Home / Servers / ENCRYPTED VPS

Encrypted VPS. Your passphrase, your data.

Real LUKS2 full disk encryption on hardware we own. Not a marketing checkbox. Your root partition is encrypted with a passphrase only you know. We can't read your data even if we wanted to.

Deploy Encrypted VPS
Starting in Montreal, Canada / Owned hardware / 30-second deployment / No KYC

How it works

Order a Debian 12 server

In Montreal and select "Disk Encryption" during OS selection.

SSH into Dropbear

When prompted. The server boots into a minimal initramfs environment.

Set your LUKS passphrase

The root partition encrypts in-place with LUKS2 + argon2id. Takes about a minute.

Done

On every boot, SSH in and enter your passphrase to unlock. That's it.

What makes this different from everyone else

Real encryption, not theater Most providers that claim "encryption" just encrypt the underlying storage array. That protects against physical theft of drives, not against the provider reading your data. Our encryption happens inside your VM. The passphrase never leaves your terminal. We literally cannot decrypt your disk.
Enable or disable anytime Encryption isn't a one-way street. You can enable it from your dashboard on any running Debian 12 server, and disable it later if you change your mind. The process is fully automated and takes about a minute each way.
Owned hardware This runs on servers Servury physically owns in a Montreal colocation facility. No third-party provider sits between your encrypted disk and the bare metal. The entire stack is ours.
LUKS2 + argon2id We use LUKS2 with the argon2id key derivation function (the same one used by modern password managers). The in-place encryption preserves your existing data.

Technical details

For the curious.

  • Partition layout: sda1 = BIOS boot (1MB), sda2 = /boot ext4 (512MB, always unencrypted), sda3 = root ext4 (encrypted with LUKS2)
  • Encryption method: LUKS2 in-place reencrypt with argon2id KDF. cryptsetup reencrypt --encrypt --reduce-device-size 32M
  • Boot unlock: Dropbear SSH in initramfs. Server boots, waits at Dropbear, you SSH in and enter passphrase, server continues boot.
  • Key storage: LUKS header on sda3. Passphrase is never transmitted to or stored by Servury. It exists only in your terminal during unlock.
  • Disable flow: One click in dashboard. Server reboots into initramfs, decrypts in-place, removes crypttab, rebuilds GRUB. Data preserved.
  • Compatible OS: Debian 12 only (custom template with pre-installed encryption tooling). Other OSes on this hardware do not support FDE.

Fair questions

Can Servury read my encrypted data?

No. The LUKS passphrase is set by you inside a Dropbear SSH session. We never see it, store it, or transmit it. Without the passphrase, the disk contents are indistinguishable from random noise.

What happens if I forget my passphrase?

Your data is gone. There is no recovery mechanism, no backdoor, no master key. This is by design. If you lose the passphrase, you can reinstall the OS but your encrypted data is unrecoverable.

Does encryption affect performance?

Minimal impact. LUKS2 with AES-XTS runs at near-native speeds on modern CPUs with AES-NI hardware acceleration, which all our processors support.

Can I enable encryption on an existing server?

Yes. Any running Debian 12 server in Montreal can have encryption enabled from the Administration tab. Your existing data is preserved during the in-place encryption process.

Is this available in other locations?

Currently Montreal only, because it requires our owned hardware with a custom Debian 12 template. Other locations use third-party infrastructure where we can't customize the boot process.

Other use cases

AnythingLLM VPS Self-host AnythingLLM to chat with your PDFs, codebases, and knowledge bases privately. Coolify VPS Run Coolify on your own VPS to deploy apps, databases, and services with one click. A self-hosted Vercel/Heroku. CrewAI VPS Run multi-agent CrewAI workflows on your own VPS, 24/7, without Replit or notebook tabs open. Crypto VPS Anonymous VPS for crypto trading bots, nodes, and miners. Dev/Staging VPS Disposable dev and staging VPS, deployable in 30 seconds, paid by the day. Dify VPS Self-host Dify on a no-KYC VPS for private LLM apps and RAG pipelines. Discord Bot VPS Host Discord bots 24/7 on an anonymous VPS. discord.js, discord.py, JDA, anything. No KYC. Flowise VPS Self-host Flowise to build LLM apps, chatbots, and agents with a visual drag-and-drop UI. Forex VPS Low-latency VPS for forex trading and MT4/MT5 EAs. FreeBSD VPS Anonymous FreeBSD VPS on owned hardware, no KYC, crypto accepted. Gaming VPS Low-latency VPS for game servers and dedicated lobbies. Gitea / Forgejo VPS Self-host Gitea or Forgejo on a no-KYC VPS. A lightweight GitHub alternative with full Actions support. Hermes Agent VPS Self-host Hermes Agent 24/7 on a no-KYC VPS, anonymous signup, crypto accepted. Immich VPS Self-host Immich to replace Google Photos with AI search, face recognition, and mobile auto-upload. LibreChat VPS Self-host LibreChat on a no-KYC VPS as a private multi-provider chat UI. Mastodon VPS Run a self-hosted Mastodon instance on your own VPS. Federated, ad-free, no algorithmic feed. Matrix Synapse VPS Self-host a Matrix Synapse server. End-to-end encrypted, federated chat, voice, and video. Minecraft Server VPS Host a Minecraft server (Vanilla, Paper, Fabric, Forge) on an anonymous VPS. Full root, no KYC. n8n VPS Self-host n8n on a no-KYC VPS for unlimited workflows, no n8n Cloud bill. Nextcloud VPS Self-host Nextcloud to replace Google Drive, Docs, Photos, Calendar, and Contacts with one private suite. Ollama VPS Self-host Ollama on a no-KYC VPS for a private LLM API endpoint. Open WebUI VPS Self-host Open WebUI as a private ChatGPT alternative on a no-KYC VPS. OpenBSD VPS Anonymous OpenBSD 7.8 VPS with full root access on owned hardware. OpenClaw VPS Run an OpenClaw AI assistant gateway 24/7 on a no-KYC VPS. Pi-hole VPS Run Pi-hole on a VPS to block ads and trackers across every device, including phones on mobile data. Plausible Analytics VPS Self-host Plausible Analytics on your own VPS. Cookieless, GDPR-compliant Google Analytics alternative. Scraping VPS Web scraping VPS with no KYC, fast IP rotation, and crypto payments. Telegram Bot VPS Host Telegram bots 24/7 on an anonymous VPS. Long-poll or webhook. aiogram, Telegraf, anything. Tor Relay & Bridge VPS Run a Tor middle relay or obfs4 bridge on a privacy-friendly VPS. Help users in censored regions reach the open internet. Vaultwarden VPS Self-host Bitwarden (Vaultwarden) on a no-KYC VPS. Free Premium features, family-friendly, end-to-end encrypted. VPN VPS Self-hosted VPN VPS for personal WireGuard or OpenVPN endpoints. WireGuard VPS Self-host a WireGuard VPN on a dedicated VPS. Faster than commercial VPNs, no shared IP, no logs.