Skip to content
TLDBunker

Transparency

Transparency report

The short answer

We publish a semi-annual transparency report listing every authority request we receive, how many produced any data, and how many accounts were affected. As of 2026-07-14 those figures are zero to date. Each report is PGP-signed. We disclose customer data only when a valid legal order compels it — never voluntarily.

Current period

The semi-annual report

A short, extractable table you can read, cite, and check against a signed copy. This is what we have received — not a promise about the future.

Authority requests received, requests that produced data, and accounts affected, to date
Metric Value
Authority requests received 0 to date
Requests that produced data 0 to date
Customer accounts affected 0 to date
Cadence
Semi-annual. Periods close 30 June and 31 December; each edition is signed and published after the period ends.
Reporting period
Begins at launch.
Signature
Clear-signed with our published PGP key.

What these figures mean

This page reports three things, measured on a fixed schedule: how many requests we received from a government, court, or law-enforcement body; how many of those requests resulted in us handing over any customer data; and how many customer accounts were touched. The figures above are current as of 2026-07-14. TLDBunker is a pre-launch service — no VPS has yet been sold — so the honest running total is zero to date. We are publishing the report now to lock in the format and the cadence before there is anything to hide behind.

The gap between the first row and the second is the point of the whole exercise. A request can be lawful, correctly served, and still produce nothing, because the data it asks for was never collected. That is by design. Our no-logs policy specifies, in a Git-versioned document, exactly what we retain, why, and for how long — which is what determines what could ever be surrendered under compulsion. Read the two pages together: this report tells you what was asked; the no-logs policy tells you what could possibly be answered.

How we respond to legal process

We do not advertise immunity. TLDBunker is a privacy host with a published Acceptable Use Policy and a working abuse desk — not a “bulletproof” host. When a request arrives, we check that it is valid and binding under the law of our operating jurisdiction and properly served. We narrow it to the minimum the order actually requires. We surrender only what exists, and we never volunteer customer data — not to accelerate an abuse complaint, not for a commercial partner, not to anyone who simply asks. Where the law permits us to notify an affected customer, we aim to do so. Where a valid order forbids notice, we comply with the order.

The editing entity that stands behind these commitments is the TLDBunker team, and the same entity signs every edition of this report. Nothing on this page is legal advice; it is a description of our operating practice and our public commitments, which are constrained by the law that applies to us.

Why there is no warrant canary — yet

You will not find a warrant canary on this site today, and that is a deliberate choice rather than an oversight. A warrant canary is a load-bearing legal signal: a standing statement that we have not received a certain kind of secret order, quietly removed if we ever do. Its value depends entirely on whether the courts in our jurisdiction would treat its removal as protected speech or as an illegal disclosure — and in many jurisdictions the honest legal answer is that a canary is worthless or actively counter-productive.

So we gate it. A canary will be adopted only if written legal advice validates it for our specific jurisdiction (gate G0) — pending our legal review. If counsel advises against it, there will be no canary, and this semi-annual report stands as the mechanism. If counsel validates it, we will publish it under strict governance: a fixed calendar, quorum PGP signing by multiple key-holders, and a public page setting out precisely what the canary covers, what it does not, and its legal limits. We would rather run a boring, signed report we can honour every six months than a dramatic signal we cannot legally stand behind.

We also do not make running representations about the existence or non-existence of any non-public order. That silence is not a hint — it is the absence of a canary we have chosen not to fake. Until the mechanism is validated, judge us by what is signed and dated on this page.

Verify this report

Every edition is clear-signed with our published PGP key. To verify: fetch our key, confirm its fingerprint against the one we publish, then check the signature over the report text. A copy that is unsigned, signed by an unknown key, or older than the current period should be treated as unverified. The same key signs our reproducible benchmarks, so a single trusted fingerprint covers both. If you want the wider picture of how the five sites we publish relate to one another, that is laid out on the network page; who we are is on about.

Scope and limits

This report covers legal process directed at TLDBunker as a hosting provider. It is general information about our practice, not legal advice, and it does not waive any right or create any obligation beyond what the law imposes. Figures are re-confirmed and re-signed at each period close; between editions, the signed copy for the stated period is authoritative.

Frequently asked questions

Do you run a warrant canary?

Not at this time. A warrant canary is only worth publishing if written legal advice confirms it is valid and low-risk in our jurisdiction; in many places it is legally hollow or counter-productive. Until counsel signs off (gate G0), this semi-annual transparency report is the mechanism, and we will not fake a canary to look tougher than we are.

What does "requests that produced data" actually count?

It counts how many valid legal orders resulted in us handing over any customer data at all. Because we run a versioned no-logs policy, most data an authority might ask for was never collected and cannot be produced. A request can be lawful and still yield nothing, and we count those separately from requests we complied with.

How often is the report published, and how do I verify it?

Semi-annually. Each edition is clear-signed with our published PGP key so you can confirm it was issued by us and not altered. Verify the signature against the fingerprint we publish, then compare the period and figures. An unsigned or stale report should be treated as unverified.

Will you ever hand over my data?

Only when a valid, binding legal order compels it — never voluntarily, never for commercial reasons, and never to make an abuse complaint go away faster. Even under compulsion, we can only surrender what exists, which our no-logs policy deliberately keeps to a minimum. We never expose customer data beyond what the law forces.

Privacy you can check, not just claims

Read the versioned no-logs policy and the AUP, then order a VPS with no email and pay in Monero.