What Is a VPN Warrant Canary (and Can You Trust One)?
A warrant canary is a statement a company publishes and updates routinely to say that it has not received a secret government order — such as a subpoena or a gag order it is legally forbidden to disclose. The idea is indirect: the company can be barred from telling you an order arrived, but it can stop actively telling you one hasn't. If the canary quietly disappears or stops being updated, users are meant to infer the worst. It is a clever workaround, and also a legally untested one, which is exactly why it deserves a careful look rather than blind trust.
What a warrant canary is
In its simplest form, a canary is a dated notice on a company's site reading something like “As of this date, we have received no secret subpoenas, gag orders or warrants.” The company re-publishes it on a schedule — monthly or quarterly. As long as it keeps appearing, the implication is that nothing has arrived. The signal is not in the statement's presence but in its potential absence: a canary that stops being renewed is the message.
Why they exist
Canaries exist because some legal orders come with a gag. In the United States, a National Security Letter can compel a company to hand over certain records and simultaneously forbid it from telling anyone the letter exists. Similar secrecy provisions exist elsewhere. The theory behind a canary is that while the law can force silence about a specific order, it is much harder to compel a company to actively lie by publishing a false “all clear.” Removing a true statement, the argument goes, is not the same as being forced to make a false one.
The famous example that worked
The best-known case of a canary doing its job comes from Riseup, an activist collective that provides email and other services. In 2016, Riseup stopped updating its warrant canary. Observers noticed, and the collective later confirmed it had received two sealed FBI warrants it could not discuss at the time. The vanished canary was the signal, and it was read correctly. Riseup is not a commercial VPN, but the case is the clearest real-world demonstration that the mechanism can function as intended.
Which country a provider sits in shapes what orders it can receive and whether it can talk about them, so canaries and VPN jurisdiction are closely linked. A canary is most relevant where secret, gagged orders are a genuine legal possibility.
Why a canary's legal force is untested
Here is the honest problem: no court has clearly ruled on whether a warrant canary works, so the whole concept rests on an untested legal theory. A government determined to preserve secrecy might argue that pulling a canary is itself a prohibited disclosure, or might compel a company to keep publishing it. There are also practical failure modes — a canary can lapse simply because someone forgot to update it, triggering a false alarm, or a company can word it so narrowly that it covers almost nothing. A canary is a signal, not a guarantee, and it should be read as one.
Treat a warrant canary as a small positive signal, never as proof of anything. Its value is entirely in the vigilance of the people watching it, and its legal standing has never actually been settled in court.
Warrant canary vs transparency report
A transparency report is usually more useful than a canary. Where a canary is a binary “nothing has happened” flag, a transparency report is a periodic, concrete account of how many legal requests a company received and how many it complied with. Because a no-logs provider can honestly report that it received requests and handed over nothing — since it had nothing — a transparency report can demonstrate the policy working in practice, request by request. When a provider publishes both a maintained canary and a detailed transparency report, that is a stronger position than either alone.
How to use canaries when choosing a VPN
Do not choose a VPN on the basis of a canary alone. It is a nice supporting signal, but it sits well below the essentials: an independent audit, RAM-only servers, and a clear no-logs policy. If a provider maintains a canary and a transparency report on top of those, take it as evidence of a privacy-first culture. If a canary is the only thing a provider offers, it is not enough. Start from the fundamentals in our comparison of audited no-logs VPNs and treat the canary as a tie-breaker, not a headline.
How to check a canary properly
If a provider you use maintains a warrant canary, checking it well takes a little more than glancing at the page. First, look at the date: a canary is only meaningful if it is updated on a stated schedule, so a statement that has not been refreshed in a year tells you nothing useful and may simply have been forgotten. Second, read the exact wording, because a narrowly drafted canary — one that covers only a specific type of order, or only certain countries — can technically stay true while important requests slip through the gap it leaves. Third, prefer canaries that are cryptographically signed and timestamped, since a signature makes it much harder for the statement to be forged or quietly altered after the fact. And finally, do not rely on your own memory to notice a canary vanishing; the entire mechanism depends on someone watching, and in practice it is the wider privacy community, not individual users, who catch these changes and raise the alarm. A canary you never look at again protects you exactly as much as no canary at all.
Warrant canaries, answered
What is a VPN warrant canary?
Has a warrant canary ever actually worked?
Is a warrant canary legally reliable?
Is a transparency report better than a canary?
The through-line to everything here: a VPN shifts trust to its provider. See which no-logs claims are actually audited, or read the honest threat model.