ASIC hosting security covers custody of valuable hardware, access to pool and wallet configuration, remote dashboards, facility power controls, customer records and the evidence needed after an incident. A SOC 2 report can provide independent assurance over stated controls for a defined system and period.
But it is not a universal data-centre certification and does not replace serial ownership, insurance, physical controls, contractual access or tested hardware return.
ASIC hosting security in simple English
ASIC hosting security is a chain of custody and control, not a single camera or certificate. Verify the operator, site and subcontractors.
Simple example
A site operator is checking ASIC hosting security. SOC 2 can add independent assurance only when its exact system and period cover the service. Never describe a facility or The Mining Shop UK as SOC 2 or ISO certified when that accreditation has not been awarded for the relevant scope.
Key terms in plain English
- ASIC:
- A computer built to do one specialised job. A mining ASIC is designed for a particular proof-of-work algorithm.
- Hashrate:
- The amount of mining work a machine attempts each second. More hashrate does not guarantee more profit.
- Mining pool:
- A service that combines work from many miners and shares rewards using stated rules.
- Firmware:
- Software stored on the miner that controls its hardware. Use a trusted source and check model compatibility.
- Wallet:
- Software or hardware that manages the keys used to control cryptocurrency. A wallet is not the same as an exchange account.
Map the assets and control points
List each miner, PSU, serial number, owner, rack or container location and custody status. Add customer portal accounts, pool credentials, payout addresses, network equipment, firmware, logs, invoices and personal data.
Identify who can enter the site, move hardware, change pools, update firmware, power down a unit, alter billing or export data. Security fails when these powers are treated as one administrator role.
| Area | Control | Evidence |
|---|---|---|
| Custody | Serial intake, location and movement approval | Signed inventory and movement log |
| Physical | Layered perimeter, visitor and rack controls | Access records and alarm tests |
| Accounts | Individual identity, 2SV and least privilege | Role register and access review |
| Mining | Approved pool and wallet changes | Change log and pool confirmation |
| Network | Segmentation and restricted management | Diagram, rules and vulnerability results |
| Incident | Notification, evidence and recovery | Plan, exercises and retained logs |
Verify the operator and facility
Confirm the contracting entity, company registration, address, directors, bank beneficiary, site operator, electricity counterparty and any subcontractor. A sales office is not proof of the mining location.
get evidence that the host can lawfully occupy and operate the site and accept your equipment. Check planning, electrical, fire, environmental and insurance responsibilities relevant to the facility.
A site visit can help with commercial due diligence but should not be universally available. A secure operator restricts facility access to people with a need, with controlled exceptions and evidence.
Protect physical custody
Use photographed serial intake, tamper and condition records, rack assignment and an authorised movement process. Reconcile inventory periodically and after every repair or relocation.
Separate customer hardware from spare or operator-owned stock in records. Replaced hashboards and parts need serial or identifying evidence and an agreed ownership rule.
Control keys, badges, visitors, delivery areas and contractor access. Retain records long enough for a dispute or incident without exposing them unnecessarily.
Secure accounts and pool destinations
Give each user an individual account with the minimum role. Require two-step verification and an owned recovery path. Remove staff and customer access promptly when roles end.
Treat payout address, pool account, firmware and fleet-power changes as high risk. Require a second approval or out-of-band confirmation, preserve the previous value and notify the owner.
Never store private wallet keys on miners or ordinary hosting dashboards. The host needs a payout address or pool worker, not custody of the customer’s private key.
Segment and maintain the mining network
Keep miners and management services away from office, payment and customer systems. Restrict administration to managed hosts or a secure access service rather than public web interfaces.
Maintain firmware, proxies, VPNs, dashboards and network equipment. Record approved versions, backups and recovery. Test updates on a representative group before the fleet.
Monitor outbound destinations, failed logins, configuration changes, unexpected firmware, scans and loss of logging. Pool hashrate can reveal an operational incident even when the dashboard appears online.
Define incident response
The contract should state what counts as a security incident, who is notified, the maximum notification time, evidence preservation, customer communication, investigation, recovery and cost responsibility.
Retain system, account, access, network, pool, power and hardware-movement logs with synchronised time. NCSC guidance notes that investigations are often hindered by missing log data.
Exercise realistic events: unauthorised wallet change, stolen miner, compromised firmware, dashboard breach, lost VPN credential, fire-zone isolation and subcontractor incident.
Understand SOC 2 accurately
SOC 2 is an assurance report by an independent service auditor on controls relevant to the AICPA Trust Services Criteria. This can include security, availability, processing integrity, confidentiality and privacy.
A Type 1 report addresses control design at a point in time. A Type 2 report also examines operation over a stated period. Read the actual report or an appropriate bridge letter under confidentiality, not just a badge.
Check the named legal entity, system description, locations, services, subservice organisations, criteria, period, auditor opinion, tests, exceptions and complementary customer controls. A report for an office SaaS product may not cover the mining facility.
Use assurance when no SOC 2 exists
A host without SOC 2 is not automatically insecure, and a host with a report is not automatically suitable. Get policies, control evidence, external testing, incident exercises, access reviews, insurance and references proportionate to risk.
NCSC supplier-assurance guidance recommends understanding security ownership, network and data protection, personnel and physical controls, incidents and independent testing.
Record gaps and contractual actions. Never describe a facility or The Mining Shop UK as SOC 2 or ISO certified when that accreditation has not been awarded for the relevant scope.
Check insurance and loss allocation
get insurer, policy scope, insured perils, territory, customer-owned-equipment treatment, valuation basis, exclusions, excess and claims process. A certificate without wording may not answer these questions.
The contract should address used-market valuation, excess, underinsurance, business interruption, cyber events, theft, transit and force majeure. Mining revenue should not be assumed covered.
Confirm whether hardware remains insured during repair, relocation and return shipping, and which party arranges each journey.
Test termination and return
Security includes a controlled exit. Define notice, final billing, power-down, data export, credential removal, packaging, insured return, unpaid balances and hardware not collected.
Request an inventory and settings export before termination. Change pool, portal, VPN and support credentials after return and inspect firmware.
A host that cannot explain how a customer retrieves identified hardware is not ready to hold it.
Common hosting-security mistakes
- Treating CCTV as the complete security programme.
- Using shared dashboard accounts without 2SV.
- Giving technicians unrestricted wallet-change authority.
- Keeping private wallet keys in the hosting portal.
- Accepting a SOC 2 logo without scope or period.
- Ignoring subcontractors and remote management providers.
- Failing to reconcile serials after repair or relocation.
- Signing without an incident or hardware-return process.
Frequently asked questions
What is the main point of ASIC hosting security?
ASIC hosting security is a chain of custody and control, not a single camera or certificate.
For ASIC hosting security, what should a beginner know about map the assets and control points?
List each miner, PSU, serial number, owner, rack or container location and custody status.
For ASIC hosting security, what should a beginner know about verifying the operator and facility?
Confirm the contracting entity, company registration, address, directors, bank beneficiary, site operator, electricity counterparty and any subcontractor.
For ASIC hosting security, what should a beginner know about protect physical custody?
Use photographed serial intake, tamper and condition records, rack assignment and an authorised movement process.
Key points to remember
ASIC hosting security is a chain of custody and control, not a single camera or certificate. Verify the operator, site and subcontractors. Record every serial. Restrict physical, account and pool-change powers. Segment the network. Retain useful logs. And test incidents and exit.
SOC 2 can add independent assurance only when its exact system and period cover the service. Contractual evidence and daily controls remain essential.
Next steps
Use The Mining Shop UK’s hosting terms, verification page, security guidance and acceptable-use policy as a due-diligence pack, then request the site-specific controls and evidence before deploying customer hardware.
Conclusion: ASIC hosting security
Verify the legal operator, facility, serial custody, staff and visitor controls, insurance and hardware-return process before sending miners. Use individual accounts, two-step verification, least privilege, approved pool changes, segmented networks, logs and a defined incident-notification time.
Sources and further reading
- AICPA SOC suite resources: Primary SOC 2, SOC 3 and Trust Services Criteria scope.
- NCSC supplier assurance questions: UK supplier governance, physical, personnel, network, incident and testing questions.
- NCSC cloud asset protection and resilience: UK physical-security and assurance-scope principles.
- NCSC choosing a managed service provider: Current UK access, 2SV, logging, SLA and incident due diligence.
- NCSC technical incident response: UK logging, evidence and response-capability guidance.
- NCSC supply-chain mapping: UK subcontractor, incident, audit and access-control clauses.



Join the ASIC Mining Discussion
Members can read and join the discussion
Log in to read comments from other miners. Create a free account if you would like to ask a question or share your experience.
Membership helps us protect the discussion from spam and keep answers useful.