# The Full Opsec Checklist for an Anonymous Server — 12 Items | NulNet

> Twelve opsec controls for an anonymous server — alias, SSH keys, PTR, backups, XMR renewals — each under an hour, with the matching NulNet guide linked.

Source: https://nulnet.com/full-opsec-checklist-anonymous-server/

[Home](https://nulnet.com/) / The Full Opsec Checklist for an Anonymous Server — 12 Items Guide

# The Full Opsec Checklist for an Anonymous Server — 12 Items

![Padlocks and chain on a dark background](https://nulnet.com/img/photo-nokyc-1.jpg) Twelve opsec controls for an anonymous server — alias, SSH keys, PTR, backups, XMR renewals — each under an hour, with the matching NulNet guide linked.

Published 2026-08-30 · Updated 2026-09-19 · NulNet Editorial

**Short answer** Twelve controls across account, access, network, data and payment: an alias that touches nothing else, keys-only SSH, neutral PTR, restic backups to a Storage SKU, XMR renewals from self-custody — each item sized under an hour.

21 locations · 16 coins · SLA 99.95% · no KYC · [public canary](https://nulnet.com/warrant-canary/)

VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.

[Launch now](https://nulnet.com/deploy/?kind=vps&plan=business/) NulNet: VPS from $3/mo and dedicated from $30.80/mo annual. The map spans twenty-one locations — Reykjavik (Iceland) and Zurich (Switzerland) among them, plus Singapore, Dubai, Cape Town and fourteen others. Signup is email plus a 12-character password, or token-only. No KYC. Checkout is crypto-only across BTC, XMR, ETH, BNB, SOL, LTC, TRX, XRP, DOGE, DASH, ADA, GRAM (TON), and USDT (TRC-20/ERC-20/BEP-20/SPL). No payload or guest traffic logs; connection metadata ≤24h. DDoS included. One SKN company, one crypto checkout. Deploy at https://nulnet.com/deploy/.

## The checklist

- **Dedicated email alias** for the hosting account — used nowhere else.
- **Monero payments** from self-custody; never exchange-withdrawals straight to invoices.
- **SSH keys only**; password auth off; named sudo user, not root.
- **Default-deny firewall**: 22 (moved), 80/443, service ports only.
- **fail2ban** + moved SSH port: log noise drops an order of magnitude.
- **Unattended security upgrades** on the base OS.
- **2FA on the hosting panel** — the panel is attack surface too.
- **Panel over Tor/VPN** when local observers figure in your threat model.
- **Neutral PTR/DNS**: no names, no patterns in record labels.
- **LUKS container** for data at rest (see [the encryption guide](https://nulnet.com/guides/encrypted-vps-full-disk-encryption/)).
- **Off-box encrypted backups** — Restic/Borg to a Storage VPS.
- **Monthly review**: canary check, DNS audit, credential rotation.

## The matrix of failures

| Skip this item | Typical failure |
|---|---|
| #1 email | One breach links every account |
| #2 payments | Public BTC trail to your exchange |
| #3/#5 access | Credential stuffing in days |
| #9 DNS/PTR | Historical records name you forever |
| #11 backups | Ransom or deletion ends the project |

## Where each item lives

On the hosting side, NulNet already supplies: no documents, crypto-only billing, editable PTR, no traffic logs (≤24 h connection metadata). The remaining eight items belong to you — each one links to a guide on this site.

## The full checklist — purchase through month one

- Dedicated privacy email; unique password; 2FA enabled.
- Checkout through Tor or VPN when local observers matter.
- Privacy flag (IS/CH) unless the latency model dictates otherwise.
- Pay XMR from self-custody; exact amount; one transaction.
- SSH keys only; passwords disabled; firewall default-deny.
- Neutral PTR; privacy DNS or none.
- Unattended upgrades; snapshot before risky changes.
- Encrypted offsite backups; prove a restore.
- Admin device habits kept apart from daily browsing.
- Re-read the limits page; check the warrant canary monthly. Ranger ($12.50) in Zurich is the default build with room to split services; Sentry serves when the checklist is followed ruthlessly on a single service. Ticking a list once is not opsec — schedules and renewals are where people slip.

Print the list or keep it in an encrypted note. Blog posts skimmed once will not rescue you at renewal time.

Month-two additions: verify a backup restore into a second location, rotate SSH keys if any laptop left your control, confirm 2FA recovery codes still exist offline, and re-read the limits page once comfort sets in — comfort is when leaks creep in. Ranger in Zurich at $12.50 remains the balanced default. When the checklist feels long, that is the price of private infrastructure; no shorter honest version exists.

Operational footnote: renewals and restores are where checklists die. Hold Ranger in Zurich ($12.50) as the default, XMR for payments, Tor or VPN to the panel, and a tested backup. Re-read limits whenever safety starts feeling assured. Private infrastructure is a practice, not a purchase.

Final note: checklists expire at renewal and restore time. Ranger $12.50 Zurich, XMR, Tor or VPN to the panel, tested backups, quarterly drills, the limits page reread when comfortable. Private infrastructure is practice. No shorter honest list exists.

Store 2FA recovery offline. Name servers generically inside password managers. If the alias provider itself dies, treat the panel as burned and migrate accounts. Boredom is the skill.

## Checklist arrogance

High-risk nation-state models demand specialist advice beyond any VPS article. This checklist is a solid baseline for lawful private infrastructure — not a costume.

## Month-two controls after the honeymoon ends

Past the first renewals: restore a snapshot into a second flag, rotate SSH keys whenever a laptop left your control, verify 2FA recovery still exists offline, and re-read the limits page while comfort persists. Ranger ($12.50) in Zurich stays the balanced default; XMR for payments; Tor or VPN to the panel. Checklists fail at renewal and restore - calendar those drills or the day-one work evaporates.

## Month-two proofs, not merely day-one ticks

Once the twelve items read green, prove them again: restore a backup into a second datacenter, rotate panel 2FA, verify the canary date, and re-scan PTR for name leaks. Ranger ($12.50) in Zurich is the usual checklist home; Sentry serves a ruthless single-service operator. Schedules beat blog posts skimmed once.

## Recommended setup

**Plan:** Ranger — 4 vCPU/8 GB with room for the LUKS container and backup tooling, $12.50/mo. **Location:** [Zurich](https://nulnet.com/locations/switzerland/). Pair with the [opsec guide](https://nulnet.com/anonymous-vps-opsec-guide/) and its [honest limits](https://nulnet.com/limits-of-no-kyc-vps-anonymity/).

Opsec-ready VPS from $12.50/mo in Zurich.

[Launch now](https://nulnet.com/deploy/?kind=vps&plan=business/)

## More rankings and guides

- [Anonymous VPS opsec guide](https://nulnet.com/anonymous-vps-opsec-guide/)
- [Limits of no-KYC anonymity](https://nulnet.com/limits-of-no-kyc-vps-anonymity/)
- [How to buy an anonymous VPS](https://nulnet.com/how-to-buy-anonymous-vps-2026/)
- [How to pay a VPS with Monero](https://nulnet.com/how-to-pay-vps-with-monero-complete-guide/)
- [Best privacy jurisdictions 2026](https://nulnet.com/best-privacy-jurisdictions-2026/)
- [VPS for a privacy tools stack](https://nulnet.com/vps-for-privacy-tools-stack/)
Is 12 items overkill? Every item takes under an hour once; recovering from even one failure costs more. Pick by threat model — but items 1–3 are non-negotiable.

Does the host do any of this for me? We hold no documents, log no traffic and give PTR control. Access, DNS and backups stay yours by design — that is the privacy model.

Best backup target? A Storage SKU on the same rails: restic over SSH into 1 TB NVMe from $24/mo annual-eff, kept in a second location away from the app server.

Does this checklist cover high-risk threats? It is a solid baseline. Nation-state models call for specialist advice beyond a VPS article.

Monthly or annual billing? Monthly trims large single-payment correlation; annual trims invoice count - choose deliberately.

## Primary sources

- [FATF: virtual assets](https://www.fatf-gafi.org/en/topics/virtual-assets.html)

## Related guides

- [Minimum-data no-KYC checkout](https://nulnet.com/guides/anonymous-vps-crypto-no-kyc/)
- [Buy a VPS with crypto](https://nulnet.com/buy-vps-with-crypto/)
- [No-KYC VPS: requirements and limits](https://nulnet.com/no-kyc-vps/)
- [Pay with Monero](https://nulnet.com/monero-vps/)
- [Offshore VPS](https://nulnet.com/offshore-vps/)
- [VPS vs dedicated bare-metal](https://nulnet.com/guides/vps-vs-dedicated/)
- [Best no-KYC VPS 2026](https://nulnet.com/best-no-kyc-vps-2026/)
- [FAQ: crypto VPS](https://nulnet.com/guides/faq-crypto-vps/)

## Checkout facts

- **Price** VPS from $3/mo. Dedicated from $30.80/mo.
- **Identity** No KYC. Token-only (no email) or email plus a 12-character password. No passport, phone, or card.
- **Payment** Sixteen ways to settle, none of them a card: XMR and BTC lead, ETH, SOL, LTC, BNB and TRX follow, then XRP, DOGE, DASH and ADA, GRAM (TON) for Telegram-adjacent rails, and USDT on four networks — TRC-20, ERC-20, BEP-20, SPL. Live-rate invoice.
- **Logs** No payload / no guest traffic logs. Billing and panel actions retained. Connection metadata ≤24h.
- **Platform** KVM on ECC and local NVMe. DDoS filtering included. Facilities in 21 cities across four continents — the locations table lists each one's tier, uplink and governing law. Need Iceland or Switzerland plus no KYC? Those two carry a published premium (+20% / +35%); every other flag stays at base list. Pay BTC, USDT, XMR, BNB, XRP, GRAM (TON) or 10 more. Open deploy to pick a plan.

## Ready to launch?

Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.

[Launch now](https://nulnet.com/deploy/?kind=vps&plan=business/)[Dedicated](https://nulnet.com/dedicated/)
