Bastion 8
- vCPU
- 4 × dedicated
- RAM
- 8 GB
- Storage
- 160 GB NVMe SSD + LUKS2
- Transfer
- 15 TB
- IPv4 / IPv6
- 3 / /64 routed
Hardened offshore KVM
Maximum jurisdictional and disk-level separation.
Our hardened line, available only in offshore and privacy-tier jurisdictions. Ships with full-disk LUKS encryption keyed at boot by you, three IPv4 addresses, a routed /64, and a dedicated abuse contact that never forwards customer identity because we do not hold any.
Available in offshore and privacy-tier jurisdictions only — 29 locations.
Bastion pairs a dedicated AMD EPYC 9004 with LUKS2-encrypted RAID-10 NVMe, and ships only in jurisdictions where we hold no identity. The technical edge is the junction of that encryption, which is keyed at boot by you, and the routed /64, which gives you a full subnet to work with. Buy it when separation is the point: sensitive archives, private services, or research that must stay private. The included three IPv4 addresses give you room to segment without asking.
Journalists and researchers run Bastion for encrypted mail, secure drop boxes, and source communication relays. Whistleblower infrastructure uses the boot-time keying to keep data unreadable until the system starts. Privacy services and sensitive archives rely on the dedicated CPU and RAID-10 storage for reliable performance under constant read-heavy load.
Choose between Bastion 8, 16, and 32 by your transfer ceiling and memory appetite. Start with the smallest plan, because moving down a tier requires a rebuild. If the monitoring panel consistently shows CPU steal above zero for hours, or swap activity becomes regular, you have bought too small and should step up.
| Plan | vCPU | RAM | Storage | Transfer | IPv4 | Monthly |
|---|---|---|---|---|---|---|
| Bastion 8 | 4 | 8 GB | 160 GB NVMe SSD + LUKS2 | 15 TB | 3 | $59 |
| Bastion 16 | 8 | 16 GB | 320 GB NVMe SSD + LUKS2 | 25 TB | 3 | $109 |
| Bastion 32 | 12 | 32 GB | 640 GB NVMe SSD + LUKS2 | 40 TB | 3 | $199 |
| Included | What it means |
|---|---|
| Full root / Administrator access | Including custom kernels, nested virtualisation and raw sockets. |
| True KVM virtualisation | Not a container. Your own kernel, your own /proc, no shared namespace. |
| Custom ISO upload | Boot anything: OpenBSD, NixOS, Whonix, a hand-rolled image. |
| Out-of-band VNC console | Recover a broken network config without opening a ticket. |
| Routed IPv6 /64 | Not a single address — a whole subnet, at no cost. |
| Always-on DDoS mitigation | Up to 12 Tbps of edge scrubbing capacity, included at every tier. |
| Three free snapshots | Instant, and taken without pausing the instance. |
| Self-service reverse DNS | Set PTR records from the panel; essential for mail. |
| Full REST API and Terraform provider | Everything the panel does, scriptable. |
| No identity verification, ever | An email address you control is the only account identifier we hold. |
Our hardened line, available only in offshore and privacy-tier jurisdictions. Ships with full-disk LUKS encryption keyed at boot by you, three IPv4 addresses, a routed /64, and a dedicated abuse contact that never forwards customer identity because we do not hold any.
Yes. Each vCPU is a physical thread reserved for your instance, with no other tenant scheduled against it, so steal time is effectively zero.
CPU and RAM increase with a short reboot, and disk grows online. Moving down a tier requires a rebuild, so start smaller than you think you need.
Yes. You provide the passphrase or keyfile at boot, either through the VNC console or via an injected key. The disk stays encrypted until then. This is part of the separation: the decryption key never rests on our side, so we could not hand it over even if asked.
IPv4 addresses work for separate services or outgoing connections that need distinct identities. The /64 is a routed subnet you can partition for containers, mail, or internal experiments. Both are routable directly, and the IPv4 ones can be set with reverse DNS from the panel.