We only ask for keys that are absolutely necessary in order to produce blocks. These keys do not give access to your ADA, your rewards address nor to make changes to your pool. You can always invalidate the uploaded keys by changing your VRF-key and update your KES-keys.
The VRF-key is used by the Cardano node to determine when the pool is allowed to create a block, and is necessary for block production.
Generating pool keys →The KES-key and OpCert is used by the Cardano node to sign the blocks that are created, so the Cardano Network can verify the legitimacy of it.
More on KES-keys →Your pools cold key should never touch an internet connected machine in any way. It's the master key for your stake pool. Always keep it offline.
About Cardano keys →A managed service is only safe if leaving it is trivial. Three ways, none of which need us.
Disable block production in the dashboard. It stops at the end of the current epoch and you owe nothing further.
Generate a new KES-key with your cold key and mint one block. What we hold is dead — no cooperation from us required.
KES-keys expire in roughly three months. If PoolMan vanished tomorrow, our access would lapse on its own.
Four epochs free on mainnet, or rehearse the whole thing on the Preview testnet at no cost.