Trust Center - Blockdaemon
Blockdaemon
Blockdaemon empowers businesses to manage and deploy blockchain applications through the organization's node management platform. Our platform offers a multi-chain, multi-cloud network management tool that can deploy nodes and provide infrastructure that reduces the complexity of working with blockchains while offering faster deployment times and lower cost.
Industry-leading financial institutions, exchanges, custodians, cryptocurrency platforms, and developers trust Blockdaemon as their onramp to over 70 blockchain protocols; making us the number one institutional staking provider by volume.
Blockdaemon was founded in 2017 and is headquartered in Los Angeles.
Controls
Updated 12 minutes ago
Infrastructure security
| Control | Status |
|---|---|
| Production Database Authentication — Secure and Unique Credentials The company requires all authentication to production datastores to use approved, secure mechanisms (OIDC). |
|
| Privileged Access Restrictions — Production Systems and Authorized Users Privileged access to production systems, including applications, databases, operating systems, networks, firewalls, and deployment mechanisms, is restricted to authorized users with a documented business need. |
|
| Access Control Procedures — Requesting, Approving, and Removing Access The company maintains documented access control procedures that define how user access is requested, approved, modified, and removed for in-scope systems. |
|
| Intrusion Detection System Utilized Intrusion detection rules are configured to alert on suspicious activity. Identified alerts are logged, tracked, and resolved. In the event anomalous activity is identified within audit logs, alerts are automatically generated and follow-up actions comply with a documented incident response procedure. |
|
| Firewall Configuration — Unauthorized Access Prevention The company deploys and maintains firewalls to restrict unauthorized network access to production systems and customer data. Firewall rules are configured based on least-privilege principles, denying traffic by default and permitting only authorized connections. Configuration changes follow the change management process. |
|
| DVT Architecture — Validator Resilience and Node Failover A DVT architecture is in place, distributing validator signing duties across multiple independent nodes within a cluster. In the event of an individual node failure, signing responsibilities automatically continue via the remaining nodes without key migration or validator downtime. Validator failover and recovery procedures are documented, defining activation criteria, recovery steps, and communication requirements, and are reviewed at least annually or following a material change or outage event. |
|
| DVT Client Diversity — Consensus and Execution Client Resilience The DVT architecture supports diverse, independent client configurations across nodes — including diverse consensus and execution client implementations. This design ensures the cluster can continue performing validator duties in the event of a client-level bug or failure affecting one or more nodes. Client substitution can be performed without key migration or significant downtime, and the specific client mix per cluster is determined based on operational requirements including performance, reliability, and client maturity. |
|
| Redundancy & Resiliency Configuration — Availability Systems Monitored Systems supporting availability and resiliency are continuously monitored for uptime, resource utilization, validator duplication events, and health status. Alerts are routed to the on-call team and reviewed within a defined response window. Failover and recovery processes are periodically tested and documented to verify effectiveness and alignment with business continuity requirements. |
|
| Validator Infrastructure Monitoring and Alerting Validator infrastructure is continuously monitored with alerting configured to detect canonical chain isolation indicators, including beacon node connectivity loss, synchronization divergence, and abnormally low peer counts. Emergency reconfiguration procedures are in place and executed against approved guidance when triggered. |
|
| Infra Resilience — Multi-Region Deployment Capability Validator infrastructure can be deployed across multiple geographic regions and infrastructure providers, reducing single-region dependency. Multi-region deployment is available as an architectural capability and is confirmed and documented at client engagement based on operational requirements. |
Organizational security
| Control | Status |
|---|---|
| [CCF] Secure Media Sanitization & Equipment Disposal Assets containing sensitive company or customer data are sanitized or destroyed prior to disposal, return, or reuse using documented wiping or destruction procedures. Sanitization or destruction is performed by authorized personnel or approved vendors and is evidenced through logs, tickets, or certificates of destruction. |
|
| Code of Conduct — Maintained, Communicated, and Enforced The company maintains a formal Code of Conduct approved by management and accessible to all personnel, defining expected ethical behavior and compliance obligations. Employees are required to acknowledge the Code of Conduct upon onboarding and upon any material change to either document. Contractors are required to execute a Consulting Agreement upon engagement, which includes binding obligations related to conduct, confidentiality, security, and proprietary information handling. Processes are in place to report, investigate, and address violations in accordance with documented procedures. |
|
| Personnel Performance Evaluations — Periodic and Documented The company maintains a documented process for conducting periodic performance evaluations for personnel to assess role responsibilities, conduct, and compliance with company policies. Performance evaluations are performed in accordance with this process, with exceptions documented and approved where applicable. |
|
| MDM system utilized The company has a mobile device management (MDM) system in place to centrally manage mobile devices supporting the service. |
|
| Role-Based Access Control and Privileged Access Provisioning Access to systems, applications, and data is provisioned based on job role and least-privilege principles. Access requests require documented approval before provisioning. Privileged access is granted only where business need is established and is subject to additional scrutiny during the approval process. Access rights (including privileged access) are reviewed on a defined cadence, and modified or revoked promptly when a role change or termination occurs, in accordance with access control procedures. |
|
| Access Management Policy Review The Access Management Policy is reviewed and approved by management on an annual basis to ensure it remains current, accurate, and aligned with the organization's security requirements. Updates are made as necessary to reflect changes in the environment, risk landscape, or regulatory requirements. |
|
| Annual Key Holder Security Training Annual security training is conducted specifically for key holders, covering key-handling procedures, phishing awareness, and physical security. Training content is reviewed and updated annually to reflect current threats, security advancements, and changes to key management policies and procedures. |
|
| Clear desk and clear screen As a remote-first company, the company maintains documented requirements for personnel working from home or coworking environments. Requirements include use of private workspaces, locked and unattended device controls, and clean desk practices to protect access to sensitive systems and data. Requirements are communicated to personnel at onboarding. |
|
| Information Security Policy Framework The organization defines, approves, and maintains a comprehensive set of information security and topic-specific policies covering access control, awareness and training, audit and accountability, security assessment and authorization, configuration management, contingency planning, identification and authentication, incident response, maintenance, media protection, physical and environmental protection, planning, personnel security, risk assessment, system and services acquisition, system and communications protection, and system and information integrity. |
|
| Personnel Onboarding The company maintains documented Human Resources onboarding procedures to ensure new personnel are formally onboarded, including timely notification to IT to support access provisioning. Personnel are required to acknowledge the Acceptable Use Policy, Code of Conduct, and relevant security policies, with any exceptions documented and approved where applicable. |
Product security
| Control | Status |
|---|---|
| Secure Software Development Lifecycle (SDLC) Training All personnel with a role in the software development lifecycle, including developers, testers, and product managers, must complete mandatory and role-relevant secure development training on an annual basis. The training program's content will cover attacker methodologies, defensive principles, and the use of our internal security tools to effectively mitigate risk. Training completion and skills mastery must be verified and documented. |
|
| Automated Security Scanning — SAST, IaC, Dependency, and Container Analysis All code pushes, builds, and releases must pass automated security scanning prior to deployment. Scanning includes Static Application Security Testing (SAST), Infrastructure-as-Code (IaC) analysis, dependency vulnerability scanning, and container image scanning. Scanning is enforced through the CI/CD pipeline using Snyk. Releases that fail scanning are blocked from deployment until findings are reviewed and remediated. Evidence includes pipeline scan results, pass/fail records, and remediation logs. |
Internal security procedures
| Control | Status |
|---|---|
| Business Continuity & Disaster Recovery Testing — Annual Validation The BC/DR plan is tested at least annually through tabletop exercises, simulations, or live failover tests. Test results are documented, findings are tracked to resolution, and the plan is updated to reflect lessons learned. |
|
| Cybersecurity Insurance — Risk Transfer and Annual Coverage Review The company maintains cybersecurity insurance coverage to mitigate the financial impact of security incidents and business disruptions. Coverage scope, limits, and terms are reviewed at least annually to ensure alignment with the company's current risk profile. |
|
| Secure Development Policy Implementation The company has a Secure Development Policy in place that governs the development, acquisition, implementation, changes (including emergency changes), and maintenance of information systems and related technology requirements. |
|
| Whistleblower policy established The company has established a formalized whistleblower policy, and an anonymous communication channel is in place for users to report potential issues or fraud concerns. |
|
| Board oversight briefings conducted The company's board of directors or a relevant subcommittee is briefed by senior management at least annually on the state of the company's cybersecurity and privacy risk. The board provides feedback and direction to management as needed. |
|
| Board charter documented The company's board of directors has a documented charter that outlines its oversight responsibilities for internal control. |
|
| Board expertise developed The company's board members have sufficient expertise to oversee management's ability to design, implement and operate information security controls. The board engages third-party information security experts and consultants as needed. |
|
| Board meetings conducted The company's board of directors meets at least annually and maintains formal meeting minutes. The board includes directors that are independent of the company. |
|
| Customer Data Backup & Recovery — Policy-Governed and Validated The company maintains a documented backup policy defining requirements for the backup and recovery of customer data, including backup frequency, retention periods, storage requirements, and recovery objectives. Backup processes are executed in accordance with the policy and validated periodically through recovery testing. |
|
| System changes externally communicated The company notifies customers of critical system changes that may affect their processing. |
Data and privacy
| Control | Status |
|---|---|
| Data retention procedures established The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data. |
|
| Data classification policy established The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel. |
|
| Data Encryption at Rest Customer data stored in production datastores is encrypted at rest using approved encryption mechanisms. |
|
| Customer Data Backup & Recovery — Policy-Governed and Validated The company maintains a documented backup policy defining requirements for the backup and recovery of customer data, including backup frequency, retention periods, storage requirements, and recovery objectives. Backup processes are executed in accordance with the policy and validated periodically through recovery testing. |
|
| Data Backup Scheduling & Monitoring — Automated Alerts to IT Operations System and data backups are systematically scheduled and executed in accordance with documented backup policies, covering configurations, chain state, local anti-slashing databases, and general IT backups including databases and file servers. Alerts are configured to notify the appropriate team of backup completion status and failures. |
|
| Production Database Authentication — Secure and Unique Credentials The company requires all authentication to production datastores to use approved, secure mechanisms (OIDC). |
|
| Restrict use of confidential data in development environments Confidential and personal data is not utilized in development and testing environments unless prior authorization is provided. Authorization requires a user provisioning process that assesses confidentiality requirements. |
|
| Communicate unauthorized personal data use incidents as required Events that resulted in unauthorized use or disclosure of personal information are communicated to the data subjects, legal and regulatory authorities, and others as required. |
|
| Use DLP technologies to restrict unauthorized information movement Data loss prevention processes and technologies are used to restrict ability to authorize and execute transmission, movement and removal of information. |
|
| Designate Information Security Office for data security The organization has designated an Information Security Office to implement and monitor data security and privacy concerns. |