Transparency Report — CipherVPN
Transparency Report

Transparency Report

Our commitment to accountability: what governments ask for, what we provide, and what we challenge

Reporting Period: 1 January 2025 – 31 December 2025  ·  Published: 20 February 2026

⚑ Warrant Canary — Updated 20 February 2026

As of the publication of this transparency report, CipherVPN Ltd confirms the following:

  • We have NOT received any National Security Letters (NSLs) from any government or intelligence agency.
  • We have NOT received any orders under FISA Section 702 or any equivalent foreign intelligence surveillance statute.
  • We have NOT been placed under any gag order that would prevent us from disclosing the existence of a legal demand.
  • We have NOT received any secret or classified orders compelling bulk data collection or backdoor installation.
  • We have NOT intentionally weakened our encryption, introduced backdoors, or granted any third party covert access to our infrastructure.

Canary last updated: 2026-02-20T00:00:00Z | Next scheduled update: 2026-08-20 | Signed by: CTO & General Counsel

1. Reporting Period Overview

This report covers all formal legal requests received by CipherVPN Ltd during the calendar year 2025. We have adopted a policy of publication to the greatest extent permitted by law.

0 Requests Fully Complied With

No account data fully disclosed

0 Court Orders Received

Valid production orders received

0 Government Requests

From all jurisdictions combined

0 Emergency Disclosures

Voluntary life-safety disclosures

Result: 0 disclosures of user data in 2025. We received no valid legal requests producing disclosable data. Our privacy-by-architecture approach means we typically hold nothing responsive to account-specific queries.

2. Requests by Type

Request TypeReceivedChallenged / RejectedComplied WithData Produced
Account information (subscriber data) 000None
IP address / connection logs 000None
Email content or metadata 000None
Traffic / payload content 000None — architectural impossibility
Emergency / imminent-threat requests 000None
Civil subpoenas / litigation hold 000None
MLAT / international requests 000None

3. Requests by Jurisdiction

No formal legal requests were received from any jurisdiction in 2025. The following table reflects our historical request profile and the framework governing requests from each region.

JurisdictionGoverning Framework2025 RequestsNotes
United Kingdom Investigatory Powers Act 2016 0 Subject to UK court oversight
European Union e-Evidence Regulation (EU) 2023/1543 0 Routed through MLAT or direct court order
United States ECPA, FISA, NSL authority 0 Velocity is not a US entity; US requests require MLAT
All other jurisdictions MLAT / Mutual Legal Assistance Treaties 0 N/A

4. Request Outcomes

Reasons We Reject Requests

When requests are received, they are reviewed by legal counsel. We reject requests for the following reasons:

  • No jurisdiction — the requesting authority has no legal standing to demand data from a UK entity
  • Invalid or defective process — requests lacking proper court authorisation, served incorrectly, or not meeting threshold requirements
  • Overbroad scope — requests seeking data beyond the narrow minimum needed for the stated lawful purpose
  • No data held — we structurally do not hold the requested data category (e.g., VPN traffic content is never stored)
  • Disproportionate impact — where compliance would require bulk disclosure or would undermine user privacy disproportionately

When We May Comply

We will comply with a valid, properly-authorised court order from a competent UK or EU court that:

  • Is directed at a specific identified account
  • Relates to a serious criminal investigation (e.g., terrorism, child exploitation)
  • Contains a court-issued production order with judicial oversight
  • Requests only data that Velocity actually holds

In practice, because we do not retain VPN connection logs, DNS queries, traffic content, or origin IP addresses beyond 7 days, even a valid court order for a CipherVPN account typically yields only: account email address, subscription status, and aggregate bandwidth usage. VPN traffic content and connection history are architecturally unavailable.

5. What Data We Can (and Cannot) Provide

Data CategoryCan We Provide It?Reason
Account email address ✓ Yes (with valid court order) Retained for account management
Subscription / payment status ✓ Yes (with valid court order) Retained for billing
VPN connection logs (IPs, timestamps) ⚠ Limited — last 7 days only Automatically purged after 7 days
Original (pre-VPN) IP address ✗ Never Not logged; architecturally excluded
VPN traffic destination / DNS queries ✗ Never Not logged; architecturally excluded
VPN traffic payload / content ✗ Never Encrypted end-to-end; not logged
CipherMail content (E2E encrypted) ✗ Never Encrypted with your key; we have no decryption capability
CipherMail sender/recipient metadata ⚠ Limited (if not E2E) SMTP relay logs held 14 days; internal mail metadata encrypted in your mailbox
Support ticket contents ✓ Yes (with valid court order) Retained 3 years for QA; can be produced

6. Why Our Architecture Limits What We Hold

Our architecture is designed to be honest with law enforcement: we don't make claims about not logging that are undermined by hidden collection. Our real-time systems are technically incapable of producing the data that surveillance-focused requests typically seek:

  • VPN tunnel nodes operate in a connection-forwarding mode. They never resolve DNS queries to IP-to-host logs. They forward packets and write no per-packet metadata.
  • WireGuard session keys are ephemeral. After session close, the keys are discarded and session data is cryptographically unrecoverable.
  • End-to-end encrypted mail is stored as opaque ciphertext alongside an encrypted private key. Velocity staff cannot open messages even with full database access.

This architecture is intentional and irreversible by policy: any change to introduce logging capability would require a full infrastructure rebuild, which we have publicly committed never to undertake.

7. Our Legal Request Process

  1. Receipt — all legal demands are directed to legal@ciphervpn.eu and immediately reviewed by legal counsel
  2. Validity check — we verify the demand is from a competent authority with jurisdiction, is properly served, and contains required judicial authorisation
  3. Scope analysis — we assess whether the request is proportionate and limited to the minimum necessary data
  4. User notification — where legally permitted, we notify the affected user before responding
  5. Challenge assessment — if the request is overbroad, lacks jurisdiction, or is otherwise invalid, we challenge it through available legal channels
  6. Response — we respond with only the legally required minimum, clearly stating what data we hold vs. cannot provide
  7. Record — all received demands are recorded for inclusion in the next transparency report (to the extent permitted by law)

8. How We Fight Overbroad Orders

We actively challenge legal demands we believe are unlawful, disproportionate, or beyond the requesting authority's jurisdiction:

  • Scope reduction requests — we routinely push back on broad orders to narrow the scope to the specific account and data category at issue
  • Jurisdiction objections — requests from non-UK authorities without proper MLAT routing are declined
  • Judicial review — where we believe an order is unlawful, we apply to the relevant court for judicial review
  • Amicus participation — we participate in relevant privacy law proceedings and support digital rights organisations including the Open Rights Group

We maintain a legal reserve fund dedicated to challenging unlawful surveillance orders. Our position is that meaningful privacy protection requires real willingness to incur legal costs in defence of user rights.

9. Next Report

Our next transparency report will cover the period 1 January 2026 – 31 December 2026 and will be published by 28 February 2027.

We publish transparency reports annually and will provide an out-of-cycle update if we are legally permitted to disclose a national-security-level demand that we receive. The absence of such an update between reports means no such demand has been received — this is the substance of the warrant canary mechanism above.

Questions about this report can be directed to legal@ciphervpn.eu or our Data Protection Officer at dpo@ciphervpn.eu.