Second transit carrier live in Chișinău — 20 Gbps of blended capacity. 20 Gbps blended uplink now live Why Moldova

Jurisdiction Primer

No KYC, and the seven records that still name you

Not collecting your passport is a true statement about one company’s filing cabinet. Being unidentifiable is a property of a chain — seven separate holders, each with one link, most of them under laws your host has never heard of. Here is who holds what, what it costs to join two of them, and which link you are most likely to break yourself.

17 min read Published 14 September 2026 Checked 25 days ago

“No KYC” is the shortest promise in hosting and the most widely misread. It is a statement about one company’s filing cabinet: this business did not ask for your identity documents, so it does not have them. That is a real and unusually verifiable claim. What it is not is a claim about you. Whether a server can be connected to a person is a property of a whole chain of records held by different companies in different countries, and your host is one link in it — often not even the weakest. This is what the phrase actually buys, who holds the other six links, and which one you are most likely to break without noticing.

Where the demand for your passport comes from

Start with the thing almost nobody checks: there is no hosting law anywhere that requires a server provider to identify its customers. KYC is not a hosting term at all. It is borrowed from anti-money-laundering practice, where the international standard-setter is the Financial Action Task Force, and where the relevant text is Recommendation 10 — customer due diligence. That recommendation binds financial institutions, plus a closed list of what the FATF calls designated non-financial businesses and professions: casinos, estate agents, dealers in precious metals and stones, lawyers, notaries, accountants, and company and trust service providers. Web hosting has never appeared on that list, in any revision.

The European implementation is worth reading for where it stops rather than where it starts. The fifth anti-money-laundering directive, Directive (EU) 2018/843, which member states had to transpose by 10 January 2020, extended the list of obliged entities to virtual-currency exchange platforms and to custodian wallet providers. That is the point at which coin meets currency, and at which somebody holds keys on your behalf. It is not the point at which a coin is spent. The whole framework is built around money moving between people — the threshold at which an occasional transaction triggers due diligence is 15 000 euro or dollars — and renting a machine for thirty euro a month was never the thing it was designed to catch.

So when a hosting company asks for a passport scan and a selfie, it is not complying with a rule about hosting. It is doing one of three things, and they are worth separating because only one of them is about you.

Three reasons a host asks for identity documents, and whether a customer can remove the reason
The reasonComes from lawLeaves with the cardWhat is actually going on
Its payment processor requires it Not of hosting Yes The acquirer or the payment service provider genuinely is an obliged entity, and it pushes the requirement down its contract chain to the merchant. The obligation is real; it just is not the host’s, and it is attached to the rail rather than to the product. Take the card away and the requirement leaves with it, which is why “no KYC” and “crypto only” are so often the same sentence stated twice.
Card fraud economics No Yes A stolen card used to rent a server costs the merchant the service, the chargeback and a fee, months after the fact. Identity checks are a blunt but effective filter against that. It is a commercial defence rather than a legal duty — and it exists only because the payment can be reversed by somebody else long after it settled.
Deterrence against abuse No No The only one that survives removing the card, and the only one that is a choice. A provider can deter abuse by answering complaints quickly and suspending services that earn them, which requires knowing what a machine is doing and not who owns it. Collecting documents instead is cheaper for the provider and more expensive for every honest customer, permanently.

Two of the three reasons are properties of the payment rail, not of the server. A provider that has removed the rail has removed the reasons, and can then say something unusually concrete — the stage-by-stage version of that is a separate page, because “what is asked at signup, at payment, at support and at cancellation” is a list rather than an argument.

Two sentences that sound identical and are not

Here are the two sentences a hosting company can write about your identity documents. They are read as synonyms by almost everybody, and they are not even the same kind of statement.

We do not share your documents. This is a policy. Policies are made by companies, and companies are acquired, restructured, re-domiciled, insured, audited and occasionally compelled. The sentence is true on the day it is written and remains true exactly as long as the conditions that produced it. Nothing about it is dishonest. It is simply revocable, and it is revocable by people who are not the person who wrote it.

We never asked for documents. This is a fact about what exists. It cannot be revoked, because the past is not a policy. A demand for records that were never created returns nothing, in any jurisdiction, under any amount of pressure, from any future owner of the business. A breach of a database that was never built leaks nothing.

The asymmetry to keep in mind: a document you hand over is permanent, and the promise protecting it is revocable. Those two properties run in opposite directions, and every argument about identity in hosting is really an argument about that gap.

And the third sentence, which is the one people hear: you are anonymous. No host can write that one. Not because of modesty — because it is a claim about the entire world, and a hosting company can only make claims about itself.

That distinction matters far more than it sounds, because identity documents are the one category of personal data you cannot rotate. A leaked password is an afternoon. A leaked passport scan is a document that is still valid in eight years, still matches your face, and is now in somebody’s archive of a support ticket system that was breached in a year you will not hear about until later. Judging a provider on how well it protects the scan is judging the wrong variable. The variable is whether the scan exists.

Seven holders, one link each

Now the part the phrase does not cover. A running service is connected to a human being by a chain of records, and the links are held by different companies, incorporated in different countries, under different laws, with different retention periods and different appetites for a fight. Removing one link is worth doing. Believing you have removed the chain is the mistake that makes people careless about the other six.

Seven holders of a link between a service and a person, what each holds, and whether it can be removed
Who holds a linkRemovableNeeds a courtWhat that party actually has, and what reaches it
The exchange that sold you the coin Yes Sometimes Your legal name against the addresses you withdrew to. Exchanges have been obliged entities across the EU since 2020 and in most comparable regimes since, so this record is created by law, kept for years by law, and reachable through ordinary financial process rather than a criminal one. It is the single strongest link in the chain, and it is also the easiest to never create.
Your bank or card issuer Yes Sometimes Everything, if fiat touched the arrangement anywhere — not only at the host, but at the registrar, the CDN, the monitoring service or the mailbox. One card payment at one layer names the whole stack, because the other layers are joinable to it by timing alone.
The domain registrar Partly Often not The registrant record. Public WHOIS redaction hides it from strangers, never from the registrar, and the direction of travel is now the other way: under Article 28 of the NIS 2 directive, transposed across the Union by 17 October 2024, registries and registration service providers must hold accurate and complete registration data, verify it, and release it to “legitimate access seekers”. Europe spent five years redacting the public record and is now legislating for a verified one behind it.
The mailbox you signed up with Yes Sometimes Not the mailbox — the recovery address and the phone number attached to it. A free mailbox opened against a phone number is a named mailbox with extra steps, and it is the account that every other account in the chain can be reset through.
The host No Yes Which machine is rented, an invoice carrying an amount, a coin and a date, the address you chose to be reachable at, and short-lived connection metadata. This is the link “no KYC” shrinks: you cannot remove the holder, but you can choose how much it holds and which country’s courts can compel it. Ours keeps login metadata for 24 hours and no traffic records at all, which is published as a list rather than as a slogan.
Everything in front of the origin Partly Often not The CDN, the DNS operator, the certificate issuer, the uptime monitor, the status page. Each is an account with its own signup, its own payment and its own login history, and each of them knows your origin by design. The layer-by-layer version of this is a guide of its own, because the failure is rarely the layer you were thinking about.
You Partly No A handle reused from another life, a PGP key that signed something under your name, a commit address, an analytics or advertising property shared with a site that identifies you, a favicon, a certificate ordered for two names at once, a sentence you have written before. Nobody can sell you a product that fixes this link, and it is the one that breaks most often.

Read the two right-hand columns together. Four of the seven holders are removed by decisions that cost nothing at the start and are impossible to undo later — and only one of the seven is the thing being advertised when a provider says “no KYC”.

What it takes to join two links

Holding a link is not the same as joining links, and the whole practical question lives in the difference. To connect a service to a person, somebody needs either one party that holds both ends, or a legal process that reaches two parties, in two countries, in the right order, while the records still exist. Every one of those is a cost, and the costs multiply rather than add.

Which is what makes a public ledger such an unusual object, and why is bitcoin traceable has an answer nobody enjoys. Bitcoin is not anonymous; it is pseudonymous and permanent. The transaction half of the link — this address paid that address, on this date, this amount — is published, free, forever, to everyone, with no process required. The only missing half is the name against the address, and an exchange is legally required to hold exactly that. So the join does not require compelling two parties at all. It requires compelling one, and the other half was already sitting in public. Worse, it works backwards: analysis performed next year runs against data recorded years before anyone was interested in you, and no amount of care afterwards deletes it.

This is the entire practical argument for a chain built differently. Monero hides the three fields a ledger normally publishes — ring signatures conceal which input was actually spent, stealth addresses conceal the recipient, and RingCT conceals the amount — and the minimum ring size was raised from 11 to 16 in the network upgrade of 13 August 2022, mandatory for every transaction since. The claim to take from that is narrow and worth being precise about: it is not that the coin is untraceable. It is that the free half of the join stops being free. An adversary who cannot read recipients and amounts off a public ledger has to compel somebody, and compelling somebody takes time, leaves a record, and stops at a border. Why we price it as the default rather than as a curiosity comes down to that one sentence.

There is a fourth joiner that no table can show, because it is not a record anyone holds deliberately: timing. Two accounts created four minutes apart from the same address. An invoice settled twenty minutes after a withdrawal from a named exchange, for an amount that matches to the decimal. A domain registered the same afternoon the server was ordered. Correlation of this kind needs no subpoena and no cooperation — only two datasets and patience — and it is how most real attributions actually happen, long before anybody drafts an order.

The number worth optimising is not “does my provider know my name”. It is: how many independent parties, in how many jurisdictions, would have to be reached, in what order, before the records expire — and how much of the work is already done for free in public.

The links people break themselves, in order

Ranked by how often each one is the actual failure, rather than by how dramatic it sounds. The first three cost nothing to get right on day one and cannot be repaired on day two hundred, which is the only ranking criterion that matters.

  1. The domain registered in your own name, or paid for with a card (an hour, once). The most common single failure, by a wide margin. A domain is a separate contract with a separate company under separate law, and Article 28 has made that company’s records more accurate rather than less. Anonymous hosting sitting behind a domain registered to a named person protects the strong link and leaves the weak one in place.
  2. The mailbox you already use for something else (ten minutes). A fresh address costs nothing. Reusing one that has ever been typed into a service that knows you links every account in the chain to that service through a password reset flow, and no provider can un-link it for you.
  3. Coin bought on an exchange that knows you and sent straight to the invoice (a decision). One hop, one permanently public record, one obliged entity holding the other half. This is the strongest link in the whole chain and it is created by convenience, not by necessity — the mechanics of paying without creating it are worth an afternoon of reading before the first invoice rather than after.
  4. The handle you have used since you were nineteen (free). Search engines, archive sites and old forums are all more persistent than the projects they discuss, and a reused name is a join that requires no legal process at all.
  5. Logging into the control panel from home (five minutes). Trivial to avoid and skipped constantly. Some record of panel logins has to exist or nobody could stop an account being brute-forced; the question is how long it lives and whether using Tor is quietly held against you. Here it is 24 hours and it is not, but that is a thing to verify per provider rather than assume.
  6. A shared analytics property, ad account or certificate (ten minutes). The same measurement ID on two sites, or one certificate covering two names, publishes a relationship that nothing else in your setup would have revealed. Certificate transparency logs are public and permanent by design.
  7. Telling somebody (free, irreversible). Not a technical control, and consistently the first one to fail. Every link above is a record held by a company that needs a reason to look; this one is a person who does not.

Notice what is not on the list: anything you buy. Six of the seven are decisions made in the first hour, and the seventh is a habit. This is the opposite of how the subject is normally sold, and it is why the honest version of the advice is cheaper than the dishonest version.

What it is actually worth, and when it is not

The everyday value of not handing over identity documents has almost nothing to do with hiding from anybody. It is this: the copy of your passport that was never made cannot be stolen in 2031 from the support-ticket archive of a hosting company you stopped using in 2027, cannot be sold in a bundle, cannot be used to open an account in your name, and cannot be produced in response to a request from a country whose courts you have never heard of. Data that does not exist has no retention period, no breach notification and no access-request procedure. It is the only category of security that never degrades.

So the useful comparison is not anonymous against identified. It is: how many copies of your identity documents exist, in how many companies, in how many backups, under how many future owners. Every provider that does not ask is one fewer copy, permanently, and that is worth having on its own terms even if you have never had a reason to be private about anything.

Being equally clear about the other direction. This is not a defence against a serious criminal investigation, and no provider that tells you otherwise is worth buying from. A host with a real address in a real country answers real legal process from that country; what changes is what it has to give, which is the point of publishing the list of what it holds and which instruments actually reach it. Somebody selling immunity is selling a story, and the story ends at the first correctly drafted order.

And there are cases where the whole question is the wrong one. If you invoice companies that need a legal counterparty, if you take card payments yourself, if you are in a regulated trade, or if your users are in a jurisdiction that requires a named operator, then an anonymous supply chain creates problems it does not solve — the honest list of those cases is a short one, and it is short on purpose. There is also a middle position that people rarely consider: a named company can perfectly well buy infrastructure from a provider that never asked for documents, because the absence of the documents is about breach surface rather than about secrecy.

If you are comparing providers on this, three questions sort them faster than any feature table, and all three are answerable in writing before money changes hands. What exactly do you hold about a customer, as an exhaustive list rather than a reassurance? For how long, and is that a choice or a legal floor in your country? What is the process that makes you produce it, and have you ever had to? A provider that answers the first with a list, the second with a number and the third with a procedure has told you more than a page of shield icons ever will. The payment page is usually the fastest place to check the first answer, because the rail determines the record: wherever a card is accepted, a name is being collected somewhere, whatever the homepage says.

The last thing worth saying is a subtraction, in the spirit of the rest of this library. Not collecting your documents is one good property among several, and on its own it protects a single link in a chain of seven. Spend the first hour on the domain, the mailbox and the coin, because those three are yours, they are free, and they are the ones that cannot be fixed afterwards. Then buy from somebody who never asked — not because it makes you invisible, but because it is the only part of the arrangement that keeps being true after everyone involved has forgotten they promised it.

Written by the engineers who run the platform, and re-read 25 days ago. If something here is wrong or has gone out of date, say so from the panel — that is where about half of these came from.

Language

Read this site in your language