Skip to main content

Dedicated machines

DS Lite

DS Lite is the entry dedicated tier — an Intel Xeon E-2236 with six physical cores, thirty-two gigabytes of error-correcting memory, two NVMe drives in RAID-1, eighty-gigabit DDoS shield. It exists for projects where the shared hypervisor itself is part of the threat model: leak archives, source-protection workloads, and journalism where deniability about co-tenancy matters as much as deniability about the operator.

$89 per month

Order this plan → No KYC · No DMCA · Crypto only
  • Intel Xeon E-2236 (6c / 12t @ 3.4 GHz)
  • 32 GB DDR4 ECC
  • 2× 480 GB NVMe (RAID-1)
  • 30 TB / month

Specification

Processor
Intel Xeon E-2236 (6c / 12t @ 3.4 GHz)
Memory
32 GB DDR4 ECC
Storage
2× 480 GB NVMe (RAID-1)
Bandwidth
30 TB / month
IPv4 addresses
1
IPv6
yes
Virtualization
Bare-Metal
Uplink
1 Gbps
Uptime SLA
99.9%
Operating systems
Ubuntu, Debian, AlmaLinux, Windows Server, Proxmox

Who this plan suits

A leak archive whose threat model includes side-channel attacks from a hostile co-tenant, an investigative team's source-protection workload where the hardware boundary is part of the deniability story, a regional press-freedom organisation consolidating member-outlet infrastructure on machines they fully control, a working publication that has decided that the upgrade from a shared hypervisor is worth the lead-time and the higher monthly invoice. The tier matches the moment when 'no co-tenants' becomes a hard requirement rather than a preference.

It is undersized for projects that need deterministic high-clock CPU performance for video transcoding or a high-throughput scraping load — DS Mid with the Ryzen 9 5950X is the answer there. It is undersized for a multi-property consortium consolidating dozens of services on one machine; DS Pro on the EPYC platform is the answer for that workload. VPS-16 is the right answer when the upgrade from a smaller plan is driven by capacity rather than by threat model.

Where this plan can be operated

DS Lite is racked in Iceland or Switzerland. Bare-metal provisioning is not instant: we order the hardware, rack it, configure the network, run the customer's chosen install, and confirm by email. The lead time is typically two to five business days, stated honestly here rather than implied to be shorter; we would rather a customer wait the right amount of time than be told 'instant provisioning' and end up on a tier where it is not.

Iceland's IMMI posture and the absence of a Höfundalög-side notice-and-takedown obligation make it the conservative answer for a leak archive — see also the source-protection entry. Switzerland's revFADP plus the courtroom culture established by ProtonMail v UVEK A-550/2019 produce comparable outcomes through a different statutory route. For a project whose adversary is an EU domestic prosecutor with bilateral cooperation channels, Iceland's geographical and treaty distance is the more conservative choice; for a project whose adversary is more diffuse, Switzerland's central-European latency and longer history of mail-server jurisprudence may matter more.

What the operator sees, and what it does not

On dedicated hardware, the operator's mechanical view shrinks: there is no hypervisor between the operator and the customer's workload, so the operator sees the IPMI/BMC interface (used for hardware-level operations like reset and console access; we leave it disabled by default and enable it on customer request only), the network counters at the rack switch, and the billing metadata. The customer's disk contents, memory contents, and application-layer behaviour are all behind the customer's own operating-system boundary, not the operator's hypervisor.

Full disk encryption with TPM-backed keys is feasible at this tier and we recommend it for any workload where it matters; the customer chooses whether the disk is encrypted and the operator does not retain the key. The bare-metal boundary changes the threat picture compared to a virtualised tier — the operator cannot snapshot a running disk image, cannot read VM memory, cannot take a guest console — and that boundary is the reason a customer pays the dedicated premium. Payment in Monero, Lightning, on-chain Bitcoin, or cash.

Jurisdictions

The offering is available from the jurisdictions listed below. The choice between them is made at the order step; this section discloses what the choice is, so the reader knows before the form opens.

Ordering this plan

The order step confirms the jurisdiction, the payment rail, and the contact detail before any service is provisioned. Questions about the plan or migration ahead of an order go through the contact form.

Order this plan →