en
Offshore Hosting for a SecureDrop Whistleblower Instance
You are the technical lead at a newsroom, NGO, or research organization that needs a Tor-only intake channel for sensitive documents. You have read the Freedom of the Press Foundation hardening guide. You understand that SecureDrop is a substantial commitment with dedicated hardware in your office for reviewer airgap. You need an offshore VPS for the public-facing source interface. This page is the Anubiz substrate guide for that VPS specifically.
Need this done for your project?
We implement, you ship. Async, documented, done in days.
What SecureDrop actually needs at the VPS layer
SecureDrop runs the source-facing Tor hidden service on a hardened Ubuntu server. Hardware requirements are modest: 2 vCPU, 4 GB RAM, 40 GB disk. The catch is the configuration constraints. SecureDrop expects a clean machine with no other services running, no exposed clearnet ports, and a specific kernel grsec configuration on the dedicated hardware path. On a VPS, the kernel hardening side is limited - you cannot install grsec on a virtualized kernel - so the VPS path is appropriate for SecureDrop staging and small NGO deployments, not for high-profile newsrooms (which should follow the dedicated-hardware path).
Stack and isolation
On an Anubiz VPS, install Ubuntu Server LTS, install Tor from torproject.org, and follow the SecureDrop install playbook. Do not co-host anything else on this VPS. Do not install Cockpit, do not install a web admin panel, do not enable SSH password authentication, do not open any clearnet port other than what the install requires. The journalist interface should be on a separate VPS or on dedicated hardware in your office. The reviewer workstations must be airgapped Tails machines. None of that workstation security is the VPS's job.
Anubiz binding and payment
Anubiz offshore VPS plans start at $17.90/mo. Iceland is the recommended jurisdiction for SecureDrop - the country has strong press shield laws. Romania is the alternative. Both refuse to act on informal foreign requests. Crypto payment, no KYC. Use a dedicated email for the hosting account, not linked to any staff identity. Internal links: /en/securedrop-hosting (parent), /en/anonymous-vps, /en/iceland-vps.
Limits of this configuration
A VPS-based SecureDrop is not a substitute for the dedicated-hardware deployment that FPF recommends for high-risk newsrooms. We are honest about this. If your sources include people whose lives depend on operational security being perfect - intelligence community whistleblowers, organized-crime witnesses - follow the dedicated-hardware path. For an NGO investigating corporate fraud or a regional newsroom investigating local corruption, the VPS path is reasonable.
Related Services
Why Anubiz Host
100% async — no calls, no meetings
Delivered in days, not weeks
Full documentation included
Production-grade from day one
Security-first approach
Post-delivery support included
Ready to get started?
Skip the research. Tell us what you need, and we'll scope it, implement it, and hand it back — fully documented and production-ready.