Our commitment to accountability: what governments ask for, what we provide, and what we challenge
Reporting Period: 1 January 2025 – 31 December 2025 · Published: 20 February 2026
As of the publication of this transparency report, CipherVPN Ltd confirms the following:
Canary last updated: 2026-02-20T00:00:00Z | Next scheduled update: 2026-08-20 | Signed by: CTO & General Counsel
This report covers all formal legal requests received by CipherVPN Ltd during the calendar year 2025. We have adopted a policy of publication to the greatest extent permitted by law.
No account data fully disclosed
Valid production orders received
From all jurisdictions combined
Voluntary life-safety disclosures
Result: 0 disclosures of user data in 2025. We received no valid legal requests producing disclosable data. Our privacy-by-architecture approach means we typically hold nothing responsive to account-specific queries.
| Request Type | Received | Challenged / Rejected | Complied With | Data Produced |
|---|---|---|---|---|
| Account information (subscriber data) | 0 | 0 | 0 | None |
| IP address / connection logs | 0 | 0 | 0 | None |
| Email content or metadata | 0 | 0 | 0 | None |
| Traffic / payload content | 0 | 0 | 0 | None — architectural impossibility |
| Emergency / imminent-threat requests | 0 | 0 | 0 | None |
| Civil subpoenas / litigation hold | 0 | 0 | 0 | None |
| MLAT / international requests | 0 | 0 | 0 | None |
No formal legal requests were received from any jurisdiction in 2025. The following table reflects our historical request profile and the framework governing requests from each region.
| Jurisdiction | Governing Framework | 2025 Requests | Notes |
|---|---|---|---|
| United Kingdom | Investigatory Powers Act 2016 | 0 | Subject to UK court oversight |
| European Union | e-Evidence Regulation (EU) 2023/1543 | 0 | Routed through MLAT or direct court order |
| United States | ECPA, FISA, NSL authority | 0 | Velocity is not a US entity; US requests require MLAT |
| All other jurisdictions | MLAT / Mutual Legal Assistance Treaties | 0 | N/A |
When requests are received, they are reviewed by legal counsel. We reject requests for the following reasons:
We will comply with a valid, properly-authorised court order from a competent UK or EU court that:
In practice, because we do not retain VPN connection logs, DNS queries, traffic content, or origin IP addresses beyond 7 days, even a valid court order for a CipherVPN account typically yields only: account email address, subscription status, and aggregate bandwidth usage. VPN traffic content and connection history are architecturally unavailable.
| Data Category | Can We Provide It? | Reason |
|---|---|---|
| Account email address | ✓ Yes (with valid court order) | Retained for account management |
| Subscription / payment status | ✓ Yes (with valid court order) | Retained for billing |
| VPN connection logs (IPs, timestamps) | ⚠ Limited — last 7 days only | Automatically purged after 7 days |
| Original (pre-VPN) IP address | ✗ Never | Not logged; architecturally excluded |
| VPN traffic destination / DNS queries | ✗ Never | Not logged; architecturally excluded |
| VPN traffic payload / content | ✗ Never | Encrypted end-to-end; not logged |
| CipherMail content (E2E encrypted) | ✗ Never | Encrypted with your key; we have no decryption capability |
| CipherMail sender/recipient metadata | ⚠ Limited (if not E2E) | SMTP relay logs held 14 days; internal mail metadata encrypted in your mailbox |
| Support ticket contents | ✓ Yes (with valid court order) | Retained 3 years for QA; can be produced |
Our architecture is designed to be honest with law enforcement: we don't make claims about not logging that are undermined by hidden collection. Our real-time systems are technically incapable of producing the data that surveillance-focused requests typically seek:
This architecture is intentional and irreversible by policy: any change to introduce logging capability would require a full infrastructure rebuild, which we have publicly committed never to undertake.
We actively challenge legal demands we believe are unlawful, disproportionate, or beyond the requesting authority's jurisdiction:
We maintain a legal reserve fund dedicated to challenging unlawful surveillance orders. Our position is that meaningful privacy protection requires real willingness to incur legal costs in defence of user rights.
Our next transparency report will cover the period 1 January 2026 – 31 December 2026 and will be published by 28 February 2027.
We publish transparency reports annually and will provide an out-of-cycle update if we are legally permitted to disclose a national-security-level demand that we receive. The absence of such an update between reports means no such demand has been received — this is the substance of the warrant canary mechanism above.
Questions about this report can be directed to legal@ciphervpn.eu or our Data Protection Officer at dpo@ciphervpn.eu.