---
title: "What Can My VPS Provider See? Files, Traffic & Memory"
description: "What a VPS provider can technically see: account data, network metadata, disk and RAM. What encryption hides, why bare metal helps, and what we keep."
url: https://offshoreserv.com/blog/what-can-your-vps-provider-see
lang: en
updated: 2026-09-26
source: HTML page at the url above (canonical); this is its Markdown version
---

[Privacy & payments](https://offshoreserv.com/blog/category/privacy-payments)

# What can your VPS provider see? A technical answer

What a VPS provider can technically see in your account, on the network and inside the server, what encryption hides, and what a dedicated server changes.

26 September 2026 8 min read By the OffshoreServ team

Key takeaways

- On a standard KVM host, the provider can technically read a VPS's disk and memory and see all of its network traffic.
- Encryption hides traffic content and data at rest, but not network metadata, and not the memory of a running VM.
- OffshoreServ keeps an email address, billing and service records and a security log without IP addresses, and never looks inside your server.
- Confidential computing, with AMD SEV-SNP or Intel TDX, is the technology built to protect a VM's memory from its host.
- A dedicated server with full-disk encryption removes the hypervisor; the provider keeps physical access and IPMI.

**Technically, whoever runs the host of a virtual server can read its disk and memory, and see its network traffic: the metadata always, the content whenever it is not encrypted.** What protects you is encryption, the provider's policy and the law it operates under. A dedicated server removes the hypervisor layer, but not physical access.

So what can my VPS provider see in practice? Below, layer by layer, with our [offshore VPS](https://offshoreserv.com/offshore-vps) and [dedicated servers](https://offshoreserv.com/offshore-dedicated-servers) as the example: the account, the network, the disk and memory, and what encryption changes. We say where our protection is technical and where it is a promise.

## What can my VPS provider see about my account?

Whatever its sign-up and payment steps collect: at hosts that check identities, a name, an address, a phone number and a card; at many, the IP address you sign in from. Our [privacy policy](https://offshoreserv.com/privacy-policy) lists every item we hold; in short:

> We ask for an email address and a password, nothing else: no name, no ID, no phone. We keep your billing and service records, and no IP address with your account. We never look inside your server.

- **Sessions and security log:** "a summary of the browser and operating system, and the country as reported by Cloudflare. Never your IP address."
- **No traffic logging or inspection:** no deep packet inspection, no scanning of your server's content, no records of what it sends or receives.
- **No IP addresses in our web access logs.** Form rate limits use a salted IP hash kept for at most 1 hour.

Billing records hold each top-up's coin, amount, deposit address and transaction ID. On public blockchains such as Bitcoin's, anyone can see amounts, timing and wallet addresses; Monero hides the sender, the receiver and the amount. More in our [no-KYC hosting explainer](https://offshoreserv.com/blog/no-kyc-hosting-explained).

## What can my VPS provider see on the network?

Can my host see my traffic? Every packet crosses its network, so the provider sits on the path, like your internet provider and every transit network in between. Each of them sees:

- **Addresses and ports**, which travel unencrypted in every packet header.
- **Timing and volumes.** Even [TLS 1.3](https://www.rfc-editor.org/rfc/rfc8446.html) "does not hide the length of the data it transmits".
- **DNS lookups, unless encrypted.** Otherwise, "DNS traffic can be seen by an eavesdropper like any other traffic" ([RFC 9076](https://www.rfc-editor.org/rfc/rfc9076.html)). DNS over TLS or HTTPS hides it on the wire; the resolver still sees it.
- **Site names.** TLS 1.3 encrypts the server certificate, but the Server Name Indication stays in plaintext unless both ends use Encrypted Client Hello ([RFC 9849](https://www.rfc-editor.org/rfc/rfc9849.html), March 2026).

Encryption hides the content: TLS protects HTTPS pages, forms and URL paths; SSH, your commands and file transfers; [WireGuard](https://www.wireguard.com/), whole IP packets sent over UDP between two visible endpoints. Plaintext protocols such as HTTP, FTP or unencrypted DNS are readable by anyone on the path. A VPN on your server, such as one built with our [WireGuard VPN guide](https://offshoreserv.com/docs/vps/wireguard-vpn), moves that boundary without removing it: traffic leaves the VPS as ordinary traffic. We do not log or inspect customer traffic, but that is a policy; encryption is the technical protection.

## Inside a KVM VPS: disk, memory and console

A VPS is a guest on someone else's computer: its disk is an image on the host, its memory part of the host's RAM. In traditional virtualization, says the Linux kernel's [confidential computing threat model](https://docs.kernel.org/security/snp-tdx-threat-model.html), "the host has unlimited access to guest data". Any standard KVM host, ours included, can:

- copy or mount the disk image, running or not;
- dump the memory with QEMU's [`dump-guest-memory`](https://www.qemu.org/docs/master/system/monitor.html), or take a [VM snapshot](https://www.qemu.org/docs/master/system/images.html) that includes the RAM;
- choose what the VM boots from and use its console, which is how password resets work without your password;
- read files and set passwords through the [QEMU guest agent](https://www.qemu.org/docs/master/interop/qemu-ga.html), if it runs in the VM.

So can a hosting provider see my files? On an unencrypted VPS, technically yes. Our protection here is a policy, "We never look inside your server", and the process in our [law-enforcement guidelines](https://offshoreserv.com/law-enforcement): we act only on a valid order from a court or authority competent where the server runs, respond only to the extent the law requires, and tell the customer unless the law forbids it. Genuine emergencies go faster. A policy lasts as long as the provider and the law allow; encryption depends on neither, within the limits below.

## Confidential computing: the technology that changes this

Confidential computing treats "a potentially misbehaving host" as an attacker and aims to "preserve the confidentiality and integrity of CoCo guest's private memory and registers", in the same kernel document's words. On x86, two technologies implement it:

- **AMD SEV-SNP.** SEV encrypts a guest's code and data so that "a decrypted version is available only within the VM itself", says the [kernel's AMD documentation](https://docs.kernel.org/arch/x86/amd-memory-encryption.html). SEV-SNP adds a reverse map table, "used to ensure a one-to-one mapping between system physical addresses and guest physical addresses".
- **Intel TDX.** Trust Domain Extensions ["protect confidential guest VMs from the host and physical attacks"](https://docs.kernel.org/virt/kvm/x86/intel-tdx.html).

Both support attestation, so the guest can verify its protection instead of trusting a product page. The limits: the host "retains full control over the CoCo guest resources, and can deny access to them at any time", and disk and network data still pass through devices it manages, so they need encryption inside the guest.

## How to encrypt a VPS, and what it does not hide

LUKS full-disk encryption turns the disk image, its snapshots and any discarded drive into ciphertext. For the whole system, boot your own ISO from Server actions and choose guided partitioning with encrypted LVM in the Debian installer: [everything but a separate `/boot`](https://www.debian.org/releases/trixie/amd64/ch06s03.en.html), swap included, is encrypted, and the server waits for your passphrase after every reboot. To keep your template, use an encrypted container file; cryptsetup attaches it to a loop device by itself:

```
fallocate -l 10G /root/vault.img
cryptsetup luksFormat /root/vault.img
cryptsetup open /root/vault.img vault
mkfs.ext4 /dev/mapper/vault
mkdir -p /mnt/vault
mount /dev/mapper/vault /mnt/vault
```

To lock it, unmount it and run `cryptsetup close vault`, which ["wipes the key from kernel memory"](https://manpages.debian.org/trixie/cryptsetup-bin/cryptsetup-close.8.en.html). Files outside the container, such as logs, stay in plaintext.

The limit: for LUKS2, the [cryptsetup FAQ](https://gitlab.com/cryptsetup/cryptsetup/-/wikis/FrequentlyAskedQuestions) notes, "the keys of a mapped (open) container are now stored in the kernel key-store", and a VPS kernel runs in memory the host can read. So LUKS on a VPS protects stored copies, not a running VM. Application-level and client-side encryption go further, because the server never decrypts the data: GnuPG-encrypted uploads, restic or Borg backups, and end-to-end encrypted apps whose keys stay on users' devices.

## VPS vs dedicated privacy: what bare metal changes

A dedicated server has no hypervisor and no host system beneath yours. The provider keeps physical access and IPMI: the baseboard management controller, a separate computer on the mainboard, provides the console, power control and virtual media. On ours, IPMI access is limited to the IP addresses you ask us to allow.

Full-disk encryption makes a powered-off server or a removed disk unreadable without your passphrase. Debian's `dropbear-initramfs` lets you "unlock your rootfs on bootup remotely, using SSH", as its [README](https://sources.debian.org/src/dropbear/2025.89-1~deb13u1/debian/README.initramfs/) explains: add your public key to `/etc/dropbear/initramfs/authorized_keys`, run `update-initramfs -u -k all`, and after each reboot log in and run `cryptroot-unlock`. A passphrase typed in the IPMI console instead passes through the controller.

Two limits remain. A running server keeps the key in memory. And `/boot` "is usually not encrypted", as the same README notes, so someone with access to the machine, in person or through IPMI virtual media, could alter it to capture your passphrase at the next unlock: treat a reboot you did not cause as a warning. Still, reading a running VPS takes tools its host already has; an encrypted dedicated server takes an attack on its hardware or boot chain.

## Side by side: what each setup exposes

What the provider can technically see; "with encryption" means LUKS inside the VM and TLS, SSH or WireGuard for all traffic.

| What can be seen | VPS without encryption | VPS with encryption | Dedicated server with full-disk encryption |
| --- | --- | --- | --- |
| Account details | What you gave at sign-up; at OffshoreServ, an email address | Same | Same |
| Payment trail | Top-up records; public chains show the sending wallet, Monero hides it | Same | Same |
| Network metadata | Addresses, ports, timing, volumes, DNS lookups, site names | Addresses, ports, timing, volumes; names too, unless DNS is encrypted and ECH is used | As on a VPS: disk encryption changes nothing on the network |
| Traffic content | Readable by the host and every network on the path | Hidden on the wire; plaintext only inside the VM | Readable if sent in plaintext; hidden with TLS, SSH or WireGuard |
| Disk contents | Readable at any time, snapshots included | Ciphertext at rest and in snapshots; readable through the running VM's memory | Ciphertext when off or removed; exposed only by attacking the running machine or its boot partition |
| Memory contents | Readable by the host at any time | Readable by the host, disk key included | No hypervisor to read it; takes an attack on the running hardware |

## Checklist: minimize what any provider can see

VPS privacy is layered: each step removes something a provider could see or hold.

1. **Sign up with an email alias** used nowhere else, as our guide to [buying a VPS anonymously](https://offshoreserv.com/blog/buy-a-vps-anonymously) explains.
2. **Pay with Monero,** which hides sender, receiver and amount: see our [Monero VPS](https://offshoreserv.com/monero-vps) page.
3. **Log in with SSH keys.** The first root password is shown in your client area, so it is not a secret only you hold: change it, then follow our [hardening guide](https://offshoreserv.com/docs/security/hardening).
4. **Encrypt all traffic** with HTTPS, SSH, WireGuard and encrypted DNS.
5. **Encrypt data at rest** with LUKS, and client-side for data the server never needs to read.
6. **Use a dedicated server** with full-disk encryption for sensitive workloads.
7. **Verify the warrant canary** each quarter: our [warrant canary](https://offshoreserv.com/warrant-canary) is PGP-signed and states the date of the next renewal.

## Frequently asked questions

### Can my VPS provider see my files?

Technically, yes, unless they are encrypted: a standard KVM host can read the virtual disk and the VM's memory. LUKS keeps the disk image and snapshots unreadable at rest, but a running VM holds its key in memory. Client-side encryption protects files everywhere. Our privacy policy adds: "We never look inside your server."

### Can my hosting provider see my traffic?

It sees the metadata of all of it: addresses, ports, timing and volumes, plus DNS lookups and site names unless those are encrypted. It reads content only when a protocol sends it in plaintext; TLS, SSH and WireGuard hide it. We do not log or inspect customer traffic, but encryption makes that technical, not a promise.

### Does full-disk encryption protect a VPS?

Partly. LUKS protects data at rest: disk images, snapshots and discarded drives hold only ciphertext. It does not protect a running VPS from its host, because the unlocked key sits in the VM's memory. For protection while it runs, use a dedicated server, or a confidential VM that proves its protection through attestation.

### Can a VPS provider access my server without my password?

Technically, yes. A KVM host controls the virtual disk, the boot and the console, so it can read files or reset a password without yours, or set one through the QEMU guest agent if it runs in the VM. A dedicated server has no hypervisor, but the provider keeps physical and IPMI access. Encryption protects the data; a password does not.

### What does OffshoreServ log?

Very little: your email address; balance, top-up and service records; the tickets and requests you send; and sessions and a security log with the browser, operating system and country, never an IP address. Our web access logs hold no IP addresses, and server traffic is never logged or inspected.

**Host it where the law is on your side.**

Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions. No KYC, paid in crypto.

## More from the blog.

- [Privacy & payments How to buy a VPS anonymously (and legally), step by step Five steps to a VPS that is not tied to your name, what the host can still see, and the mistakes that quietly undo your privacy.26 September 2026 9 min read](https://offshoreserv.com/blog/buy-a-vps-anonymously)
- [Privacy & payments How to buy a VPS with crypto: BTC, ETH, XMR, USDT and SOL From the deploy page to a running server: which coin to pick, how the top-up, rate lock and bonus work, and what to do when a payment goes wrong.26 September 2026 9 min read](https://offshoreserv.com/blog/buy-a-vps-with-crypto)
- [Privacy & payments No-KYC hosting explained: what it is and why it's legal What KYC means at a hosting company, why most hosts ask for ID, what no-KYC hosting really covers, and why it is legal in most countries.26 September 2026 9 min read](https://offshoreserv.com/blog/no-kyc-hosting-explained)

---

OffshoreServ is an offshore hosting provider: VPS, dedicated servers, Windows RDP and GPU servers in seven jurisdictions (Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria and Malaysia), paid only in cryptocurrency (Bitcoin, Ethereum, Monero, Tether (USDT) and Solana), with no identity checks (no KYC).

Prices and plans: https://offshoreserv.com/pricing · Answers: https://offshoreserv.com/faq · Every page: https://offshoreserv.com/llms.txt
