Skip to content
qProxy
qProxy

Warrant Canary

Last signed: August 5, 2026 · renewed every 120 days

What this page is

A warrant canary is a statement we publish and re-sign on a fixed schedule, saying that nothing has forced us to compromise our users. Because we don't keep logs, we can't hand over data we don't have — this page is our way of making that claim independently checkable, without opening our source code.

Signed statement

The statement below is cryptographically signed with our PGP key, so anyone can verify it was published by us and hasn't been altered.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

qProxy Warrant Canary
Last signed: August 5, 2026
Renewed every 120 days.

As of the date above, qProxy confirms:

1. We have not received any court order, subpoena, warrant, or national-security
   letter compelling us to log, monitor, or hand over user traffic.
2. We have not received any gag order prohibiting us from disclosing a request
   for user data.
3. We have not been compelled to insert any backdoor, master key, or monitoring
   capability into our infrastructure.
4. We have not been served with a demand to weaken or bypass our zero-logs
   architecture for any government or third party.
5. No third party has been granted access to proxy traffic, connection
   metadata, or customer identity beyond what is described in our Privacy
   Policy.

If this statement is more than 120 days old, has disappeared, or any line
above has been quietly altered, treat that as a signal that something is
wrong.
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEhx4svW9F4/4srJuP9EMPgs0Uq1YFAmpzjkIACgkQ9EMPgs0U
q1bdLQ//ahKiPI8XOlQt2BI64ApIR8+d3Ty3qPeCvbtRJcSIkmZ8QpdEyJuHK5BD
fXCIsWJoM1sqI7LF7kI6SdRs1XBWsHGKBlMtKq2yaT3P/KbewMM01Epg/pyqE0z4
R+bq6MuoaWRwE0mVQTAhyj/szC/kZxASSka0AAld47Iu5kYO2hiFvefbv7yZdwnb
uXKj8BQVQr+tTCQgHSbKy/5ycOj3fOYIvie9KPtC7PuIXcMUCGK7O8+bvKjSun8/
98my1dxPGX0AoRLw52Iy8tXxLKMpIHI8B2AbKjAJqZGGD6UPm4aKxE7tdrMuxQKk
7Et2lF5JPBQknyE1r/mbPOK4swho5/fjF5mLdw32fpqKfbHSYm34GUn44JOE2ynP
dfztBSmwu+SWKmddEzBxLguAJUOVQEqsu6AmKHSSNPACHb04G00XB2zcQHtCdpyU
ri1fy1Fm4g7yqIK5vKNj0h74vuAW/j2SJCL7BH3jgWIdFipxDW2o0RQIS50cUD56
PxeDxZ72jDfYhfO5+4Zyg3FSn0j6bB1MZ5/Tcx0oXSSWg2GPIfPnfDKYOJZ4ceeo
Rz7eikGo0ptIowP+5AAQCw/5atx75UpkaEmSUMqkBRevcO4QfRw7sYOSWSMTe9qS
wUH111Ba4p0D0cHWyEH7Vhc9eqv8O9uyXEztbF90Mfiy3YEo/Uw=
=rBhw
-----END PGP SIGNATURE-----

Verify it yourself

Fingerprint of the signing key:

47DF 2CB1 C91D 295D 1C2E 772F 3969 8DC5 69CC C19F

Download the public key, save the signed statement above to a file, then run:

gpg --import qproxy-canary-public.asc
gpg --verify canary-message.asc

How to read it

This statement is renewed every 120 days. If the date above is more than 120 days old, if this page disappears, or if any statement above is quietly removed, treat that as a signal — it may mean we are under a legal order that prevents us from speaking honestly, and we would rather go silent than lie to you.

Why not open source

A warrant canary doesn't require us to publish our codebase to be verifiable — it relies on the legal fact that we can be compelled to act, but (in most jurisdictions) not compelled to lie. A missing or stale canary is itself the signal. We pair this with our zero-logs policy and plan to commission an independent third-party audit of our no-logs infrastructure.