Tor v3 hidden services use 56-character onion addresses derived from an Ed25519 public key. The address is self-authenticating, end-to-end encrypted between client and service, and never advertises a clearnet IP. The recommended deployment pattern for high-sensitivity services is onion-only: the VPS firewall drops all inbound clearnet traffic, the web server binds only to the loopback interface, and the tor daemon is the single process that talks to the outside world. This kills the most common deanonymization vector, which is a misconfigured web server leaking its public IP through default error pages, server-status endpoints or upstream redirects.
The HiddenServiceDir lives on the VPS filesystem and contains the secret key that defines the onion address. Back this directory up to an offline encrypted volume; if it is lost the onion address is gone permanently. If it is compromised, anyone with the secret key can impersonate the service. Set the file permissions to 0700 owned by the tor user, and avoid keeping copies on any device that is not under your direct physical control.
AnubizHost provisions onion-capable VPS plans with the tor package preinstalled on request. Operators typically deploy a minimal nginx or caddy on 127.0.0.1, point the HiddenServicePort 80 directive at it, and start serving traffic within ten minutes of provisioning. There is no DNS step, no certificate authority involvement and no clearnet exposure required at any point in the deployment.