Technical question regarding private keys on mainnet nodes


My organization, LunaNova Technologies, is just about to submit our application to be a foundation node.
We would be very interested in knowing the answer to the following:
Are mainnet nodes required to store online a private key that can control spending/moving of the staked DAG tokens or can this key live safely offline and the node only needs to operate with a lesser-privileged key that can’t move tokens?

