KYC stands for know-your-customer: the process of verifying who a customer is before serving them. It began in banking, where anti-money-laundering rules genuinely require regulated institutions to identify account holders. Hosting providers borrowed the term and the habit, even though renting a virtual server is not a regulated financial activity. In practice a host’s KYC looks like some combination of these:
- a working email you must confirm, often with disposable addresses blocked;
- a phone number and an SMS or call verification code;
- a payment card whose billing name has to match the account;
- a scan of a government ID or passport, sometimes with a selfie or liveness check;
- geolocation and device fingerprinting to flag “risky” signups.
Why do they bother? Rarely because a law tells a VPS company to collect passports. The real drivers are commercial: card networks impose chargeback liability, so hosts try to tie every order to a recoverable, identifiable person; fraud teams treat anonymity itself as a risk score; and resellers inherit the KYC demands of whatever upstream they build on. Identity verification is the path of least resistance for a business that settles in fiat — not a legal necessity for selling compute.