: What is realistic API latency from a VPS? A: Under 1 ms of server time is achievable for simple handlers on dedicated cores. Total user-perceived latency is dominated by distance: roughly 1 ms per 100 km each way, so placement decides the outcome. Q: Does anycast help API latency? A: Yes, by routing each user to the nearest healthy instance without DNS propagation delay. It requires instances in several regions and is available in our anycast-capable locations. Q: Why is my p99 much worse than my average? A: Usually CPU steal time on shared cores, or garbage collection. Dedicated cores remove the first; the second is a code problem. Source: https://onionvps.com/solutions/low-latency-api --- ## 8. Guides (10) ### Secure a new VPS in 10 minutes Beginner · 10 min · updated 2026-06-18 Five changes eliminate essentially every automated attack against a new server: key-based SSH with passwords disabled, no direct root login, a default-deny firewall covering both IPv4 and IPv6, unattended security updates, and fail2ban. Together they take about ten minutes and matter more than any provider feature. #### Generate and install an SSH key Do this from your own machine, not the server. Ed25519 keys are shorter and faster than RSA and are supported everywhere that matters. ```bash ssh-keygen -t ed25519 -C "onionvps-$(date +%Y%m)" ssh-copy-id -i ~/.ssh/id_ed25519.pub root@YOUR_SERVER_IP ``` #### Create a non-root user Working as root all the time removes a useful safety net and makes every mistake maximally expensive. ```bash adduser --gecos "" ops usermod -aG sudo ops rsync --archive --chown=ops:ops ~/.ssh /home/ops ``` #### Harden the SSH daemon Disable password authentication entirely — brute force against key-only SSH is not possible. Keep a second terminal connected while you do this, so a mistake does not lock you out. ```bash cat >/etc/ssh/sshd_config.d/99-hardening.conf <<'EOF' PasswordAuthentication no PermitRootLogin no KbdInteractiveAuthentication no AllowUsers ops EOF sshd -t && systemctl reload ssh ``` #### Set a default-deny firewall Cover IPv6 as well as IPv4. Every OnionVPS instance has a routed /64, so a v4-only ruleset leaves every service publicly reachable over v6. ```bash ufw default deny incoming ufw default allow outgoing ufw allow 22/tcp ufw allow 80,443/tcp ufw enable ufw status verbose # confirm IPv6 shows as enabled ``` #### Turn on automatic security updates Unattended upgrades close the window between a patch being published and you noticing it exists. ```bash apt install -y unattended-upgrades dpkg-reconfigure -plow unattended-upgrades ``` #### Install fail2ban and take a snapshot fail2ban mostly reduces log noise once passwords are disabled, but it is cheap. Then snapshot the configured state — that becomes your known-good baseline. ```bash apt install -y fail2ban && systemctl enable --now fail2ban ``` Q: Should I change the SSH port? A: It is noise reduction rather than security, but it is effective noise reduction — the vast majority of scanners only try port 22. Combined with key-only authentication, the residual risk is negligible either way. Q: What if I lock myself out? A: Use the out-of-band VNC console in the control panel. It attaches to the virtual serial console and works with no network at all. Source: https://onionvps.com/guides/secure-a-new-vps-in-10-minutes ### Set up a WireGuard VPN on a VPS in 5 minutes Beginner · 5 min · updated 2026-05-30 A working WireGuard server needs four things: a key pair, a wg0 interface configuration, IP forwarding with NAT, and one peer block per device. On a $4 instance the whole process takes about five minutes and will saturate a gigabit port. #### Install WireGuard and generate keys The kernel module is already present on any modern Linux distribution running on KVM. ```bash apt update && apt install -y wireguard umask 077 wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub ``` #### Write the server configuration Replace eth0 with your actual interface name if it differs — check with ip -br link. The Address line defines the tunnel subnet, not your public address. ```ini # /etc/wireguard/wg0.conf [Interface] Address = 10.66.66.1/24, fd42:42::1/64 ListenPort = 51820 PrivateKey = PostUp = nft add table ip nat; nft add chain ip nat post { type nat hook postrouting priority 100 \; }; nft add rule ip nat post oifname "eth0" masquerade PostDown = nft delete table ip nat ``` #### Enable forwarding and start the tunnel Forwarding must be enabled for both address families, or IPv6 clients will fail silently. ```bash cat >/etc/sysctl.d/99-wg.conf <<'EOF' net.ipv4.ip_forward=1 net.ipv6.conf.all.forwarding=1 EOF sysctl --system systemctl enable --now wg-quick@wg0 ufw allow 51820/udp ``` #### Add a peer for each device Generate a key pair per device. AllowedIPs on the server side is the address that device will hold inside the tunnel — not a range. ```bash wg set wg0 peer allowed-ips 10.66.66.2/32,fd42:42::2/128 wg-quick save wg0 ``` #### Client configuration AllowedIPs of 0.0.0.0/0 and ::/0 routes all traffic through the tunnel. Narrow it for split tunnelling. ```ini [Interface] PrivateKey = Address = 10.66.66.2/32, fd42:42::2/128 DNS = 10.66.66.1 [Peer] PublicKey = Endpoint = YOUR_SERVER_IP:51820 AllowedIPs = 0.0.0.0/0, ::/0 PersistentKeepalive = 25 ``` Q: How many devices can one VPS handle? A: A single shared core comfortably handles 20+ concurrent peers. The limit is your uplink, not the instance. Q: Why is my connection slow? A: Almost always MTU. Try MTU = 1420 on the client interface; WireGuard adds overhead that can push packets over the path MTU and trigger fragmentation. Source: https://onionvps.com/guides/wireguard-vpn-in-5-minutes ### How to pay for hosting with Monero, step by step Beginner · 8 min · updated 2026-07-02 Acquire XMR through an atomic swap or a decentralised exchange, hold it in a wallet you control, then select Monero at checkout and send the exact invoice amount to the address shown. Ten confirmations — about twenty minutes — and the server provisions automatically. #### Get a wallet you control Feather Wallet on desktop or Cake Wallet on mobile are the usual recommendations. Both are open source and neither requires an account. Write the seed phrase down on paper; there is no recovery process. #### Acquire Monero without an exchange account Atomic swaps exchange BTC for XMR directly between wallets, with cryptography guaranteeing that both sides complete or neither does. Haveno is a decentralised exchange for the same purpose. Peer-to-peer markets are the third route. Buying on a centralised exchange and withdrawing to your own wallet still breaks the on-chain link, because the Monero chain reveals nothing — but the exchange retains a record of the withdrawal. #### Order and select XMR at checkout Choose the plan, location and billing term, supply an email address you control, and select Monero as the payment method. The invoice shows a fresh address, an exact amount and a QR code, valid for 90 minutes at a locked rate. #### Send the exact amount Let the wallet add the network fee on top rather than subtracting it from the amount — that is the most common cause of an underpayment. Shortfalls up to 3% are accepted automatically. #### Wait for confirmations Ten confirmations, roughly twenty minutes. The status page updates live. When it completes, credentials are emailed to the address you supplied, and provisioning takes under a further minute. Q: Do I need an account with anyone? A: No. No account with us, none with the payment processor, and none with an exchange if you use an atomic swap. Q: What if the invoice expires before it confirms? A: The payment is still credited when it lands. Contact support with the transaction hash and the order is completed or refunded. Source: https://onionvps.com/guides/pay-for-hosting-with-monero ### The anonymous VPS purchase checklist Intermediate · 12 min · updated 2026-07-11 Anonymity is a chain, and it breaks at the weakest link. Four steps close the ones that matter: a no-KYC provider, a signup connection that is not your home network, an email alias used nowhere else, and payment in Monero. Everything after purchase is operational discipline. #### Before you start: define the threat Anonymity from a casual observer, from a civil litigant and from a state adversary are three very different problems with three different budgets. Deciding which one you are solving prevents both under- and over-engineering. #### Step 1 — connection Sign up over Tor Browser, or over a VPN you did not buy with a card. Your signup IP is one of the few things a provider might record even when it collects nothing else. #### Step 2 — identity Create an email alias used for nothing else. Providers that require no verification still need somewhere to send credentials. Do not reuse an address that appears in a breach corpus alongside your name. #### Step 3 — payment Monero. This is the step most often done badly: paying with Bitcoin withdrawn from an identity-verified exchange links the purchase to you permanently, no matter how careful the other three steps were. #### Step 4 — after provisioning Generate a fresh SSH key used nowhere else. Administer over Tor or a VPN, consistently — one login from home is all it takes. Keep the server out of accounts that identify you, and register any domain with a registrar that accepts crypto. - Fresh SSH key, never reused, never in a public repository - Consistent administration path — no exceptions - No personal accounts, API keys or analytics on the instance - Strip metadata from anything you publish - Bastion line with LUKS if data at rest matters Q: Is this legal? A: Yes. Buying hosting without volunteering identity documents is an ordinary commercial transaction, and privacy is not evidence of wrongdoing. Q: What is the single most common mistake? A: Payment. People do everything else carefully and then pay with coins withdrawn from an exchange account tied to their passport. Source: https://onionvps.com/guides/buy-a-vps-anonymously-checklist ### A self-hosted mail server that actually reaches the inbox Advanced · 45 min · updated 2026-06-04 Installing a mail server is easy; being trusted by receivers is not. You need outbound port 25, a PTR record matching your banner hostname, SPF, DKIM and DMARC published correctly, address space with no spam history, and a gradual volume ramp. Miss any one and mail lands in spam. #### Set the hostname and reverse DNS first Do this before installing anything. The PTR must resolve to the hostname the server announces, and that hostname must have a forward record pointing back to the same address. ```bash hostnamectl set-hostname mail.example.com # then set the PTR to mail.example.com in the OnionVPS panel ``` #### Install the stack Mailcow gives you a complete Docker-based stack. Stalwart is a single Rust binary if you prefer fewer moving parts. ```bash git clone https://github.com/mailcow/mailcow-dockerized /opt/mailcow cd /opt/mailcow && ./generate_config.sh docker compose up -d ``` #### Publish SPF, DKIM and DMARC All three are DNS records. DKIM keys are generated by the mail stack; copy the public key from its admin interface. ```dns example.com. TXT "v=spf1 mx -all" dkim._domainkey TXT "v=DKIM1; k=rsa; p=MIGfMA0..." _dmarc TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com" ``` #### Warm the address up A few dozen messages a day for the first week, then roughly double weekly. A volume spike from a new IP is indistinguishable from a compromised host, and receivers treat it accordingly. #### Tighten DMARC once the reports are clean Read aggregate reports for a fortnight at p=none, fix whatever is failing, then move to p=quarantine and eventually p=reject. Going straight to reject reliably breaks systems you forgot were sending mail. Q: Why is my mail going to spam? A: In order of likelihood: missing or mismatched PTR, missing DKIM, a new IP sending too much too soon, or address space with prior abuse history. The first three are yours to fix; the fourth is the provider's. Q: Do I need a static IP? A: Yes, and one you can set reverse DNS on. Both are standard on every OnionVPS instance. Source: https://onionvps.com/guides/self-hosted-mail-server-that-delivers ### Private DNS with AdGuard Home and Unbound Intermediate · 20 min · updated 2026-05-12 AdGuard Home filters and serves DNS-over-HTTPS; Unbound behind it performs full recursion so no upstream resolver ever sees your queries. On a $4 instance the pair uses under 200 MB of RAM and replaces the single richest source of behavioural data about you — your ISP's resolver. #### Install Unbound as a recursive resolver Bind it to localhost on a non-standard port so AdGuard Home can take 53. ```bash apt install -y unbound cat >/etc/unbound/unbound.conf.d/local.conf <<'EOF' server: interface: 127.0.0.1@5335 do-ip6: yes prefetch: yes hide-identity: yes hide-version: yes qname-minimisation: yes EOF systemctl restart unbound ``` #### Install AdGuard Home The installer sets up a systemd unit and a web interface on port 3000 for initial configuration. ```bash curl -sSL https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh | sh -s -- -v ``` #### Point AdGuard at Unbound In Settings → DNS, set the upstream to 127.0.0.1:5335 and disable all other upstreams. Full recursion means no third party sees your queries at all. #### Enable DNS-over-HTTPS Get a certificate with Certbot, then enable DoH on 443 and DoT on 853 in the encryption settings. Clients then reach the resolver privately in transit as well as at rest. ```bash certbot certonly --standalone -d dns.example.com ``` #### Lock it down Restrict access by client IP, or require DoH with a secret path. An open resolver is recruited into DNS amplification attacks within days and will be null-routed. Q: Is this better than a public resolver? A: Privately, yes — no third party sees your queries at all with full recursion. Public resolvers are faster because of their cache size; the trade is speed for visibility. Q: How much does it cost to run? A: $4 a month. It is the cheapest meaningful privacy improvement available. Source: https://onionvps.com/guides/private-dns-with-adguard-and-unbound ### A production Docker Compose stack on a VPS Intermediate · 25 min · updated 2026-06-27 A workable production stack is Caddy for automatic TLS, your application, PostgreSQL and Redis, defined in one Compose file with named volumes and health checks. On 8 GB of RAM with NVMe this handles substantial traffic, and a snapshot before each deploy makes rollback a two-minute operation. #### Install Docker from the official repository Distribution packages lag significantly. The convenience script is fine on a fresh instance. ```bash curl -fsSL https://get.docker.com | sh systemctl enable --now docker ``` #### Write the Compose file Caddy obtains and renews certificates automatically, which removes the single most common source of production breakage. ```yaml services: caddy: image: caddy:2-alpine restart: unless-stopped ports: ["80:80", "443:443", "443:443/udp"] volumes: - ./Caddyfile:/etc/caddy/Caddyfile:ro - caddy_data:/data app: build: . restart: unless-stopped depends_on: { db: { condition: service_healthy } } environment: DATABASE_URL: postgres://app:${DB_PASS}@db:5432/app db: image: postgres:17-alpine restart: unless-stopped environment: POSTGRES_USER: app POSTGRES_PASSWORD: ${DB_PASS} volumes: [pgdata:/var/lib/postgresql/data] healthcheck: test: ["CMD-SHELL", "pg_isready -U app"] interval: 10s volumes: { caddy_data: {}, pgdata: {} } ``` #### Configure Caddy Three lines is a complete TLS-terminating reverse proxy with automatic certificate renewal. ```caddy app.example.com { encode zstd gzip reverse_proxy app:8000 } ``` #### Back up the database, not the container A file copy of a running Postgres data directory produces a corrupt backup that appears to succeed. Dump it properly. ```bash docker compose exec -T db pg_dump -U app app | zstd > /backups/app-$(date +%F).sql.zst ``` #### Snapshot before every deploy Free, instant, and it converts a failed deployment from an incident into a rollback. Q: How much RAM does this need? A: Sum the container memory limits and add about 1 GB for the host. This stack is comfortable in 8 GB. Q: Should I use Docker Swarm or Kubernetes instead? A: Not for a single server. Compose is the correct tool until you genuinely have more than one node. Source: https://onionvps.com/guides/docker-compose-production-stack ### A correct nftables firewall, including IPv6 Intermediate · 15 min · updated 2026-04-22 nftables replaces iptables with a single unified ruleset that covers IPv4 and IPv6 together through the inet family. A correct base policy drops inbound by default, accepts established connections, permits loopback and ICMP, and opens only the ports you serve. #### Why the inet family matters The most common firewall mistake on a modern VPS is a v4-only ruleset. Every OnionVPS instance has a routed IPv6 /64, so services remain fully reachable over v6 unless the ruleset covers both. The inet family covers both in one place. #### A complete base ruleset Write it to /etc/nftables.conf and enable the service. Keep a second session open while testing. ```nft #!/usr/sbin/nft -f flush ruleset table inet filter { chain input { type filter hook input priority 0; policy drop; ct state established,related accept ct state invalid drop iif lo accept ip protocol icmp accept ip6 nexthdr icmpv6 accept tcp dport { 22, 80, 443 } accept udp dport 51820 accept # WireGuard limit rate 5/minute burst 10 packets log prefix "nft-drop: " } chain forward { type filter hook forward priority 0; policy drop; } chain output { type filter hook output priority 0; policy accept; } } ``` #### Apply it safely Schedule a flush before applying, so a mistake resolves itself rather than requiring the console. ```bash echo 'nft flush ruleset' | at now + 10 minutes nft -f /etc/nftables.conf # verify you are still connected, then: atrm $(atq | cut -f1) systemctl enable nftables ``` #### Never block ICMPv6 IPv6 depends on ICMPv6 for neighbour discovery and path MTU discovery. Blocking it wholesale, which people do out of IPv4 habit, produces intermittent failures that are extremely hard to diagnose. Q: Should I use nftables or ufw? A: ufw is a friendlier front end and handles both address families correctly by default. Use nftables directly when you need rules ufw cannot express, such as rate limiting or NAT. Q: How do I see what is being dropped? A: The log rule above writes to the kernel log with an "nft-drop" prefix; read it with journalctl -k -g nft-drop. Source: https://onionvps.com/guides/set-up-nftables-and-ipv6-firewall ### Multi-region failover with a WireGuard mesh Advanced · 40 min · updated 2026-07-08 Three instances in three countries, meshed over WireGuard, with the application bound only to the mesh and a health-checked DNS record in front, gives genuine fault tolerance for under $110 a month. The design constraint is database replication: synchronous within a region, asynchronous across them. #### Choose three independent failure domains Different countries, ideally different transit mixes. Amsterdam, Ashburn and Singapore is the classic triangle. Three is the minimum for quorum — two gives you a split-brain problem rather than redundancy. #### Build the mesh Each node gets a stable private address. Every node peers with every other node; with three nodes that is three tunnels. ```ini # node A — /etc/wireguard/mesh.conf [Interface] Address = 10.10.0.1/24 ListenPort = 51821 PrivateKey = [Peer] # node B PublicKey = Endpoint = b.example.net:51821 AllowedIPs = 10.10.0.2/32 PersistentKeepalive = 25 [Peer] # node C PublicKey = Endpoint = c.example.net:51821 AllowedIPs = 10.10.0.3/32 PersistentKeepalive = 25 ``` #### Bind services to the mesh only The database, the cache and the internal API should listen on 10.10.0.x, never on the public address. This removes an entire class of exposure without a single firewall rule. #### Replicate the database appropriately Synchronous replication across regions is impractical — a 160 ms round trip becomes the floor for every write. Use asynchronous replication across regions and know your recovery point objective. #### Health-check at the DNS layer Short TTLs plus health-checked failover records, or anycast if your regions support it. Then run a failure drill: kill a region deliberately, on a weekday, while you are watching. Q: Why not just buy a bigger server? A: A bigger server has the same number of failure domains as a small one: one. Availability comes from independence, not from capacity. Q: How far apart can etcd or Postgres synchronous replicas be? A: Keep synchronous replicas within about 100 ms of each other. Beyond that the write latency becomes the dominant cost of every transaction. Source: https://onionvps.com/guides/multi-region-failover-with-wireguard ### Full-disk encryption on a VPS with remote unlock Advanced · 30 min · updated 2026-06-11 LUKS2 with a dropbear SSH daemon in the initramfs lets you encrypt the root filesystem and supply the passphrase remotely at every boot. The provider never holds the key, so a powered-off disk is ciphertext. It does not protect against a compromised hypervisor, and no provider can honestly claim otherwise. #### Understand exactly what this protects Protects against: physical seizure of a powered-off disk, decommissioned hardware, a datacentre incident, a technician with physical access. Does not protect against: a compromised running hypervisor, or a compromise of the running instance. The key is in memory while the machine runs. #### Install to an encrypted root On the Bastion line this is preconfigured. On any other instance, boot the distribution installer through the out-of-band console and choose an encrypted LVM layout. #### Add dropbear to the initramfs This is what lets you supply the passphrase over SSH before the root filesystem is mounted. ```bash apt install -y dropbear-initramfs cryptsetup-initramfs echo 'DROPBEAR_OPTIONS="-p 2222 -s -j -k"' >> /etc/dropbear/initramfs/dropbear.conf cat ~/.ssh/id_ed25519.pub > /etc/dropbear/initramfs/authorized_keys update-initramfs -u -k all ``` #### Configure the boot network The initramfs has no DHCP client by default; give it a static configuration matching your instance. ```bash # /etc/initramfs-tools/initramfs.conf IP=203.0.113.10::203.0.113.1:255.255.255.0::eth0:off ``` #### Unlock after each reboot Connect on the initramfs port and supply the passphrase. The boot then continues normally. ```bash ssh -p 2222 root@203.0.113.10 # then: cryptroot-unlock ``` Q: What happens if the server reboots while I am asleep? A: It waits at the unlock prompt. That is the trade: unattended reboots are impossible, which is exactly what makes the key genuinely yours. Q: Can OnionVPS unlock my disk? A: No. We never hold the passphrase, and there is no recovery mechanism. If you lose it, the data is gone. Source: https://onionvps.com/guides/encrypted-vps-with-luks-remote-unlock --- ## 9. Glossary (68) ### KVM (Kernel-based Virtual Machine) KVM is full hardware virtualisation built into the Linux kernel, giving each guest its own kernel and hardware-enforced isolation from other tenants. Because a KVM guest runs its own kernel, it can load kernel modules, run non-Linux operating systems, use real swap and support nested virtualisation. Memory allocated to a KVM guest is genuinely reserved, which is the practical difference from container-based virtualisation. Source: https://onionvps.com/glossary/kvm ### OpenVZ (Virtuozzo) OpenVZ is container-based virtualisation in which every instance shares the host kernel, so guests cannot load kernel modules or run a different operating system. OpenVZ is why unusually cheap virtual servers exist: density is much higher and memory is routinely oversold. It is also why Docker, WireGuard on older hosts and custom kernels frequently fail on budget providers. Source: https://onionvps.com/glossary/openvz ### LXC (Linux Containers) LXC is Linux-native containerisation that isolates processes with namespaces and cgroups while sharing the host kernel. LXC is excellent inside a trust boundary you already own and weak as a multi-tenant boundary, because a kernel escape affects every container on the host. Source: https://onionvps.com/glossary/lxc ### Hypervisor A hypervisor is the software layer that creates and runs virtual machines, allocating physical CPU, memory and IO between them. A type-1 hypervisor runs directly on the hardware; KVM is unusual in being a type-1 hypervisor implemented as a Linux kernel module, which lets it use the whole Linux driver ecosystem. Source: https://onionvps.com/glossary/hypervisor ### Nested virtualisation Nested virtualisation lets a virtual machine itself run virtual machines, by exposing the processor virtualisation extensions to the guest. It is required for Proxmox VE, VM-based CI jobs and some Docker configurations. Many providers disable it, which is the usual reason those workloads fail elsewhere. Source: https://onionvps.com/glossary/nested-virtualisation ### vCPU (virtual CPU) A vCPU is a virtual processor presented to a guest, backed by scheduling time on a physical core or thread. The decisive question is whether the backing thread is shared with other tenants or reserved. A dedicated vCPU has no other tenant scheduled against it; a shared one competes, producing steal time. Source: https://onionvps.com/glossary/vcpu ### CPU steal time (st time) Steal time is the proportion of time a virtual CPU was ready to run but the hypervisor gave the physical core to another guest. It appears as the "st" column in top and vmstat. Sustained values above 2–3% indicate contention and show up as tail-latency spikes rather than as uniformly slow throughput. Source: https://onionvps.com/glossary/steal-time ### cloud-init cloud-init is the standard mechanism for configuring a virtual machine on first boot, using metadata supplied by the platform. It handles SSH key injection, hostname, network configuration and arbitrary user scripts, which is what makes fully automated provisioning possible. Source: https://onionvps.com/glossary/cloud-init ### NVMe (NVM Express) NVMe is a storage protocol that connects solid-state drives directly over PCIe, reaching roughly 500,000 random IOPS with sub-100-microsecond latency. Its deep parallel queue model is architecturally different from SATA, which inherits a single-queue design intended for mechanical disks. For database-backed applications the random-IOPS gap is the difference users actually feel. Source: https://onionvps.com/glossary/nvme ### IOPS (input/output operations per second) IOPS measures how many individual read or write operations a storage device completes per second. Random 4K IOPS at a queue depth of one is the number that predicts database behaviour; sequential throughput is the number that appears in marketing. Source: https://onionvps.com/glossary/iops ### RAID 10 (RAID 1+0) RAID 10 mirrors data across pairs of drives and stripes across the mirrors, giving both redundancy and high performance at the cost of half the raw capacity. It is the standard choice for virtualisation storage because it tolerates a drive failure without the write-amplification penalty of parity RAID. RAID 5 and RAID 6 store parity instead of a full mirror, which is cheaper per usable terabyte but turns every small write into a read-modify-write cycle — ruinous for a host running dozens of database-backed guests. RAID 10 also rebuilds far faster after a failure, because it copies from one surviving mirror rather than recomputing parity across the whole array, and a long rebuild is exactly when a second drive is most likely to fail. Every OnionVPS NVMe pool is RAID 10; the Hold line uses RAID 6 on its bulk HDD arrays, where the access pattern is large and sequential and parity costs nothing noticeable. Source: https://onionvps.com/glossary/raid-10 ### LUKS (Linux Unified Key Setup, LUKS2) LUKS is the standard Linux full-disk encryption format, storing key material in a header on the encrypted volume itself. On a VPS it protects data at rest against physical seizure and disk decommissioning. It does not protect against an attacker with access to the running hypervisor, because the key is in memory while the machine runs. Source: https://onionvps.com/glossary/luks ### Snapshot A snapshot is a point-in-time copy of a virtual machine disk, taken instantly and stored on the same infrastructure. Snapshots protect against your own mistakes and are ideal before an upgrade. They are not backups: if the underlying storage is lost, the snapshots go with it. Source: https://onionvps.com/glossary/snapshot ### ASN (Autonomous System Number) An ASN identifies a network that controls its own routing policy and announces its address space to the global routing table via BGP. A provider running its own ASN controls its routing, peering and address space directly rather than reselling someone else's. OnionVPS operates AS200558. Source: https://onionvps.com/glossary/asn ### BGP (Border Gateway Protocol) BGP is the protocol that autonomous systems use to exchange routing information and decide how traffic crosses the internet. BGP path selection is why two servers the same physical distance apart can have very different latency: the route matters as much as the distance. Source: https://onionvps.com/glossary/bgp ### IXP (Internet Exchange Point, peering exchange) An IXP is a shared physical facility where networks interconnect directly rather than paying a transit provider to carry traffic between them. Direct exchange traffic is shorter, cheaper and usually lower-latency. Presence at DE-CIX, AMS-IX, LINX or Equinix Ashburn is a meaningful signal about a provider's network quality. Source: https://onionvps.com/glossary/ixp ### Peering Peering is a direct interconnection between two networks that exchange traffic with each other without paying a third party to carry it. Settlement-free peering reduces both cost and hop count. A provider that peers widely delivers lower latency than one that buys all its connectivity as transit. Source: https://onionvps.com/glossary/peering ### IP transit Transit is a paid service in which one network carries another network's traffic to the rest of the internet. Multiple diverse transit providers is what keeps a network reachable when one upstream has an outage. OnionVPS buys transit from Cogent, Lumen, Arelion, GTT and Telia. Source: https://onionvps.com/glossary/transit ### Anycast Anycast announces the same IP address from several locations at once, so each user is routed to the nearest instance by BGP. It reduces latency without DNS propagation delay and absorbs volumetric attacks by spreading them across sites. It requires the provider to control its own address space and ASN. Source: https://onionvps.com/glossary/anycast ### RTT (round-trip time, ping) RTT is the time for a packet to travel to a destination and for the response to return, measured in milliseconds. The physical floor is about 1 ms per 100 km each way: light in fibre travels at roughly two-thirds of c and real routes are around 1.35 times the great-circle distance. No provider beats that floor, which is why placement decides more about perceived speed than any hardware specification. What a good network does is get close to the floor — direct peering rather than three transit hops, and uncongested links that do not add queueing delay on top of distance. Note that ICMP ping and application-layer round trip are not the same measurement: routers routinely de-prioritise ICMP, so a ping can look worse than the TCP handshake your users actually experience. Every OnionVPS location page publishes an estimated RTT to every other region, computed from the formula above so the number is reproducible rather than promotional. Source: https://onionvps.com/glossary/rtt ### Jitter Jitter is variation in packet delay over time, as distinct from the average delay itself. For voice, gaming and trading, jitter often matters more than latency: a consistent 60 ms is far more usable than an average of 40 ms that regularly spikes to 200 ms, because buffers are sized for the worst case rather than the mean. Jitter usually comes from queueing on a congested link, from route flapping, or — on the server side — from CPU steal time delaying the process that should have replied. That last cause is invisible in a network trace and is the reason dedicated vCPU matters for latency-sensitive workloads. Measure it with mtr or a long iperf3 run rather than a handful of pings; a five-packet sample tells you almost nothing about variance. Source: https://onionvps.com/glossary/jitter ### IPv6 IPv6 is the current version of the Internet Protocol, using 128-bit addresses to replace the exhausted 32-bit IPv4 space. A routed /64 subnet, which is the standard allocation, contains about 18 quintillion addresses — enough to give every container and service its own public address without network address translation. Source: https://onionvps.com/glossary/ipv6 ### Reverse DNS (PTR record, rDNS) Reverse DNS maps an IP address back to a hostname through a PTR record, the inverse of a normal DNS lookup. It is effectively mandatory for outbound mail: most large receivers reject messages from addresses whose PTR does not resolve back to the sending hostname. Source: https://onionvps.com/glossary/reverse-dns ### Port 25 (SMTP port) Port 25 is the TCP port used for server-to-server SMTP mail delivery. Most hosting providers block it permanently to limit spam, which makes self-hosted mail impossible on much of the market. It is open by default on every OnionVPS instance. Source: https://onionvps.com/glossary/port-25 ### Unmetered bandwidth Unmetered means transfer volume is not counted, though the port speed still caps how much can move. It is distinct from "unlimited", which is usually marketing. An unmetered gigabit port can physically move about 324 TB a month; the honest constraint is the port, not a policy. Source: https://onionvps.com/glossary/unmetered ### DDoS (distributed denial of service) A DDoS attack floods a target with traffic or expensive requests from many sources at once, to exhaust bandwidth, connection state or processing capacity. Volumetric attacks at layers 3 and 4 are stopped by upstream scrubbing; application-layer attacks at layer 7 send requests that look legitimate and need protocol-aware filtering. Source: https://onionvps.com/glossary/ddos ### Traffic scrubbing (DDoS mitigation) Scrubbing routes traffic through filtering infrastructure that discards attack packets and forwards legitimate ones. Always-on scrubbing filters continuously; on-demand scrubbing diverts traffic only once an attack is detected, which means the first minutes of every attack succeed. Source: https://onionvps.com/glossary/scrubbing ### Null route (blackhole) A null route discards all traffic to an IP address, protecting the wider network by making the target completely unreachable. From the customer's point of view a null route is indistinguishable from a successful attack: the service is unreachable, which is precisely what the attacker wanted. It exists because the alternative can be worse — an attack large enough to saturate a shared uplink degrades every other customer behind it, so the address under attack is dropped upstream to protect the rest. A provider that reaches for null-routing quickly is telling you its scrubbing capacity is thin. OnionVPS filters first and null-routes only when an attack exceeds what the edge can absorb without collateral damage, and tells the affected customer when it happens rather than leaving them to diagnose an outage that has no cause on their server. Source: https://onionvps.com/glossary/null-route ### fail2ban fail2ban monitors log files for repeated authentication failures and temporarily firewalls the offending addresses. It reduces log noise and slows brute-force attempts, and it is genuinely useful in front of services that must accept passwords. It is not a substitute for disabling password authentication on SSH, which removes the attack class entirely rather than throttling it — a key-based login cannot be brute-forced at all. Tune it carefully: an aggressive findtime and maxretry will eventually ban you from your own server, which is one of the more common reasons people discover their provider has no out-of-band console. Modern equivalents such as sshguard and CrowdSec work the same way, and nftables can express simple rate limits without any daemon at all. Source: https://onionvps.com/glossary/fail2ban ### Warrant canary A warrant canary is a regularly republished statement that a provider has not received a secret legal demand; its disappearance implies that one has arrived. It is only meaningful with a fixed schedule, a cryptographic signature and a recent external timestamp proving it could not have been pre-signed. Its legal status is largely untested. Source: https://onionvps.com/glossary/warrant-canary ### KYC (know your customer) KYC is the set of identity-verification duties imposed on regulated financial institutions before providing services. These duties bind banks, exchanges and payment institutions because they handle money transmission. Hosting is not a regulated financial activity, so a compute provider has no equivalent obligation in the jurisdictions where we operate. Hosts that demand a passport do so for chargeback and fraud control, not because a statute requires it — which is why crypto-settled providers, who cannot receive a chargeback, generally do not ask. The distinction matters practically: an identity document collected for fraud control is still an identity document that can be breached, sold, or produced in response to a demand years later. Source: https://onionvps.com/glossary/kyc ### No-KYC hosting (anonymous hosting) No-KYC hosting is server hosting that requires no identity verification — no government ID, billing address, phone number or payment card. The provider therefore holds no identity information that can be breached, sold or compelled. That is an architectural property rather than a policy promise. Source: https://onionvps.com/glossary/no-kyc-hosting ### Offshore hosting Offshore hosting means placing a server in a jurisdiction other than your own, typically one outside the Fourteen Eyes alliances and outside EU data-retention rules. It changes which law governs the server and which court can compel disclosure. It does not make illegal content legal, and it does not exempt you from the law where you live. Source: https://onionvps.com/glossary/offshore-hosting ### Five Eyes (FVEY) The Five Eyes is a signals-intelligence sharing alliance between the United States, United Kingdom, Canada, Australia and New Zealand. Nine Eyes adds Denmark, France, the Netherlands and Norway; Fourteen Eyes adds Belgium, Germany, Italy, Spain and Sweden. Privacy-oriented hosting typically avoids all fourteen. Source: https://onionvps.com/glossary/five-eyes ### Fourteen Eyes (14 Eyes, SIGINT Seniors Europe) The Fourteen Eyes is the widest of the signals-intelligence sharing groupings, comprising the Five Eyes plus Denmark, France, the Netherlands, Norway, Belgium, Germany, Italy, Spain and Sweden. Membership is a legitimate jurisdiction signal but not a complete analysis: a non-member can still have aggressive domestic retention law, and a member can have strong judicial oversight. Source: https://onionvps.com/glossary/fourteen-eyes ### MLAT (mutual legal assistance treaty) An MLAT is a treaty through which one country formally requests another to gather evidence on its behalf. Requests routinely take six to eighteen months, most treaties require dual criminality, and many exclude civil matters entirely — which is why offshore jurisdiction is particularly effective against speculative civil discovery. Source: https://onionvps.com/glossary/mlat ### DMCA (Digital Millennium Copyright Act) The DMCA is United States copyright statute whose notice-and-takedown procedure and safe harbour apply to service providers situated in the United States. A server outside the US is governed by local copyright law instead, which in most countries requires a court order rather than a private notice. Copyright still applies; only the enforcement mechanism differs. Source: https://onionvps.com/glossary/dmca ### Data retention Data retention laws require communications providers to store connection metadata for a defined period so that authorities can obtain it later. The EU's original Data Retention Directive was invalidated by the Court of Justice in 2014, and Romania struck its national law down twice on constitutional grounds. Several offshore jurisdictions impose no such obligation at all. Source: https://onionvps.com/glossary/data-retention ### GDPR (General Data Protection Regulation) The GDPR is the EU regulation governing processing of personal data of people in the EU, regardless of where the processing happens. It follows the data subject rather than the server, so hosting outside the EU does not exempt you — it adds a transfer-mechanism obligation such as standard contractual clauses. Source: https://onionvps.com/glossary/gdpr ### IBC (International Business Company) An IBC is a corporate form offered by jurisdictions such as Seychelles, Belize and the British Virgin Islands, characterised by confidentiality and minimal reporting. Typical features include no public beneficial-ownership register, no local tax on foreign income, and limited exposure to foreign legal process. Source: https://onionvps.com/glossary/ibc ### Bulletproof hosting Bulletproof hosting describes a provider that claims to ignore all abuse complaints and law enforcement, including for criminal activity. It is distinct from anonymous hosting, which simply does not collect identity data. Bulletproof providers' address space is blocklisted wholesale, so mail is rejected and users face constant CAPTCHAs. Source: https://onionvps.com/glossary/bulletproof-hosting ### Monero (XMR) Monero is a cryptocurrency that hides sender, receiver and amount at the protocol level using ring signatures, stealth addresses and RingCT. Unlike Bitcoin there is no public balance or transaction graph to analyse, which makes it the default recommendation for privacy-motivated purchases. Source: https://onionvps.com/glossary/monero ### Ring signature A ring signature proves that one member of a group signed a message without revealing which one. In Monero it hides which output is actually being spent, by mixing the real input with decoys drawn from the chain. Source: https://onionvps.com/glossary/ring-signature ### Stealth address A stealth address is a one-time destination address generated for each payment so that transactions to the same recipient cannot be linked. It is why a Monero recipient can publish a single address without every payment to it becoming publicly correlatable. Source: https://onionvps.com/glossary/stealth-address ### RingCT (Ring Confidential Transactions) RingCT conceals transaction amounts on the Monero blockchain while still allowing the network to verify that inputs equal outputs. It closed the last major analytical surface in Monero: before RingCT, visible amounts allowed transactions to be correlated even when parties were hidden. Source: https://onionvps.com/glossary/ringct ### Stablecoin (USDT, USDC) A stablecoin is a token pegged to a fiat currency, typically the US dollar, and backed by reserves held by an issuer. Stablecoins remove exchange-rate risk from an invoice but are the least private option: the ledger is transparent and the issuer can freeze or blacklist addresses. Source: https://onionvps.com/glossary/stablecoin ### TRC-20 TRC-20 is the token standard on the TRON blockchain, most commonly used for USDT. It is usually the cheapest network for a hosting-sized payment, with fees measured in cents and confirmation in about a minute. Source: https://onionvps.com/glossary/trc20 ### Confirmation (block confirmation) A confirmation is a block added to the chain after the block containing a transaction, each making reversal exponentially harder. Merchants require more confirmations on chains where reorganisations are cheap. The requirement is shown on the invoice before payment. Source: https://onionvps.com/glossary/confirmation ### Atomic swap An atomic swap exchanges two cryptocurrencies directly between wallets, with cryptography guaranteeing that either both sides complete or neither does. It is the common route from Bitcoin to Monero without an exchange account, and therefore without identity verification. Source: https://onionvps.com/glossary/atomic-swap ### WireGuard WireGuard is a VPN protocol implemented in about 4,000 lines of kernel code with a fixed modern cipher suite. It is roughly three to four times faster than OpenVPN on the same hardware, reconnects instantly, and is small enough to be meaningfully auditable. It is UDP-only, which makes it blockable on restrictive networks. Source: https://onionvps.com/glossary/wireguard ### OpenVPN OpenVPN is a mature userspace VPN protocol with configurable ciphers that can run over TCP or UDP. Its remaining advantage over WireGuard is that it can run over TCP port 443 and closely resemble ordinary TLS, which matters where VPN traffic is filtered. Source: https://onionvps.com/glossary/openvpn ### Tor (The Onion Router) Tor routes traffic through three volunteer-operated relays chosen so that no single relay knows both the origin and the destination. It provides anonymity from the destination at the cost of latency. Middle relays and bridges are permitted on any OnionVPS instance; exit relays are permitted in approved jurisdictions. Source: https://onionvps.com/glossary/tor ### Tor exit node (exit relay) A Tor exit node is the final relay in a circuit, which connects to the destination and therefore appears to be the source of the traffic. Exits receive abuse complaints for traffic carried on behalf of others, which is why many hosts prohibit them and why we permit them only in approved jurisdictions with a published abuse contact. Source: https://onionvps.com/glossary/tor-exit-node ### Onion service (hidden service) An onion service is a service reachable only through Tor, whose address is derived from its public key rather than registered with any authority. Because there is no DNS registrar and no public IP, an onion service removes two of the main points at which a conventional site can be identified or seized. Source: https://onionvps.com/glossary/onion-service ### SOCKS5 SOCKS5 is a proxy protocol that forwards arbitrary TCP and UDP traffic, with optional authentication. Unlike an HTTP proxy it is protocol-agnostic, which is why it is the usual choice for tunnelling application traffic. An unauthenticated SOCKS5 proxy is found by scanners within hours. Source: https://onionvps.com/glossary/socks5 ### Shadowsocks Shadowsocks is an encrypted proxy protocol designed to be difficult to identify by traffic analysis. It is widely used where VPN protocols are actively blocked, since its traffic does not present a recognisable handshake. Source: https://onionvps.com/glossary/shadowsocks ### No-logs policy A no-logs policy is a commitment not to retain records of user activity such as connection metadata, netflow or DNS queries. The distinction that matters is between logs that are not kept and logs that are never generated. Ask specifically about netflow: a provider can truthfully say it does not sell data while retaining a complete connection record. Source: https://onionvps.com/glossary/no-logs ### SPF (Sender Policy Framework) SPF is a DNS record listing which servers are authorised to send mail for a domain. It is the first of three records receivers check. Without it, mail from a new server is treated as suspicious by default. Source: https://onionvps.com/glossary/spf ### DKIM (DomainKeys Identified Mail) DKIM cryptographically signs outgoing messages so a receiver can verify the domain and that the content was not altered in transit. The public key is published in DNS. Together with SPF it forms the basis on which DMARC makes a pass or fail decision. Source: https://onionvps.com/glossary/dkim ### DMARC DMARC tells receivers what to do with messages that fail SPF and DKIM, and where to send aggregate reports. Start at p=none and read the reports for a fortnight before tightening. Going straight to p=reject on an established domain reliably breaks systems you had forgotten were sending mail. Source: https://onionvps.com/glossary/dmarc ### SLA (service level agreement) An SLA is a contractual commitment to a service level, usually availability, with defined compensation when it is missed. 99.99% permits about 4.4 minutes of downtime a month; 99.9% permits about 43 minutes. Check what the SLA covers — network and hypervisor availability, not your application. Source: https://onionvps.com/glossary/sla ### Out-of-band console (VNC console, KVM console) An out-of-band console attaches to a virtual machine's display and keyboard independently of its network connection. It is how a firewall mistake, a broken SSH configuration or a boot failure gets fixed without a support ticket, and how custom ISO installation is performed. Source: https://onionvps.com/glossary/out-of-band-console ### Custom ISO Custom ISO support lets you upload an installer image and boot the instance from it, rather than choosing from a fixed template list. It is the escape hatch that makes a VPS genuinely general-purpose: BSDs, hardened images, appliance operating systems and anything you built yourself. Source: https://onionvps.com/glossary/custom-iso ### Terraform (OpenTofu) Terraform declares infrastructure in configuration files and reconciles the real environment against them. A provider with a Terraform provider can be treated as code: instances, addresses and firewall rules become reviewable, versioned artefacts. Source: https://onionvps.com/glossary/terraform ### TTFB (time to first byte) TTFB measures the time from a request being sent to the first byte of the response arriving. It combines network latency with server processing time, which is why it is dominated by distance for a fast application and by the application for a distant one. It feeds directly into Core Web Vitals. Source: https://onionvps.com/glossary/ttfb ### Seedbox A seedbox is a server dedicated to downloading and seeding torrents at high speed, typically with large storage and a fast uplink. The technology is entirely lawful; what is transferred determines legality. Jurisdiction is the main selection criterion, because copyright enforcement mechanisms differ sharply between countries. Source: https://onionvps.com/glossary/seedbox ### Control panel (hosting panel) A control panel is a web interface for administering servers, websites, mail and databases — cPanel, DirectAdmin, CyberPanel and similar. Panels save time and add attack surface. Several require an enterprise-family Linux distribution such as AlmaLinux or Rocky. Source: https://onionvps.com/glossary/control-panel ### Provisioning Provisioning is the process of creating, configuring and delivering a server so that it is ready to use. On a modern platform it is fully automated and takes under a minute. Delays are almost always payment confirmation or a manual fraud review, not the machine itself. Source: https://onionvps.com/glossary/provisioning --- ## 10. Policies ### Acceptable Use Policy Effective 2026-07-01, last reviewed 2026-07-01. OnionVPS prohibits child sexual abuse material, malware command-and-control, ransomware infrastructure, phishing, spam, outbound attacks, and proof-of-work mining on shared hardware. Everything else lawful is permitted, including VPNs, Tor relays, scraping of public data, adult content lawful where it is hosted, and security research with written authorisation. #### The principle The line is active harm to third parties, not offensiveness, controversy or commercial inconvenience. We do not scan your storage, inspect your traffic or profile what you run, so enforcement is complaint-driven and evidence-driven. That is the only approach compatible with not surveilling customers. #### Absolutely prohibited These result in immediate termination without notice, and CSAM is reported to the appropriate authority. - Child sexual abuse material, in any form, without exception - Malware command-and-control, ransomware infrastructure, exploit kits, botnet controllers - Phishing, credential harvesting, and impersonation of financial institutions or public bodies - Denial-of-service attacks, port scanning at scale, and any attack originating from your instance - Unsolicited bulk email, and hosting infrastructure that supports it - Trafficking in stolen credentials, payment data or personal records #### Prohibited for platform reasons These are not moral judgements; they degrade the service for everyone on the same hardware. - Proof-of-work mining on shared infrastructure - Deliberate resource exhaustion designed to affect neighbouring instances - Open relays, open resolvers and unauthenticated proxies, which are recruited into amplification attacks #### Explicitly permitted Listed because other providers commonly prohibit them, and because it is more useful to know what is allowed than to guess. - VPN endpoints and proxy servers, personal or commercial - Tor middle relays and bridges anywhere; exit relays in approved jurisdictions with a published abuse contact - Web scraping and crawling of lawfully accessible public data at reasonable rates - Adult content that is lawful in the jurisdiction hosting it and involves only consenting adults - Cryptocurrency nodes, validators, RPC endpoints and trading infrastructure - iGaming and betting platforms where properly licensed - Security research and penetration testing with written authorisation from the target owner - Reselling and white-labelling of our infrastructure as your own product - Mail servers, including bulk mail to recipients who opted in #### How complaints are handled Complaints are triaged by evidence, not by volume. Automated copyright notices sent to non-US locations are forwarded to you for information and no action follows, because the DMCA procedure has no application outside the United States. Reports of active harm receive a response within hours. You will always receive the complaint and a stated window to act — normally 72 hours — unless the harm is ongoing and severe. We never disclose customer identity in response to an abuse complaint, because we hold none. #### Suspension Suspension is reserved for active, ongoing harm. When we suspend, network access is cut but storage is preserved and you retain console access to retrieve your data. We do not use deletion as an enforcement tool. #### Sanctions We do not provide service to jurisdictions or persons subject to comprehensive international sanctions. This is a legal constraint on us as a Seychelles company with international transit relationships, not a customer-identification requirement. Source: https://onionvps.com/legal/acceptable-use ### Privacy Policy Effective 2026-07-01, last reviewed 2026-07-01. OnionVPS collects an email address, a payment reference from the processor, and the technical state needed to run your instance. It does not collect names, addresses, government identification, phone numbers or payment cards, and does not generate netflow, connection or DNS query logs. There are no analytics, cookies or third-party scripts on this website. #### What we collect - An email address you supply — the only identifier we hold - A payment reference and amount from OxaPay, which does not include a wallet identity - Instance metadata: plan, region, assigned addresses, operating system, power state - Aggregate bandwidth counters, for billing and capacity planning - Support correspondence you send us, retained for 90 days after resolution #### What we do not collect - Legal name, postal address, date of birth or government identification - Payment card details or bank information — we cannot accept them - Phone numbers - Netflow records or connection logs of any kind - DNS query logs on our resolvers - Signup or control-panel IP addresses, beyond the lifetime of the session - The contents of your instance storage #### This website No analytics, no cookies, no third-party scripts, no fonts loaded from a CDN, no tracking pixels. Nothing on any page of this site makes a request to a host we do not operate. Server access logs are retained for 24 hours for operational debugging and then discarded. #### Disclosure We disclose data only where compelled by valid legal process from a court with jurisdiction over OnionVPS, and then only what is ordered. Where the law permits, we notify the affected customer first so they can challenge the order themselves. Where a gag order forbids notification, the warrant canary carries that information instead. We do not sell, rent, share or trade customer data with anyone, under any circumstances, and there is no advertising or analytics relationship through which it could leak. #### Data at rest Any provider with hypervisor access can technically read an unencrypted guest disk. That is true of every virtualisation platform including every hyperscaler, and claims to the contrary are false. Our staff do not access guest storage except where you ask us to, or where a valid order compels it. On the Bastion line, disks are LUKS2-encrypted with a passphrase we never hold. #### Your rights You may request a copy of everything we hold about you, or its deletion, by writing to the address below from your account email. Because we hold so little, both requests are usually satisfied within one business day. Deletion of an active account terminates service. Source: https://onionvps.com/legal/privacy ### Terms of Service Effective 2026-07-01, last reviewed 2026-07-01. OnionVPS provides unmanaged KVM virtual servers on a prepaid basis in US dollars, settled in cryptocurrency. We are responsible for the hardware, network, hypervisor and control plane; you are responsible for the operating system and everything above it, and for the lawfulness of what you host. #### The service OnionVPS Systems L.L.C., a Seychelles International Business Company, provides virtual private servers on an unmanaged basis. We maintain the physical infrastructure, network connectivity, hypervisor and control plane. You maintain the guest operating system, applications, security configuration and data. #### Accounts An account is identified by an email address. We do not verify identity and do not require any. You are responsible for maintaining access to that address; if you lose it, we have no alternative means of authenticating you, and we will not restore access on the basis of unverifiable claims. That is the direct consequence of collecting nothing else. #### Billing Service is prepaid for the selected term. Prices are in US dollars and settled in cryptocurrency at the rate quoted on the invoice. Renewal invoices are issued seven days before the term ends. Service is suspended three days after a term expires unpaid, and data is retained for a further fourteen days before deletion. #### Refunds First orders carry a seven-day money-back guarantee, refunded in full to an address you nominate. After seven days, terms run to their end and partial months are not pro-rated. SLA credits are separate and are not time-limited. #### Your obligations - Comply with the Acceptable Use Policy - Keep your instance secure and patched — a compromised instance that attacks others is your responsibility - Ensure what you host is lawful in the jurisdiction hosting it - Maintain your own backups; snapshots are a convenience, not a disaster-recovery guarantee #### Limitation of liability Our aggregate liability is limited to the fees you paid in the three months preceding the claim. We are not liable for lost data, lost profits or consequential damages. This is standard for unmanaged infrastructure and is the basis on which the price is set. #### Termination You may terminate at any time from the control panel; the current term is not refunded beyond the seven-day window. We may terminate for material breach of the Acceptable Use Policy, with notice except where harm is ongoing. #### Governing law These terms are governed by the laws of the Republic of Seychelles. Nothing here limits rights you hold under mandatory law in your own jurisdiction. Source: https://onionvps.com/legal/terms ### Copyright & DMCA Policy Effective 2026-07-01, last reviewed 2026-07-01. The DMCA is United States copyright statute and applies to our United States locations. For locations outside the US, DMCA notices carry no procedural effect and are forwarded to the customer for information only; removal there requires a court order from a court with jurisdiction. Copyright itself applies everywhere under the Berne Convention. #### United States locations For instances in New York, Ashburn, Miami, Dallas, Chicago, Los Angeles, Seattle, Phoenix, Atlanta, San Juan and Hagåtña, we operate a standard DMCA notice-and-takedown process. Send a compliant notice to the address below and we will forward it and act as the statute requires. #### Non-US locations The DMCA is domestic US legislation. Its notice-and-takedown procedure and safe harbour apply to service providers situated in the United States. A notice sent regarding a server in Panama, Moldova or Seychelles is a letter, not a legal instrument: we forward it to the customer for information and take no further action absent a valid order. This is often described as "DMCA ignored", which misstates it. Nothing is defied — the procedure simply has no application. Copyright infringement remains unlawful in every jurisdiction we operate in; the enforcement mechanism is judicial rather than administrative. #### What a valid notice must contain - Identification of the copyrighted work claimed to be infringed - Identification of the material and its location, precisely enough for us to find it - Your contact details - A statement of good-faith belief that the use is not authorised - A statement, under penalty of perjury, that the information is accurate and you are authorised to act - A physical or electronic signature #### Counter-notices and abuse of process Customers may submit counter-notices, which we forward. We keep a record of notice volume per complainant and disregard senders with a demonstrated pattern of automated, inaccurate or bad-faith notices. Sending a knowingly false notice carries liability in most jurisdictions. Source: https://onionvps.com/legal/copyright ### Refund Policy Effective 2026-07-01, last reviewed 2026-07-01. First orders carry a seven-day money-back guarantee, refunded in full in cryptocurrency to an address you nominate, usually within one business day. After seven days terms run to their end. SLA credits are separate, automatic and not time-limited. Terminations for Acceptable Use Policy breach are not refunded. #### The seven-day guarantee It applies to your first order and to your first order only. No reason is required. Write to support from your account email within seven days of provisioning and supply a receiving address. #### How crypto refunds work A crypto payment cannot be reversed, so a refund is a new payment that we initiate. It is sent in the coin you paid with, or in an agreed equivalent, at the rate at the time of refund. Network fees are deducted. #### SLA credits Where monthly availability falls below the committed 99.99%, credits are applied automatically without a claim: 10% below 99.99%, 25% below 99.9%, 50% below 99.5% and 100% below 99%. Credits apply to future terms and are not paid out in cash. #### What is not refunded - Terms beyond the seven-day window on a first order - Renewals - Accounts terminated for Acceptable Use Policy breach - Add-ons already consumed, such as a Windows licence month in progress Source: https://onionvps.com/legal/refund ### Service Level Agreement Effective 2026-07-01, last reviewed 2026-07-01. OnionVPS commits to 99.99% monthly availability per instance, measured on network reachability and hypervisor availability. Breaches earn automatic service credits: 10% below 99.99%, 25% below 99.9%, 50% below 99.5% and 100% below 99%. Observed fleet availability over the last twelve months was 99.993%. #### What is measured Availability is measured per instance, per calendar month, as the proportion of one-minute intervals in which the instance was reachable from at least two independent external probes and the hypervisor reported it running. Measurement is ours; the method is published so it can be checked against your own monitoring. #### Credit schedule - Below 99.99% — 10% of the monthly fee - Below 99.9% — 25% of the monthly fee - Below 99.5% — 50% of the monthly fee - Below 99.0% — 100% of the monthly fee #### Exclusions The SLA does not cover your operating system, your applications, a firewall rule that locked you out, scheduled maintenance announced at least 72 hours in advance, or suspension under the Acceptable Use Policy. No provider SLA covers those, and any that claims to is not describing something it can measure. #### Claiming You do not need to. Credits are applied automatically once a breach is confirmed against our measurement. If your own monitoring disagrees with ours, send it to support and we will reconcile. Source: https://onionvps.com/legal/sla --- End of corpus. 100 answers, 24 comparisons, 31 workload guides, 10 tutorials, 68 defined terms, 138 locations, 18 plans.