Case file · Email
Riseup
A no-KYC, invite-based activist mail collective that moved to encrypted storage after being served two sealed FBI warrants under a gag order in 2016 - which it complied with rather than face contempt, and its warrant canary lapsed. Mission-trusted, but US jurisdiction is the structural weakness.
The systematized overview
The bureau vs the internet.
6.9/10 · No identity required
Riseup is a mission-driven activist tech collective offering no-KYC, invite-based email, and after a 2016 incident it moved to encrypted storage so it can no longer hand over readable stored mail. That incident is the point: it was served two sealed FBI warrants under a gag order, complied rather than face contempt, and its warrant canary lapsed. The service is genuinely no-KYC and widely trusted in its community, but its US jurisdiction - and the demonstrated reach of a gagged US warrant - is the structural risk.
3 recurring praises · 2 recurring gripes
Most praised: genuinely no-kyc and mission-trusted. Most cited downside: us jurisdiction and gagged-warrant compliance.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Jurisdiction, sign-up & encryption.
- Jurisdiction
- Riseup Networks, Seattle, USA
- Sign-up needs
- Invite-based; no personal information
- KYC trigger
- None at signup; gagged US federal warrants can compel disclosure
- Encryption
- Encrypted personal storage since 2017; open-source stack
- Provider access
- Cannot hand over readable stored mail post-2017; metadata subject to US orders
- Anon. payment
- Free; donation-funded (crypto donations accepted)
- Logging
- Minimized by policy
- Open source
- Yes
- Audited
- Community-trusted; no formal public audit
- Custom domain
- No (riseup.net addresses)
- Free tier
- Yes (free, invite-based)
- Since
- 1999
The full read
Our analysis, in plain words.
Riseup is not a commercial provider but a long-running activist tech collective, and it is genuinely no-KYC: accounts require no personal information and are invite-based to manage abuse rather than to identify anyone. It is deeply trusted in the communities it serves, runs an open-source stack, and after 2016 moved to encrypted personal storage so it can no longer hand over readable stored mail.
The reason 2016 matters is that it is the clearest documented example of the US-jurisdiction risk. Riseup was served two sealed FBI warrants accompanied by a gag order, and it complied - the alternative being contempt of court, which could mean jail for staff or the end of the organization. It could not say so directly; instead its warrant canary lapsed in November 2016, and the situation was confirmed in February 2017. Riseup says its servers were not seized, and its subsequent move to encrypted storage was a direct response.
That leaves Riseup mission-trusted but structurally exposed in a way the German providers are not. A gagged US warrant is powerful precisely because the provider cannot warn you and cannot easily refuse. Encrypted storage limits the damage to metadata and future plaintext-path mail, which is why Riseup still scores respectably - but anyone whose threat model includes a US federal order should weigh jurisdiction heavily and prefer a strongly encrypted mailbox based elsewhere.
The score, broken down
How the 6.9 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
72 × 50% = 3.6 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
72 × 30% = 2.2 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
55 × 20% = 1.1 of 10
Weighted total 6.9 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“Riseup received two sealed warrants accompanied by gag orders in 2016; it complied to avoid being held in contempt (which could have meant jail for staff or termination of the organization), and its warrant canary was allowed to lapse.”
What it meansThis is the US-jurisdiction risk made concrete. A gagged federal warrant legally forbids the provider from telling you it happened, and refusing risks contempt - jail or the end of the organization. Riseup complied and could only signal it obliquely by letting its warrant canary lapse. It has since encrypted stored mail so future warrants get less, but the episode shows that even a trusted, mission-aligned US provider can be compelled, silently, to cooperate.
Read the source →Riseup asks for no personal information; accounts are invite-based to control abuse, not to identify you, so it is genuinely no-KYC. The privacy limit is jurisdictional: as a US provider it can be served gagged federal warrants and must comply. It has minimized what it can hand over by encrypting stored mail. We rate it KYC level 1.
Policy review — point by point
-
Complied with gagged FBI warrants
Two sealed 2016 warrants with a gag order were complied with; the warrant canary lapsed as the only signal. ↗
-
Encrypted storage since 2017
Riseup encrypted personal storage after the warrants so it can no longer hand over readable stored mail. ↗
-
No-KYC, open source
No personal information at signup; runs an open-source stack; transparent after the fact. ↗
Riseup is based in the United States, which allows gagged federal warrants (National Security Letters and sealed orders) that legally bar the recipient from disclosing them. Riseup’s 2016 experience is the documented proof of that reach; its move to encrypted storage is the mitigation. US jurisdiction is the single biggest factor in its score. Its canary statement and press coverage are the sources.
We keep watching
Incident & policy timeline.
- 2016-2017
Two sealed FBI warrants + gag order; canary lapses
Riseup was served two sealed FBI warrants under a gag order (targets described as a DDoS-extortion contact and a ransomware-extortion account) and complied to avoid contempt. Its warrant canary lapsed in November 2016 and the situation was disclosed in February 2017. Riseup stated its servers were not seized.
source ↗ - 2017
Moved to encrypted storage
Following the warrants, Riseup rolled out encrypted personal storage so that it can no longer hand over readable stored mail in response to future orders.
source ↗
The verdict
Where it stands.
Strengths
- Genuinely no-KYC (no personal info; invite-based)
- Encrypted storage since 2017 - cannot hand over readable stored mail
- Long-running, mission-driven, open-source stack
- Transparent after the fact about the warrants and canary
Trade-offs
- US jurisdiction exposes it to gagged federal warrants
- Complied with two sealed FBI warrants in 2016
- Invite-only signup limits access
- Donation-funded (sustainability depends on community)
Across the internet
What reviewers report.
Consistently praised
- Genuinely no-KYC and mission-trusted
- Encrypted storage after 2016
- Transparent about the warrants once able
Recurring complaints
- US jurisdiction and gagged-warrant compliance
- Invite-only; donation-dependent
Riseup is highly trusted within activist and privacy communities for its mission and transparency, while the same communities cite its US jurisdiction and the 2016 warrants as the reason it is not a fit for threat models involving US legal orders. Synthesized from Riseup’s canary statement and press coverage.
Keep exploring
Related lists & categories.
Ask the bureau
Riseup, common questions.
Is Riseup no-KYC?
Yes. Riseup requires no personal information; accounts are invite-based to manage abuse rather than to identify you. We rate it KYC level 1 - genuinely identity-free, if you can get an invite.
Did Riseup give data to the FBI?
Yes, under legal compulsion. In 2016 it was served two sealed federal warrants with a gag order and complied to avoid contempt, signalling this obliquely by letting its warrant canary lapse (disclosed in 2017). It has since encrypted stored mail so future orders yield less. This is the clearest example of the US-jurisdiction risk for private email.
Is Riseup safe to use?
For its intended community, it is trusted and genuinely privacy-minded, and encrypted storage now limits what it can disclose. But be clear-eyed about jurisdiction: as a US provider it can be served gagged warrants and must comply. For content that must resist a US legal order, an encrypted mailbox in a stronger jurisdiction is a better fit.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.