Solution

VPS for journalism, research and source-protection infrastructure

Bastion 8 · $59/moBastion 16 · $109/mo
Short answer

Source-protection infrastructure is a legal architecture problem before it is a technical one. What matters is that the provider holds no identity information, keeps no connection records, sits outside mutual legal assistance reach, and encrypts disks with a key it does not have. The Bastion line in Seychelles, Panama, Iceland or Switzerland is built exactly for this.

What you need

Specification floor for journalism & source protection
ResourceWhat you actually need
JurisdictionOutside the Eyes alliances and outside easy MLAT reach
DiskLUKS2 full-disk encryption, unlocked at boot by you over SSH
AccountNo identity data held; email alias plus crypto payment
LoggingNo connection logs, no netflow, no access records retained

Recommended plans

Bastion

Bastion 8

$ 59 /month
vCPU
4 × dedicated
RAM
8 GB
Storage
160 GB NVMe SSD + LUKS2
Transfer
15 TB
IPv4 / IPv6
3 / /64 routed
Configure
Bastion

Bastion 16

$ 109 /month
vCPU
8 × dedicated
RAM
16 GB
Storage
320 GB NVMe SSD + LUKS2
Transfer
25 TB
IPv4 / IPv6
3 / /64 routed
Configure
Bastion

Bastion 32

$ 199 /month
vCPU
12 × dedicated
RAM
32 GB
Storage
640 GB NVMe SSD + LUKS2
Transfer
40 TB
IPv4 / IPv6
3 / /64 routed
Configure

Recommended locations

Location is usually the decision that matters most for this workload — either because latency dominates, or because jurisdiction does.

Why OnionVPS for this

  • We cannot disclose identity data we never collected — that is an architectural property, not a promise.
  • Bastion instances encrypt at rest with a key you hold; a seized disk is ciphertext.
  • A warrant canary, updated on a published schedule, with the signing key on the same page.
  • Seychelles incorporation with no public beneficial-ownership register and limited MLAT exposure.

How to set it up

  1. Order a Bastion instance from a network you do not normally use

    Tor or a VPN, with an email alias created for the purpose.

  2. Pay in Monero

    Protocol-level privacy; there is no public ledger entry to correlate.

  3. Set the LUKS passphrase at first boot

    Unlock over dropbear SSH after each reboot. We never see the key.

  4. Deploy SecureDrop or a hardened onion service

    Tor-only, no clearnet listener at all.

  5. Rehearse the failure cases

    Practise the wipe and the restore before you need either.

Frequently asked questions

Can hosting genuinely protect a source?

Hosting is one layer. It removes the provider as a point of compulsion and puts the server outside easy legal reach, but it cannot fix operational security mistakes elsewhere. Treat it as necessary, not sufficient.

What happens if you receive a subpoena?

We assess whether it is valid legal process from a court with jurisdiction over us. If it is, we comply with exactly what is ordered — which is very little, because we hold an email address and a payment reference. If it is not, we reject it. Either way, the warrant canary reflects reality.

Is full-disk encryption really useful on a VPS?

Against physical seizure of a powered-off disk, yes, decisively. Against an attacker with access to the running hypervisor, no — and no provider can honestly claim otherwise. We say so plainly because the distinction matters.