Managed validator

Validator security, stated plainly.

Who holds which key, how the host is run, and what we don't claim. Controls we operate, not a certificate we don't have.

A validator taking in stake and sending out its voteAn abstract drawing of light on the page's dark ground. Faint streams, the stake, flow in from the left toward a bright stepped block, the validator; from its top a single bright stream, its vote, rises and runs away to the upper right.A validator taking in stake and sending out its voteAn abstract drawing of light on the page's dark ground. Faint streams, the stake, flow in from the left toward a bright stepped block, the validator; from its top a single bright stream, its vote, rises and runs away to the upper right.

Who holds which key

Solana splits a validator's power across several keys. The one that controls money never leaves you.

Withdraw authorityYou, off the hostSets the commission, withdraws from the vote account, and can replace the other authorities. We never need it.
Identity keyYour validator's host, run by usIdentifies the validator, signs its blocks and pays its vote fees. Yours to take elsewhere.
Vote authorityYour validator's host, run by usSigns the validator's votes. It cannot move funds.
Stake accountsYour delegatorsDelegate, deactivate and withdraw their SOL. We never hold them.

How the host is run

  • Dedicated bare metal

    Your validator runs on a machine that carries no other customer's workload, in Frankfurt or Amsterdam.

  • Watched around the clock

    Monitoring and alerting on every host, with our 24/7 NOC behind it.

  • One identity, one voting machine

    We never run your identity on two machines at once; that is how duplicate votes happen. Failover and migration both follow this rule.

  • Upgrades are ours

    We schedule and run client upgrades and restarts as part of the service.

What we don't claim

No certification. We do not hold SOC 2 Type II or ISO 27001. If either is a procurement gate for you, raise it before anything else.

No uptime figure. Your validator's voting record is public on-chain. Judge us by that.

No screening by default. Sanctions screening is not in the standard plan. Ask before you buy and we answer in writing.

Questions

Are you SOC 2 or ISO 27001 certified?

No. We do not hold SOC 2 Type II or ISO 27001 certification, and this page describes how we operate, not an attestation. If certification is a procurement gate for you, tell us early.

Who has access to the validator host?

Our operations team, and no other customer's workloads run on it. If your procurement needs the access model in detail, ask and we will answer in writing before you buy.

How are identity and vote keys stored?

The identity and vote keys live on your validator's host, where the validator needs them to sign. The withdraw authority, the key that controls funds and commission, stays with you and never touches the host.

How do you prevent slashing during failover?

By never letting two machines vote with the same identity. The old node stops voting before the new one starts, so the validator never signs twice.

What is your OFAC SDN screening policy?

Screening is not part of the standard plan. If you need it, tell us before you buy and we will say in writing what we can apply to your validator.

What does the audit trail capture?

Your validator's votes, blocks and any change to its commission or authorities are public on-chain. For the operational record your auditors need, ask and we will set out what we can provide before you buy.

How are upgrades handled safely?

We schedule client upgrades and run them ourselves, following the same one-identity, one-voting-machine rule as failover.

What is your incident response process?

Monitoring alerts our 24/7 NOC, which works the incident until your validator is voting again.

The managed validator