Operator client
One command-line client configures, runs and inspects a validator or node. Configuration comes from the environment; keys are referenced, never stored on the host.
Validators and node operators
Validators secure the settlement layer of ORBITRA ONE™. Under QSE, they accept explicit duties, prove the service they deliver and sign the transitions that make trades, transfers and contracts final.

Quorum-Staked Execution
QSE is a HotStuff-family BFT composition. Stake provides economic security, authority defines proposer and committee duties, and verified work measures availability, validation and service. It is not proof-of-work mining.
Validator votes
Quorum certificate
Finalized state
7 / 10
Stake, authority and verified work flow into the validator set. Validators vote on the same state transition; once the configured Byzantine quorum has signed, the votes combine into a quorum certificate and the state is final — with no reorganization after finality under the stated fault model.
Roles
Orders the transitions produced by VectorLanes into a proposal and sends it to the committee. Authority rotates the role according to validator policy.
Re-executes each proposal, checks the resulting state root and signs a vote. When the configured quorum signs the same transition, the votes form a quorum certificate.
Replays every finalized transition and serves state, history, index streams and proofs to applications, wallets and institutional systems.
Verified work
Stake alone does not define a validator’s role. QSE measures the work each operator actually performs and feeds it back into duties and rewards.
Accountability
Stake creates slashing exposure for provable misbehavior, such as signing conflicting transitions. The evidence is verifiable by any participant, so penalties follow protocol rules rather than operator discretion.
Weak service is treated differently from misbehavior. Sustained gaps in availability or validation lower an operator’s verified-work measurements, which in turn shape future duties and rewards.
Client diversity protects the network from correlated failure. Formal specifications allow independent implementations, so a defect in one client need not become a defect of the network.
Security posture
The validator security model keeps signing keys in hardware security modules or MPC signing services, apart from the host that runs the node. Separating keys from operations means a compromised machine cannot sign on its own.
Node software ships as signed releases that are verified before installation. When cryptographic standards evolve, Q-Switch rotates validator credentials through versioned signature suites and hybrid credentials rather than emergency re-keying.
Suite v1 · classical
Suite v2 · hybrid
Suite v3 · post-quantum ready
Tooling
Commands and configuration are covered in the developer documentation.
One command-line client configures, runs and inspects a validator or node. Configuration comes from the environment; keys are referenced, never stored on the host.
Assigned proposer and committee duties, quorum participation and missed duties, exposed for alerting.
Availability, validation and service-quality measurements, exported to your own monitoring stack.
Every release is signed, and the client checks signatures before an upgrade is staged.
Rewards
Validator rewards are potential, not promised.
Rewards depend on stake, duties performed, measured service quality and network parameters, and can be reduced by slashing. Operating a validator carries infrastructure, security and market risk. Validator services is one of the twelve AlphaStack channels; see the general risk disclosure.
Validator interest
Tell us about your infrastructure, your key-custody approach and your jurisdiction. Participation depends on eligibility and network parameters.