---
title: "Law Enforcement Guidelines | OffshoreServ"
description: "How we handle law-enforcement requests: the little we hold, what a valid request looks like, emergencies, preservation, customer notice."
url: https://offshoreserv.com/law-enforcement
lang: en
updated: 2026-09-27
source: HTML page at the url above (canonical); this is its Markdown version
---

Legal & privacy

# Law Enforcement Guidelines

How OffshoreServ handles law-enforcement requests: what little we hold, what a valid request looks like, emergencies, preservation, and customer notice.

Updated 27 September 2026 4 min read All services, all 7 jurisdictions

Key points

- We hold very little: an email, billing and service records, sign-in records without IP addresses, and no traffic logs.
- A valid request must come through an authority competent where the server is located.
- Emergencies involving threat to life or CSAM are handled immediately.
- We can preserve existing records on request while a proper order is obtained.
- We tell the affected customer unless the law forbids it, and we report counts publicly.

Version 1.2[How support works](https://offshoreserv.com/contact)

These guidelines are for law-enforcement and government authorities seeking data from OffshoreServ. They explain what we can and cannot provide, what a valid request looks like, and how we handle emergencies, preservation, and customer notice. They are written for transparency; customers can read them too.

## 1. What we can and cannot provide

OffshoreServ is built to minimize data, so most requests can only ever return a small amount.

**What we may hold for an account:**

- the account **email address** (which may be private or disposable);
- **payment transaction IDs and hashes**, and the account's **balance ledger**;
- **sessions and a security log** that record the browser and the country, never an IP address; and
- **service records**: plans, IP addresses assigned, and renewals.

**What we do not have:**

- **No traffic logs.** We do not log or inspect customer server traffic, run deep packet inspection, or record what a server sends or receives.
- **No content access for running servers.** Customer servers are under the customer's control; we do not have their keys and we do not look inside them.
- **No identity documents.** We run no KYC, so we have no name, address, phone, or ID to disclose.
- **No IP addresses for accounts.** Sign-ins are recorded with the browser and the country only.

> A request can only ever return data we actually hold. We do not create, reconstruct, or begin new logging in response to a request unless a valid preservation order lawfully requires us to preserve data going forward.

## 2. What a valid request looks like

To be actionable, a request must:

- come through a **court or authority competent in the jurisdiction where the server is located** (Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria, or Malaysia);
- identify the account or service precisely (email, service ID, or IP address, with the relevant time frame);
- state the legal basis and specify what data is sought; and
- be properly issued and served on the operating entity stated in our [Terms of Service](https://offshoreserv.com/terms).

**Foreign authorities.** An authority outside the server's country should proceed through the appropriate **mutual legal assistance** channel so the request is validated under the law of the location where the server runs. We are not bound by orders from jurisdictions that have no authority over that location, and a request under a law that does not apply, such as a US DMCA notice, is not actioned. See our [DMCA & Complaints Policy](https://offshoreserv.com/dmca-policy).

We review each request for validity and scope and respond only to the extent the law requires. Overbroad requests are narrowed or challenged. We also confirm that a request is genuine before acting, so send it through official channels and identify the issuing officer; we may decline to act on a request we cannot authenticate.

## 3. Emergency requests

Where there is an **imminent threat to life**, or a report of **child sexual abuse material**, we act immediately. In a genuine emergency we can respond to a request from a competent authority without waiting for the usual process, and we may act on our own initiative to remove CSAM and report it to the competent authorities. Emergency requests should be clearly marked as such, with a description of the threat and the time frame involved.

## 4. Preservation requests

A competent authority can ask us to **preserve** the limited records we already hold for a specific account while it obtains a proper order for disclosure. We honor valid preservation requests for a reasonable period. Preservation freezes existing data; it does not create new data, and it is not by itself an order to disclose. Several of our locations have specific preservation regimes, such as Moldova's Law 20/2009 on cybercrime.

## 5. Customer notification

We believe customers should know when their data is sought. **We notify the affected customer of a request, in their client area, unless we are legally prohibited from doing so**, for example by a court-ordered gag or where notice would defeat a lawful emergency. Where notice is only delayed, we inform the customer once the restriction lifts. Notice gives the customer the chance to respond or to challenge a request through their own counsel.

## 6. How requests appear in the transparency report

We publish the number of law-enforcement and government requests we receive, by category and outcome, in our [transparency report](https://offshoreserv.com/transparency-report), released quarterly within 15 days of quarter end and containing no customer data. Categories of secret request that a transparency report cannot itself disclose are addressed by our [warrant canary](https://offshoreserv.com/warrant-canary).

## 7. How to send a request

We have no email address for law-enforcement requests. We strongly prefer **encrypted** requests, encrypted with our public key, whose fingerprint is on [/pgp](https://offshoreserv.com/pgp). Requests should be issued through the competent court or authority, and should identify the issuing officer and give a contact for follow-up. We do not accept service of process through support tickets.

**Questions about this page?**

Customers with an active dedicated or GPU server can ask us by ticket from the [client area](https://offshoreserv.com/account/support). To send something sensitive, encrypt it with our [PGP key](https://offshoreserv.com/pgp) first.

---

OffshoreServ is an offshore hosting provider: VPS, dedicated servers, Windows RDP and GPU servers in seven jurisdictions (Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria and Malaysia), paid only in cryptocurrency (Bitcoin, Ethereum, Monero, Tether (USDT) and Solana), with no identity checks (no KYC).

Prices and plans: https://offshoreserv.com/pricing · Answers: https://offshoreserv.com/faq · Every page: https://offshoreserv.com/llms.txt
