Rendered here for reading. The file the signature actually covers is at /canary.asc, and that is the one to verify.
VPSOffshore warrant canarySigned 2026-08-24 · next due 2026-08-31
We have never received a National Security Letter or any equivalent instrument.
We have never received a gag order, a secrecy directive, or any demand that we not publish this notice.
We have never been compelled to hand over encryption keys, credentials, or the contents of any customer disk.
We have never been compelled to modify our systems, our hypervisors, or our images to assist any third party.
We have never placed a wiretap, a port mirror or any interception device at anyone’s request.
No Moldovan court has ordered the removal, suspension or disclosure of any customer service.
We remain in sole possession of our infrastructure. No third party administers it, and none has ever asked to.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
VPSOffshore warrant canary
Date : 2026-08-24
Next due : 2026-08-31
Block : 963820
Block hash : 00000000000000000001aff2f9dc7a830fd1265665889fc572f49afe8edc3ac0
As of the date above, all of the following remain true:
1. We have never received a National Security Letter or any equivalent instrument.
2. We have never received a gag order, a secrecy directive, or any demand that we not publish this notice.
3. We have never been compelled to hand over encryption keys, credentials, or the contents of any customer disk.
4. We have never been compelled to modify our systems, our hypervisors, or our images to assist any third party.
5. We have never placed a wiretap, a port mirror or any interception device at anyone’s request.
6. No Moldovan court has ordered the removal, suspension or disclosure of any customer service.
7. We remain in sole possession of our infrastructure. No third party administers it, and none has ever asked to.
This statement is signed by hand, weekly, with a key held offline.
Its absence, its lateness, or the disappearance of any line above is
the signal. Treat it as one.
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQTwJhl7VvffpWk5RIRhGvTcclXCuAUCaovhKgAKCRBhGvTcclXC
uJGAAP9FJ8eKimQvbOg9O92fRVJ7+k1T0eBEIJvJ8RX667aDWQD7BOOKOlm/kNqx
Y/xYKkRTDtWIU44kBzYvGVdlWk7uyw8=
=gNpF
-----END PGP SIGNATURE-----
The block hash is what stops a stack of statements being signed in advance and released one a week: it did not exist seven days ago, so no signature carrying it is older than that. It does not, on its own, prove who holds the key — which is why the custody question is answered plainly below rather than left to the word “offline”.
Four commands
Do not take the word “signed” from the page that is signed
The entire value of this mechanism is that it does not require trusting us. Four commands, about a minute, no account.
Then compare the fingerprint against a copy obtained somewhere other than this site. A key served by the same host it authenticates only proves that host is internally consistent.
Fetch the statement
curl -O https://vpsoffshore.com/canary.asc
The signed file, exactly as signed. The page you are reading renders it for comfort; this is the byte sequence the signature actually covers.
Verify it
gpg --verify canary.asc
Look for “Good signature” and the expected fingerprint. A statement that verifies against a different key is precisely the event this mechanism exists to surface.
Check the block hash
Compare against any block explorer
The statement carries a recent Bitcoin block hash. That hash did not exist a week ago, so the signature cannot have been produced in advance and left running by somebody who is not us.
Get the fingerprint from a second source if you can. We give it to any customer over an existing encrypted channel, and it is repeated on the law enforcement page — two places that would both have to be edited together.
The part that matters
What to do if this page goes quiet
A canary is worth nothing while it is being signed. It is worth something on the day it is not — and only if you decided in advance what that would mean to you.
It is late by more than seven days
Treat it as unresolved rather than as an answer. Signing has slipped for ordinary reasons before, and when it does we say so on the status page — but the correct default while you wait is suspicion, not patience.
A statement disappears without explanation
That is the designed signal. Removing a line from a signed document is a deliberate act by somebody holding the key, and it is the one thing an order to stay silent cannot compel us to keep saying.
The key changes without an announcement
A new key should arrive in a message signed by the old one. A key that simply appears is not a rotation, it is a different signer, and it should be treated as one.
What to do about any of the above
Assume the position stated here no longer holds, and act on that assumption rather than waiting for a confirmation which by definition cannot come. Decide this now, while nothing is happening.
What this cannot tell you
Whoever controls our infrastructure controls the signing key, so a canary proves the statement was signed — not that the signer is still the party you think. Read it alongside the transparency report rather than instead of it.
The honest limits
Three things a canary cannot do
Stated plainly, because a canary sold as a guarantee is a canary nobody reads correctly on the one day it matters.
Compelling a false statement is a materially harder thing to obtain than compelling silence, in Moldova as in most places — which is the entire theory behind canaries, and also their weakest point, because it remains a theory rather than a tested guarantee. Nobody has established it in court here.
The custody question deserves a straight answer rather than the word “offline”. The signing key is held by us, on our own infrastructure, and the weekly statement is produced by an automated job. That is a deliberate trade: an offline key in a safe is a stronger guarantee on paper, and it is also the arrangement where a signature quietly stops happening because the person with the safe was travelling — which sends precisely the alarm this page exists to make meaningful. We would rather the cadence be kept than the theory be perfect. If you need the stronger property, ask us and we will tell you honestly whether it has changed by the time you read this.
Why weekly, and not daily?
Because daily signing gets automated, and an automated canary is a cron job with a key sitting on a server — precisely the arrangement that can be kept running without us. Weekly is a cadence a person can genuinely keep by hand, and seven days is short enough to be meaningful. When it is late, the status page says why.
Does this protect my data?
No. It protects your ability to find out, which is a different and much smaller thing. Nothing here stops an order from arriving; it makes an arrived order visible to you sooner than the alternative, which is never. What actually limits the damage is the shortness of the list in the privacy policy — an order can only ever reach records that exist.
Both halves
What arrived is counted. What did not is signed.
Neither is worth much on its own. Read them together, and check the second one yourself.