# 5, 9 & 14 Eyes Explained — Does It Matter for Hosting? | VPSbit

> The 5, 9 and 14 Eyes are intelligence-sharing alliances, not hosting laws. Who sits in each tier, what they do and don't do, how much weight to give the map.

Source: https://vpsbit.io/glossary/fourteen-eyes/

[Home](https://vpsbit.io/) / [Glossary](https://vpsbit.io/glossary/) / The 5, 9 and 14 Eyes, explained Glossary · Jurisdictions

# The 5, 9 and 14 Eyes, explained

![Dark server hall lit by status-LED rows](https://vpsbit.io/img/photo-brand-3.jpg) The 5, 9 and 14 Eyes are intelligence-sharing alliances, not hosting laws. Who sits in each tier, what they do and don't do, how much weight to give the map.

Published 2026-10-06 · Updated 2026-10-06 · VPSbit Editorial

**Short answer** The 5, 9 and 14 Eyes are intelligence-sharing alliances of the US, UK, Canada, Australia, New Zealand and European partners — a real factor when picking a region, but never a substitute for reading the hosting country's actual law.

VPSbit: VPS from $4.80/mo and dedicated from $39.20/mo annual. The map spans twelve locations — Reykjavik (Iceland) and Zurich (Switzerland) among them, plus Tokyo, Singapore, Hong Kong, Taipei and eight others. Signup is email plus a 12-character password, or token-only. No KYC. Checkout is crypto-only across BTC, XMR, ETH, BNB, SOL, LTC, TRX, XRP, DOGE, DASH, ADA, GRAM (TON), and USDT (TRC-20/ERC-20/BEP-20/SPL). No payload or guest traffic logs; connection metadata ≤24h. DDoS included. One SKN company, one crypto checkout. Deploy at https://vpsbit.io/deploy/.

## The definition, precisely

The 5, 9 and 14 Eyes are shorthand for intelligence-sharing alliances descended from the wartime UKUSA signals agreement: an inner circle of five national signals-intelligence agencies that pool collected intelligence by default, plus two wider circles that join specific sharing tiers. The Five Eyes are the United States, the United Kingdom, Canada, Australia and New Zealand. Nine Eyes adds Denmark, France, the Netherlands and Norway. Fourteen Eyes adds Germany, Belgium, Italy, Spain and Sweden.

What the labels are not: hosting regulations, data-protection laws, or treaties any VPS provider signs. They classify how cooperatively a set of countries' intelligence services share what they collect. That is a real fact about the world and worth weighing — but it is one fact, and most of what determines what happens to your server is written in statutes the Eyes map never mentions.

VPS from $4.80* — Core on the annual term (list $6/mo), one invoice for 12 months, no auto-charges. Dedicated with IPMI from $39.20/mo. Crypto invoice, no KYC.

[Launch now](https://vpsbit.io/deploy/?kind=vps&plan=core/)

## Who is in which tier

The tiers are concentric, and the membership list has been stable for years.

| Tier | Members |
|---|---|
| Five Eyes (UKUSA) | United States, United Kingdom, Canada, Australia, New Zealand |
| Nine Eyes (adds) | Denmark, France, Netherlands, Norway |
| Fourteen Eyes (adds) | Germany, Belgium, Italy, Spain, Sweden |
Read the list against other facts and the label's limits show immediately. Germany is a Fourteen Eyes member with some of the strictest constitutional privacy protections anywhere; Switzerland and Iceland sit in no tier at all, yet so do plenty of jurisdictions nobody shortlists for rule-of-law reasons. Membership describes signals sharing between states — nothing in the table tells you the retention law, the data-protection statute or the process a host actually answers in that country.

## How the map got its shape

The inner tier is the oldest: the UKUSA agreement dates to 1946, signed by the United States and the United Kingdom, with Canada, Australia and New Zealand joining over the following decade. The wider tiers are newer labels than they are commitments — "Nine Eyes" and "Fourteen Eyes" entered public vocabulary during the 2000s and around the 2013 disclosures, naming second- and third-party cooperation arrangements that predate their nicknames. The map is therefore a historical artefact as much as a legal one: it grew with alliance politics, not with hosting, and it was never redesigned around data centres, cloud providers or the way evidence crosses borders today.

## What the alliances actually do

The members share signals intelligence collected under national programmes, divide collection areas to reduce duplication, and agree on handling rules for what passes between them. The practical effect that concerns privacy-minded users is jurisdiction arbitrage between allies: intelligence gathered by one member under its domestic rules can inform another whose own rules might have restricted that collection directly. Documented cooperation of that kind is precisely why the map earns its place in hosting decisions at all.

The sharing, though, runs on collected intelligence about targets of interest to states — not on a standing feed of hosting customers. Nothing in the alliance machinery ingests a VPS invoice, and the members are rivals in commerce even as they are allies in signals. Weigh the label as a statement about how easily intelligence moves between five, nine or fourteen capitals, which is a real quantity, and resist letting it stand in for the law of the rack.

Practically, the tiers also grade how much moves in both directions. Second-party relationships exchange bulk intelligence continuously; third-party arrangements are more selective, and partners outside the map sit in looser bilateral arrangements still. The useful translation for a hosting buyer is approximate: inside the inner circle, intelligence travels with the fewest questions asked, and each outer ring adds selectivity. Approximation is all it will ever be — the classifications above these arrangements are higher than anything a glossary can quote.

## What the alliances do not do

They issue no warrants, override no domestic courts and operate no shared tribunal. Reaching data on a specific server still runs through each country's own legal process — subpoenas, court orders, and mutual legal assistance treaties when the target sits elsewhere. A host in any country, inside the map or outside it, answers the lawful process of its own facility first; an alliance membership neither adds a shortcut for foreign requesters nor deletes the domestic safeguards that requester would have faced at home.

The honest limit runs the other way too: oversight of classified programmes is imperfect, history has leaks, and the full depth of cooperation is not public. Treat the Eyes tier as a risk weight on metadata and signals collection — not as proof of surveillance, and not as proof of safety. On the hosting layer specifically, what the alliances demonstrably do not change is the statute that governs the disks, and that statute is what your provider actually operates under.

## How much weight to give it when picking a region

Order the factors by how often they decide anything. First, the law of the facility country: retention rules, data-protection statute and process discipline. Iceland carries no mandatory data retention; Switzerland applies the FADP outside the EU framework; the Netherlands runs full EU GDPR process with the densest peering in Europe. Those differences bite in real requests far more often than alliance membership does, which is why each of our twelve locations publishes its law line at checkout.

Second, your own exposure: if you live under a Five Eyes legal system, moving the server's flag changes little about what follows you personally, and the map says nothing about your own devices. Third, technical reality — encryption at rest and in transit shrinks what any collection tier can read from the box, per [the full-disk-encryption guide](https://vpsbit.io/guides/encrypted-vps-full-disk-encryption/). Fourth, the boring economics of latency, SLA and peering, which no Eye counts. Practical selections pair one of [Iceland](https://vpsbit.io/locations/iceland/), [Switzerland](https://vpsbit.io/locations/switzerland/) or [Netherlands](https://vpsbit.io/locations/netherlands/) with an honest reading of the [limits of no-KYC anonymity](https://vpsbit.io/limits-of-no-kyc-vps-anonymity/) — statute first, meme second.

A workable rule: let the Eyes map eliminate nothing by itself, and let the statutes decide. A member state with strong domestic safeguards can host a lawful project better than an unranked jurisdiction with a capricious court, and no alliance label predicts uptime, peering quality or whether the provider answers abuse mail at all. Read the tier, then read the data-retention act, then read the provider's published terms — in that order, and only then open the checkout.

Is hosting in a Five Eyes country unsafe? Not automatically. The alliance describes intelligence sharing between states, not hosting law, and day-to-day process against a server runs through domestic courts either way. Weight it as one jurisdictional factor alongside retention law, data-protection statute and your own personal exposure.

Does a Fourteen Eyes country mean my VPS is monitored? No. Membership means agencies may pool signals intelligence under national programmes; it is not a standing tap on hosting customers. Any specific collection still requires legal process in the country where the server physically stands, regardless of the tier.

Which Eyes tier is Switzerland in? None. Switzerland sits outside all three tiers, as do Iceland and Saint Kitts and Nevis, where our contract entity is registered. That absence is one reason they appear on privacy shortlists, alongside their domestic statutes — never instead of them.

If I encrypt everything, does the Eyes map still matter? Far less. Full-disk and end-to-end encryption reduce what any collection tier can read from the server itself. What remains exposed is metadata — who connected, when and to where — which encryption does not conceal, so the alliance label retains weight there.

Is the Netherlands bad for hosting because it is Nine Eyes? Not in practice. Amsterdam combines GDPR protections, dense peering at AMS-IX and established hosting case law, and it is among our most-booked locations. Jurisdiction is a bundle of statutes you can read; the alliance label is one thread of that bundle.

## Related guides

- [Minimum-data no-KYC checkout](https://vpsbit.io/guides/anonymous-vps-crypto-no-kyc/)
- [Buy a VPS with crypto](https://vpsbit.io/buy-vps-with-crypto/)
- [No-KYC VPS: requirements and limits](https://vpsbit.io/no-kyc-vps/)
- [Pay with Monero](https://vpsbit.io/monero-vps/)
- [Offshore VPS](https://vpsbit.io/offshore-vps/)
- [VPS vs dedicated bare-metal](https://vpsbit.io/guides/vps-vs-dedicated/)
- [Best no-KYC VPS 2026](https://vpsbit.io/best-no-kyc-vps-2026/)
- [FAQ: crypto VPS](https://vpsbit.io/guides/faq-crypto-vps/)

## Checkout facts

- **Price** VPS from $4.80/mo. Dedicated from $39.20/mo.
- **Identity** No KYC. Token-only (no email) or email plus a 12-character password. No passport, phone, or card.
- **Payment** Nineteen ways to settle, none of them a card: XMR and BTC lead, ETH, SOL, LTC, BNB and TRX follow, then XRP, DOGE, DASH and ADA, GRAM (TON) for Telegram-adjacent rails, and USDT on seven networks — TRC-20, ERC-20, BEP-20, SPL, Polygon, Arbitrum, Optimism. Live-rate invoice.
- **Logs** No payload / no guest traffic logs. Billing and panel actions retained. Connection metadata ≤24h.
- **Platform** KVM on ECC and local NVMe. DDoS filtering included. Facilities in 12 elite cities across Europe and Asia — the locations table lists each one's tier, uplink and governing law. Need Iceland or Switzerland plus no KYC? Those two carry a published premium (+20% / +35%); every other flag stays at base list. Pay BTC, USDT, XMR, BNB, XRP, GRAM (TON) or 10 more. [Open deploy](https://vpsbit.io/deploy/?kind=vps&plan=core&location=netherlands&period=12/) to pick a plan.

## Ready to launch?

Build the box — VPS or bare metal — create the password, pay the invoice that follows.

[Launch now](https://vpsbit.io/deploy/?kind=vps&plan=core/)[Dedicated](https://vpsbit.io/dedicated/)
