On this page
- What can my VPS provider see about my account?
- What can my VPS provider see on the network?
- Inside a KVM VPS: disk, memory and console
- Confidential computing: the technology that changes this
- How to encrypt a VPS, and what it does not hide
- VPS vs dedicated privacy: what bare metal changes
- Side by side: what each setup exposes
- Checklist: minimize what any provider can see
- Frequently asked questions

Technically, whoever runs the host of a virtual server can read its disk and memory, and see its network traffic: the metadata always, the content whenever it is not encrypted. What protects you is encryption, the provider's policy and the law it operates under. A dedicated server removes the hypervisor layer, but not physical access.
So what can my VPS provider see in practice? Below, layer by layer, with our offshore VPS and dedicated servers as the example: the account, the network, the disk and memory, and what encryption changes. We say where our protection is technical and where it is a promise.
What can my VPS provider see about my account?
Whatever its
We ask for an email address and a password, nothing else: no name,
no ID , no phone. We keep your billing and service records, and no IP address with your account. We never look inside your server.
- Sessions and security log: "a summary of the browser and operating system, and the country as reported by Cloudflare. Never your IP address."
- No traffic logging or inspection: no deep packet inspection, no scanning of your server's content, no records of what it sends or receives.
- No IP addresses in our web access logs. Form rate limits use a salted IP hash kept for at most
1 hour .
Billing records hold each
What can my VPS provider see on the network?
Can my host see my traffic? Every packet crosses its network, so the provider sits on the path, like your internet provider and every transit network in between. Each of them sees:
- Addresses and ports, which travel unencrypted in every packet header.
- Timing and volumes. Even
TLS 1.3 "does not hide the length of the data it transmits". - DNS lookups, unless encrypted. Otherwise, "DNS traffic can be seen by an eavesdropper like any other traffic" (RFC 9076). DNS over TLS or HTTPS hides it on the wire; the resolver still sees it.
- Site names.
TLS 1.3 encrypts the server certificate, but the Server Name Indication stays in plaintext unless both ends use Encrypted Client Hello (RFC 9849,March 2026 ).
Encryption hides the content: TLS protects HTTPS pages, forms and URL paths; SSH, your commands and file transfers; WireGuard, whole IP packets sent over UDP between two visible endpoints. Plaintext protocols such as HTTP, FTP or unencrypted DNS are readable by anyone on the path. A VPN on your server, such as one built with our WireGuard VPN guide, moves that boundary without removing it: traffic leaves the VPS as ordinary traffic. We do not log or inspect customer traffic, but that is a policy; encryption is the technical protection.
Inside a KVM VPS: disk, memory and console
A VPS is a guest on someone else's computer: its disk is an image on the host, its memory part of the host's RAM. In traditional virtualization, says the Linux kernel's confidential computing threat model, "the host has unlimited access to guest data". Any standard KVM host, ours included, can:
- copy or mount the disk image, running or not;
- dump the memory with QEMU's
, or take a VM snapshot that includes the RAM;dump-guest-memory - choose what the VM boots from and use its console, which is how password resets work without your password;
- read files and set passwords through the QEMU guest agent, if it runs in the VM.
So can a hosting provider see my files? On an unencrypted VPS, technically yes. Our protection here is a policy, "We never look inside your server", and the process in our
Confidential computing: the technology that changes this
Confidential computing treats "a potentially misbehaving host" as an attacker and aims to "preserve the confidentiality and integrity of CoCo guest's private memory and registers", in the same kernel document's words. On x86, two technologies implement it:
- AMD
SEV-SNP . SEV encrypts a guest's code and data so that "a decrypted version is available only within the VM itself", says the kernel's AMD documentation.SEV-SNP adds a reverse map table, "used to ensure aone-to-one mapping between system physical addresses and guest physical addresses". - Intel TDX. Trust Domain Extensions "protect confidential guest VMs from the host and physical attacks".
Both support attestation, so the guest can verify its protection instead of trusting a product page. The limits: the host "retains full control over the CoCo guest resources, and can deny access to them at any time", and disk and network data still pass through devices it manages, so they need encryption inside the guest.
How to encrypt a VPS, and what it does not hide
LUKS /boot
fallocate -l 10G /root/vault.img
cryptsetup luksFormat /root/vault.img
cryptsetup open /root/vault.img vault
mkfs.ext4 /dev/mapper/vault
mkdir -p /mnt/vault
mount /dev/mapper/vault /mnt/vault
To lock it, unmount it and run cryptsetup close vault
The limit: for LUKS2, the cryptsetup FAQ notes, "the keys of a mapped (open) container are now stored in the kernel
VPS vs dedicated privacy: what bare metal changes
A dedicated server has no hypervisor and no host system beneath yours. The provider keeps physical access and IPMI: the baseboard management controller, a separate computer on the mainboard, provides the console, power control and virtual media. On ours, IPMI access is limited to the IP addresses you ask us to allow.
dropbear-initramfs/etc/dropbear/initramfs/authorized_keys, run update-initramfs -u -k allcryptroot-unlock
Two limits remain. A running server keeps the key in memory. And /boot
Side by side: what each setup exposes
What the provider can technically see; "with encryption" means LUKS inside the VM and TLS, SSH or WireGuard for all traffic.
| What can be seen | VPS without encryption | VPS with encryption | Dedicated server with |
|---|---|---|---|
| Account details | What you gave at | Same | Same |
| Payment trail | Same | Same | |
| Network metadata | Addresses, ports, timing, volumes, DNS lookups, site names | Addresses, ports, timing, volumes; names too, unless DNS is encrypted and ECH is used | As on a VPS: disk encryption changes nothing on the network |
| Traffic content | Readable by the host and every network on the path | Hidden on the wire; plaintext only inside the VM | Readable if sent in plaintext; hidden with TLS, SSH or WireGuard |
| Disk contents | Readable at any time, snapshots included | Ciphertext at rest and in snapshots; readable through the running VM's memory | Ciphertext when off or removed; exposed only by attacking the running machine or its boot partition |
| Memory contents | Readable by the host at any time | Readable by the host, disk key included | No hypervisor to read it; takes an attack on the running hardware |
Checklist: minimize what any provider can see
VPS privacy is layered: each step removes something a provider could see or hold.
- Sign up with an email alias used nowhere else, as our guide to buying a VPS anonymously explains.
- Pay with Monero, which hides sender, receiver and amount: see our Monero VPS page.
- Log in with SSH keys. The first root password is shown in your client area, so it is not a secret only you hold: change it, then follow our hardening guide.
- Encrypt all traffic with HTTPS, SSH, WireGuard and encrypted DNS.
- Encrypt data at rest with LUKS, and
client-side for data the server never needs to read. - Use a dedicated server with
full-disk encryption for sensitive workloads. - Verify the warrant canary each quarter: our warrant canary is
PGP-signed and states the date of the next renewal.
Frequently asked questions
Can my VPS provider see my files?
Technically, yes, unless they are encrypted: a standard KVM host can read the virtual disk and the VM's memory. LUKS keeps the disk image and snapshots unreadable at rest, but a running VM holds its key in memory.
Can my hosting provider see my traffic?
It sees the metadata of all of it: addresses, ports, timing and volumes, plus DNS lookups and site names unless those are encrypted. It reads content only when a protocol sends it in plaintext; TLS, SSH and WireGuard hide it. We do not log or inspect customer traffic, but encryption makes that technical, not a promise.
Does full-disk encryption protect a VPS?
Partly. LUKS protects data at rest: disk images, snapshots and discarded drives hold only ciphertext. It does not protect a running VPS from its host, because the unlocked key sits in the VM's memory. For protection while it runs, use a dedicated server, or a confidential VM that proves its protection through attestation.
Can a VPS provider access my server without my password?
Technically, yes. A KVM host controls the virtual disk, the boot and the console, so it can read files or reset a password without yours, or set one through the QEMU guest agent if it runs in the VM. A dedicated server has no hypervisor, but the provider keeps physical and IPMI access. Encryption protects the data; a password does not.
What does OffshoreServ log?
Very little: your email address; balance,
Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions.


