noKYCme

Case file · Email

Riseup

A no-KYC, invite-based activist mail collective that moved to encrypted storage after being served two sealed FBI warrants under a gag order in 2016 - which it complied with rather than face contempt, and its warrant canary lapsed. Mission-trusted, but US jurisdiction is the structural weakness.

No-KYC · Level 1
Based
Riseup Networks, Seattle, USA
Price
Free, donation-funded; invite-based signup
Reviewed
2026-07-21
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

6.9/10 · No identity required

Riseup is a mission-driven activist tech collective offering no-KYC, invite-based email, and after a 2016 incident it moved to encrypted storage so it can no longer hand over readable stored mail. That incident is the point: it was served two sealed FBI warrants under a gag order, complied rather than face contempt, and its warrant canary lapsed. The service is genuinely no-KYC and widely trusted in its community, but its US jurisdiction - and the demonstrated reach of a gagged US warrant - is the structural risk.

What the internet says

3 recurring praises · 2 recurring gripes

Most praised: genuinely no-kyc and mission-trusted. Most cited downside: us jurisdiction and gagged-warrant compliance.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Jurisdiction, sign-up & encryption.

Jurisdiction
Riseup Networks, Seattle, USA
Sign-up needs
Invite-based; no personal information
KYC trigger
None at signup; gagged US federal warrants can compel disclosure
Encryption
Encrypted personal storage since 2017; open-source stack
Provider access
Cannot hand over readable stored mail post-2017; metadata subject to US orders
Anon. payment
Free; donation-funded (crypto donations accepted)
Logging
Minimized by policy
Open source
Yes
Audited
Community-trusted; no formal public audit
Custom domain
No (riseup.net addresses)
Free tier
Yes (free, invite-based)
Since
1999

The full read

Our analysis, in plain words.

Riseup is not a commercial provider but a long-running activist tech collective, and it is genuinely no-KYC: accounts require no personal information and are invite-based to manage abuse rather than to identify anyone. It is deeply trusted in the communities it serves, runs an open-source stack, and after 2016 moved to encrypted personal storage so it can no longer hand over readable stored mail.

The reason 2016 matters is that it is the clearest documented example of the US-jurisdiction risk. Riseup was served two sealed FBI warrants accompanied by a gag order, and it complied - the alternative being contempt of court, which could mean jail for staff or the end of the organization. It could not say so directly; instead its warrant canary lapsed in November 2016, and the situation was confirmed in February 2017. Riseup says its servers were not seized, and its subsequent move to encrypted storage was a direct response.

That leaves Riseup mission-trusted but structurally exposed in a way the German providers are not. A gagged US warrant is powerful precisely because the provider cannot warn you and cannot easily refuse. Encrypted storage limits the damage to metadata and future plaintext-path mail, which is why Riseup still scores respectably - but anyone whose threat model includes a US federal order should weigh jurisdiction heavily and prefer a strongly encrypted mailbox based elsewhere.


The score, broken down

How the 6.9 is built.

Privacy 3.6Trust 2.2Reliability 1.1 Headroom 3.1

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

72/100

72 × 50% = 3.6 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

72/100

72 × 30% = 2.2 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

55/100

55 × 20% = 1.1 of 10

Weighted total 6.9 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +6No-KYC, invite-based signup; no personal information required
  • +4Moved to encrypted storage (post-2016) - cannot hand over readable stored mail
  • +-5US jurisdiction exposes it to gagged federal warrants

Trust

  • +5Long-running, mission-driven collective; runs an open-source stack
  • +3Transparent after the fact: disclosed the canary lapse and the warrants
  • +-42016-17 complied with two sealed FBI warrants under a gag order

The fine print, read for you

The clause they bury.

Verbatim — the trapdoor
“Riseup received two sealed warrants accompanied by gag orders in 2016; it complied to avoid being held in contempt (which could have meant jail for staff or termination of the organization), and its warrant canary was allowed to lapse.”

What it meansThis is the US-jurisdiction risk made concrete. A gagged federal warrant legally forbids the provider from telling you it happened, and refusing risks contempt - jail or the end of the organization. Riseup complied and could only signal it obliquely by letting its warrant canary lapse. It has since encrypted stored mail so future warrants get less, but the episode shows that even a trusted, mission-aligned US provider can be compelled, silently, to cooperate.

Read the source →
KYC trigger threshold

Riseup asks for no personal information; accounts are invite-based to control abuse, not to identify you, so it is genuinely no-KYC. The privacy limit is jurisdictional: as a US provider it can be served gagged federal warrants and must comply. It has minimized what it can hand over by encrypting stored mail. We rate it KYC level 1.

Policy review — point by point

  • Complied with gagged FBI warrants

    Two sealed 2016 warrants with a gag order were complied with; the warrant canary lapsed as the only signal.

  • Encrypted storage since 2017

    Riseup encrypted personal storage after the warrants so it can no longer hand over readable stored mail.

  • No-KYC, open source

    No personal information at signup; runs an open-source stack; transparent after the fact.

Jurisdiction analysis

Riseup is based in the United States, which allows gagged federal warrants (National Security Letters and sealed orders) that legally bar the recipient from disclosing them. Riseup’s 2016 experience is the documented proof of that reach; its move to encrypted storage is the mitigation. US jurisdiction is the single biggest factor in its score. Its canary statement and press coverage are the sources.


We keep watching

Incident & policy timeline.

  1. 2016-2017

    Two sealed FBI warrants + gag order; canary lapses

    Riseup was served two sealed FBI warrants under a gag order (targets described as a DDoS-extortion contact and a ransomware-extortion account) and complied to avoid contempt. Its warrant canary lapsed in November 2016 and the situation was disclosed in February 2017. Riseup stated its servers were not seized.

    source ↗
  2. 2017

    Moved to encrypted storage

    Following the warrants, Riseup rolled out encrypted personal storage so that it can no longer hand over readable stored mail in response to future orders.

    source ↗

The verdict

Where it stands.

Strengths

  • Genuinely no-KYC (no personal info; invite-based)
  • Encrypted storage since 2017 - cannot hand over readable stored mail
  • Long-running, mission-driven, open-source stack
  • Transparent after the fact about the warrants and canary

Trade-offs

  • US jurisdiction exposes it to gagged federal warrants
  • Complied with two sealed FBI warrants in 2016
  • Invite-only signup limits access
  • Donation-funded (sustainability depends on community)
Visit Riseup No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Genuinely no-KYC and mission-trusted
  • Encrypted storage after 2016
  • Transparent about the warrants once able

Recurring complaints

  • US jurisdiction and gagged-warrant compliance
  • Invite-only; donation-dependent

Riseup is highly trusted within activist and privacy communities for its mission and transparency, while the same communities cite its US jurisdiction and the 2016 warrants as the reason it is not a fit for threat models involving US legal orders. Synthesized from Riseup’s canary statement and press coverage.


Keep exploring

Related lists & categories.


Ask the bureau

Riseup, common questions.

Is Riseup no-KYC?

Yes. Riseup requires no personal information; accounts are invite-based to manage abuse rather than to identify you. We rate it KYC level 1 - genuinely identity-free, if you can get an invite.

Did Riseup give data to the FBI?

Yes, under legal compulsion. In 2016 it was served two sealed federal warrants with a gag order and complied to avoid contempt, signalling this obliquely by letting its warrant canary lapse (disclosed in 2017). It has since encrypted stored mail so future orders yield less. This is the clearest example of the US-jurisdiction risk for private email.

Is Riseup safe to use?

For its intended community, it is trusted and genuinely privacy-minded, and encrypted storage now limits what it can disclose. But be clear-eyed about jurisdiction: as a US provider it can be served gagged warrants and must comply. For content that must resist a US legal order, an encrypted mailbox in a stronger jurisdiction is a better fit.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.