Transparency
socks.cat is operated by Femboy Cyber Networks LLC. This page documents our warrant canary, transparency reporting, and how we handle legal requests. See also our privacy policy.
Some things we have never done
If we are ever compelled to do any of the following, the corresponding statement will be removed — not replaced with a lie.
- Femboy Cyber Networks LLC has never received a gagged national-security letter, FISA order, or equivalent order prohibiting disclosure that we had received it.
- We have never installed law-enforcement software or hardware on socks.cat gateway, API, or router infrastructure under our control.
- We have never provided a live feed of customer proxy traffic content (payloads, URLs, or DNS queries) to any third party.
- We have never turned over whisker secrets, pawprint peppers, or bulk credential material — we do not store whisker secrets; verifiers and paw keys are stored only as needed for authentication.
- We have never modified purroute, the gateway, or customer routing at the request of law enforcement to weaken authentication or enable targeted interception.
- We have never disclosed per-connection browsing metadata we do not collect (destination hosts, URLs, or DNS lookups tied to an account).
Transparency report
| Year | Requests received | Legally valid | Data provided |
|---|---|---|---|
| 2026 | 0 | 0 | 0 |
Requests received — any government, court, or law-enforcement request for customer information or infrastructure access.
Legally valid — requests we determine we are obligated to answer after review (with counsel when needed).
Data provided — cases where we produced data beyond a nil or “we do not have it” response.
Warrant canary
Last signed: 2026-07-21 · Expires: 2026-10-19
Machine-readable: /.well-known/canary.txt
PGP fingerprint: 9A9A39B9A52E324890DDB79D4FBB2ABF37C6D5FF
Archive: past statements
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 socks.cat Warrant Canary As of 2026-07-21 Femboy Cyber Networks LLC (socks.cat) states: - - No national security letters, FISA orders, or other gagged legal process prohibiting disclosure have been served on us or our employees. - - No searches or seizures have been performed on socks.cat infrastructure under our control. - - We have not been compelled to install backdoors or monitoring in purroute, socks-cat-api, or the public gateway. - - We have not disclosed whisker secrets, pawprint peppers, or per-connection browsing metadata (which we do not collect) to any third party under gag. This statement expires 2026-10-19. If not replaced before then, assume a gagged process may have occurred. Freshness anchor — Bitcoin mainnet: height: 959061 hash: 000000000000000000022645eee1e171b271a92e6527728e85441efc88fa04a5 Freshness anchor — Monero: height: 3723024 hash: 7438d7619b5522eaf14d84473d1a5dc50057b928f8df36447d3097f5983d65dc Transparency report (2026): received=0 valid=0 provided=0 -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQSamjm5pS4ySJDdt51Puyq/N8bV/wUCal/m0AAKCRBPuyq/N8bV /9WkAQD6gjLj7LKDJxXfcT4FavGBUEPcuLEuZNM4xFYYs6NqzgD/VDAIMjSS/6Hf YccVeDI00ycgQQbJTR2s/0gDz68QfgU= =bx0p -----END PGP SIGNATURE-----
How to verify
- Fetch the public key from /.well-known/pgp-key.txt.
- Fetch the signed statement from /.well-known/canary.txt.
- Run
gpg --verify canary.txt(after importing the public key). - Confirm the signed date and expiry in the message body.
- Check the Bitcoin and Monero block height and hash anchors against public chain data — both must post-date the previous canary.
For encrypted security reports, use the age key at /.well-known/age-key.txt and email security@router.sex.
Staleness protocol
If the canary is not updated within 95 days of the date in the signed message, assume a gagged legal process may have been received and treat the service accordingly until we publish an explanation.
Limitations
A valid PGP signature proves the message was not forged by a third party. It does not prove the operator was not forced to sign a false statement under duress.
How we handle requests
Contact security@router.sex with proper legal process. We do not log per-connection destinations. We retain aggregate byte metering, payment records, and optional IP allowlists as described in our privacy policy. Signup collects no email or name.