GhostVPSghostvps.shop Deploy a VPS

← All policies

Transparency

Warrant canary

Last updated: August 8, 2026 · Next update due: November 8, 2026

This page carries a statement signed with the GhostVPS PGP key. We publish a fresh one every quarter. The signature is what makes it meaningful — anyone can copy text, but only the holder of our private key can sign it.

Read the silence, not just the statement. The value of a canary is in its disappearance. If this page stops being updated, if an update is late without explanation, or if the wording quietly changes, treat that as the signal — not the reassurance. Do not assume a missing update is an oversight.

Current statement

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

GhostVPS Warrant Canary

Statement date: 2026-08-08
Next statement due: 2026-11-08

As of the date above, and to the knowledge of the person signing this statement,
GhostVPS:

  1. has never received a warrant, subpoena, court order or other legal demand
     compelling disclosure of user data;
  2. has never received a National Security Letter or any equivalent demand
     accompanied by a gag order;
  3. has never been compelled to modify its systems, software or infrastructure
     to facilitate surveillance or to weaken security;
  4. has never handed over encryption keys, wallet keys or account tokens to any
     third party;
  5. remains in sole operational control of its systems and signing keys.

This statement covers GhostVPS only. It does not speak for our upstream
infrastructure providers, who are separate companies subject to their own legal
processes.

Freshness proof, so that an older signature cannot be presented as a current one:

  Monero block height: 3735517
  Monero block hash:   f35ddb75654f91072149dd45bf3ca5352073e6024f87b18154617e344bba6e3c

This canary is republished every quarter. Absence of an update, a late update,
or a silent change in wording should be treated as the signal.

Signing key fingerprint: 7225 CE95 B1FC 29F0 E513 242D D674 87C3 3558 E2B1
-----BEGIN PGP SIGNATURE-----

iJEEARYKADkWIQRyJc6Vsfwp8OUTJC3WdIfDNVjisQUCanboyxsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDEACgkQ1nSHwzVY4rFYlAD/co3MnRDSXsOnFociJ41Q
sd48ZRUrgNKYrO6A9LQ/3m0BAPZHmC0whqgiqBjQ5Dwmvx2NGRYDpW+OpTAHvFRS
GbQM
=vB7T
-----END PGP SIGNATURE-----

How to verify it

Do not take our word for the signature. Check it yourself:

  1. Import our public key:
    curl -s https://www.ghostvps.shop/legal/pgp-key.txt | gpg --import
  2. Save the signed block above to a file, e.g. canary.txt
  3. Verify:
    gpg --verify canary.txt

A good signature will report the key fingerprint 7225 CE95 B1FC 29F0 E513 242D D674 87C3 3558 E2B1. If it reports anything else, or the signature does not verify, do not trust the statement. The same key is published at /legal/pgp-key.txt and /.well-known/pgp-key.txt, and is recorded on our Monerica listing as an independent copy.

Freshness

Each statement quotes a recent Monero block height and hash. That block did not exist when earlier statements were signed, which is what stops an old signature from being passed off as a current one. You can check the quoted block on any Monero explorer.

What this does and does not tell you

A canary is a narrow instrument. It speaks only about the specific things listed in the statement, only up to the date it was signed, and only about GhostVPS itself — not about our upstream infrastructure providers, who are separate companies subject to their own legal processes. It is not a guarantee about the future, and its legal standing has never been comprehensively tested in court. Read it alongside our privacy policy and terms rather than instead of them.

Past statements

Previous signed statements are kept below as they are replaced, so the record can be checked over time.

No previous statements yet — this is the first.