Updated August 2, 2026

No-logs hosting

Answer

No-logs hosting means the provider does not retain traffic, connection or DNS records. Incognito VPS keeps no NetFlow, no packet capture, no DNS query logs and no customer IP history. Hypervisor records are limited to server ID, plan, location and billing term. The full field list is published below.

Everything we store, listed

"No logs" is an unfalsifiable claim when a provider states it and stops. So here is the schema instead. If a field is not on this list, it is not in the database.

Account record
token hash (Argon2id), USD balance, created-at
Server record
server ID, plan SKU, location, term start/end, OS image
Payment record
invoice ID, amount, coin, confirmed-at
Network
aggregate per-port bandwidth counters, 5-minute buckets
Console
nothing — VNC sessions are not recorded
DNS
nothing — resolvers run without query logging
NetFlow / sFlow
not enabled on any edge or aggregation device
Customer IP history
not recorded at any layer

Why aggregate counters still exist

Per-port bandwidth counters in five-minute buckets are how we bill metered plans and detect a link saturating. They contain a byte count and a timestamp per virtual interface. They contain no addresses, no ports and no payload, so they cannot reconstruct who talked to what.

We are explicit about this because a provider claiming literally zero telemetry is either lying or unable to run a network. The useful claim is not "we record nothing"; it is "here is exactly what we record, and here is why it cannot identify you".

What you can verify

Our warrant canary is signed with the key at /pgp and rotated on the first business day of each quarter, with the current Bitcoin block hash embedded to prove it was signed after that date. A missing or stale canary is meaningful.

The quarterly transparency report publishes the number of legal requests received by jurisdiction, how many produced any data, and what that data consisted of. So far the answer to the last question has consistently been a token hash and a balance, because that is all there is.

FAQ

Frequently asked questions

01 Do you keep any logs at all?

Aggregate per-port bandwidth counters in five-minute buckets, for billing and capacity. They hold a byte count and a timestamp — no addresses, ports or payload. No NetFlow, packet capture, DNS query logs or customer IP history exists.

02 What about the logs my own server writes?

Those are yours, inside your VM, and we do not read them. If you want them gone, configure your syslog accordingly — sshd authentication logging is on by default in most distributions and records every connecting address.

03 How can I verify the no-logs claim?

You cannot verify it absolutely — nobody can, at any provider. What you can check is the signed quarterly warrant canary, the transparency report, and whether the published field list matches what legal requests actually produce.

04 Do you log VNC or console sessions?

No. Console access is proxied, not recorded. There is no session capture, no keystroke logging and no screenshot retention at any point.

Related

55-second deploy

Pick a jurisdiction. Pay in crypto. Be running in a minute.

No account to create, no email to confirm, no card to enter.