Hardened offshore KVM

Bastion

Maximum jurisdictional and disk-level separation.

Dedicated AMD EPYC 9004NVMe (RAID-10) + LUKS2From $59/moOffshore regions only
Short answer

Our hardened line, available only in offshore and privacy-tier jurisdictions. Ships with full-disk LUKS encryption keyed at boot by you, three IPv4 addresses, a routed /64, and a dedicated abuse contact that never forwards customer identity because we do not hold any.

Bastion plans

Bastion 8

$ 59 /month
vCPU
4 × dedicated
RAM
8 GB
Storage
160 GB NVMe SSD + LUKS2
Transfer
15 TB
IPv4 / IPv6
3 / /64 routed
Configure

Bastion 16

$ 109 /month
vCPU
8 × dedicated
RAM
16 GB
Storage
320 GB NVMe SSD + LUKS2
Transfer
25 TB
IPv4 / IPv6
3 / /64 routed
Configure

Bastion 32

$ 199 /month
vCPU
12 × dedicated
RAM
32 GB
Storage
640 GB NVMe SSD + LUKS2
Transfer
40 TB
IPv4 / IPv6
3 / /64 routed
Configure

Available in offshore and privacy-tier jurisdictions only — 29 locations.

What Bastion is for

Bastion pairs a dedicated AMD EPYC 9004 with LUKS2-encrypted RAID-10 NVMe, and ships only in jurisdictions where we hold no identity. The technical edge is the junction of that encryption, which is keyed at boot by you, and the routed /64, which gives you a full subnet to work with. Buy it when separation is the point: sensitive archives, private services, or research that must stay private. The included three IPv4 addresses give you room to segment without asking.

Journalists and researchers run Bastion for encrypted mail, secure drop boxes, and source communication relays. Whistleblower infrastructure uses the boot-time keying to keep data unreadable until the system starts. Privacy services and sensitive archives rely on the dedicated CPU and RAID-10 storage for reliable performance under constant read-heavy load.

Choosing a size

Choose between Bastion 8, 16, and 32 by your transfer ceiling and memory appetite. Start with the smallest plan, because moving down a tier requires a rebuild. If the monitoring panel consistently shows CPU steal above zero for hours, or swap activity becomes regular, you have bought too small and should step up.

Specifications

Bastion — full specification
PlanvCPURAMStorageTransferIPv4Monthly
Bastion 848 GB160 GB NVMe SSD + LUKS215 TB3$59
Bastion 16816 GB320 GB NVMe SSD + LUKS225 TB3$109
Bastion 321232 GB640 GB NVMe SSD + LUKS240 TB3$199

Best suited to

Journalism & researchWhistleblower infrastructurePrivacy servicesSensitive archives

In every plan, at every tier

IncludedWhat it means
Full root / Administrator accessIncluding custom kernels, nested virtualisation and raw sockets.
True KVM virtualisationNot a container. Your own kernel, your own /proc, no shared namespace.
Custom ISO uploadBoot anything: OpenBSD, NixOS, Whonix, a hand-rolled image.
Out-of-band VNC consoleRecover a broken network config without opening a ticket.
Routed IPv6 /64Not a single address — a whole subnet, at no cost.
Always-on DDoS mitigationUp to 12 Tbps of edge scrubbing capacity, included at every tier.
Three free snapshotsInstant, and taken without pausing the instance.
Self-service reverse DNSSet PTR records from the panel; essential for mail.
Full REST API and Terraform providerEverything the panel does, scriptable.
No identity verification, everAn email address you control is the only account identifier we hold.

Frequently asked questions

Who is the Bastion line for?

Our hardened line, available only in offshore and privacy-tier jurisdictions. Ships with full-disk LUKS encryption keyed at boot by you, three IPv4 addresses, a routed /64, and a dedicated abuse contact that never forwards customer identity because we do not hold any.

Are Bastion cores dedicated?

Yes. Each vCPU is a physical thread reserved for your instance, with no other tenant scheduled against it, so steal time is effectively zero.

Can I upgrade later?

CPU and RAM increase with a short reboot, and disk grows online. Moving down a tier requires a rebuild, so start smaller than you think you need.

Does the LUKS encryption require any interaction at each boot?

Yes. You provide the passphrase or keyfile at boot, either through the VNC console or via an injected key. The disk stays encrypted until then. This is part of the separation: the decryption key never rests on our side, so we could not hand it over even if asked.

How do the three IPv4 addresses and the /64 differ in use?

IPv4 addresses work for separate services or outgoing connections that need distinct identities. The /64 is a routed subnet you can partition for containers, mail, or internal experiments. Both are routable directly, and the IPv4 ones can be set with reverse DNS from the panel.