Transparency

socks.cat is operated by Femboy Cyber Networks LLC. This page documents our warrant canary, transparency reporting, and how we handle legal requests. See also our privacy policy.

Some things we have never done

If we are ever compelled to do any of the following, the corresponding statement will be removed — not replaced with a lie.

  1. Femboy Cyber Networks LLC has never received a gagged national-security letter, FISA order, or equivalent order prohibiting disclosure that we had received it.
  2. We have never installed law-enforcement software or hardware on socks.cat gateway, API, or router infrastructure under our control.
  3. We have never provided a live feed of customer proxy traffic content (payloads, URLs, or DNS queries) to any third party.
  4. We have never turned over whisker secrets, pawprint peppers, or bulk credential material — we do not store whisker secrets; verifiers and paw keys are stored only as needed for authentication.
  5. We have never modified purroute, the gateway, or customer routing at the request of law enforcement to weaken authentication or enable targeted interception.
  6. We have never disclosed per-connection browsing metadata we do not collect (destination hosts, URLs, or DNS lookups tied to an account).

Transparency report

YearRequests receivedLegally validData provided
2026000

Requests received — any government, court, or law-enforcement request for customer information or infrastructure access.
Legally valid — requests we determine we are obligated to answer after review (with counsel when needed).
Data provided — cases where we produced data beyond a nil or “we do not have it” response.

Warrant canary

Last signed: 2026-07-21 · Expires: 2026-10-19
Machine-readable: /.well-known/canary.txt
PGP fingerprint: 9A9A39B9A52E324890DDB79D4FBB2ABF37C6D5FF
Archive: past statements

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

socks.cat Warrant Canary
As of 2026-07-21 Femboy Cyber Networks LLC (socks.cat) states:

- - No national security letters, FISA orders, or other gagged legal process
  prohibiting disclosure have been served on us or our employees.
- - No searches or seizures have been performed on socks.cat infrastructure
  under our control.
- - We have not been compelled to install backdoors or monitoring in purroute,
  socks-cat-api, or the public gateway.
- - We have not disclosed whisker secrets, pawprint peppers, or per-connection
  browsing metadata (which we do not collect) to any third party under gag.

This statement expires 2026-10-19. If not replaced before then,
assume a gagged process may have occurred.

Freshness anchor — Bitcoin mainnet:
height: 959061
hash: 000000000000000000022645eee1e171b271a92e6527728e85441efc88fa04a5

Freshness anchor — Monero:
height: 3723024
hash: 7438d7619b5522eaf14d84473d1a5dc50057b928f8df36447d3097f5983d65dc

Transparency report (2026): received=0 valid=0 provided=0
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQSamjm5pS4ySJDdt51Puyq/N8bV/wUCal/m0AAKCRBPuyq/N8bV
/9WkAQD6gjLj7LKDJxXfcT4FavGBUEPcuLEuZNM4xFYYs6NqzgD/VDAIMjSS/6Hf
YccVeDI00ycgQQbJTR2s/0gDz68QfgU=
=bx0p
-----END PGP SIGNATURE-----

How to verify

  1. Fetch the public key from /.well-known/pgp-key.txt.
  2. Fetch the signed statement from /.well-known/canary.txt.
  3. Run gpg --verify canary.txt (after importing the public key).
  4. Confirm the signed date and expiry in the message body.
  5. Check the Bitcoin and Monero block height and hash anchors against public chain data — both must post-date the previous canary.

For encrypted security reports, use the age key at /.well-known/age-key.txt and email security@router.sex.

Staleness protocol

If the canary is not updated within 95 days of the date in the signed message, assume a gagged legal process may have been received and treat the service accordingly until we publish an explanation.

Limitations

A valid PGP signature proves the message was not forged by a third party. It does not prove the operator was not forced to sign a false statement under duress.

How we handle requests

Contact security@router.sex with proper legal process. We do not log per-connection destinations. We retain aggregate byte metering, payment records, and optional IP allowlists as described in our privacy policy. Signup collects no email or name.