Evidence and risk■Verified evidence/△CautionMaterial claims checked against current sources.; those sources show trade-offs worth reading.
Last reviewedReviewed 5 Sep 2026KYC checked 5 Sep 2026 · unknown jurisdiction · Source → official siteHow to cite this pageSource coverageVerified evidenceRecorded riskCaution
Evidence and facts
Evidence and facts
CUNICULA SCORE 4.0
59/100△Limited evidencePrivacy 21/25 · Control 7/20 · Transparency 8/20 · Security 17/25 · Accountability 6/10 · Cap 79 · Method
JURISDICTIONUnknown
CAUTIONCryptostorm says VPN nodes do not retain per-session activity logs, but its website logs IP, user agent, referrer, request and time for up to two weeks. Applicable payment flows retain email, delivered token and a processor transaction ID; XMR and NOWPayments do not request email. These are operator claims, not an independent audit.
AUDITED BYNo audit listed
OPERATOR DATAUnknown
SOURCE COVERAGE
■Verified evidenceTHIRD-PARTY REPORTED1/5Reviewed 5 Sep 2026 · Source → official site
LAST CHECKED2026-08-27
LAST UPDATED2026-09-05
Specs
DOCUMENT CHECKNone recorded
IDENTITY EXPOSURELevel 0/4
KYC TRIGGERSNo account KYC for token use; XMR and NOWPayments options avoid email according to official privacy policy. Card/CCBill paths retain payment processor transaction IDs.
FEATURESToken-based, No accounts, No email for XMR/NOWPayments, Tor and I2P access, OpenVPN, WireGuard, Multihop, Open-source tooling
TORYes
REGIONSGlobal availability
Review analysis, source material, related services, and history
Analysis
OVERVIEW
Token-based access with no accounts at all: a token bought with Monero carries no email or identity, and the service publishes Tor and I2P access paths.
LIMITS
Operator opacity is the recorded warning: no verified legal entity, and the privacy policy itself states web logs persist up to two weeks. The design is strong; the accountability evidence is thin.
USEFUL FOR
Users who weight account-less architecture above operator transparency and accept that trade knowingly.
No identity verification is recorded for typical use. No account KYC for token use; XMR and NOWPayments options avoid email according to official privacy policy. Card/CCBill paths retain payment processor transaction IDs.
Which payment methods are accepted?
Please check the provider site for accepted payment methods.
Where is it available?
Recorded availability: GLOBAL.
Is the operator based in a Five Eyes country?
The jurisdiction is not publicly confirmed. Check the provider site for incorporation details.
How are identity, operator, and evidence fields reported?
Identity exposure is level 0 of 4. Hosted operator data has not been established. Jurisdiction is shown as context, not a safety verdict. Source coverage is verified evidence, last reviewed 2026-09-05, and recorded risk is caution.
No changes to the documents we watch since we started checking on 9 Aug 2026. Last checked 9 Aug 2026.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.
Service history
Latest meaningful changes to the facts shown on this provider page.
Review overdue providers against current sources
Fee, KYC last checked, Last reviewed, Privacy warning, and 2 more
Apply full-service rereview and score 4.0
Features, Fee, Recorded risk, Score assessment
Corporate registry information updated
Corporate
Full service history
updated
Review overdue providers against current sources
Fee
$1.86/week; $6/month; $52/year; $94/two years → $1.86/week; $6/month; $16/three months; $28/six months; $52/year; $94/two years; simultaneous-device limits vary by duration.
KYC last checked
2026-06-22 → 2026-09-05
Last reviewed
2026-06-22 → 2026-09-05
Privacy warning
Official privacy policy says web logs are retained up to two weeks and that cryptostorm has no active EU business entity. Existing founder/operator opacity warning remains relevant. → Cryptostorm says VPN nodes do not retain per-session activity logs, but its website logs IP, user agent, referrer, request and time for up to two weeks. Applicable payment flows retain email, delivered token and a processor transaction ID; XMR and NOWPayments do not request email. These are operator claims, not an independent audit.
not set → Outcome: HOLD; Checked at: 2026-08-27; Inputs: Operator data exposure: limited; Control model: hosted-account; Source model: partial; Audit: Score eligible: no; Reason: No current independent audit citation/date/scope.
Token-based, No accounts, No email, Tor exit, Open-source → Token-based, No accounts, No email for XMR/NOWPayments, Tor and I2P access, OpenVPN, WireGuard, Multihop, Open-source tooling
Fee
not set → $1.86/week; $6/month; $52/year; $94/two years
Recorded risk
standard → caution
Score assessment
not set → Operator data exposure: moderate; Control model: hosted-account; Source model: open
not set → Entity type: company; Repository url: https://github.com/cryptostorm; Legal entity: Cryptostorm LLC; Incorporation jurisdiction: Delaware, United States; Registered address: Dover, DE, US
Token-based VPN with no account/email required for XMR purchase path, Tor/I2P site access, bare-metal servers, no-logs claim, and server/client-side multihop options. → Token-based VPN with no account or email on the XMR purchase path, plus Tor and I2P site access and multihop.
Token-based VPN — no accounts, no email, no identity. Buy a token, activate, connect. Supports Tor exit nodes. Open-source client. → Token-based VPN with no account/email required for XMR purchase path, Tor/I2P site access, bare-metal servers, no-logs claim, and server/client-side multihop options.
Jurisdiction
IS → not set
Jurisdiction confidence
inferred → unknown
KYC last checked
2026-03-28 → 2026-06-22
Kyc note
not set → No account KYC for token use; XMR and NOWPayments options avoid email according to official privacy policy. Card/CCBill paths retain payment processor transaction IDs.
Last reviewed
2026-03-28 → 2026-06-22
Privacy warning
Founder Douglas Spink has a controversial personal history. Current operators are pseudonymous. → Official privacy policy says web logs are retained up to two weeks and that cryptostorm has no active EU business entity. Existing founder/operator opacity warning remains relevant.
Source reviewed
older source, not independently verified → official site