Transparency report
The abuse policy commits to publishing aggregate stats on abuse reports, action distribution, and lawful orders. This page is where those numbers go. The first full report covers our first 12 months of operation. Until then, the methodology is committed below and the PGP key for sensitive disclosures is published; the numbers section will populate as we operate.
Pre-launch state. ViaductCDN has not yet opened to public signups. There is nothing to report yet. The first annual report will publish 12 months after the first paying customer, or sooner if we receive our first lawful order before then. Whichever comes first.
Operating history
A WHOIS check on viaductcdn.com will show a domain registered in late April 2026. The project behind the domain predates it by months; the two-week-old domain is a fair skepticism marker and the entries below are the verifiable counterweight.
ViaductCDN is operated by Inertial Navigation LLC, a Washington-state limited liability company registered 2015-06-16 (UBI 603 516 505). The LLC has been an active operating entity for over a decade; formation date and registered agent are public record on the Washington Secretary of State’s Corporations and Charities Filing System. ViaductCDN’s engineering was carried out by a related Inertial project (scheducal.com, on the public web since 2023-10-17). The PGP key published below carries its creation date in the self-signature and has been uploaded to keys.openpgp.org, so the key’s age is independently verifiable as well.
Public, dated milestones:
| Date | Milestone |
|---|---|
| 1997-09-15 | Founder’s personal domain llew.net registered. A 28-year continuous online identity; predates this venture by decades. |
| 2015-06-16 | Inertial Navigation LLC formed in Washington state (UBI 603 516 505). The operating entity behind ViaductCDN; not a corporation spun up for this venture. |
| 2023-10-17 | scheducal.com registered. A related Inertial project that did the engineering for ViaductCDN; its public web presence has been continuous since registration. |
| Late 2024 | ViaductCDN project work begins under Inertial. Architecture and infrastructure prototyping. |
| 2026-04-25 | Per-site Tor v3 hidden-service provisioning shipped. Every customer site gets its own .onion address, customer-owned. A previous shared-front design (using OnionBalance) was retired the same day in favour of this per-site model. |
| 2026-04-28 | This transparency page goes live, with methodology committed before any numbers exist. PGP key for sensitive disclosures published. |
| 2026-04-29 | First internal end-to-end customer (VIDS on Demand) live on the alpha cluster. |
| 2026-05-09 | Newsletter pipeline live (Buttondown, all tracking off, subprocessor disclosed on this page and on /privacy). |
If you’re evaluating whether this project is a scam or a rug-pull rather than a real ongoing operation, the load-bearing artefacts are the Washington-state LLC record, the PGP key on keys.openpgp.org, and the threat-model document at /security. A short domain history is not the same thing as a short project history; the two are easy to conflate.
Methodology (committed before any numbers exist)
A transparency report without a methodology is a marketing artifact, not a transparency artifact. We define our terms here so future numbers are interpretable.
What counts as “a report”
A report is any inbound message to abuse@viaductcdn.com or via the form at /abuse that names a specific site_id or .onion address and includes either a description of the alleged violation or a lawful order. Spam and duplicate-of-prior reports are excluded from counts; we publish the de-duplication count as a separate line.
What counts as “acted on”
A report is “acted on” when our triage process produces one of these outcomes:
- Dismissed — report doesn’t evidence a policy violation.
- Forwarded to operator — for non-urgent matters where the site operator should respond first (DMCA forwards, customer complaints).
- Site suspended — clear policy violation, site state set to suspended at the edge.
- Account suspended — pattern of violations across multiple sites under one tenant.
- Reported to NCMEC — CSAM specifically, per 18 U.S.C. § 2258A.
How we measure time-to-action
Timer starts when the report arrives in our queue (inbound timestamp on abuse@). Timer stops at the first operator action: dismissal, forwarding, suspension. We publish median and 95th-percentile, broken down by category.
What “lawful order” means
Court orders, subpoenas, search warrants, NSLs, and equivalent legal process from any jurisdiction. Counted by category and by jurisdiction. For each we also track:
- Whether we complied as-served, complied after pushback (narrowed scope), or fully refused (jurisdiction lacked nexus, request facially overbroad, etc.).
- Whether disclosure was permitted (we publish counts even when individual orders are sealed).
Specific orders are not described individually. The counts are enough; itemizing would risk identifying parties involved in sealed proceedings.
Numbers
First reporting cycle has not yet begun. This section will populate on the publication date.
| Period | Reports | Lawful orders | Status |
|---|---|---|---|
| 2026 (first 12 months) | – | – | Reporting cycle in progress; first publish 12 months post-launch. |
Subprocessor list
The third parties we use to operate the platform. Each is named in our privacy policy at /privacy along with what specifically they see. We list them here too because a privacy-positioned product’s subprocessor list belongs in the same place as the rest of the trust artifacts.
| Processor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Infrastructure (compute, storage, DNS, Key Vault) | USA (East US) |
| SendGrid (Twilio) | Transactional email delivery | USA |
| Buttondown | Newsletter delivery (subscriber emails + broadcast content); only populated by opt-in subscribers, never from account data | USA |
| Stripe | Card payment processing | USA + global |
| BTCPay (self-hosted) | Cryptocurrency invoice management; runs on our Azure infrastructure | USA (East US) |
| Let’s Encrypt | TLS certificate issuance for custom domains | USA |
Subprocessor changes are announced via in-portal notification before they take effect.
PGP key for sensitive disclosures
Reports that touch on identifying information (CSAM tip-offs, sealed court orders, doxing complaints, security vulnerabilities) can be sent encrypted. The key below is the org key for abuse@viaductcdn.com; the same key handles security@viaductcdn.com for vulnerability disclosures. Private half is held on a hardware token; rotation is annual on the subkey, primary key non-expiring. Verify by fingerprint against keys.openpgp.org.
Fingerprint
DE90 9005 05C1 9240 9DD7 351B 0F44 77CD BE1D 9AE8
Public key block
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBGn03dABEADNfJqeIMmCsJSwpikoHObXiQyUXaFiRFyl6YBhf1t8gmud79h2 AkjQVMggpBI5E7SdMY1ZWjZRAlDzSQJ0Xj/0cucIjImv62eIZw45qMV9emyMYsPX Etjmm/am2pqkOb7KUwDrjAH70LFrKR1lEk8VmPWFJ76hVz5gQApoKnKQDax3P+b6 zji+GPBVKfgvRrnXkd3RxUwafx7Sbk+vt3oB7qXpOHocAPsasr2oUtN1IG5NaFhz J0yC2v2OUHvZlrHpARimcC/E/ZEJa6X4lQpONOdHnYJM84SA0vr6piq1cQSwaPZ8 guORXsofBA1vxDVF3NuVo00jWH88MZzT9pqK+s6pO7wrglqNuGtAMITecIhihVMk k44M6A3KohGQpNHX5JKKoQKK3wjJk0KLA4/24kOFCnfWeVbsEfSgGI+C2WoG9XfQ IO4nw3v9FZaScdDLiO5qQY49JrtZPCtlZw71dXMYoaeygO7ZT4iYm+tufp5ugedZ IiSRCCvRzIOBdqGHbEIxYRBYVM+dUQQUjVGAR5LMNCEAHAv2rWnLXwoBk3GwtUwx TnUwbBrR/9gjD1J1e/EVkYPXXp4H4Wa8uaFwnjpA5850UtXJOczRcpzcEZs23XkV WIQb/pKKzh4puzD/4SCVdmZ1GfEW/Ee/y85q/NZ8pIOJTac1r6amp/INjQARAQAB tCpWaWFkdWN0Q0ROIFNlY3VyaXR5IDxhYnVzZUB2aWFkdWN0Y2RuLmNvbT6JAnME EwEIAF0WIQTekJAFBcGSQJ3XNRsPRHfNvh2a6AUCafTd0BsUgAAAAAAEAA5tYW51 MiwyLjUrMS4xMiwyLDECGwMFCQPD0uAFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcC F4AACgkQD0R3zb4dmuh3JhAAzNYSx+IdsNo1INNzQRwOwCrhww1JKgsvYoI7xEJZ rcDhlqds1QTr3fXWG//5xde61YnEnyr9rev5xHQS99/bjmxnR8tbyt6UWt7Bo34Q TC1C9j/JFLARStzXoz6jpfFGwlYKTHNRBgG0D6PvfQocXKvU5mHhlQsAO5/WYqlk vA1U8pyaXrfe/e13FhOVyxCruFh1p8n6Ahg1hM7epLMGGTsdafGQFUN3GBdL+C/6 e//A8OPkjaViafVSwM60kZi/6nyM9vtmmKR7MGSp5MeYnAQsMuYSpMwmu4jcDtk/ SCMzL1GrhQgG0M3j91Ru1gZPVqrNRIkxsCjwH+uMZwnDkQw/kH4y7tIep7JXRJHc SsOSYTgkBCj+fbcDKB9Ay4df/etNAHsI3/G5NbQBo+YjZuqsI9s4/oqeSj6SWOOn J6Jcme5ECxT0no3jUr1aVVTZtPJmkBdICU+wRouupzzPaFYgVUezzcEkGVUpQojB 4kKLtHNX+nxSWm5Bv+TkXvsWhQgXNlmmYa8TLANOcfWaU8UqcOsh+nU0nBHc5wcU Hl/hPOCrI5EyEPJeiJnlgKVETPSu/igS22KbnKfDuaxay4YDXE3Iba51s5hb2G8w lmfOvu2EMw9IELb9O0cinMyvi4cmgb8vzKuVA7flux+ThVHqTdl5w1XPjWV/m8RV FV65Ag0EafTd0AEQAMO7CwvgdMoQB2UyFSprZXns5K2hLmNRmJSjdFAzZ5a6aX4Y P5+t8lY0/jcV6KmXneHeqe3opQNCBSSBP85Lc0+IEiJFugow2bQYefinbS5aWi8b 7jAJ0wDHDKzeykHUb+jt3ejfX0Wj/KQwP+8FFnu1XoWU5Ghpx8yJ2eLqOnAJLCu/ 6iv4NspN7UIftpYCbbXsqP98ojNGjxRIhMUxlm+VtUS0NWG064TS8D9VBS4U7Tqm UzYWXkV6021lhwCH24iIKefkQ7liY7bDe5Bifsd/q2S7nJox3EiQwf+kyy9i03K9 qB34DCzEZ+ixfJbelSmaEuGU4z6gbFJFpzI1Ql1S5r3A/VOCaoJGTEWc+4IHLxsZ DYyAHpo10AoWP5JnELsFqJdDTC3nAWmEmRiec8FhNi7Cc+Cn36WaMDJbQgxRqSrw Jr3tZm5RoaHlLC8mzwdxOK/sjS1V6MySD8gkBBZRCN1mIxysJxuO6c6afTpNUT8i YAsPhOaXF6MemxtvC8XvrmwpN2wiNY9ZFtuEgIBk8GfuM2awgQze38i1dPczAmc6 YwSbGQd2BUjDh8C1U+PGfZIxDp6u3NOuoFEJ+Z5xa/c3vQ4dyxbrvWnpCjpNVwH4 nmsrU3wz3ltkBoFW2uzbWBGhcCUQJF7SDCWdvfTNwQMElI00I1uHguM325dHABEB AAGJAlgEGAEIAEIWIQTekJAFBcGSQJ3XNRsPRHfNvh2a6AUCafTd0BsUgAAAAAAE AA5tYW51MiwyLjUrMS4xMiwyLDECGwwFCQPD0uAACgkQD0R3zb4dmujj1g/+PTHO wRttI+9waXbGUjNowj9RLqGBvVwx+3jQ1lPc8+SXo+7p9dyX2sf0S7/52RoHQoyj przKp7C+GZPOAnqAcN8xxM1/BH3cjpdUH5QXjhiyQFRgCdZbbjYM/AXn9St1FWUe HvbWP47wzmHnvqnvOuOZonmx9wsnmRwLqH6XuFpfsYUmR7+VWhqPYTcqd4Rdh9t5 5yIEMtnmtyvZ/Vvr33FHXTRirp526oL9+H7ymGq0pGPw3R7OCPfSZhzY3Qgk8R2p sA14DIjqmrBqR0Q7eHUXehHA1chPKKpCytBeylYgdJ6Q+lH/6jrQ8SdPlTMOHMEI +x2PbEJudri05ZMd8RCY/NSfzDoYnIuX62wjhABdxYH3aMRkdwJHwVhE4MQx56Pn puMnraslxk9eQNlgFlaXv7zT7ZeeS8wM5a/ILBVIp861uHxSGEFhOWwBXmy81Mzy xUYMP9SY//6mjAUfWbg57ScQjTLobPMlHmv2/Atk49vyNJvaavy4I/GIH+6CSDmH usQNmtlyGXCOijws/4MvckkGdRgELEC08pIvhwrsguXb2+uWDXep7S2oxNdfnlvv b3S4owB9FkiB1fb8+Er8EFEMVyHTWkqyDRk1i1MESF6xe4nntsIf9b8+eTnp/+KE 5DT8yZDTC/kjBXyXrEXUzD3LvHJ5W5kT6zM5Uvw= =NHth -----END PGP PUBLIC KEY BLOCK-----
Cross-references
- /abuse — abuse policy and reporting flow
- /security — threat model and what we see
- /privacy — data we collect, retention, customer rights
- /terms — service terms
Questions
Privacy / methodology questions: legal@viaductcdn.com. Abuse reports: abuse@viaductcdn.com. Security disclosures: security@viaductcdn.com.