Skip to content
SpaceFile

Capacity & sizing

How much satellite do we actually need to buy?

This page does the arithmetic in public. It starts from the ledger's own numbers, derives the compute, power, storage and bandwidth one orbital node requires, checks that envelope against the published specifications of real third-party cubesat platforms, and ends with how many nodes and how much rented capacity each phase of the network needs.

10 W per node256 GB per node8 buses for full fault toleranceAssumptions stated, not hidden

Scope of the orbital tier

Put in orbit only what has to be in orbit.

The economics of this network depend on a narrow definition of the orbital workload. Everything below is what a node does — and, just as importantly, what it does not.

Checkpoint validation

Continuous, low duty cycle

Verify the aggregate signature over each 10-second checkpoint and counter-sign it. This is the notarisation product: proof that a batch of transactions existed at a time, witnessed off-planet.

Store-and-forward transaction relay

Burst during passes

Accept signed transactions from wallets and Connectivity Boxes with no terrestrial path, hold them, and inject them into the network on the next contact.

Independent time and position witness

Per checkpoint

Attach a GNSS-disciplined timestamp and orbital state to each anchor, so the record cannot be back-dated by anyone holding terrestrial infrastructure.

Cold survival copy of the chain head

Write-mostly archive

Hold a pruned, self-verifying copy of the checkpoint chain so the ledger can be reconstructed after a terrestrial loss event.

Deliberately not in orbit

  • Full transaction execution at peak throughput — terrestrial validators carry the peak; orbit carries the proof.
  • The full historical archive — an unpruned chain grows at roughly 100 GB per day at design throughput and belongs in SuperFile Cloud.
  • Customer-facing latency — a payment confirms terrestrially in seconds and is anchored in orbit afterwards.
  • Heavy AI inference — that moves to orbital data-centre capacity only when it can be rented, in a later phase.

The ledger arithmetic

From transactions per second to bytes and watts.

Each row is an explicit planning assumption. Change one and the numbers below it move; nothing here is asserted without the calculation that produced it.

QuantityValueHow it is derived
Signed transaction, post-quantum≈ 2.8 kB raw / ≈ 300 B batchedA Dilithium-2 signature is 2,420 bytes. Inside a checkpoint, signatures aggregate and the per-transaction cost falls to roughly 300 bytes.
Design throughput, whole network5,000 tx/s sustained, 17,000 tx/s burstSustained figure is the planning number for the network as a whole across terrestrial and orbital validators.
Share of traffic routed via satellite5% ≈ 250 tx/sOnly users with no terrestrial path use the orbital relay. This is the number that sizes the radio, and it is small.
Relay bandwidth needed≈ 0.6 Mbps aggregate250 tx/s × 300 B ≈ 75 kB/s. A single S-band link at 2 Mbps carries the entire orbital relay load with margin.
Checkpoint rate and size8,640 / day × ≈ 4 kBOne checkpoint every 10 seconds: header, Merkle root and aggregate signature. Roughly 35 MB of chain state per node per day.
Pruned chain growth per node≈ 12.6 GB / yearCheckpoint chain only. Ten years of anchors is about 126 GB — one radiation-tolerant NAND module.
Rolling transaction cache≈ 45 GB (7 days)250 tx/s × 300 B held for a week, so a node can serve replay to a region that has been offline.
Storage specified per node256 GBPruned chain plus cache plus wear and redundancy margin. Well inside a single 1U slice.
Signature verification load≈ 0.5 CPU core at peakA 1.5 GHz ARM core verifies on the order of 10,000 Dilithium signatures per second; a checkpoint of 50,000 transactions verifies in well under a second.

One node, itemised

The resulting hardware envelope. This is the specification we take to a hosting provider.

Compute

Quad-core rad-tolerant ARM SoC, 4 GB ECC RAM

6 W average

Crypto acceleration

FPGA lattice-signature core (optional in phase 1)

2 W average

Storage

256 GB rad-tolerant NAND, triple-redundant metadata

1 W average

Radio use (payload share)

S-band, ≈ 2 Mbps during contact

8 W peak, duty-cycled

Thermal and margin

Conductive path to bus radiator, 30% reserve

1 W

Node total

≈ 1.2 kg, ≈ 1.5U (100 × 100 × 150 mm)

10 W orbit-average, 18 W peak

Orbit-average power of 10 W is about 240 watt-hours a day — comfortably inside the generation of a 6U bus with deployable panels, and a fraction of a 16U bus.

The result

The node fits inside every platform we would want to fly on.

10 watts, 1.2 kilograms and 1.5U against buses that publish 10–60 watts and 7–24 kilograms of payload capacity. The margin is the point: it means we are a welcome, low-risk tenant rather than a demanding one.

Platform fit

What each third-party platform could carry.

Capability figures are taken from public supplier datasheets and product pages current in 2026, and are indicative rather than contractual. Node counts assume the 10 W / 1.5U envelope above with 30 percent reserve.

Spire — LEMUR 3U software slot

Best first step

5–10 W payload power · software-defined slot · no hardware to build

1 node

Fits the 10 W node with nothing to launch. Spire's Space as a Service sells exactly this: your flight software on their existing satellite. This is the cheapest credible first node and the natural way to re-fly the 2020 signature.

Spire — LEMUR 16U configuration

Scale-up on the same bus

Up to 24 kg / 16U class · high-rate downlink · on-orbit processing

3–4 nodes

Enough power and volume to host a redundant node pair plus the store-and-forward cache. Same operator as the 3U slot, so one integration effort covers both.

EnduroSat — 6U platform

Comfortable

10–30 W average payload power · 7.2–7.8 kg · 197 × 197 × 225 mm

1–2 nodes

A commodity bus with a published interface document. One node uses a third of the available power and under a quarter of the payload volume, which leaves headroom for the radio and a second cold node.

EnduroSat — 16U platform

Best capacity per satellite

25–60 W average payload power · 24 kg payload · 218 × 218 × 254 mm · up to 1 Gbps payload downlink

3–5 nodes

The most headroom per pound in the cubesat class. A gigabit-class downlink makes bulk archive sync possible, not just checkpoint anchoring, and there is power left for an inference accelerator later.

Loft Orbital — Hub on YAM / Longbow

Lowest execution risk

ESPA-class bus · standardised Hub payload interface · mission-managed operations

4–8 nodes

Our node ships as a qualified module against a documented interface, and Loft flies and operates it. Highest capacity per bus, and the route that removes the most programme risk — at a higher fixed price.

D-Orbit — ION carrier

Demonstration only

Hosted payload slots on an orbital transfer vehicle

1 node

A months-long in-orbit demonstration without committing to a bus. Right for proving the node, wrong for permanent capacity because ION missions are finite.

Iridium — Certus 9704 (ground side)

Wallet uplink

Pole-to-pole messaging · tens of kbps · hosted-payload heritage on all 66 satellites

n/a — user link

Not a place to host the ledger, but the cheapest way for a wallet to reach it: a 300-byte batched transaction crosses a Certus link in a fraction of a second, anywhere on Earth.

Starlink / OneWeb / Amazon Leo

Bought connectivity

Mbps to Gbps ground backhaul, bought as a service

n/a — backhaul

These are the pipes for Connectivity Boxes and ground stations. We buy transit; we do not host nodes on them.

How many satellites

Coverage geometry, then consensus, then cost.

The instinct is to size the constellation from coverage. For an anchoring network that is the wrong starting point, and it is the difference between a $30M programme and a $6M one.

One satellite sees a 1,160 km circle

At 550 km altitude with a 25° minimum elevation mask, the usable ground footprint is roughly 580 km in radius. That is the geometric fact everything else follows from.

Continuous equatorial coverage would need ~35 satellites

The equator is 40,075 km around. Filling it continuously from a single low-inclination plane takes on the order of 35 spacecraft — a constellation programme, not a first raise.

Anchoring does not need continuity — it needs availability

A payment settles terrestrially in seconds and is anchored afterwards. With 8 satellites at ~20° inclination, an equatorial site gets 12–16 contacts a day and a worst-case gap under two hours, which meets the anchoring latency budget with room to spare.

Consensus sets the floor, not coverage

Byzantine fault tolerance needs 3f+1 nodes: 4 to survive one failure, 7 to survive two. Nodes must sit on independent buses, because two nodes on one satellite fail together. Eight nodes on eight buses is the smallest configuration that is genuinely fault-tolerant.

Four configurations, priced

Costs combine the node envelope above with published hosted-payload and rideshare pricing. They are planning ranges for the capital plan, not quotations, and every configuration is fundable on its own.

ConfigurationNodesWhat we buyIndicative costWhat it gives us
A — Demonstration1 node1 software slot (Spire) or one ION mission$0.2M – $0.6M one-offRe-flies the 2020 in-orbit signature with post-quantum signing. No launch, no hardware, no constellation.
B — Minimum fault-tolerant quorum4 nodes4 software slots across 2 operators$1.0M – $2.2M + ≈ $0.3M / yrSurvives one node loss. Enough to issue commercially meaningful notarisation with an orbital witness.
C — Equatorial anchor cluster8 nodes on 8 independent busesMixed: 4 software slots + 4 hosted modules on 6U/16U buses$6M – $12M + ≈ $0.6M / yrSurvives two simultaneous failures, 12–16 contacts per day over the tropics. This is the target configuration of the plan.
D — Continuous coverage24–35 nodesDedicated and shared satellites, replenished from an equatorial range$30M+Only funded once traffic, sovereign contracts and unit economics prove ownership beats renting.
Configurations B–D plannedConfiguration A repeats a result already achieved in orbit in December 2020.

Rented capacity

Ground time and bandwidth, bought by the minute.

The orbital tier moves very little data, which is why the ground segment is a subscription rather than a construction project.

Downlink volume per satellite

≈ 250 MB / day

Checkpoint chain plus relayed transactions plus housekeeping. Tiny by Earth-observation standards, which is why pass time is cheap for us.

Contact time required

≈ 17 min / satellite / day

250 MB at 2 Mbps S-band. Spread over 4–6 short passes for latency, not for volume.

Ground segment cost, cluster C

$0.3M – $0.8M / yr

Leased pass time from commercial ground-station-as-a-service networks plus a software mission-operations centre. No teleport is built.

Terrestrial capacity per Connectivity Box

$50 – $250 / month

Starlink, OneWeb or Iridium transit sized to the site. Scales with revenue, not ahead of it.

Cost per anchored checkpoint

fractions of a cent

Cluster C runs 8,640 checkpoints a day. Against roughly $1.0M a year of orbital operating cost, each anchor costs well under a cent — and each anchor covers up to 50,000 transactions.

Sensitivity

What breaks the model, and what does not.

The sizing is deliberately conservative. These are the four assumptions most likely to be wrong, and what each one would actually cost us.

If satellite-routed traffic is 4× our estimate

1,000 tx/s over the relay is 2.4 Mbps. It fits the same S-band radio at a higher duty cycle and adds pass minutes, not satellites.

If post-quantum signatures get larger

Storage and bandwidth scale linearly and are both an order of magnitude below platform limits. A 3× signature growth still fits a 6U bus.

If a supplier withdraws

Every fit in the table above is met by at least three unrelated suppliers. The node is specified against a power and volume envelope, not against one vendor's bus.

If launch prices stop falling

Configurations A and B need no launch at all — they are software on satellites already in orbit. Launch cost only enters at configuration C.

Sizing FAQ

The engineering questions investors ask.

How can a whole blockchain run on 10 watts?

Because the orbital node does not run the whole blockchain. It validates and counter-signs one checkpoint every ten seconds and relays a few hundred transactions a second. Verifying a lattice signature costs on the order of a hundred microseconds of CPU time; the workload is tiny compared with the imaging and radar payloads these same buses fly every day.

Why 8 satellites rather than a full constellation?

Eight independent buses is the smallest configuration that tolerates two simultaneous node failures under Byzantine fault tolerance, and at ~20° inclination it already gives every equatorial site 12–16 contacts a day. Continuous coverage needs roughly 35 spacecraft and buys latency we do not need, because settlement happens on the ground in seconds and orbit anchors it afterwards.

Where do the platform numbers come from?

Public supplier datasheets and product pages as of 2026 — EnduroSat's 6U and 16U platform specifications, Spire's LEMUR and Space Services material, Loft Orbital's Hub interface documentation and Iridium's Certus module data. They are indicative planning figures, not quotations, and any real mission would be sized against a signed interface control document.

Is storage a problem after ten years?

No. The orbital node keeps a pruned, self-verifying checkpoint chain — about 12.6 GB a year. Ten years of anchors fits in 126 GB. The unpruned archive, which grows around 100 GB a day at design throughput, lives in SuperFile Cloud across sovereign terrestrial regions.

What is the cheapest path to a real, useful orbital node?

A software slot on a satellite that is already flying. No bus, no launch, no licence of our own, and a cost measured in hundreds of thousands rather than millions. Configuration A can be contracted and flown without any of the constellation capital in the plan.

Sources and basis: EnduroSat 6U and 16U platform specifications; Spire LEMUR platform and Space Services material; Loft Orbital Hub payload interface documentation; D-Orbit ION hosted-payload material; Iridium Certus 9704 module data; published rideshare pricing. All figures on this page are planning estimates derived from public information as of 2026 and are not quotations, offers or contractual commitments.