Launch pricing: every plan costs 30% less than the cheapest offshore competitor we track. See the benchmarkEvery plan 30% under the cheapest offshore host

Privacy & payments

What is a warrant canary? How to read and verify one

A warrant canary lets a provider's silence speak when a gag order forbids words. Here is what one contains, how to verify ours with GnuPG, and what a missing canary does and does not prove.

9 min readBy the OffshoreServ team

Key takeaways

  • A warrant canary says what a provider has not received. When a secret order arrives, it stops being renewed.
  • It rests on an untested theory: a gag can compel silence, but courts have not upheld compelled false statements.
  • To verify one, check the key's fingerprint, then the signature with gpg, then the dates.
  • A late or missing canary is a reason to investigate, not proof of a raid.
On this page
  1. Warrant canary meaning
  2. Why warrant canaries exist
  3. What a good warrant canary contains
  4. How to verify a warrant canary, step by step
  5. What a missing or stale canary means
  6. The legal limits of warrant canaries
  7. Warrant canary vs transparency report
  8. Frequently asked questions

A warrant canary is a statement, published on a regular schedule, that a service provider has not received certain secret legal orders, such as gagged requests for user data. If such an order arrives, the provider stops renewing the statement instead of lying. Readers who notice the missing update learn what the provider is not allowed to say.

OffshoreServ, which runs offshore VPS, dedicated, RDP and GPU servers in seven countries, publishes a PGP-signed canary every quarter. Below: what a good canary contains, how to verify ours with GnuPG, and what a stale one does and does not prove.

Warrant canary meaning

The name comes from the canaries that coal miners once carried underground: a bird that stopped singing warned of gas. A warrant canary works the same way. The provider says "we have received no secret orders" on a fixed schedule. On the day it can no longer say so truthfully, it says nothing, and the silence is the warning.

The Electronic Frontier Foundation defines it as "a regularly published statement that a service provider has not received legal process that it would be prohibited from saying it had received".

Why warrant canaries exist

Some legal orders forbid the recipient to mention them. In the United States, the FBI can obtain subscriber and transactional records from a communications provider with a National Security Letter. When the FBI certifies that secrecy is needed, 18 U.S.C. § 2709 forbids the provider to "disclose to any person" that the FBI sought or obtained them. EFF's warrant canary FAQ adds orders of the Foreign Intelligence Surveillance Court and subpoenas that come with a gag order.

A canary rests on the difference between silence and speech. A gag can compel silence. EFF argues that it cannot compel a lie, because the First Amendment protects against compelled speech: its example is a ruling that New Hampshire could not require drivers to display "Live Free or Die" on their license plates. Courts, it notes, have not upheld compelled false statements.

Timing does the rest. In EFF's words, "the gag order only attaches after the ISP has been served with the gagged legal process." Before that, a provider may say "none". Afterwards, a US provider may publish national security requests only in ranges, such as 0 to 999 per half-year, under 50 U.S.C. § 1874, added by the USA FREEDOM Act of 2015.

What a good warrant canary contains

Look for five elements. The last column shows how ours measures up.

ElementWhy it mattersIn our canary
A dateShows how current it is25 September 2026
The next update dateMakes a missed renewal obviousBy 25 December 2026, then every quarter
Specific statementsShows what the silence would coverNo national security letters, FISA or similar secret orders, gag orders, warrants or orders for customer data, or requests for monitoring or backdoors; no customer data handed to any third party
A signatureProves who wrote it and that nothing changedPGP, in a separate file, canary.txt.asc
A proof of freshnessShows it was written on or after its dateNot included: ours relies on the signed date and the schedule

A freshness proof is something nobody could know earlier, such as that day's news headlines or a recent Bitcoin block hash. Without one, a provider could sign future canaries in advance. The time stamp in a PGP signature does not settle this, because it comes from the signer's own clock.

Warrant canary examples

  • rsync.net, a cloud storage provider, publishes a weekly signed canary with news headlines and sports scores, which "serves to demonstrate that that update could not have been created prior to that date".
  • Riseup missed a renewal in 2016 and later explained why, as described below.
  • Apple once wrote a canary into a transparency report. EFF's FAQ quotes it: "Apple has never received an order under Section 215 of the USA Patriot Act."

How to verify a warrant canary, step by step

You need GnuPG. gnupg.org notes that it is part of the base system of common Linux distributions; on Windows, use Gpg4win, and on macOS a build such as Mac GPG. The method works for any provider; our warrant canary page sets out our schedule.

1. Import our key and check its fingerprint

curl -sO https://offshoreserv.com/pgp/security.asc
gpg --import security.asc
gpg --fingerprint 9115B17ECE0944BCC461285FF3826B4FF2F38213

gpg prints the fingerprint in ten groups of four characters:

pub   ed25519 2026-09-25 [SC] [expires: 2028-09-24]
      9115 B17E CE09 44BC C461  285F F382 6B4F F2F3 8213
uid           [ unknown] OffshoreServ (offshoreserv.com)
sub   cv25519 2026-09-25 [E] [expires: 2028-09-24]

Compare it character by character with our PGP key page and the canary itself. A fingerprint read on the same page as the key only proves that the page was not altered in transit, so also check it through a second channel, such as the page loaded over Tor or a canary you verified before.

2. Download the canary and its signature

curl -sO https://offshoreserv.com/canary.txt
curl -sO https://offshoreserv.com/canary.txt.asc

canary.txt is the statement. canary.txt.asc is a detached signature, a separate file that signs it. Some providers publish a clearsigned file instead, with text and signature together.

3. Verify the signature

gpg --verify canary.txt.asc canary.txt

Name the signature file first and the text file second: the GnuPG manual calls letting gpg guess the data file "strongly discouraged". A valid canary gives these lines, with the time in your own time zone:

gpg: Signature made Fri Sep 25 17:35:24 2026 GMT
gpg:                using EDDSA key 9115B17ECE0944BCC461285FF3826B4FF2F38213
gpg: Good signature from "OffshoreServ (offshoreserv.com)" [unknown]
Primary key fingerprint: 9115 B17E CE09 44BC C461  285F F382 6B4F F2F3 8213

gpg also warns that the key "is not certified with a trusted signature". That only means you have not certified it in your own web of trust, as the GnuPG FAQ explains; your fingerprint check is what establishes trust. Change one character of canary.txt and gpg reports BAD signature and exits with an error.

4. Check the dates

canary.txt states its date, 25 September 2026, and the next one, due by 25 December 2026; the "Signature made" date should match. Past the due date with no new statement, the canary is stale. Keep the files you verified, so you can see whether the next canary quietly drops a statement.

What a missing or stale canary means

Three changes deserve attention: no renewal by the due date, a canary that disappears or stops verifying against the published key, and a new version that drops a statement. Any of them may mean that the provider can no longer make the statement truthfully.

It proves no more than that. Canaries lapse for ordinary reasons too, such as a holiday, an expired key or a mistake. Riseup's canary was "not updated on time" in the winter of 2016. In a statement of February 2017, Riseup explained that it had complied with two sealed FBI warrants, about an account used by an international DDoS extortion ring and one used for ransomware, and that "the canary was so broad that any attempt to issue a new one would be a violation of a gag order". It then narrowed its canary to "significant events that could compromise the security of Riseup users".

Treat a stale canary as a prompt, not a verdict: verify again from a fresh download, read the provider's transparency report and notices, allow a short grace period, then decide whether to move what matters to you. Never rely on a screenshot or someone else's copy.

In the United States, a truthful canary is legal: "there is no law that prohibits a service provider from reporting all the legal processes that it has not received," EFF writes. What happens after a gagged order arrives is untested. Asked whether any case has upheld warrant canaries, EFF answered "Not yet", and it advises a provider whose canary is triggered to ask a court to rule that it cannot be required to publish false information.

The closest US case concerns transparency reports, and the provider lost. In Twitter v. Garland, decided in March 2023, the Ninth Circuit upheld the FBI's redactions of the aggregate numbers of national security requests that Twitter wanted to publish for July to December 2013.

Elsewhere, canaries are untested in court in most countries, and secrecy rules differ. A canary is a signal, not a guarantee: it covers only the orders it lists, it cannot speak for the data centers and networks a provider relies on, and it is only as honest as the people who sign it. This is general information, not legal advice; check the law of your own jurisdiction. Our guide to whether offshore hosting is safe covers other signals worth checking.

Warrant canary vs transparency report

A transparency report counts the requests a provider received and what it did about them. A canary covers what a report may not mention at all.

AspectWarrant canaryTransparency report
What it saysThat certain secret orders have not been receivedHow many requests arrived, by type, and how many were actioned
What silence meansA missed renewal is itself the signalNothing; the counts are published either way
Legal pressure pointGag orders attached to specific requestsLimits on disclosing numbers, such as US reporting ranges
How you check itA signature you verify yourselfFigures you compare over time
At OffshoreServQuarterly; next due by 25 December 2026Quarterly, within 15 days of quarter end; first report covers Q3 2026

Our transparency report publishes counts only, never customer data. Our law enforcement guidelines explain that we act on valid orders from an authority competent where the server runs, and tell the customer in the client area unless the law forbids it. Our privacy policy lists what exists to hand over: an email address, billing and service records, sign-in records without IP addresses, and no traffic logs.

Frequently asked questions

What is a warrant canary?

A warrant canary is a statement that a service provider publishes on a fixed schedule, saying it has not received certain secret legal orders. If such an order arrives, the provider stops renewing the statement instead of lying, so the missing update itself warns readers. A good canary is dated, signed and specific.

How do I verify a warrant canary?

Import the provider's public key and check its fingerprint through a second channel. Download the canary and its signature, run gpg --verify with the signature file first, and look for "Good signature" from the expected key. Then check that the signed date is recent and the announced renewal date has not passed.

What does it mean if a warrant canary disappears?

It may mean that the provider received an order it cannot mention, but it proves nothing on its own: canaries also lapse through mistakes, expired keys or holidays, and a lapse says nothing about how many users are concerned. Verify again from a fresh download and allow a short grace period before you act.

In the United States, publishing a truthful canary is legal: no law forbids a provider to list orders it has not received, and a gag attaches only once an order is served. Whether a court could force a provider to keep renewing its canary afterwards remains untested. Other countries have their own secrecy rules, so check your jurisdiction.

How often should a warrant canary be updated?

Often enough that a missed update is noticed quickly, and always on a published schedule. rsync.net renews weekly; we renew every quarter, with the next statement due by 25 December 2026. EFF suggests leaving a few months between a report and the period it covers, so that a triggered canary can be taken to court in time.

Host it where the law is on your side.

Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions. No KYC, paid in crypto.

Welcome back

Sign in to manage your servers and your balance.

No KYCHuman check by Cloudflare TurnstileNo tracking