Skip to content
Anonymous VPS

Anonymous VPS hosting is a chain. We are one link.

Any provider claiming to make you anonymous is overselling. What we can do is remove ourselves as a point of correlation — no identity collected, no card, no logs. The rest of the chain is operational, and this page is about which parts are yours.

No KYCMonero accepted0-day log retentionOwn ASN
Updated

Maintained by the NimbusVPS engineering team. We publish under the company name rather than a personal byline, and the structured data on this page says the same.

Anonymity is a chain, and it breaks at the weakest link

A server is traceable to you if any link in the chain between you and it can be resolved. There are five, and a provider controls exactly one of them:

  1. The payment path — how money got from you to the provider.
  2. The registration data — what the provider asked for and stored. This is the link we control.
  3. The access path — the network route you use to administer the server.
  4. The workload — what the server itself reveals, in logs, headers, certificates and DNS.
  5. Operational discipline — reused SSH keys, reused usernames, reused hostnames, and everything else that correlates one identity to another over time.

A provider that removes link 2 entirely, as we do, has done something genuinely useful and completely insufficient on its own. Links 1, 3, 4 and 5 are yours. This page is mostly about those, because that is where anonymity is actually won or lost.

What we remove (link 2)

  • No identity collection. No name, address, ID document, phone number or payment card exists anywhere in the ordering system. Not optional — the fields do not exist.
  • No card payments at all. Cards create a chargeback path, which creates a fraud-control incentive, which creates identity collection. Removing the cause removes the effect.
  • Monero accepted. Bitcoin is a public ledger, so a BTC-only provider offers materially less privacy than one taking XMR, regardless of what its front page says.
  • 0-day access log retention. No deep packet inspection, no traffic mirroring, no identity-linked NetFlow.
  • Our own address space. IPv4 address space announced from our own autonomous system, so no upstream can be leaned on to pull your prefix over our objection. The AS number and its current status are on the network page.
  • Tor and VPN traffic explicitly permitted, with a free checkout toggle that flags the server so abuse handling is correct from day one.

Full detail on what is and is not stored is on the no-KYC page.

Link 1: the payment path

This is where most people's anonymity actually fails, and it fails before they ever reach a hosting provider.

Bitcoin is not anonymous. It is a permanently public ledger. If you buy BTC on an exchange that holds your passport and send it straight to a hosting invoice, you have created a durable, auditable link between your legal identity and your server. The hosting provider knowing nothing about you is irrelevant — the exchange knows, and the chain is public.

In rough order of effectiveness:

  • Monero (XMR), acquired without KYC. Ring signatures, stealth addresses and confidential transactions mean the ledger does not reveal sender, recipient or amount. This is the strongest option available and it is why we accept it.
  • Monero acquired on a KYC exchange. Still substantially better than Bitcoin — the exchange knows you bought XMR, but the on-chain path to the invoice is not publicly traceable.
  • Bitcoin from a non-KYC source — peer-to-peer, an ATM under reporting thresholds, or earned rather than bought.
  • Bitcoin from a KYC exchange. Convenient, and effectively pseudonymous at best. Fine if your concern is data breaches and marketing databases rather than a determined investigator.

All of these work at checkout. We are describing the trade-offs so you can pick knowingly, not steering you.

Link 3: the access path

Your server sees the IP address you connect from, and so does anyone with visibility into that path. SSH from your home connection and the server's own auth log is a record of where you live.

  • Use Tor for administration. ProxyCommand torsocks nc %h %p in your SSH config is enough for most people, and costs a little latency.
  • Better: run a hidden service on the box. Bind sshd to an onion address and firewall public SSH off entirely. There is a guide in our docs.
  • Or chain through a second VPS paid for separately. A jump host in a different jurisdiction, bought in a different session, breaks a single-provider correlation.
  • Do not administer from a network associated with you — home, office, or a phone hotspot — even once. A single connection is enough.

Link 4: what the server reveals about itself

Servers are talkative. Common leaks, all self-inflicted:

  • TLS certificates. Certificate Transparency logs are public and permanent. A certificate for internal.yourrealname.com on an anonymous server has published the association forever.
  • Reverse DNS and WHOIS. Set rDNS to something neutral. Register domains through a privacy-respecting registrar, or use an onion service and no domain at all.
  • Application headers and error pages. Default installs leak versions, paths, hostnames and sometimes email addresses in stack traces.
  • Analytics and CDNs. Third-party JavaScript reports your visitors — and your admin sessions — to companies that log everything and answer subpoenas.
  • Outbound updates and telemetry. Package managers, crash reporters and license checks all phone home with identifiable patterns.
  • NTP and DNS. Default resolvers see every lookup the box makes. Run your own resolver or use DNS over TLS to somewhere you trust.

Link 5: operational discipline

The failures here are boring and extremely common:

  • Reusing an SSH key that also authenticates to a personal GitHub account.
  • Reusing a username, hostname naming scheme or password across identities.
  • Using the same email alias for the anonymous server and for something tied to your name.
  • Paying for two "separate" identities from the same wallet.
  • Referencing the server in a support ticket from an address that is linked to you elsewhere.
  • Deploying with an infrastructure-as-code repository that has your name in the commit history.

Generate a fresh key. Use a fresh alias. Use a fresh wallet. Keep the identities genuinely separate, or accept that they are one identity.

Be honest about your threat model

Anonymity is not binary, and the honest question is "anonymous against whom?"

Adversary What it takes
Marketing databases, data brokersNo-KYC provider. Done — nothing to sell or leak.
A breach at the providerNo-KYC provider. An empty database breaches harmlessly.
Civil litigant with a subpoenaNo-KYC plus offshore jurisdiction. There is little to compel and a foreign court to persuade first.
Competitor or harasser doing OSINTAll of the above plus clean rDNS, certificates and WHOIS.
Local police, ordinary investigationAll of the above plus Monero and Tor-only administration.
A state intelligence service targeting you specificallyNo hosting provider can help you. Anyone claiming otherwise is selling something.

We will not pretend to the last row. Most people are somewhere in the middle, and for the middle the combination of no-KYC, Monero, an offshore jurisdiction and Tor administration is genuinely strong.

Frequently asked questions

What is an anonymous VPS?

An anonymous VPS is a virtual server that cannot readily be traced back to the identity of the person operating it. That requires two independent things: a provider that does not collect identity — no KYC, no card, no phone number — and operational practices on your side covering how you paid, how you connect and what the server discloses about itself. NimbusVPS supplies the first; the second is yours and no provider can supply it for you.

Is a VPS bought with Bitcoin anonymous?

Not by itself. Bitcoin is a permanently public ledger, so if the coins came from an exchange holding your identity documents, the link between you and the payment is durable and publicly auditable regardless of what the hosting provider knows. Monero, which conceals sender, recipient and amount at the protocol level, is a materially stronger choice and is accepted at checkout.

Can NimbusVPS identify its own customers?

In the general case, no. What exists in our systems is an email address, a cryptocurrency transaction reference produced by the payment processor, and the technical configuration of the server. There is no name, address, identity document, phone number or card on file, because those fields do not exist in the ordering system. If you supplied a personal email address or paid from a wallet linked to your identity, that association exists — but it was created by you, not collected by us.

Do you log what I do on the server?

No. There is no deep packet inspection, no traffic mirroring, and no identity-linked NetFlow. Aggregate port-level counters exist for capacity planning and DDoS detection and contain no payload and no per-destination data. Access logs have 0-day retention, meaning they are not kept. What runs inside your VPS is not visible to us short of a hypervisor-level action we do not take absent a court order in the server's jurisdiction.

Can I run Tor on the server?

Yes. Relays, bridges and VPN endpoints are explicitly permitted, and there is a free toggle at checkout that flags the server so our abuse desk handles the resulting reports correctly rather than treating them as violations. Tor exit relays are permitted in the Netherlands, Iceland, Romania and Moldova, and not permitted in the United States location.

What is the single most common mistake?

Paying with Bitcoin bought on a KYC exchange, then administering the server from a home connection. That combination defeats everything a no-KYC provider does, because the association chain simply routes around us — through the exchange on one side and the ISP on the other. Fix the payment path and the access path and you have addressed the two links that matter most.

Questions this page did not answer? Ask support — first-reply target 12 minutes, 24/7.

We remove our link. You handle yours.

No identity collected, Monero accepted, Tor permitted, and our own ASN behind it.

7-day money-back guarantee · No KYC · Cancel any time from the panel