ASIC hosting security covers custody of valuable hardware, access to pool and wallet configuration, remote dashboards, facility power controls, customer records and the evidence needed after an incident. A SOC 2 report can provide independent assurance over stated controls for a defined system and period, but it is not a universal data-centre certification and does not replace serial ownership, insurance, physical controls, contractual access or tested hardware return.
Map the assets and control points
Reassess ASIC hosting security whenever network conditions, firmware, tariffs or official guidance changes.
List each miner, PSU, serial number, owner, rack or container location and custody status. Add customer portal accounts, pool credentials, payout addresses, network equipment, firmware, logs, invoices and personal data.
Identify who can enter the site, move hardware, change pools, update firmware, power down a unit, alter billing or export data. Security fails when these powers are treated as one administrator role.
| Area | Control | Evidence |
|---|---|---|
| Custody | Serial intake, location and movement approval | Signed inventory and movement log |
| Physical | Layered perimeter, visitor and rack controls | Access records and alarm tests |
| Accounts | Individual identity, 2SV and least privilege | Role register and access review |
| Mining | Approved pool and wallet changes | Change log and pool confirmation |
| Network | Segmentation and restricted management | Diagram, rules and vulnerability results |
| Incident | Notification, evidence and recovery | Plan, exercises and retained logs |
Verify the operator and facility
When reviewing ASIC hosting security, separate measured facts from forecasts so the result can be reproduced.
Confirm the contracting entity, company registration, address, directors, bank beneficiary, site operator, electricity counterparty and any subcontractor. A sales office is not proof of the mining location.
Obtain evidence that the host can lawfully occupy and operate the site and accept your equipment. Check planning, electrical, fire, environmental and insurance responsibilities relevant to the facility.
A site visit can help with commercial due diligence but should not be universally available. A secure operator restricts facility access to people with a need, with controlled exceptions and evidence.
Protect physical custody
Use photographed serial intake, tamper and condition records, rack assignment and an authorised movement process. Reconcile inventory periodically and after every repair or relocation.
Separate customer hardware from spare or operator-owned stock in records. Replaced hashboards and parts need serial or identifying evidence and an agreed ownership rule.
Control keys, badges, visitors, delivery areas and contractor access. Retain records long enough for a dispute or incident without exposing them unnecessarily.
Secure accounts and pool destinations
Give each user an individual account with the minimum role. Require two-step verification and an owned recovery path. Remove staff and customer access promptly when roles end.
Treat payout address, pool account, firmware and fleet-power changes as high risk. Require a second approval or out-of-band confirmation, preserve the previous value and notify the owner.
Never store private wallet keys on miners or ordinary hosting dashboards. The host needs a payout address or pool worker, not custody of the customer’s private key.
Segment and maintain the mining network
Keep miners and management services away from office, payment and customer systems. Restrict administration to managed hosts or a secure access service rather than public web interfaces.
Maintain firmware, proxies, VPNs, dashboards and network equipment. Record approved versions, backups and recovery. Test updates on a representative group before the fleet.
Monitor outbound destinations, failed logins, configuration changes, unexpected firmware, scans and loss of logging. Pool hashrate can reveal an operational incident even when the dashboard appears online.
Define incident response
The contract should state what counts as a security incident, who is notified, the maximum notification time, evidence preservation, customer communication, investigation, recovery and cost responsibility.
Retain system, account, access, network, pool, power and hardware-movement logs with synchronised time. NCSC guidance notes that investigations are often hindered by missing log data.
Exercise realistic events: unauthorised wallet change, stolen miner, compromised firmware, dashboard breach, lost VPN credential, fire-zone isolation and subcontractor incident.
Understand SOC 2 accurately
SOC 2 is an assurance report by an independent service auditor on controls relevant to the AICPA Trust Services Criteria, which can include security, availability, processing integrity, confidentiality and privacy.
A Type 1 report addresses control design at a point in time; a Type 2 report also examines operation over a stated period. Read the actual report or an appropriate bridge letter under confidentiality, not only a badge.
Check the named legal entity, system description, locations, services, subservice organisations, criteria, period, auditor opinion, tests, exceptions and complementary customer controls. A report for an office SaaS product may not cover the mining facility.
Use assurance when no SOC 2 exists
A host without SOC 2 is not automatically insecure, and a host with a report is not automatically suitable. Obtain policies, control evidence, external testing, incident exercises, access reviews, insurance and references proportionate to risk.
NCSC supplier-assurance guidance recommends understanding security ownership, network and data protection, personnel and physical controls, incidents and independent testing.
Record gaps and contractual actions. Never describe a facility or The Mining Shop UK as SOC 2 or ISO certified when that accreditation has not been awarded for the relevant scope.
Check insurance and loss allocation
Obtain insurer, policy scope, insured perils, territory, customer-owned-equipment treatment, valuation basis, exclusions, excess and claims process. A certificate without wording may not answer these questions.
The contract should address used-market valuation, excess, underinsurance, business interruption, cyber events, theft, transit and force majeure. Mining revenue should not be assumed covered.
Confirm whether hardware remains insured during repair, relocation and return shipping, and which party arranges each journey.
Test termination and return
Security includes a controlled exit. Define notice, final billing, power-down, data export, credential removal, packaging, insured return, unpaid balances and hardware not collected.
Request an inventory and settings export before termination. Change pool, portal, VPN and support credentials after return and inspect firmware.
A host that cannot explain how a customer retrieves identified hardware is not ready to hold it.
Common hosting-security mistakes
- Treating CCTV as the complete security programme.
- Using shared dashboard accounts without 2SV.
- Giving technicians unrestricted wallet-change authority.
- Keeping private wallet keys in the hosting portal.
- Accepting a SOC 2 logo without scope or period.
- Ignoring subcontractors and remote management providers.
- Failing to reconcile serials after repair or relocation.
- Signing without an incident or hardware-return process.
Frequently asked questions
What should an ASIC host protect?
Customer hardware, pool and payout settings, accounts, network controls, logs, personal data, billing records and custody evidence.
Should a host hold my private wallet key?
No. A normal mining host needs a payout address or pool worker, not the private key.
What is a SOC 2 Type 2 report?
An independent report examining described controls and their operation over a stated period under selected Trust Services Criteria.
Does SOC 2 certify a data centre?
It provides assurance over the system and scope in the report. It is not a universal facility certification.
Can a secure host ban customer visits?
Yes. Restricting routine visits can support physical security, while suitable audit evidence or controlled exceptions can provide assurance.
What security logs matter?
Physical access, accounts, configuration, network, pool, power, alarms, incidents, repairs and hardware movement.
How do I verify hardware ownership?
Use invoice, serial intake, photographs, location history, repair records and a contract stating title and return rights.
Conclusion
ASIC hosting security is a chain of custody and control, not a single camera or certificate. Verify the operator, site and subcontractors; record every serial; restrict physical, account and pool-change powers; segment the network; retain useful logs; and test incidents and exit. SOC 2 can add independent assurance only when its exact system and period cover the service. Contractual evidence and daily controls remain essential.
Next steps
Use The Mining Shop UK’s hosting terms, verification page, security guidance and acceptable-use policy as a due-diligence pack, then request the site-specific controls and evidence before deploying customer hardware.
Conclusion: ASIC hosting security
Verify the legal operator, facility, serial custody, staff and visitor controls, insurance and hardware-return process before sending miners. Use individual accounts, two-step verification, least privilege, approved pool changes, segmented networks, logs and a defined incident-notification time.
Sources and further reading
- AICPA SOC suite resources: Primary SOC 2, SOC 3 and Trust Services Criteria scope.
- NCSC supplier assurance questions: UK supplier governance, physical, personnel, network, incident and testing questions.
- NCSC cloud asset protection and resilience: UK physical-security and assurance-scope principles.
- NCSC choosing a managed service provider: Current UK access, 2SV, logging, SLA and incident due diligence.
- NCSC technical incident response: UK logging, evidence and response-capability guidance.
- NCSC supply-chain mapping: UK subcontractor, incident, audit and access-control clauses.
