CrestVPS

33 jurisdictions · 36 cities

Offshore hosting: jurisdiction, not immunity

Offshore hosting means choosing which country's law governs your server. It does not mean the server is beyond law, and anyone telling you otherwise is selling something.

Offshore hosting is a jurisdiction decision. You pick a country, your server sits in a named facility there, and that country's law governs what happens to it: what a court can compel, what an operator must retain, what notice you are owed. That is the whole mechanism. It is not extraterritoriality. It is not immunity from process. A server in Zurich is subject to Swiss law, which is a different set of rules from German law, not an absence of rules. CrestVPS runs 36 cities in 33 countries, with our own cages in twelve of them. Signup is an email address and payment is cryptocurrency, so we hold little about you. Jurisdiction decides who can ask us for it.

01

What jurisdiction determines

Jurisdiction sets the legal process that reaches the machine. Which authority can issue an order. Which court reviews it. Whether a foreign request must clear mutual assistance or a domestic judge first. Whether the host carries a general data retention duty. Whether you are notified, and how fast a gag order expires. It also sets the data protection regime covering the records we do hold: the revised FADP in Switzerland, PDPA in Singapore, PIPEDA in Canada, GDPR across the EU sites. Those regimes constrain us as much as they protect you, and they are the reason the country label on a server is a real variable rather than a flag on a page.

02

What jurisdiction does not determine

Jurisdiction does not put a server outside law. Every CrestVPS machine sits in a named country, and we answer valid legal process from that jurisdiction. We publish a transparency report twice a year so the volume is visible rather than asserted. Jurisdiction also does not follow you. It governs the host and the hardware, not your residency, your company's, or your users'. If you are resident in one country and your server sits in another, both systems are in play. It does nothing about the network path either: traffic crosses transit networks under their own rules before it reaches us.

Choosing against a real threat model

Start with the adversary. A civil claimant filing in a US court is a different problem from a national regulator, a competitor issuing takedowns, or a scraper mapping your infrastructure. Write down who can plausibly move against you, what they can compel, and where. Then pick the country that adds friction to that specific path: a mutual assistance step, judicial review, a language barrier, a regulator with standing. Latency and peering usually matter more to your users than the flag does, so choose a site that survives both tests. If nobody in your model can reach a court, jurisdiction is not your bottleneck and you are optimising the wrong layer.

Jurisdiction is a filter. Encryption is a control.

Jurisdiction changes who may ask, and how hard the asking is. It never changes what is legible once someone has the disk. Only encryption does that, and only one of the two is under your control. We can place the machine in Reykjavik. We cannot make an unencrypted volume unreadable. Encrypt at rest with keys you hold, unlock remotely over SSH at boot, terminate TLS on your own instance, and keep secrets out of anything we store. Assume the hypervisor is in scope. Every family boots images you control, so this is your decision, not a feature we grant.

By region

Six jurisdictions worth knowing

CH · 01

Switzerland: outside the EU, revised FADP

Switzerland is not an EU member and not bound by EU instruments, so requests from EU authorities travel through mutual assistance rather than direct cooperation. The revised FADP applies to the data we hold and carries its own breach and access duties. Swiss process is available to Swiss authorities, and we answer it. Own cage. Choose Zurich for legal distance from EU and US courts, not for immunity.

Zurich

IS · 02

Iceland: IMMI-aligned source protection

Iceland's 2011 Media Act, drawn from the IMMI resolution, gives unusually strong protection to journalistic sources. Other parts of IMMI, intermediary liability among them, were never enacted. The country is in the EEA, so GDPR-equivalent rules apply, but it sits outside the EU and off the main transit spine. Reykjavik suits publishing, archives and anything where disclosure of a source is the real risk. Transit costs more and continental latency is higher.

Reykjavik

MD · 03

Moldova: outside EU instruments

Moldova sits outside the EU and outside its enforcement instruments, so orders from member states require formal mutual assistance rather than a direct channel. Domestic Moldovan process still applies and we answer it. Moldova is the least integrated of the six, which cuts both ways: fewer automatic routes into the country, and a thinner body of data protection practice to rely on.

Chisinau

SG · 04

Singapore: PDPA and dense APAC peering

Singapore pairs a strict data protection statute, the PDPA, with the densest peering in South East Asia. It is a rule-of-law jurisdiction with an active regulator, which means predictable process rather than absent process. Content rules are stricter than in Europe and enforcement is real. Own cage, direct APAC latency. Pick Singapore for proximity to users, not for distance from authority.

Singapore

NL · 05

Netherlands: no general retention duty

Dutch law places no general data retention duty on hosting providers after the national retention regime was struck down. GDPR applies in full. AMS-IX is one of the two largest European exchanges and our own cage sits on it. Notice-and-takedown is well developed and actively used, so expect a functioning complaints process, not an absent one. Amsterdam is the default European choice on network grounds alone.

Amsterdam

CA · 06

Canada: PIPEDA, outside US jurisdiction

Canada is a separate jurisdiction from the United States, with its own privacy statute, PIPEDA, and its own courts. US orders do not run directly; they take the treaty route. Canada is also a Five Eyes member, which is a signals intelligence arrangement rather than a legal process shortcut, but it belongs in your threat model. Latency to US metros stays low.

Toronto

FAQ

Offshore hosting: jurisdiction, not immunity

Yes. Offshore hosting is renting a server in a country other than your own. That is an ordinary commercial act. What is legal is a question about what you run on it, judged by the law where the server sits and, often, where you sit. CrestVPS answers valid legal process from the country hosting each machine. No KYC changes what we collect at signup; it changes nothing about which laws apply.

No. Signup is an email address and we take cryptocurrency only, so there is little identity data to hand over. That is a data minimisation position, not a jurisdictional one. Each server sits in a named country and we answer valid legal process from that jurisdiction. We publish a transparency report twice a year covering requests received and how they were handled. Anyone promising to ignore all process is either lying or about to be closed.

There is no universal answer, because the right country depends on who can plausibly compel disclosure against you. Switzerland and Moldova add distance from EU instruments. Iceland favours publishing and source protection. The Netherlands carries no general retention duty and sits on one of Europe's two largest exchanges. Canada separates you from US courts. Singapore covers APAC. Pick against your adversary, then check latency to your users.

No. Jurisdiction governs who may compel us; it says nothing about what is readable on the disk. Only encryption does that. Encrypt volumes with keys you hold, unlock remotely over SSH at boot, terminate TLS on your own instance, and keep secrets out of anything we store. Assume the hypervisor is in scope. Jurisdiction is our variable to offer. Encryption is yours to apply.

Yes. Provision in the new city and migrate. Median provisioning is 47 seconds, so the constraint is your data transfer and DNS, not our queue. Billing is monthly or annual at 30% off, with fleet discounts from three servers, so running a standby in a second country is cheap. Keep configuration in code and backups portable, and a jurisdiction change becomes an afternoon rather than a project.

Ninety seconds from here to root.

There is no hourly billing, no negotiated rate and no sales call. You pay monthly, or annually at 30% off. Servers ordered together take another 3, 6 or 10% off the whole invoice, so a ten-server annual order settles 37% below the monthly list price.

Build your server