Skip to content
  1. Home
  2. Abuse
Abuse and law enforcement

We stop abuse by what it does, not by watching who you are

If traffic from a PryVPN server hit you with spam, scans or attacks, tell us. Our servers already slow down and block that kind of behavior on their own, and a person acts on every report within 72 hours at most. Here is exactly what we do, and what we can't do.

Report abuseFor authorities

  • 24 to 72 hours to act on a report, depending on how serious it is
  • Automatic limits on every server, day and night
  • No activity logs, so no IP-to-person lookups
Automatic, on every server

What our servers stop on their own

These rules run inside each server's kernel, in real time. They look at how much and how fast a connection behaves, never at what it contains or where you browse. The numbers are our defaults; we can make them stricter for a single server.

Abuse ports are closed

Outgoing TCP 25 (email), 23 and 2323 (Telnet), 137–139 and 445 (Windows file sharing), and UDP 19 (chargen), 137–138 (NetBIOS), 1900 (SSDP) and 11211 (memcached). These ports are how spam and worms spread and how amplification attacks start, and ordinary apps don't need them.

Per-client connection limits

Each device can open 150 new connections a second (bursts up to 300) and keep 2,000 open at once. That is far above normal use, and far below what an attack needs.

Scans, brute force and floods

More than 300 different destinations a minute, more than 20 login attempts a minute against SSH, remote desktop or databases, or 20,000 packets a second at one target: each one is a strike.

Throttling and quarantine that expire

A strike slows that connection down for 2 minutes. A second strike quarantines it for 30 minutes. Then the server forgets it: nothing is written down.

Fair sharing

Every server splits its bandwidth evenly between the people using it, so no one can hog it. It needs no record of who anyone is.

Malware and phishing domains blocked

Our DNS always refuses known malware command-and-control and phishing domains, for everyone, even with other blocking switched off in the app.

The life of a strike

Stricter only while it misbehaves. Then it's forgotten.

The server tracks a connection by its address inside our network, never by account or real IP, and keeps it only in memory with a timer. Here's what happens when a device starts scanning the internet.

  1. Limits sit far above everyday use: 150 new connections a second and 2,000 open at once. Streaming, gaming and big downloads never come close.

  2. The device reaches more than 300 different destinations in a minute. The same happens for bursts of login attempts or a flood at one target.

  3. Only 5 new connections a second. What's already open keeps working, so a person on a busy page barely notices. An attack stalls.

  4. A second strike while throttled leaves only web browsing (ports 80 and 443) and our DNS, at 2 new connections a second.

  5. The timer runs out and the kernel drops the entry. No log, no account flag, no history of it having happened.

Only the server's running totals are reported to us, for example "3 connections throttled right now", without saying which.
What we can't do

No logs means no "who was it?"

Each PryVPN server's IP address is shared by many people at the same moment, and we don't record which account or device used it, when, or where their traffic went. So if you ask who used 203.0.113.7 at 14:02, the honest answer is that nobody can tell, including us.

That is the point of a no-logs VPN, and it is also why we put so much into stopping abuse automatically, at the server, before it reaches you.

  • We can act on the server named in your report: tighten its limits, block a port, or take it out of service.
  • We can suspend an account when a report gives us its PryVPN account number.
  • We can tell you which of our servers an IP address belongs to, and what we changed.

What exists about a connection

  • Which server an IP belongs toPublic, and in our records
  • Running totals per serverHow many connections are throttled right now, with no identities
  • Who used an IP at a given timeNever recorded
  • Sites, destinations or DNS queriesNever recorded
  • Your real IP next to your activityNever recorded
See everything we store
Report abuse

Tell us what happened

The more exact the details, the faster we can find the server and act on it.

  1. The PryVPN IP addressThe source address in your logs or email headers.
  2. Date and time, with time zoneFor example 2026-09-23 14:02 UTC.
  3. Port and protocolWhat was targeted, such as TCP 22 or UDP 53.
  4. What you sawA log excerpt helps. Remove personal data about other people.

Prefer email? Write to abuse@pryvpn.com. Automated reports in the usual formats (ARF, X-ARF) are welcome there.

Send your report by email

The report form needs JavaScript, which is off in your browser. Email the details listed here to abuse@pryvpn.com, with "Abuse report" as the subject. A person reads every message.

Response times

What happens after you report

Every report gets a ticket and a deadline based on how serious it is. A person reads each one, matches the IP address to one of our servers and decides what to change. If you left an email, you get an automatic acknowledgment right away (at most one a day per address) and our answer when we act.

  1. Within 24 hours

    Child abuse material and authorities

    Reports of child sexual abuse material, and requests from law enforcement or judicial authorities, go first.

  2. Within 48 hours

    Attacks and network abuse

    Spam, port scanning, brute force, flooding, phishing and malware. Often we tighten that server's limits for 24 hours or block a port.

  3. Within 72 hours

    Everything else

    Copyright notices, fraud, harassment and anything else. We reply with what we did, or why there was nothing we could act on.

For authorities

Point of contact for authorities

This is our single point of contact for authorities of EU member states, the European Commission and the European Board for Digital Services, and for users, under Articles 11 and 12 of the EU Digital Services Act.

PryVPN transmits traffic without originating or changing it, and keeps no activity logs. For any IP address and time, we can confirm whether the address is one of our servers. We can't say who used it. If an order names a PryVPN account number, we can say whether it exists and which device public keys it holds, which is all we store about an account.

We answer every request in writing, and each one is counted in our transparency report.

Subject line
Start with "Authority request"
Languages
English or Spanish
Please include
Your authority and a way to verify it, the legal basis, the IP address, the date and time with time zone, and a deadline if there is one.
Company
[The legal entity and registered address will be added before launch.]
FAQ

Questions about abuse

Using PryVPN yourself?The rules are in our acceptable use policy, and what these limits count is in our privacy policy.
Can you tell me who used a PryVPN IP address at a certain time?

No. Many people share each server's IP address at the same moment, and we don't log which account or device used it, or where their traffic went. There is no record to look up, for you or for anyone else.

Will the person be banned?

We can't single out the person from an IP address and a time, because we don't keep that link. What we can do is act on the server: its automatic limits are already running, and we can apply stricter limits or block a port on that server. When a report includes a PryVPN account number, we can suspend that account.

Do I need to give my email?

No, but without it we can't acknowledge your report or reply. We use it only to handle this report, and erase it a year after the report once it has been dealt with. The automatic acknowledgment never repeats what you wrote, so the form can't be used to send mail to someone else.

Where can I see how many reports you get?

In our transparency report, which counts reports by type and requests from authorities every quarter, including how much user data we handed over: none, because we don't have it.