Your keys never leave the chain — TrueStake's security model
We designed TrueStake around a simple rule: if we don't need it, we don't collect it. Verifying your staking income never requires a private key, an exchange login, or your identity documents — so TrueStake never asks for any of them.
What TrueStake reads
TrueStake reads public on-chain data only. Your validator's public key, its balance history, and its withdrawal events are already visible to anyone running a beacon node or querying a block explorer — TrueStake reads that same public record, reconciles it to the wei, and turns it into an audit-defensible history.
What you give us
The only thing we ask for is a withdrawal address — public information, since it's written into your validator's on-chain credentials the moment you set them. That's it. We don't ask for a private key, a mnemonic, a keystore file, or any signing credential, because none of those are needed to read data that's already public.
What TrueStake never touches
- No private keys. Ever. Not held, not requested, not touchable. There's no field for one, no import flow, no "connect your wallet" step that requests signing authority.
- No exchange API keys. TrueStake doesn't connect to exchange accounts. It reads from the Ethereum chain, not from a trading platform.
- No KYC. No government ID, no SSN, no date of birth. A permanent product non-goal, not a deferred feature.
- No custody. TrueStake never holds, transmits, or has any claim on your ETH.
Why a withdrawal address is safe to give us
A withdrawal address is where your validator's exit and sweep payouts land — it identifies where funds go, but it can't authorize funds to move. Giving TrueStake your withdrawal address is like giving a CPA a copy of your bank statement: it lets us read what happened, and gives us no ability to make anything happen.
Read-only by design
TrueStake cannot transact, withdraw, or sign anything on your behalf. There's no code path that could — the product simply doesn't hold a signing key, so it structurally cannot originate a transaction. This isn't a permission we could misconfigure; it's a capability that doesn't exist.
How we treat this data internally
Even though your validator pubkey and withdrawal address are technically public on-chain, TrueStake treats them as sensitive personal data in our own systems — the linkage between those identifiers and your email address is exactly what we're built to protect. For the full picture of what we do and don't store and how account data is protected, see our security posture and what we don't collect.
Questions?
Email support@truestake.io if anything here is unclear, or if you want to understand exactly what a specific field in your account is used for.