
Co-authored by Uphold and Luganodes
In our previous piece, we examined the compliance stack behind regulated staking: the certifications, the custody model, and the regulatory frameworks that determine whether a staking product is sound. In this piece, we focus on Uphold's own fiduciary decision-making, and specifically on how we choose the partner that runs the infrastructure behind a customer's stake.
That choice is made well before a customer ever sees a dashboard or a yield figure, and this piece sets out the methodology behind it.
A fiduciary act, not a procurement exercise
Validator selection is a counterparty decision a platform makes on the customer's behalf. As we argued previously, that makes it a fiduciary act rather than a procurement exercise, and the distinction is not semantic. A procurement decision optimizes for price and convenience; a fiduciary decision begins from the obligation owed to the person whose capital is at stake.
The consequences of getting it wrong fall on the holder rather than on the platform that chose: missed rewards from downtime, slashing losses that reduce the staked principal, compliance gaps, or a custody failure. Because Uphold makes the choice, Uphold owns those outcomes, and we structure the decision accordingly.
Beyond the minimum bar
SOC 2 Type II, ISO 27001, and the rest, are the entry requirements. They establish that an operator is run with external oversight and can be assessed at all, and a validator that lacks them is not a candidate.
However, Uphold goes beyond clearing the minimum bar. Most operators that reach our compliance team already hold the certifications. The decision that matters happens above that threshold, in the judgment about operational quality, risk concentration, and conduct that no certificate captures.
The judgment calls behind the choice
Track record has to be read in context
Uptime is the figure most often quoted and the easiest to misread. 99.9% over three months on one network, from a recently launched operator, is not the same claim as 99.9% sustained across dozens of networks over several years. What we weigh most heavily is performance through network upgrades and protocol migrations, the moments when validators actually fail.
It is the kind of record we required of Luganodes, which has operated across more than forty proof-of-stake networks through successive upgrade cycles without a slashing event.
Assessment and insurance
Slashing is the failure mode that reduces principal directly, so we require two distinct safeguards rather than one: an independent risk assessment that measures the exposure, and insurance that covers it if an event occurs anyway. Luganodes holds both, a slashing risk assessment by Quantstamp and institutional insurance through Chainproof.
Concentration is a risk the platform absorbs
Stake distribution is another key decision. Routing all customer stake to a single operator, however capable, concentrates operational and counterparty risk in one place. We treat single-operator concentration as its own risk category and spread exposure across operators and networks. This is a cost we take on deliberately, because the alternative quietly transfers that concentration risk to the customer.
Stable rewards over high headline yield
A high advertised yield is easy to produce and hard to sustain. We prefer a lower, stable commission and a consistent payout history to an aggressive structure that changes, or one that reaches for headline numbers in ways that add operational risk.
The evaluation process also prioritizes Maximal Extractable Value (MEV) policies, as an operator's handling of this additional value has a direct effect on net yields.
Support as an operational function
When a network has an incident, what matters is whether the people running the infrastructure can diagnose and act on it directly, at any hour. We look for a dedicated site reliability function with round-the-clock coverage and defined escalation paths, and for direct contact between the operator's engineers and our own rather than a ticket queue. With Luganodes, that means a 24/7 SRE team that coordinates continuously with our team, so incidents are handled as operational events between engineers.
Keeping the decision honest over time
Choosing a validator is the start of the relationship, not the end of the diligence. We continue to monitor performance and compliance posture after selection and stay in close working contact with the operator, so the standards in place on the first day of operations are sustained, and improved on, as the partnership matures.
Where this leaves the customer
Individual stakers should understand how a platform selects and oversees the validator behind their stake, and should expect clear answers on its certifications, insurance, and how their principal is protected. That awareness is what lets a customer judge any platform, ours included.
At Uphold, we treat transparency about how we make these decisions as part of providing a trusted service, and we hold the experience of individual customers to the same standard as that of institutions. Our latest validator partner, chosen through exactly the diligence described here, is Luganodes, a non-custodial infrastructure provider with whom we share a commitment to quality operations, including this series on staking. If you have questions about any of it, we would be glad to hear from you.