Asymmetric Research Asymmetric Research × Solana Foundation Solana Foundation

STRIDE HW

Seven pillars and seventy-three controls for the bare-metal and colocation providers that host Solana validator hardware, each scored on a four-point scale from not implemented to verified.

Why STRIDE HW

A large share of Solana stake runs on hardware operated by a small number of hosting providers. A compromise at a provider reaches every tenant at once.

Existing standards stop above this layer. Node-operation and key-custody frameworks assess the validator operator, and facility certifications assess the building. None of them asks what software the provider adds to the OS image it delivers, or who inside the provider can open a console on a tenant machine. In June 2026, a breach of one provider's legacy monitoring system reached customer hosts through the agent the provider had installed. Validators across the ecosystem rotated keys and rebuilt.

STRIDE HW assesses the provider directly. The controls cover the facility, personnel, the management plane, the delivered OS image, the network, and the hardware supply chain. The assessment also records the concentration data behind the Solana Foundation's delegation criteria, which cap stake at 25% per ASN and 15% per facility.

Who it's for

The unit of assessment is the hosting provider, not the validator operator.

STRIDE HW covers bare-metal and colocation providers that host Solana validator hardware, and the component and firmware supply chain behind them. Asymmetric Research runs each assessment privately. Providers receive a scorecard and a prioritized improvement plan; we do not publish scores. Existing certifications such as SOC 2, ISO 27001, and facility tier certifications count as evidence and reduce the interview scope.

Methodology

Scoring scale
0 Not implemented
1 Ad hoc
2 Documented
3 Verified
Control tiers
Core (48 controls)

The minimum bar for any provider that hosts stake-weighted validator hardware. The screening interview covers these controls alone.

Extended (25 controls)

Adds depth for providers hosting concentrated stake, or where the Core pass surfaced weakness.

Maturity bands
Nascent 0 to 34%
Developing 35 to 54%
Established 55 to 74%
Mature 75 to 100%

Seven pillars

73 controls, 48 core

HF1.1
Facility inventory Core
HF1.2
Perimeter and layered access zones Core
HF1.3
Physical access authorization and review Core
HF1.4
Visitor management and escort Core
HF1.5
Cage and rack-level containment Core
HF1.6
Camera coverage and retention Core
HF1.7
Physical access logging visible to tenant Core
HF1.8
Power redundancy and generator testing Core
HF1.9
Environmental controls and monitoring Extended
HF1.10
Media sanitization and decommissioning Core
HF1.11
Delivery and removal control Extended
HF1.12
Facility resilience certification Extended
HA2.1
Background screening Core
HA2.2
Screening of remote-hands and NOC staff Core
HA2.3
Least privilege for facility staff Core
HA2.4
Termination and transfer revocation Core
HA2.5
MFA on provider control surfaces Core
HA2.6
Separation of duties Extended
HA2.7
Insider-risk monitoring Extended
HA2.8
Subcontracted personnel Extended
HA2.9
Duress and coercion Extended
HA2.10
Targeted social-engineering awareness Extended
HM3.1
BMC / IPMI network isolation Core
HM3.2
BMC credential management Core
HM3.3
Firmware update policy Core
HM3.4
Signed firmware and rollback protection Core
HM3.5
Firmware integrity detection and recovery Extended
HM3.6
Disclosure of out-of-band access holders Core
HM3.7
Tenant control over out-of-band access Core
HM3.8
Remote-hands request authentication Core
HM3.9
Dual control and evidence for physical touch Core
HM3.10
Chain of custody for components Extended
HB4.1
Inventory of provider-added software Core
HB4.2
Verifiable diff against the upstream image Core
HB4.3
Right to refuse provider-installed software Core
HB4.4
Privilege held by provider agents Core
HB4.5
Provider agent control channel Core
HB4.6
Legacy and deprecated management systems Core
HB4.7
Provider agent credential scope Core
HB4.8
Change control on live tenant hosts Core
HB4.9
Bring-your-own image and install attestation Extended
HB4.10
Image build pipeline integrity Extended
HB4.11
Blast-radius disclosure on provider compromise Core
HN5.1
Upstream transit and peering disclosure Core
HN5.2
DDoS mitigation Core
HN5.3
QoS, bandwidth and latency assurances Core
HN5.4
Routing security Extended
HN5.5
Tenant network isolation Core
HN5.6
Contention and oversubscription Extended
HN5.7
IP address stability Extended
HN5.8
Network change management Extended
HN5.9
Traffic interception and lawful access Extended
HS6.1
Supplier inventory and tiering Core
HS6.2
Authorized procurement channel Core
HS6.3
Counterfeit component detection Core
HS6.4
Per-machine provenance record Core
HS6.5
Tamper evidence in transit and at receipt Core
HS6.6
Secure staging Extended
HS6.7
Hardware root of trust Core
HS6.8
Device attestation Extended
HS6.9
Hardware bill of materials Extended
HS6.10
Third-party hardware assessment Extended
HS6.11
Supplier security flow-down Extended
HR7.1
Incident response plan covering tenant hardware Core
HR7.2
Incident notification SLA Core
HR7.3
Incident response testing Extended
HR7.4
Business continuity and disaster recovery Core
HR7.5
Security contact and vulnerability disclosure Core
HR7.6
Log retention Core
HR7.7
Tenant-accessible audit trail Core
HR7.8
Concentration and dependency disclosure Core
HR7.9
Maintenance notification Extended
HR7.10
Insurance and liability disclosure Extended

How an assessment runs

01
Intake

Tell us who you are and what you host. We schedule a kickoff call from there.

02
Evidence

We request existing certifications and artifacts first. Each artifact you already hold removes questions from the interview.

03
Screening

Asymmetric Research engineers run an interview of 60 to 90 minutes covering the 48 Core controls.

04
Scorecard

We score each control from 0 to 3 and roll the results into pillar scores and a maturity band. You receive the scorecard privately, with prioritized recommendations.

05
Depth & re-assessment

The Extended controls apply where a provider hosts concentrated stake. Re-assessment tracks improvement over time.

Fast-track evidence

Artifacts that reduce the interview

Send what you already hold. Each artifact removes questions from the screening interview, and none is required to start.

SOC 2 Type II report

Access control, change management, monitoring, vendor management.

ISO/IEC 27001:2022 certificate + Statement of Applicability

ISMS scope, including the Annex A physical controls.

Uptime Institute Tier Certification (per site)

Facility redundancy for the certified site.

ISO 22301:2019 certificate

Business continuity and tested recovery objectives.

PCI DSS v4 Attestation of Compliance

Physical access controls (Requirement 9).

CSA STAR registry entry

Self-assessed cloud and data-center controls.

Penetration test summary covering the OOB / management network

Direct evidence for the management-plane pillar.

External scan attestation showing no internet-exposed BMC/IPMI

Direct verification of management-network isolation.

Generator full-load test report

Shows the power path has been tested under load.

Certificate of media destruction (sample)

Shows the sanitization process operates.

Sample remote-hands ticket with attached evidence

Dual control and evidence capture in practice.

Per-site upstream ASN / transit / IX list

Concentration disclosure against the delegation-program caps.

Software inventory for the delivered OS image

Every agent added to the stock distro, with privilege and egress.

Register of systems with credentials or reach into customer hosts

Blast radius, including decommissioned management systems.

Contract clause permitting removal of all provider agents

An enforceable opt-out with no SLA penalty.

OCP S.A.F.E. or Common Criteria report for deployed platforms

Independent firmware and hardware review.

Certificate of insurance with limits and exclusions

Residual risk transfer for tenant hardware.

The assessment starts with a short intake form and a single screening interview.

Request a STRIDE HW assessment