Launch pricing: every plan costs 30% less than the cheapest offshore competitor we track. See the benchmarkEvery plan 30% under the cheapest offshore host

Privacy & payments

No-KYC hosting explained: what it is and why it's legal

What KYC means at a hosting company, why most hosts ask for ID, what no-KYC hosting really covers, and why it is legal in most countries.

9 min readBy the OffshoreServ team

Key takeaways

  • KYC means "know your customer". EU anti-money-laundering law requires it from banks, crypto exchanges and similar businesses, not from hosting companies.
  • Most hosts check identities to limit card fraud and chargebacks. Crypto payments cannot be charged back, which removes the main reason.
  • No KYC is not no rules: the acceptable use policy, local courts and, in EU locations, the Digital Services Act still apply.
  • With no identity on file, a strong password and two-factor authentication are what protect the account.
On this page
  1. What KYC means at a hosting company
  2. Why most hosts ask for ID
  3. What no-KYC hosting means at OffshoreServ
  4. What no-KYC hosting does not mean
  5. Is no-KYC hosting legal?
  6. Account security without KYC
  7. How to tell real no-KYC hosting from marketing
  8. Frequently asked questions

No-KYC hosting is hosting you can rent without proving who you are: no ID document, selfie, phone number, name, postal address or card. At OffshoreServ, an account is an email address and a password, and servers are paid in crypto. It is legal in most countries, but it does not place a server above the law.

Below: what KYC means at a hosting company, why most hosts ask for ID, what a no KYC VPS does and does not give you, where the law stands, and how to tell a real policy from a slogan.

What KYC means at a hosting company

KYC stands for "know your customer". The term comes from anti-money-laundering law, which obliges certain businesses to identify their customers. In the EU, Article 3 of the Anti-Money Laundering Regulation, which applies from 10 July 2027, lists them: banks and other financial institutions, including crypto-asset service providers, plus businesses and professions such as notaries, estate agents and gambling operators. The current directive, which applies until then, has a similar list. Hosting companies are on neither.

So what is KYC hosting? It is hosting where the provider chooses, as a business policy, to verify who you are before or after you order. The checks vary, but they usually look like this:

Verification stepAt a host that runs KYCAt OffshoreServ
Government ID (passport, ID card)Upload, often with a selfieNever
Phone number and SMS codeOftenNever
Full name and postal addressRequiredNever
Payment card or bank accountUsually, with a fraud checkNot accepted
Manual review of the orderCommon for new accountsNever
Email addressRequired and verifiedYour login only, never verified or written to

Some hosts run none of these at sign-up but keep the right to ask later. That kind is harder to spot; the last section shows how.

Why most hosts ask for ID

The main reason is money, not law. A card payment can be reversed: when a fraudster pays with a stolen card, the real cardholder disputes the charge and the host loses the payment. Stripe's documentation notes that cardholders generally have up to 120 days, sometimes more, to dispute a payment, that the card industry treats dispute activity above 0.75% as excessive, and that card networks can fine businesses that stay above their thresholds.

So a host that takes cards checks identities to stop fraud before it happens and to keep its dispute rate low enough to keep its payment processor. The checks also slow down spammers who burn through accounts.

Regulation is a smaller reason than many people assume, and it varies by country:

  • European Union. No anti-money-laundering duty applies to hosting, as the list above shows.
  • United States. An executive order of 19 January 2021 told the Commerce Department to propose rules requiring US infrastructure-as-a-service providers to verify the identity of their foreign customers. A proposed rule followed on 29 January 2024; we found no final rule in the Federal Register as of September 2026.
  • Switzerland. A 2025 draft of the surveillance ordinance would require services with at least 5,000 users to identify their customers. After a hostile consultation, the Federal Council announced a second one in February 2026: the plan is paused, not dropped.

We can skip identity checks because we take no cards. Crypto payments are final: there is nothing to charge back, so there is no fraud loss to insure against with your passport.

What no-KYC hosting means at OffshoreServ

At OffshoreServ, no-KYC hosting means one precise thing: an account is an email address and a password, nothing else. We never ask for a name, a postal address, a phone number or ID documents: not at sign-up, not at payment, not on large orders, not later.

  • The email is only your login. It can be a private or disposable address. We never send email to it: service notices, renewal warnings and legal notices appear in the client area.
  • The forms check for bots, not people. Sign-up and sign-in use Cloudflare Turnstile, a privacy-friendly human check.
  • Payment is crypto only. You top up a USD balance in Bitcoin, Ethereum, Monero, Tether (USDT) or Solana from any wallet, as our crypto payments page explains. The payment gateway that generates the deposit address and watches the blockchain receives the amount, the coin and a random payment reference, never your email or account details.
  • We keep little. Your email, a password hash, an encrypted two-factor secret if you use one, and your balance, payment and service records. Sign-in records keep the browser and the country, never an IP address, and we do not log or inspect your server's traffic. The privacy policy lists every item, and what your VPS provider can see covers the technical side.

No KYC is the floor, not the ceiling. If you also want your payment and your connections to stay private, read about our anonymous VPS and our guide to buying a VPS anonymously.

What no-KYC hosting does not mean

Skipping identity checks changes what we know about you. It does not change the rules for what runs on your server.

  • Not no rules. Our acceptable use policy applies to every account. Its zero-tolerance list is acted on immediately, without the usual warning: child sexual abuse material (reported to the competent authorities), malware and botnet infrastructure, spam and phishing, attacks from our network, and fraud against real people.
  • Not immunity from local courts. A valid court order from the country where the server runs can require action. We inform the customer first, unless a court forbids it. Foreign notices, including US DMCA notices, are answered, not enforced.
  • Not exempt from EU rules. In our EU locations, Romania, the Netherlands and Bulgaria, a notice that meets Article 16 of the Digital Services Act can oblige us to act on illegal content.
  • Not nothing to hand over. A valid order can obtain what we hold: the email address, payment and service records, and sign-in records with the browser and the country. Our law-enforcement guidelines set out the process.

Yes, in most countries. The answer has two sides.

Anti-money-laundering law, the usual source of KYC duties, does not cover hosting in the EU. Other duties vary by country: Moldova's cybercrime law requires service providers to keep records of their users and to preserve data when the authorities ask, and the Swiss draft would make larger services identify their customers. A no-KYC promise is only as durable as the jurisdictions behind it.

Hosting without ID is legal in most countries, and so is paying in cryptocurrency, although some countries restrict crypto payments as such. From 10 July 2027, Article 79 of the same EU regulation bars banks, financial institutions and crypto-asset service providers from keeping anonymous crypto accounts or accounts that obscure transactions, including through anonymity-enhancing coins. It binds those providers, not people who pay from their own wallets.

Your own laws keep applying to you. What you run must be legal where the server is and where you are, and spending crypto can be a taxable event: in the United States, digital assets are treated as property. This is general information, not legal advice, so check the rules in your own country.

Account security without KYC

A host that holds your passport can use it to let you back in. We hold nothing like that, so your account rests on what you keep:

  1. Keep your password in a password manager. There is no email-based reset: a lost password cannot be recovered. If it is ever exposed, change it under Security in the client area and sign out your other sessions.
  2. Turn on two-factor authentication. Every sign-in then asks for a 6-digit code from an authenticator app such as Aegis, 2FAS, Ente Auth or Bitwarden. Save the setup key when you turn it on: it adds the account to a new phone if you lose this one.
  3. Use a password you use nowhere else. There is no second identity check behind it.
  4. Glance at the security log. It lists sessions and security events with the browser and the country, so an unfamiliar sign-in stands out.

How to tell real no-KYC hosting from marketing

"No KYC" costs nothing to write on a homepage. These checks take a few minutes and show what a host actually does:

  1. Walk through the sign-up flow. Count the fields. A name, a phone number, an address or a "verify your email to continue" step each tell you something.
  2. Read the terms for a right to ask later. Phrases such as "we may request identification" let a host switch KYC on for your account at any time. Our terms of service ask for an email address and a password, nothing else.
  3. Read the privacy policy. A host that stores your IP address at every sign-in and runs third-party analytics can often identify customers without asking for ID.
  4. Check who takes the payment. Cards and PayPal tie the payment to an identity that a bank or payment company has already verified. A crypto processor that asks you for an email, an account or documents links it to you as well.
  5. Check the warrant canary. It should be signed, dated and renewed on schedule. Ours is PGP-signed, dated 25 September 2026 and due again by 25 December 2026: see our warrant canary.
  6. Read the abuse rules. No KYC combined with "anything goes" is the pattern of bulletproof hosting, and several such hosts were sanctioned or seized in 2025 and 2026.

Frequently asked questions

What does no KYC mean for VPS hosting?

It means you can rent and use a VPS without proving your identity: no ID document, selfie, phone number, name, address or card. At OffshoreServ, an account is an email address and a password. You top up a balance in crypto, and a VPS paid from it goes live about 60 seconds after you order.

Yes, in most countries. Hosting companies are not among the businesses that EU anti-money-laundering law obliges to identify their customers. What you run must still be legal where the server is and where you live, and valid local court orders still apply. Some countries impose other duties on providers, so check the rules in your own country too.

Can I use a throwaway email?

Yes. The email is only your login: we never send email to it, and notices appear in your client area. Write the exact address down, because it is your username. Since there is no email-based reset, losing that inbox does not lock you out, and whoever takes over the address later cannot use it to take over your account.

Can I run a business through a no-KYC host?

Yes. The account works the same way for a company, and nothing requires a company name. There are no per-order invoices: the client area lists every top-up, order and renewal and exports them as CSV, and the name and registered address of our operating entity are provided on request. Ask your accountant whether that covers your bookkeeping and VAT.

Do no-KYC hosts share data with the police?

A host can only hand over what it holds. We disclose data under a valid order from a court competent where the server runs, and only what it compels: an email address, payment and service records, and sign-in records without IP addresses. Only genuine emergencies, such as a threat to life, go faster. We tell the customer unless the law forbids it, and publish request counts quarterly.

Is no-KYC the same as bulletproof hosting?

No. US and allied agencies define a bulletproof host as one that "knowingly leases infrastructure to cybercriminals". Skipping identity checks is a privacy choice; tolerating abuse is the problem. In November 2025, Dutch police seized about 250 servers of a no-KYC VPS and RDP service linked to more than 80 investigations. Read offshore vs bulletproof hosting for the difference.

Host it where the law is on your side.

Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions. No KYC, paid in crypto.

Welcome back

Sign in to manage your servers and your balance.

No KYCHuman check by Cloudflare TurnstileNo tracking