REPORT 01 — OFFSHORE VPS

Offshore VPS: the test rankings

Subscriptions at public prices. Notices sent by rights holders.

From March 1, 2026 to September 1, 2026Updated September 7, 2026

Which offshore VPS held up?

The offshore VPS still online after 6 months of real copyright notices were TLDBunker, HushVPS, VPSDEN, NimbusVPS, XmrCloud, EchelonVPS — 6 of 15. Among the 6 cut off following a notice, PrivateAlps lasted longest, until notice no. 8; 3 stopped for other reasons.

15
hosts rented
6
months of monitoring
6
still running at the end
80 to 100
notices / VPS over the period

The services that lasted

6

Cut off following copyright notices

6
HostServer countryResult
PrivateAlpsprivatealps.netSwitzerlandNotice no. 8
HostSailorhostsailor.comRomaniaNotice no. 6
FlokiNETflokinet.isIcelandNotice no. 2
AlexHostalexhost.comNot recordedNotice no. 2
1984 Hosting1984.hostingIcelandNotice no. 1
HostHatchhosthatch.comNot recordedNotice no. 1

Stopped for other reasons

3
HostServer countryResult
Shinjirushinjiru.comNot recordedPhishing report.
Njallanjal.laNot recordedCut-off related to the domain name.
BitHostingbit.hostingNot recordedCut off before any notice.

Testers’ records. The notice range covers the full period; services cut off early received fewer notices.

triedandtested.org · DATA

The test data

One record per provider: status at the close, server country where established, triggering notice, reason for interruption and recorded aftermath. The data comes from the testers.

To cite this record: triedandtested.org, offshore VPS test from March 1, 2026 to September 1, 2026, updated on September 7, 2026.

Unavailable values remain null in JSON and blank in CSV. Individual counts are not inferred from the overall range.

Cut-off details

Fell to a copyright notice

From most to least resistant, by the notice that triggered the cut-off.

HostServer countryFell atWhat happened
PrivateAlpsprivatealps.net No legal entity publishedSwitzerlandNotice no. 8

Copyright notice.

Copyrighted adult or video streaming material, published without authorisation. The exact type was not recorded for this server.

  • Last to fall
  • No refund for the remaining months
HostSailorhostsailor.com HOST SAILOR LIMITED — United Arab EmiratesRomaniaNotice no. 6

Copyright notice.

Copyrighted adult material, published without authorisation.

FlokiNETflokinet.is FlokiNET ehf — IcelandIcelandNotice no. 2

Copyright notice.

Copyrighted video streaming material, published without authorisation.

  • Restoration refused, despite an offer to remove the material
AlexHostalexhost.com AlexHost SRL — MoldovaNotice no. 2

Copyright notice.

Copyrighted adult material, published without authorisation.

  • No refund for the remaining months
  • Charged twice
1984 Hosting1984.hosting 1984 ehf. — IcelandIcelandNotice no. 1

Copyright notice.

Copyrighted adult material, published without authorisation.

  • Refunded
  • Restoration refused, despite an offer to remove the material
HostHatchhosthatch.com HostHatch LLC — United StatesNotice no. 1

Copyright notice.

Copyrighted video streaming material, published without authorisation.

Stopped for other reasons

HostServer countryFell atWhat happened
Shinjirushinjiru.com Shinjiru International IncNotice no. 1

Phishing report.

Copyrighted adult or video streaming material, published without authorisation. The exact type was not recorded for this server.

Njallanjal.la Njalla SRL — Costa RicaBefore any notice

Cut-off related to the domain name.

Copyrighted adult material, published without authorisation.

Service cut in under 2 days.

BitHostingbit.hosting ОсОО «Альянс Торг Компани» — KyrgyzstanBefore any notice

Cut off before any notice.

Copyrighted adult or video streaming material, published without authorisation. The exact type was not recorded for this server.

How the test was run

VPS rented at public prices, without announcing the test. Selected tier: 2 GB of memory.

Countries reported in the records: Finland, Romania, Iceland, Switzerland. Each server’s country appears in the table where established.

Where the notices came from

Protected content was published on the VPS. Rights holders and their automated systems sent the notices; the testers sent none.

Volume and timing varied by service. VPS cut off early received fewer notices.

The figures in this report

Figures from the test and consulted sources, with their calculation methods.

15
offshore VPS hosts rentedSubscriptions paid at the public price, without announcing the test.
6
months of continuous observationFrom 1 March to 1 September 2026.
80–100
copyright notices received per serverSent by the rights holders and their automated systems, not by the testers. Hosts that dropped out early received fewer.
6/15
services still working at the end of the periodService state checked on 1 September 2026. The other 9 had been cut off, each with its reason and the rank of the notice that ended the service.
4
server countriesFinland, Romania, Iceland and Switzerland. The country is the server’s, never the company’s: several of these hosts are established elsewhere. Attributing each instance to its country remains a provider claim, absent independent verification of the routing layers.
2 GB
of memory on the plan chosen everywhereThe same tier at every host, to make comparison possible. At no fewer than four of the six services still running, that tier is the entry plan.
5/15
hosts publishing no dedicated copyright policyReading their terms, acceptable use policies and abuse pages, and testing the usual paths, which return 404.
10/15
hosts publishing the name of a legal entitySearched on contact pages and legal notices. For the other four there is no identifiable recipient, neither for a customer nor for a rights holder.
1 hour
the only numeric removal deadline in European Union lawIt concerns terrorist content and runs from an authority’s removal order. No numeric deadline exists for copyright.
6 %
of worldwide annual turnover: cap on the administrative fineThe sanction for how notices are handled under the Union regime. It depends on no court decision.
6
mandatory elements of a United States noticeA notice that does not substantially comply with them is disregarded when assessing the provider’s knowledge.
39
legal references cited article by articleEach read on its official source, then put through a review tasked with refuting it. References that could not be verified were removed.
“DMCA”: what the word names, and what it does not require

The text the whole industry calls “DMCA” is a United States federal law of 28 October 1998. Its title II inserted section 512 into title 17 of the United States Code, and that is where — and only where — the notice-and-takedown procedure lives.

That procedure is not written as an obligation to remove. Every limb of section 512 opens with the same formula: a service provider shall not be liable if certain conditions are met. Acting promptly after a notice is one of those conditions, not a duty. The text even states expressly that failing those conditions does not count against the provider when its other defences are examined.

So what is presented as the law forcing hosts to take content down is in fact a liability shelter that a host is free not to seek. The United States Copyright Office itself writes that responding to a notice is always voluntary — bearing in mind that this is a public frequently-asked-questions page, an administrative explanation with no normative force, and that the same Office adds that a service targeting United States users may incur liability under United States law.

It would be wrong, however, to conclude that section 512 imposes nothing on anyone. The recipient of a properly issued subpoena must disclose the information required, whether or not it acted on any notice. And the text provides for injunctions which do bind the provider.

What “DMCA ignored” actually describes
A stance towards a mechanism that conditions a liability shelter, not a refusal to obey an obligation to remove. The phrase says nothing about the law applicable to the host, nor about what it will do with a court order.
What the text does not require
No monitoring of the service, no active search for infringing material. Designating an agent with the Copyright Office, often presented as a mandatory formality, is a condition for the hosting limb alone: not designating one forfeits that shelter, it is not a breach sanctioned as such.
What is not settled
The United States definition of a service provider contains no criterion of nationality, seat or equipment location. Whether a foreign host can invoke section 512 before a United States court is settled by no text we were able to read. We therefore assert it in neither direction.
A false statement carries a price
Anyone who knowingly and materially misrepresents that material is infringing is liable for the damages, costs and fees incurred by the person targeted, by a rights holder, or by the host that relied on the statement.
What a notice actually triggers, country by country

In the European Union the framework is the Digital Services Act. It applies wherever a service is offered to recipients located in the Union, whatever the provider’s place of establishment. It neither displaces the United States text nor makes it applicable: these are two regimes answering different questions.

The important point lies elsewhere. Under this regime what counts is not the receipt of a message but what the notice makes it possible to establish. It gives rise to actual knowledge where it allows a diligent provider to identify the illegality without a detailed legal examination. An automated, imprecise notice, or one without the exact location of the material, may therefore have no legal effect — while a substantiated notice produces one, whatever its form. The Court of Justice so held on 22 June 2021, in joined cases C-682/18 and C-683/18, under the provision the regulation has since replaced.

Losing the benefit of the exemption is not being found liable. The regulation’s rules determine cases of non-liability; they provide no positive basis. An inactive host exposes itself to the ordinary law, not to an automatic finding against it.

A word on deadlines, because they circulate widely: the only numeric removal deadline in Union law is one hour, it concerns terrorist content, and it runs from an authority’s removal order. The twenty-four or forty-eight hours often presented as standards appear in none of the texts we verified.

Finland
Since 17 February 2024 there is no national copyright-specific procedure left: it was repealed, no regulation running parallel to the Union regulation being able to survive. No numeric deadline, only the requirement to act promptly. Compelled removals go through the courts — cessation action, interruption order, interim order that may be made without hearing the alleged infringer, blocking order where the infringer is unknown. The reputation for inertia rests on that requirement of a court decision; it holds up poorly against two findings: those interim orders can be made urgently, and the administrative fine for mishandling notices — up to 6 % of worldwide annual turnover — depends on no court decision at all. We verified no published decision applying these orders to a host: the practice remains unknown.
Romania
Of the three, this is the country where the announced regime is the least favourable — the exact reverse of its reputation. On top of the Union regime, Romania kept national obligations the Union regime does not impose: informing the competent public authorities without delay of apparently illegal activity, disclosing on request the data identifying hosting customers, and interrupting on an authority’s order. The implementing norms add informing the authorities within 24 hours of a complaint, and a free electronic complaint procedure published on the provider’s site. Qualification to carry: those norms refer to articles repealed since 18 April 2024, and no source consulted establishes whether they were adapted.
Iceland
No formalised national procedure: the one that existed for copyright was repealed in 2019. The applicable regime remains that of the e-commerce directive, transposed in 2002. The Digital Services Act is not applicable there as our sources stand — the Icelandic Ministry for Foreign Affairs’ European affairs database, consulted on 7 September 2026, classifies it among acts under review, with no decision of the European Economic Area Joint Committee; the primary EFTA record was inaccessible to us, so the finding rests on a single source. The consequence: no notice-mechanism obligation, no coordinator, no capped administrative fine. The constraint there is judicial, and it exists: an injunction against hosting data can target the host without it being liable, and breaching it intentionally or through gross negligence is punishable.
What the Icelandic reputation rests on
A parliamentary resolution of 2010, which is a mandate to the government with no substantive rule and no provision on hosting, and whose committee report explicitly rejected the idea of an extraterritorial position. What is established in Iceland is not immunity: it is an earlier regime.
What was measured

The records describe service status at the end of the test and, for cut-offs, the trigger. They do not measure individual notice handling or the legal validity of complaints.

Results cover the stated period. Server country and company country are separate data points.

Additional data

Prices paid and notice details for each service still active: unpublished. The legal analysis of Switzerland remains to be completed.

Sources

Official texts cited in the legal analysis.

Sources consulted on September 7, 2026

United States law

  1. Digital Millennium Copyright Act, Public Law 105-304, 112 Stat. 2860sections 1, 201 et 202(a)www.govinfo.gov
  2. United States Code, titre 1717 U.S.C. § 512(a), (b)(1), (c)(1)(A) à (C), (d)www.govinfo.gov
  3. United States Code, titre 1717 U.S.C. § 512(c)(3)(A)(i) à (vi) et (c)(3)(B)www.govinfo.gov
  4. United States Code, titre 1717 U.S.C. § 512(k)(1)(A) et (B)www.govinfo.gov
  5. United States Code, titre 1717 U.S.C. § 512(l) et § 512(m)(1) et (2)www.govinfo.gov
  6. United States Code, titre 17, et Code of Federal Regulations, titre 3717 U.S.C. § 512(c)(2) ; 37 CFR 201.38(a)www.ecfr.gov
  7. United States Code, titre 1717 U.S.C. § 512(h)(1), (5) et (6) ; § 512(j)(1)(B)(ii) et (j)(2)www.govinfo.gov
  8. United States Code, titre 1717 U.S.C. § 512(f)www.govinfo.gov

European Union law

  1. Règlement (UE) 2022/2065 sur les services numériquesarticle 2, paragraphe 1eur-lex.europa.eu
  2. Règlement (UE) 2022/2065 sur les services numériquesarticle 16, paragraphes 1 à 6eur-lex.europa.eu
  3. Règlement (UE) 2022/2065 sur les services numériquesarticle 6, lu avec le considérant 17eur-lex.europa.eu
  4. Règlement (UE) 2022/2065 sur les services numériquesarticle 56 et considérant 123eur-lex.europa.eu
  5. Directive 2000/31/CE sur le commerce électroniquearticle 2, point c), et considérant 19eur-lex.europa.eu
  6. Cour de justice de l’Union européenne, arrêt du 22 juin 2021, affaires jointes C-682/18 et C-683/18rendu sous l’empire de l’article 14, paragraphe 1, de la directive 2000/31/CEcuria.europa.eu
  7. Directive 2001/29/CE sur le droit d’auteur dans la société de l’informationarticle 8, paragraphe 3eur-lex.europa.eu
  8. Règlement (CE) n° 864/2007 sur la loi applicable aux obligations non contractuellesarticle 8, paragraphe 1eur-lex.europa.eu
  9. Règlement (UE) 2021/784 relatif aux contenus à caractère terroriste en lignearticle 3, paragraphe 3eur-lex.europa.eu
  10. Directive 2000/31/CE sur le commerce électroniquearticle 5, paragraphe 1, points a) à d) et g) ; considérants 19 et 57eur-lex.europa.eu

Finland

  1. Tekijänoikeuslaki 404/1961 (loi finlandaise sur le droit d’auteur)articles 60 c à 60 ewww.finlex.fi
  2. Laki 917/2014 (loi finlandaise sur les services de communications électroniques)article 185www.finlex.fi

Romania

  1. Legea nr. 365/2002 privind comerțul electronicarticle 16, alinéas 1 à 6legislatie.just.ro
  2. Normes méthodologiques approuvées par HG nr. 1308/2002article 11legislatie.just.ro
  3. Legea nr. 8/1996 privind dreptul de autorarticle 188, alinéas 3 et 5legislatie.just.ro

Iceland

  1. Lög nr. 30/2002 um rafræn viðskipti (loi islandaise sur le commerce électronique)articles 12 à 14 et 18www.althingi.is
  2. Lög nr. 54/2019articles 1 et 2, abrogeant la procédure de notification propre au droit d’auteurwww.althingi.is
  3. Höfundalög nr. 73/1972 (loi islandaise sur le droit d’auteur)article 59 a, alinéa 2www.althingi.is
  4. Þingsályktun nr. 23/138 (résolution parlementaire islandaise de 2010) et rapport de la commission des affaires généralesmandat au gouvernement, sans disposition de fond sur l’hébergementwww.althingi.is

Technical verification

  1. Registres IANA « IPv4 Address Space » et « Autonomous System (AS) Numbers »colonnes Prefix, Designation, WHOIS et RDAP ; plages et registre régional assignatairewww.iana.org
  2. RFC 3912, « WHOIS Protocol Specification »format de la réponse et considérations de sécuritéwww.rfc-editor.org
  3. RFC 9082 et RFC 9083 (format des requêtes et des réponses RDAP)motifs d’URL de recherche ; structures JSON des réponseswww.rfc-editor.org
  4. Document RIPE ripe-826, politiques d’allocation et d’assignation IPv4sections 4.0 (exigences d’enregistrement) et 6.2www.ripe.net
  5. Document RIPE ripe-705, gestion du contact abus dans la base RIPEcaractère obligatoire de « abuse-c: » et validation annuelle de « abuse-mailbox: »www.ripe.net
  6. Documentation de la base RIPE, « Descriptions of Primary Objects »objet inetnum : attributs status:, org:, mnt-by:, abuse-c:, geofeed:docs.db.ripe.net
  7. ARIN Number Resource Policy Manualsections 4.2.3.7.1, 4.2.3.7.2, 6.5.5.1 et 6.5.5.2 ; définitions de la section 2.5www.arin.net
  8. RIPE NCC, Routing Information Service et plateforme RIPEstatcollecteurs de routes ; points d’accès Routing Status, BGP State, Looking Glasswww.ripe.net
  9. RFC 9582, « A Profile for Route Origin Authorizations (ROAs) »profil de l’objet signé et procédures de validationwww.rfc-editor.org
  10. Documentation de la base de données RIPEattribut « country: »docs.db.ripe.net
  11. RFC 8805 et RFC 9632 (flux de géolocalisation auto-publiés)format et publication du geofeedwww.rfc-editor.org
  12. RFC 9224, RFC 9082 et RFC 9083 (protocole RDAP)découverte du service et requêtes d’enregistrementwww.rfc-editor.org