
Inside the Compliance Stack: What Regulated Staking Actually Means
Co-authored by Uphold and Luganodes
A staking platform's yield is the figure customers notice first. Less visible is what the platform has actually verified about the infrastructure that produces that yield, and the gap between what a platform states and what it can demonstrate is where much of the risk in staking sits.
This article looks at the compliance framework that sits behind a regulated staking product. It is the part of staking an investor rarely sees, and it is also the part that determines what happens if something goes wrong.
Why does staking need a compliance framework at all?
Staking is a financial activity. It involves the movement of client assets, custody decisions, tax reporting obligations, and, in some jurisdictions, questions about whether the activity constitutes a regulated offering.
A regulated platform cannot route user assets to any validator and consider the job done. It remains accountable for every counterparty in the chain, and if a validator is poorly run, goes offline, is slashed, or fails a compliance check, the holder's principal is affected. Because the platform selected that validator, it carries responsibility for the choice.
This is the difference between a staking product built on a compliance framework and one that is not. The latter treats the validator as a technical detail; the former treats it as a fiduciary decision. The distinction is not always stated openly, but it is visible in the compliance documentation.
How does a licensed platform navigate staking obligations?
At Uphold, staking is a product decision rather than a purely technical one. The jurisdictions we serve shape each of those choices. Uphold holds licenses or registrations in the US, UK, EU, and Bahamas, and each jurisdiction sets its own rules on what constitutes a regulated staking activity, what disclosures are required, and how client assets held in staking positions must be treated.
Our staking disclosures describe risk in plain language, covering unbonding periods, slashing risk, protocol risk, and the difference between gross yield and net user yield, rather than confining them to footnotes.
Validator selection follows the same logic. We look for validators whose operational history, insurance coverage, and risk posture reduce the probability of a slashing event.
In selecting Luganodes, we relied on their zero-slashing-event track record, independent risk assessment via Quantstamp, and insurance coverage via Chainproof, each of which can be evidenced rather than simply asserted.
What does institutional-grade certification actually mean in practice?
Three credentials appear frequently in validator due diligence, and it is worth understanding what each one verifies.
ISO 27001 is an international standard for information security management. Certification means an external auditor has reviewed how an organization identifies security risks, implements controls, and manages them over time. The current version, ISO 27001:2022, covers areas such as access control, key management, incident response, and supply chain security.
SOC 2 Type II is a reporting framework, defined by the AICPA, for service organizations that handle client data. The important distinction is between Type I and Type II. A Type I report is a point-in-time assessment of whether the right controls are in place; a Type II report covers a period, typically six to twelve months, and tests whether those controls operated effectively throughout. Type II is the stronger credential because it reflects operational consistency rather than design alone.
GDPR alignment means the organization handles personal and client data in line with European data protection law. For an institutional client with European investors or operations, this governs what data a validator may hold, where it can be processed, and the notification obligations that apply in the event of a breach.
Luganodes also carries an independent slashing risk assessment via Quantstamp and insurance coverage via Chainproof.
Audits and certifications provide verifiable proof that an organization adheres to international security standards. However, since the risk of unforeseen events is never truly zero, insurance coverage serves as a critical safeguard for those rare instances.
Luganodes identifies as one of the first operators to maintain all these certifications at once.
What sits underneath the certifications?
Certifications provide a clear look at the controls of the infrastructure. Now we take a look at the operational infrastructure that actually delivers uptime and guards against slashing.
Luganodes runs bare-metal, single-tenant infrastructure on the networks where it operates. Single-tenant means that one client's workloads do not share hardware with another's, which changes the risk profile relative to shared cloud environments, where a misconfiguration in one tenant's setup can affect others. For validators, which must maintain strict uptime, single-tenant infrastructure reduces external points of failure.
Their nodes are also geographically distributed, which matters for three reasons: network resilience, since a regional outage does not take all nodes down at once; regulatory data residency, since some jurisdictions require client data to be processed within their borders; and incident isolation, since a physical failure in one location does not cascade to others.
Continuous monitoring, disciplined key management, formal change control, and a defined incident response process are the operational ground truth that certifications are designed to verify. A SOC 2 Type II audit, for instance, tests whether these processes actually ran as intended over the audit period.
All institutional clients also receive access to reporting APIs, a necessary feature for data accessibility.
What is non-custodial staking and why does it matter?
Non-custodial staking means the validator never holds your assets. You, or your custodian, retain control of the private keys, and the validator's role is limited to operating the node software that processes transactions on your behalf. At no point can the validator move, freeze, or access your principal.
This matters for two reasons. First, it removes the validator as a source of custody risk. If a custodial staking provider fails, becomes insolvent, or is compromised, the assets it holds are exposed; in a non-custodial arrangement, a validator's operational failure can affect rewards but not the principal itself.
Second, regulators have increasingly indicated that non-custodial structures sit more comfortably within existing frameworks for asset management and custody. The EU's MiCA regime, for example, distinguishes between custodial and non-custodial models in ways that affect licensing requirements.
Both Luganodes and Uphold operate within non-custodial structures, so your assets remain in your custody throughout. This is not an added feature but the basis on which the product is built.
Why should an investor care about any of this?
The compliance posture of the infrastructure behind a stake determines what happens in the rare cases where something goes wrong.
A slashing event, an outage, or a custody failure are low-probability events, but they are not zero-probability, and their consequences are real. The certifications, the insurance, and the non-custodial model are hence necessary credentials that actually define the floor of protection available to the holder in adverse scenarios.
When you stake through Uphold, you are relying on us to have carried out that due diligence on your behalf. The validator behind your stake holds a SOC 2 Type II audit, an ISO 27001 certification, an independent slashing risk assessment, and insurance coverage.
Luganodes takes the view that institutional-grade standards should not be reserved for large allocators, and that the infrastructure a sovereign wealth fund would require should be available to anyone staking their assets. That principle sits behind its operating model, and it is the standard to which we hold our validator partners, regardless of the size of the position on the other side of the stake.