null_route / cetoc.org — August 2026
Anonymous hosting
Most guides on private hosting focus on the wrong thing. They list services that “accept Monero” and call it done. But accepting XMR is the bare minimum. The harder question is: what happens when law enforcement shows up? What does the provider actually have on you? And does their infrastructure even belong to them?
These are different questions. And the answers vary a lot across the services actually worth using in 2026.
The three things that actually matter
Before going through specific providers, it helps to understand what separates a genuinely private host from one that just takes crypto.
First: account data. Did you have to provide an email? A name? An address? Some hosts require full account registration. Others need only an order ID. The difference matters when someone asks them for records.
Second: infrastructure ownership. A provider running on their own hardware, in their own datacenter, controls what logs get written. A reseller of DigitalOcean or OVHcloud doesn’t — those platforms have their own logging and their own legal obligations, regardless of what the reseller promises you.
Third: jurisdiction. Where is the company incorporated? Where are the servers? Iceland has strong constitutional privacy protections. Romania has EU data-sharing obligations. Moldova is outside the EU and outside most mutual legal assistance frameworks. Bulgaria has its own relationship with cross-border requests. These aren’t abstract — they determine what a court order from your country can actually compel.
Zero-identity: when not knowing you is the product
The most interesting development in private hosting lately is the “no account” model. Instead of registering, you get an order ID. That ID is your only identity in the system. If it’s lost, no recovery. If someone asks the provider who ordered that server, the honest answer is: we don’t know.
VPSO.CC takes this the furthest. No account, no email, no username — order ID only. Payment is XMR on-chain, no payment processor. VPS deploys in under two minutes, proxies under ten seconds. They also offer “ghost proxies” — datacenter, residential, and rotating — all under the same anonymous order model. Locations across seven countries. Tor .onion available. New as of July 2026, so no long track record yet, but the architecture is correct.
Ko-Net is similar — no KYC, no email, own hardware (not a reseller), instant deploy. Free speech focus, meaning they’re less likely to suspend you for content reasons. Smaller operation but the infrastructure story is clean.
GhostVPS uses token-based accounts — no email required, access via Tor v3 onion from signup through payment. The catch: they’re a reseller on DigitalOcean. That means the underlying infrastructure isn’t theirs, and DigitalOcean has its own logging and compliance obligations regardless of what GhostVPS does.
The reseller problem is underappreciated. When a provider says “we keep no logs,” that refers to their own logs. It says nothing about what the underlying platform records. This is worth asking explicitly.
Privacy-first with infrastructure: own hardware changes the picture
The second tier is providers who require an account but control their own infrastructure — and in some cases, their own network.
Serverz operates from Iceland, which has some of the strongest constitutional privacy protections in Europe. XMR payment, no KYC, anonymous registration. Iceland isn’t in the EU, which means EU data-sharing directives don’t automatically apply. It’s a real jurisdictional advantage, not just marketing.
DarkVPS runs its own hardware in Bulgaria. No network logs, XMR, LTC, BTC. Bulgaria is EU jurisdiction, which comes with its own obligations, but own hardware means they control what gets written to disk. They went offline briefly in June 2026 and came back — worth watching.
Incognetis the most established option in this category — active since 2020, own ASN (AS40663), 10 global locations, Tor exit nodes allowed. That last part matters: most hosts prohibit Tor exits. Incognet explicitly allows them, which tells you something about their operating philosophy. Downside: US jurisdiction, LLC structure, and they will comply with valid legal orders. Account required. Slow support by some reports. But five years of operation is a real track record.
AnonyMD is a different case — Moldovan operator, outside the EU, orders via email or XMPP only (no account panel). Shared hosting and VPS, .onion address included. Reseller, small operation, no SLA. But Moldova sits outside most mutual legal assistance frameworks that would normally compel a European host. We recently started using them as a backup mirror specifically for the onion setup.
VPN and dVPN: different architecture, different trust model
VPNs and hosting aren’t the same thing but they’re often needed together, so they belong in the same conversation.
Xeovo VPN is a traditional VPN done right — no KYC, XMR accepted, Tor-compatible, no-log policy, from €2.99/month. Clean operation, honest about what it is. For most use cases it’s solid.
Meile dVPN operates on Sentinel — a decentralized network of 5000+ nodes run by individuals, not a company. The architectural difference is meaningful: a subpoena against Meile doesn’t give access to the exit nodes, because those are run by people elsewhere. WireGuard and V2Ray, unlimited bandwidth, XMR direct via BTCPay. The tradeoff is consistency — decentralized means some nodes are better than others.
nadanada.me bundles VPN with eSIM and disposable phone numbers in one place. Useful if you need the full stack — connection privacy plus phone verification without a real SIM.
Domain registrars: the part people forget
Your server can be perfectly anonymous and your domain registration can still expose everything. WHOIS data, registrant contact, billing address — most registrars collect it all.
MonstaDomains offers WHOIS protection, SSL, email hosting, and accepts 150+ coins including XMR. Account required, no Tor. Not deeply reviewed yet — but it’s one of the few domain registrars in this space accepting XMR directly.
What to watch out for
A few things worth checking before committing to any host — regardless of which one.
Checkout flow. Some providers block Tor and VPN IPs at the order stage. That means to place an order, you have to expose your real IP — which somewhat defeats the purpose. Always test whether the checkout is reachable over Tor before sending payment.
IP logging in order forms. Not all providers are transparent about what gets logged during the order process. The server itself may keep no logs — but the web form that accepted your order might. Ask explicitly, or look for providers where the order flow itself runs over .onion.
Reseller infrastructure. A provider’s no-log promise covers their own systems. If they’re reselling DigitalOcean, OVHcloud, or another major platform, those underlying providers have their own logging and legal obligations. Own-hardware providers give you a cleaner chain of control — worth paying more for if privacy is the priority.
Jurisdiction vs. marketing. “Privacy-focused” is a marketing term. Jurisdiction is a legal fact. A provider incorporated in the EU operates under EU data retention and cooperation rules regardless of what their landing page says. Know where the company is registered, not just where the servers are located.
Track record. A provider that has been operating for years has demonstrated at least basic operational stability. New providers may have better privacy architecture but no proven track record under pressure. Both matter — weight them according to what you’re hosting.
Which for which situation
If you need a server and want zero registration trace: VPSO.CC or Ko-Net. Order ID, XMR, deploy, done.
If you want an established provider with a real track record and own network: Incognet — accept that it’s US jurisdiction and plan accordingly.
If jurisdiction is the main concern: Serverz (Iceland) or AnonyMD (Moldova). Different risk profiles, both outside the standard EU-US cooperation framework.
If you need VPN, not a server: Xeovo for simplicity, Meile if you want decentralized architecture where no single company can be compelled.
If you need the full anonymity stack — server + VPN + phone numbers: combine VPSO.CC with nadanada.me. Neither knows who you are, and they don’t know each other.
The right answer depends on your threat model. “Accepting crypto” is a feature, not a privacy guarantee. The guarantee comes from what they don’t collect, what they don’t control, and where they sit legally.
null_route / cetoc.org
No VC. No Agenda. XMR-first.
— NULL_ROUTE Privacy Directory
— ZERO TRACE — privacy swap aggregator
— Stablecoin Freeze Monitor


