Encapsulate · Security
Keys & isolation
The part that only shows when it fails.
Key management, slashing protection and host isolation — the work you never see until the day you need it.
Defence in depth
Scroll ↓
Security and operations · 01
How we run a validator.
Nine commitments, the same on every chain we join. Each is a practice we can show you, not a figure we would have to keep proving.
1h · for an emergency release
2×2 · regions and providers
0 · slashing events since 2020
Access · 02
Two ways to reach a validator. One door for each.
Blocks reach it through sentries we run. People reach it through a private network with no public route. Nothing else reaches it at all.
Sentry layer · Sentries · The validator peers only with nodes we run. Public traffic lands on sentries that can be replaced or re-addressed under attack, so a block proposal always reaches the network.
Separate full nodes · Full nodes · RPC, indexing and anything public run on their own hosts. The validator serves consensus and nothing else.
No public route · Tailnet · Every server sits on a private tailnet. Administration happens only inside it; SSH is reachable only there and never from the internet.
Deny by default · Firewall · Inbound is denied on every host. The only firewall rules that exist are the ones a running service actually needs.
A key you hold, a name you own · YubiKey · Every human login is a hardware security key touched by hand, to an account with one person's name on it. No passwords, no root login, no shared identities; automation runs as its own restricted identity pinned to one address.
Least privilege, timed · Sudo · Operators hold an explicit allow-list of commands; root shells are blocked. Broader rights come for a fixed window, capped at an hour, and a timer takes them back.
Nothing goes unseen · Audit · auditd on every host, shipped to Loki so it outlives the server. Wazuh watches each host and Suricata the wire; fail2ban bans repeated failures at the firewall; Trivy scans hosts and images; Alertmanager reaches a person.
Built from code · Ansible · Every server is provisioned by Ansible from version-controlled code, so machines meant to be identical are. Secrets are encrypted at rest and never in the repository in clear; ownership rules mean a change is approved before it lands.
The key is not here · 2 of 3 · The consensus key is not on the validator. It is three shards on three hosts, two of three to sign, and only one signature per height can ever exist — own any one host and you hold nothing.
How it is run · 9 rules
pick one
Keys · 03
The key is three shards, 2 of 3, and is never assembled. Each shard sits with a cosigner on its own host with no inbound ports. Every cosigner keeps the high-water mark, so the same height is never signed twice. The keys that move stake are split across people — no one alone can act. And there is no hardware: lose a cosigner and the other two keep signing.
hover a highlighted word
Hover a highlighted word for the full commitment.
Failover · 04
Built to lose a data centre and keep signing.
Bare metal, nothing on the host but the validator. Two of everything, in two places, on two providers. Failover is a signing decision measured in blocks.
Upgrades and response · 05
Routine inside a day. Emergency inside an hour.
Emergency releases are where a validator earns or loses its seat. Our path is the same every time and on every chain, so it is fast when it matters.
Routine release · Inside 24 h
Emergency release · Inside 1 h
Reply to outreach · Same day
On call · 24/7 rotation
Channel · Shared with your team
Slashing and the record · 06
0
Slashing events since 2020, across every validator we have run. On chain and checkable.
What slashing costs a validator
The seat.