Warrant canary
If we were served a secret order for user data, we could be forbidden from telling you. So we publish the opposite instead: a signed statement that no such order has arrived, renewed every month. Watch for it to stop.
Current statement — 27 July 2026
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Pangea VPN — Warrant Canary
Statement date: 2026-07-27
Signed with OpenPGP key 84D2 3B58 DF07 3D4F EDEF E738 9141 048A BB2E FC34
As of the date above, Pangea VPN:
1. has received no warrants, subpoenas, court orders, or other legal
demands for user data;
2. has received no National Security Letters or equivalent;
3. is subject to no gag order or non-disclosure obligation arising from
any such demand;
4. has received no notice under the UK Investigatory Powers Act 2016,
including technical capability notices and national security notices,
and no notice under RIPA 2000 s.49 requiring disclosure of keys;
5. has received no demand to modify its systems to weaken security, to
introduce a backdoor, or to begin logging user activity;
6. has suffered no search or seizure of its servers, and is not aware of
any unauthorised third-party access to its infrastructure;
7. retains sole control of the private key used to sign this statement.
This statement is re-signed and re-published monthly. If it has not been
updated within 45 days of the statement date above, or if any clause has been
removed, treat the omission as significant.
Proof of freshness:
Monero block 3727002, 2026-07-27 10:11:00 UTC
374238a604450472d89e394f39dfb8116617b827b2a519f999babd91a64fd56e
Next scheduled statement: on or before 2026-08-31
-----BEGIN PGP SIGNATURE-----
iJEEARYKADkWIQSE0jtY3wc9T+3v5ziRQQSKuy78NAUCamcywBsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDEACgkQkUEEirsu/DRmkgEAnYymUitUFL8qMOf6yvRl
WpbGkhgrfD9Ky7ABSjSYfswBAI0Bhno/3c/gkXQlClhdiCR841O3j2GfG8E0TDTy
yGwP
=/jco
-----END PGP SIGNATURE-----
How to check it yourself
Do not take our word for any of this. Copy the block above, save it as canary.asc, and verify the signature against our key:
gpg --keyserver keys.openpgp.org --recv-keys 84D23B58DF073D4FEDEFE7389141048ABB2EFC34 gpg --verify canary.asc
Signing key fingerprint: 84D2 3B58 DF07 3D4F EDEF E738 9141 048A BB2E FC34
Fetch the key from the keyserver rather than from this site — if we were ever compelled to serve you a doctored page, we could serve you a doctored key alongside it, and a signature that only checks out against a key you got from us proves nothing.
What would tell you something
- — The statement stops being renewed. It is republished monthly; if more than 45 days pass without an update, that is deliberate on our part or forced on us, and either way it means something.
- — A clause disappears from a new statement while the rest remain.
- — The signature stops verifying, or the signing key changes without explanation.
Past statements are never edited. If we got something wrong, a later statement corrects it and the original stays up.
Its limits, honestly
The argument that we can be gagged but not compelled to keep publishing a falsehood comes from US law. We are a UK company, no UK court has tested this, and it may not hold. A canary is a signal to you, not a shield against a government — what actually protects you is that your keys are generated on your device and we keep no traffic logs, so there is little for an order to reach.
