Bastion 8
- vCPU
- 4 × dedicated
- RAM
- 8 GB
- Storage
- 160 GB NVMe SSD + LUKS2
- Transfer
- 15 TB
- IPv4 / IPv6
- 3 / /64 routed
Solution
Source-protection infrastructure is a legal architecture problem before it is a technical one. What matters is that the provider holds no identity information, keeps no connection records, sits outside mutual legal assistance reach, and encrypts disks with a key it does not have. The Bastion line in Seychelles, Panama, Iceland or Switzerland is built exactly for this.
| Resource | What you actually need |
|---|---|
| Jurisdiction | Outside the Eyes alliances and outside easy MLAT reach |
| Disk | LUKS2 full-disk encryption, unlocked at boot by you over SSH |
| Account | No identity data held; email alias plus crypto payment |
| Logging | No connection logs, no netflow, no access records retained |
Location is usually the decision that matters most for this workload — either because latency dominates, or because jurisdiction does.
Tor or a VPN, with an email alias created for the purpose.
Protocol-level privacy; there is no public ledger entry to correlate.
Unlock over dropbear SSH after each reboot. We never see the key.
Tor-only, no clearnet listener at all.
Practise the wipe and the restore before you need either.
Hosting is one layer. It removes the provider as a point of compulsion and puts the server outside easy legal reach, but it cannot fix operational security mistakes elsewhere. Treat it as necessary, not sufficient.
We assess whether it is valid legal process from a court with jurisdiction over us. If it is, we comply with exactly what is ordered — which is very little, because we hold an email address and a payment reference. If it is not, we reject it. Either way, the warrant canary reflects reality.
Against physical seizure of a powered-off disk, yes, decisively. Against an attacker with access to the running hypervisor, no — and no provider can honestly claim otherwise. We say so plainly because the distinction matters.