Vaultwarden on Anubiz Host Finland VPS
Finland writes the secrecy of communications into Section 10 of the constitution, which is rare in Europe. The practical effect for self-hosting a password vault is that intercept and compulsion orders require a high judicial bar, and there is no key escrow statute. Finland also runs one of the cleaner IP allocation reputations in northern Europe, so abuse blocklists rarely catch a Helsinki VPS unintentionally. Vaultwarden idles around 256 MB and runs fine on a 1 GB tier. This page covers picking the VPS, Docker compose, Argon2id migration, reverse proxy specifics, and backup to Iceland or Romania.
Need this done for your project?
We implement, you ship. Async, documented, done in days.
Why Finland
Section 10 of the Constitution of Finland protects the secrecy of confidential communications. Domestic surveillance powers were tightened in 2019 but still require court oversight for individual targeting. There is no statutory power to compel a master password. EU GDPR applies. The Finnish supervisory authority (Tietosuojavaltuutettu) is active. Network reputation is good; Finnish IPs are rarely on default Spamhaus or AbuseIPDB blocks because abuse handling is fast.
VPS Plan
Anonymous Finland VPS 1 GB for up to 15 users, 2 GB for larger teams or if you colocate other services. Finland tier ships NVMe and a /29 IPv6 on request. Latency is 15 ms to Stockholm, 25 ms to Frankfurt, 30 ms to Moscow.
Docker Compose
Vaultwarden on 127.0.0.1:8080 through Caddy terminating TLS on 443. DOMAIN=https://vault.example.fi. Disable signups after creating your account. Set SHOW_PASSWORD_HINT=false; password hints leak useful entropy to attackers. Run with --cap-drop=ALL --cap-add=CHOWN,SETUID,SETGID; Vaultwarden does not need anything else.
KDF Hardening
Argon2id, 64 MiB, 3 iterations, parallelism 4. Mandatory. PBKDF2 is the Bitwarden 2022 default and is brute forceable. Walk every account through the migration in the first month.
Encryption Truth
Vault items end to end encrypted; server cannot read them. Visible to anyone with disk access: email, 2FA configuration, organisation names, attachment sizes, item timestamps. Plan organisation naming accordingly.
Backups to Iceland
Restic to an Anubiz Host Iceland VPS twice daily. Independent repository password stored offline. 14 daily, 8 weekly, 12 monthly. Monthly restore drill. Helsinki to Reykjavik latency is around 50 ms which is fine for the modest snapshot sizes a vault produces.
Related Services
Why Anubiz Host
Ready to get started?
Skip the research. Tell us what you need, and we'll scope it, implement it, and hand it back — fully documented and production-ready.