noKYCme

Case file · Email

Autistici/Inventati

A 24-year-old Italian activist email collective that requires no identity - you write why you share their anti-fascist/anti-commercial principles, a human approves it, and the request is deleted 15 days later. It holds almost no data by design - a posture forged after Italian police covertly backdoored its server in 2004-05.

No-KYC · Level 1
Based
Associazione AI-ODV, Italy (14-Eyes); mirror inventati.org
Price
Free, donation-funded (donations decoupled from the account; no crypto)
Reviewed
2026-07-31
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

7.7/10 · No identity required (values-gated)

A/I is a self-managed Italian activist collective (since 2001) that asks for no identity at all: to get an account you explain why you share their anti-fascist, anti-commercial principles, a real person reads it, and the request is deleted 15 days after approval. It logs no connection IPs, encrypts mail with keys its own staff cannot read, and caps all retention - it holds almost nothing to hand over, and says so plainly. That posture was forged the hard way: in 2004-05 Italian police covertly backdoored its server at the ISP Aruba and intercepted ~30,000 users for about a year, and its disks were cloned again in Norway in 2010. Crucially, A/I was the deceived victim of state compulsion, not a betrayer - it responded by re-architecting to hold less and publishing the whole story. We do not cap it for a 20-year-old involuntary seizure (that would be incoherent when Proton keeps 8.0 for its own lawful disclosures); it lands at 7.7/10, above Riseup, just below the audited leaders. Values-gated and Italian-jurisdiction - not a general-audience pick.

What the internet says

2 recurring praises · 3 recurring gripes

Most praised: deeply respected in privacy/activist circles; ~24-year clean-of-betrayal record. Most cited downside: twice physically seized (2004-05 mass interception; 2010 disk clone).

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Jurisdiction, sign-up & encryption.

Jurisdiction
Associazione AI-ODV, Italy (14-Eyes); EU/GDPR; mirror inventati.org
Sign-up needs
A written statement of shared political principles, human-approved, then deleted after 15 days; no ID, phone or personal info
KYC trigger
None - identity is never requested; a binding Italian/judicial order can compel what little A/I holds
Encryption
Mail encrypted with keys available only to the user, not A/I staff; forced SSL/TLS on all services; full-disk encryption on servers
Provider access
Holds no account-to-identity link; no content analysis; discloses only on a fully binding judicial request (encrypted content handed over encrypted)
Anon. payment
Free; donations decoupled from the account (bank/PayPal/Liberapay or in-person cash) - no crypto, Bitcoin explicitly refused
Logging
No IP connection logging; debug logs up to 15 days; hard ceiling - no data/log kept beyond 2 years of last use
Open source
Yes - code public at git.autistici.org / 0xacab.org
Audited
No independent security audit; radical self-transparency instead
Custom domain
Aliases; activist-oriented services (lists, sites, VPN, chat)
Free tier
Yes - all services free (donation-funded)
Since
2001

The full read

Our analysis, in plain words.

Autistici/Inventati is not a product; it is a 24-year-old activist collective, and it shows in the best way for privacy. To get an account you do not hand over a name, phone or ID - you write a short statement of why you share its anti-fascist, anti-commercial, anti-sexist principles, a real person reads it, and the request is deleted fifteen days after approval. By design it holds almost nothing: no connection-IP logs, mail encrypted with keys its own staff cannot read, a hard rule never to keep any data beyond two years, and no record linking an account to a real identity. When authorities have demanded user data, it can honestly answer "we do not have them."

That posture was forged in the worst way a provider can learn it. In 2004-05, Italian police secretly installed a backdoor on A/I’s mailserver at its ISP, captured the SSL key, and potentially intercepted around 30,000 users for roughly a year - A/I was not told, and only discovered it by accident (reported by EDRi and Statewatch). Its disks were cloned again in Norway in 2010. The critical point for scoring is that A/I was the deceived victim of state compulsion, not a service that betrayed its users - and it responded by re-architecting to hold less and by publishing the entire incident, which it still hosts today. Our reliability caps exist for services that freeze funds or flip on users; applying a 3/10 cap to a 20-year-old involuntary seizure that A/I has since remediated would be flatly incoherent when Proton keeps an 8.0 despite executing its own lawful IP and payment disclosures as recently as 2024, and Riseup sits at 6.9 despite complying with gagged FBI warrants. So the seizures weigh on reliability and feed trust (through the transparency), rather than capping the score. It lands at 7.7/10 - above Riseup, just below the audited leaders, held there by Italian jurisdiction, no anonymous payment, no external audit, and a values-gated model that is deliberately not for everyone. We grant Reviewed, not Verified: the one seizure with a documented outcome was a pre-remediation failure, and the "holds nothing" posture, while credible, has not been externally confirmed under test the way Mullvad’s raid or Posteo’s DPA audit were.


The score, broken down

How the 7.7 is built.

Privacy 4.3Trust 2.5Reliability 1.0 Headroom 2.3

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

85/100

85 × 50% = 4.3 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

82/100

82 × 30% = 2.5 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

52/100

52 × 20% = 1.0 of 10

Weighted total 7.8 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +9No ID, phone or personal info ever; the signup asks your values, not your identity, and is deleted after 15 days↗
  • +6No IP connection logging; mail keys held only by the user, not A/I staff; hard retention caps (max 2 years)↗
  • +4Holds no data linking accounts to real identities; free account needs no payment at all↗
  • +-5Italy (14-Eyes) with a standing lawful-disclosure clause; no anonymous payment (Bitcoin refused); no onion↗

Trust

  • +6Open-source; self-managed collective operating since 2001 with no betrayal on record↗
  • +4Radically transparent - publishes its own worst incident (the 2004-05 police backdoor) 20 years on↗
  • +-4No independent security audit; informal volunteer governance↗

The fine print, read for you

The clause they bury.

Verbatim — the honest version
“A/I will disclose user data and any information only if instructed to do so by a fully binding request coming from the competent Italian authorities or other compelling judicial authority.”

What it meansThis is the honest limit of the promise. A/I is in Italy (a 14-Eyes country) and will comply with a binding judicial order - the "private is not anonymous under compulsion" reality. But it is written to narrow disclosure (only fully binding requests, original hard-copy required), and because A/I deliberately holds almost nothing - no IP logs, no identity link, user-held mail keys - a compelled request reaches very little, and encrypted content is turned over still encrypted.

Read the source →
Verbatim — the catch
“If you breach or fail to comply with any of these Terms, A/I has the right to suspend or disable your access to the Services, without notice ... accounts will be suspended and erased without notice every time we will recognize a non principle-compliant behavior.”

What it meansA/I gatekeeps on values, not identity: it can suspend an account "without notice" for behaviour that conflicts with its anti-fascist/anti-commercial/anti-sexist principles, and it refuses to host commercial use, parties or organised religion. That is a real continuity caveat (your account can be pulled for content/values reasons) and it makes A/I a curated collective, not a general-audience host - but it is an affinity gate, never an identity demand, so it does not make the service KYC.

Read the source →
KYC trigger threshold

No identity is ever required or verified. The one signup step is a written statement of why you share A/I’s political principles, read by a human, then deleted 15 days after approval - a values-alignment gate, not identity verification. A/I explicitly holds no data linking accounts to real identities. It is level 1 (not 0) only because a mailbox is a persistent identifier and registration is a curated, human-approved step.

Policy review — point by point

  • No identity, deleted signup

    No ID/phone/personal info is required; the values statement at signup is deleted 15 days after approval, and A/I holds no account-to-identity link. ↗

  • Minimal retention + user-held keys

    No IP connection logging, mail keys held only by the user, and a hard ceiling of no data beyond 2 years of last use. ↗

  • Values-gated, without-notice suspension

    Access is gated on alignment with A/I’s principles and can be suspended "without notice" for non-principle-compliant behaviour - an affinity gate, not an ID demand. ↗

  • Italian jurisdiction + lawful disclosure

    Complies with fully binding Italian/judicial orders - but holds almost nothing to give, and hands over encrypted content still encrypted. ↗

Jurisdiction analysis

A/I is run by Associazione AI-ODV in Italy, an EU/GDPR jurisdiction but also part of the 14-Eyes intelligence-sharing arrangement, and it will comply with a fully binding Italian or judicial order. Its defence is architectural, not jurisdictional: it deliberately holds no IP logs, no account-to-identity link, and user-held mail keys, so a lawful order reaches very little - a design directly hardened by the 2004-05 seizure and tested again in 2010. The trade-off is that it is values-gated and volunteer-run, so it is a mission-aligned activist host, not a turnkey general-audience mailbox.


We keep watching

Incident & policy timeline.

  1. 2001

    Founded as an activist tech collective

    A/I was born in 2001 from the Italian autonomous/anti-capitalist movement, providing free privacy email and services to activists, self-managed with no coordinator and funded only by voluntary donations.

    source ↗
  2. 2004-2005

    Italian police covertly backdoored the server (the defining event)

    On 15 June 2004, Italian Postal Police, under a Bologna prosecutor’s order in the Crocenera anarchist investigation, installed a covert backdoor on A/I’s mailserver at the ISP Aruba, captured the SSL private key, and potentially intercepted ~30,000 users’ traffic for about 371 days - discovered by A/I in June 2005. A/I was NOT informed; Aruba complied and cited Italian law. (Reported by EDRi and Statewatch, 2005.) This is an involuntary state seizure via a third party, not an A/I betrayal.

    source ↗
  3. 2005-2010

    Re-architected to hold almost nothing; seized again in 2010

    A/I replaced the compromised machine and launched the "R* Plan" to re-architect for minimal data retention and user-held keys, so future seizures would yield little - and it says it now answers demands for user data with "we do not have them." In Nov 2010, Norwegian police (at Italian request) cloned an A/I server’s disks. (The claim that the 2010 clone yielded little is A/I’s own stated posture, corroborated by its low-retention design, not an externally confirmed outcome.)

    source ↗

The verdict

Where it stands.

Strengths

  • No ID, phone or personal info ever; signup deleted after 15 days
  • No IP logging; user-held mail keys staff cannot read; hard retention caps
  • Holds no account-to-identity link - a compelled order reaches almost nothing
  • Open-source, ~24 years, radically transparent (publishes its own seizure)

Trade-offs

  • Italy (14-Eyes) with a standing lawful-disclosure clause
  • No anonymous payment path (Bitcoin explicitly refused); no onion
  • Values-gated + discretionary "without notice" suspension - not general-audience
  • Volunteer/no-SLA; twice physically seized (2004-05, 2010); no independent audit
Visit Autistici/Inventati No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Deeply respected in privacy/activist circles; ~24-year clean-of-betrayal record
  • Radically transparent; data-minimal by design ("we do not have them")

Recurring complaints

  • Twice physically seized (2004-05 mass interception; 2010 disk clone)
  • Values-gated + volunteer/no-SLA; onboarding can stall
  • Italy/14-Eyes; no anonymous payment; no independent audit

Legit and well-regarded; not a scam. The Privacy Guides community declines to list it for a general audience over values-gating, crypto refusal, Italian jurisdiction and onboarding friction - all reliability/fit issues, not integrity ones. The 2004-05 and 2010 seizures are attributed to EDRi/Statewatch/A-I’s own dossier and framed as involuntary compulsion, not betrayal.


Keep exploring

Related lists & categories.


Ask the bureau

Autistici/Inventati, common questions.

Is Autistici/Inventati no-KYC?

Yes - it never asks for identity. The one signup step is explaining why you share its political principles, read by a human and deleted after 15 days. That is a values-alignment gate, not identity verification. We rate it KYC level 1 (a mailbox is a persistent identifier; registration is curated).

Didn’t the police seize it?

Yes - and it is transparent about it. In 2004-05 Italian police covertly backdoored its server at the ISP Aruba and intercepted ~30,000 users for about a year (A/I was deceived, not complicit), and its disks were cloned in Norway in 2010. A/I responded by re-architecting to hold almost no data. We do not cap it for a 20-year-old involuntary seizure it has since remediated and publicly documented - the same way we don’t cap Proton for its own lawful disclosures.

Should I use it?

If you align with its anti-fascist, anti-commercial, activist mission and can accept Italian jurisdiction, it is one of the most data-minimal, honest email providers anywhere. It is not for everyone: access is values-gated and can be suspended for principle violations, there is no anonymous payment, and it is volunteer-run with no SLA. For a general audience, Posteo or Mailbox.org are easier fits.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.