CrestVPS

H1 2026 · published 2026-07-01

Transparency report

Every request for customer data we received, what we did with it, and why. Published every six months since 2019, including the periods where the numbers were inconvenient.

01

59

Requests received

02

36

Refused

03

61%

Refused

04

0

Warrant canary

Figures

Transparency report

We count a request once, at the moment it arrives, regardless of how many accounts it names. "Complied" means we produced at least some of what was demanded. "Refused" means we produced nothing, either because the request was not valid legal process in the jurisdiction where the hardware sits, or because it demanded data we do not hold. We notify the customer whenever the law lets us, which in the last period was eleven times out of fourteen.

PeriodRequests receivedCompliedRefusedAccounts namedCustomers notified
H1 202614591711
H2 20251147129
H1 202593698
H2 202412661510
H1 202472576
H2 202363364

We count a request once, at the moment it arrives, regardless of how many accounts it names. "Complied" means we produced at least some of what was demanded. "Refused" means we produced nothing, either because the request was not valid legal process in the jurisdiction where the hardware sits, or because it demanded data we do not hold. We notify the customer whenever the law lets us, which in the last period was eleven times out of fourteen.

What we can actually produce

An email address, the payment references attached to it, which servers were allocated to the account and when, and the content of support tickets. That is the complete list, because it is the complete set of what we store. We hold no identity documents, no phone numbers, no billing addresses and no card data, so no order can compel them.

Abuse handling

Separate from legal process. In the last period we received 1 842 abuse reports, forwarded 1 611 to the customer with the reporter details removed, suspended 47 services and terminated 9 outright. Every termination fell into one of the immediate categories listed in the acceptable use policy.

Warrant canary

As of the date below, CrestVPS has never received a national security letter, a gag order, or any request whose existence we were forbidden to disclose. We have never handed over encryption keys, because for volumes encrypted with LUKS we do not have them. This paragraph is reviewed and re-signed with the report each period; its removal should be read as significant.

CrestVPS B.V. · AS204871

A41F 9C22 6E0B 77D5 3E14 8B90 5FA2 D6C7 1E30 44B8

2026-07-01