What these figures mean
This page reports three things, measured on a fixed schedule: how many requests we received from a government, court, or law-enforcement body; how many of those requests resulted in us handing over any customer data; and how many customer accounts were touched. The figures above are current as of 2026-07-14. TLDBunker is a pre-launch service — no VPS has yet been sold — so the honest running total is zero to date. We are publishing the report now to lock in the format and the cadence before there is anything to hide behind.
The gap between the first row and the second is the point of the whole exercise. A request can be lawful, correctly served, and still produce nothing, because the data it asks for was never collected. That is by design. Our no-logs policy specifies, in a Git-versioned document, exactly what we retain, why, and for how long — which is what determines what could ever be surrendered under compulsion. Read the two pages together: this report tells you what was asked; the no-logs policy tells you what could possibly be answered.
How we respond to legal process
We do not advertise immunity. TLDBunker is a privacy host with a published Acceptable Use Policy and a working abuse desk — not a “bulletproof” host. When a request arrives, we check that it is valid and binding under the law of our operating jurisdiction and properly served. We narrow it to the minimum the order actually requires. We surrender only what exists, and we never volunteer customer data — not to accelerate an abuse complaint, not for a commercial partner, not to anyone who simply asks. Where the law permits us to notify an affected customer, we aim to do so. Where a valid order forbids notice, we comply with the order.
The editing entity that stands behind these commitments is
the TLDBunker team, and the same entity signs every edition of this report. Nothing on
this page is legal advice; it is a description of our operating practice and our public
commitments, which are constrained by the law that applies to us.
Why there is no warrant canary — yet
You will not find a warrant canary on this site today, and that is a deliberate choice rather than an oversight. A warrant canary is a load-bearing legal signal: a standing statement that we have not received a certain kind of secret order, quietly removed if we ever do. Its value depends entirely on whether the courts in our jurisdiction would treat its removal as protected speech or as an illegal disclosure — and in many jurisdictions the honest legal answer is that a canary is worthless or actively counter-productive.
So we gate it. A canary will be adopted only if written legal advice validates it for our specific jurisdiction (gate G0) — pending our legal review. If counsel advises against it, there will be no canary, and this semi-annual report stands as the mechanism. If counsel validates it, we will publish it under strict governance: a fixed calendar, quorum PGP signing by multiple key-holders, and a public page setting out precisely what the canary covers, what it does not, and its legal limits. We would rather run a boring, signed report we can honour every six months than a dramatic signal we cannot legally stand behind.
We also do not make running representations about the existence or non-existence of any non-public order. That silence is not a hint — it is the absence of a canary we have chosen not to fake. Until the mechanism is validated, judge us by what is signed and dated on this page.
Verify this report
Every edition is clear-signed with our published PGP key. To verify: fetch our key, confirm its fingerprint against the one we publish, then check the signature over the report text. A copy that is unsigned, signed by an unknown key, or older than the current period should be treated as unverified. The same key signs our reproducible benchmarks, so a single trusted fingerprint covers both. If you want the wider picture of how the five sites we publish relate to one another, that is laid out on the network page; who we are is on about.