Your bot can be wrong.
Your limits can’t.
Guard runs on your machine, between your bot and Hyperliquid. It sizes every order from its stop and says no to anything that breaks your rules. Quietly, until it matters.
The market, judged by your rules.
Every dot is a real trade on Hyperliquid, as it happens. Guard reads the trader’s public account and asks one question: would your limits have let it through?
Why Guard said no
- market not on your list0
- no protective stop0
- leverage above your cap0
- too close to liquidation0
- open risk above your limit0
- trader past the daily loss stop0
- trader past the drawdown halt0
- no stop: Guard set one, sized to your risk0
- resized: risk or size above your limit0
Refused, by market
- BTC0%
- ETH0%
- SOL0%
- HYPE0%
- ALTS0%
Decisions
| TIME | TRADER | TRADE | NOTIONAL | LEV. | STOP | LIQ. | HEAT | GUARD |
|---|---|---|---|---|---|---|---|---|
| Waiting for the first trades from Hyperliquid… | ||||||||
Traders are anonymised in your browser. Trades stream from Hyperliquid’s public data and are judged on this page.
Faster than lightning. Literally.
A lightning stroke lasts tens of microseconds. Guard checks every limit in 0.3. In that time, light travels about 90 metres. Your order never waits on Guard; it waits on the wire.
- 0.3 µsevery limit checked, size computed
- 69 µsorder built and signed, p50
- 74 µsp99, over 20,000 orders
- 1 hopthe only extra stop is your own machine
Measured on AWS Graviton (c7g), release build, 20,000 orders: risk sizing p50 0.3 µs; order build and signature p50 69 µs, p99 74 µs. Network is one-way, Frankfurt to Tokyo: about 125 ms, half of the ~250 ms round trip we measured from our Frankfurt host. The local hop and signature check of the Guard proxy are not in these numbers yet; we publish them when it ships. The benchmark ships with Guard’s source, so anyone can rerun it.
Four checks. 0.3 microseconds. Every order.
Read the account
Equity, open positions and their stops, from the venue and from Guard’s own record. The riskier view wins.
Size from the stop
Your bot names a stop. Guard turns your risk limit, fees and the venue’s rounding into a quantity.
Check every limit
Leverage, open risk, the daily loss stop, the drawdown halt. One fails, the order never leaves.
Send, stop, record
The order goes out with its stop resting on the venue, and the decision lands in a journal no restart can rewrite.
The nine rules
Four refuse an order, two halt new entries, two shrink it, and one adds the stop your bot forgot. You set each one; the defaults are Guard’s policy.
- Market allowlistdefault all markets
- REFUSES · Only markets on your list can be traded.
- Required stopdefault Guard sets one
- ADDS A STOP · No stop? Guard sets one, sized to your max loss at the stop. (Or refuses, if you choose.)
- Max leveragedefault 5×
- REFUSES · Refuses an order that would take the position above your leverage cap.
- Min distance to liquidationdefault 10%
- REFUSES · Refuses an order whose position would sit closer than this to its liquidation price.
- Max open riskdefault 6%
- REFUSES · Refuses a new trade when the loss at all stops, open positions plus this one, would pass this share of the account.
- Daily loss stopdefault 6%
- HALTS · Once the account is down this much since the start of the UTC day, new entries stop until the day is over.
- Drawdown haltdefault 25%
- HALTS · Once the account is this far below its peak, new entries stop until a human resumes.
- Max positiondefault 200%
- RESIZES · Shrinks an order whose position would be larger than this share of the account.
- Max loss at the stopdefault 2%
- RESIZES · Shrinks the order until the loss at its stop, fees included, is at most this share of the account.
Always, whatever you set: stops only tighten, a restart never resets a stop, and a drawdown halt waits for a human.
The Zunder stack.
Guard is the first product. Around it, the tools we use ourselves, each with an honest status.
-
Guard
BuildingRisk firewall between any bot or AI agent and Hyperliquid.
-
Backtest
LiveReplay any address under your rules.
-
Watch
LiveYour bot’s trades judged live in the browser.
-
Live market
LiveHyperliquid’s trades judged by your rules, anonymised.
-
Agent kit (MCP)
With Guard 1.0Guarded trading tools for Claude, ChatGPT and agent frameworks.
-
Monitor
With Guard 1.0Pair the browser with your local Guard: decisions and kill switch.
-
Data
PlannedPoint-in-time Hyperliquid data: trades, books, node gossip.
recorded since Oct 2026 -
Labs
PlannedResearch notes: honest backtesting, the signal lab.
-
Guarded Arena
PlannedAI agents trading in public, every veto visible.
-
Mint
ExploringToolkit for HIP-3 market deployers.
-
Terminal
ExploringGuard in the browser for manual traders.
Live: works today. Building: in progress. With Guard 1.0: ships with Guard. Planned: decided, not started. Exploring: an idea we are testing.
Questions, answered straight.
Is Zunder Guard available today?
Not yet. Guard is being built. Its risk engine, the sizing from the stop, the daily loss stop and the drawdown halt already run in Zunder's own trading system; the proxy that puts them in front of your bot is in progress. You can join the waitlist for early access.
On this site today: the backtest and the watch steps run in your browser, and the live market section shows how Guard judges trades. All three read Hyperliquid’s public data and judge it with Guard’s risk engine, compiled to WebAssembly, in your browser.
How do I add a daily loss limit or a kill switch to my Hyperliquid bot?
Put the check outside the bot's own logic. A limit written into the strategy fails together with it: a restart resets counters kept in memory, and a bug can skip the check entirely.
A daily loss limit needs three things: the account's equity at the start of the UTC day, a check before every new order that refuses it once the day's loss reaches your limit, and a halt that survives restarts. A kill switch is the same mechanism pulled by hand: it refuses every new order at once.
That is what Guard is built to do in front of your bot (planned for Guard 1.0). It reads equity from Hyperliquid and from its own record and uses the riskier of the two, and refuses new entries once the day's loss reaches your daily loss stop (default 6%). A restart never resets a stop. The daily stop clears at the next UTC day; a drawdown halt (default 25% below the peak) waits for a human.
Until Guard ships, Watch can warn you in the browser when one of your bot's trades breaks a rule. It cannot block anything.
Is a Hyperliquid API wallet (agent wallet) safe? What can it do and not do?
Safer than your main key, but not harmless. An API wallet is a separate key that your main wallet approves to trade for the account. It can place and cancel orders; it cannot withdraw or transfer funds.
So a leaked API wallet key cannot take your funds out directly, but whoever holds it can still trade your account into losses: open oversized positions, or buy an illiquid market at a bad price from themselves.
Keep it away from code you do not fully trust. With Guard (planned), the API wallet key stays inside Guard on your machine. Your bot gets a separate client key issued by Guard, which Hyperliquid does not accept on its own, and every order still has to pass your limits. If you think a key has leaked, replace that API wallet.
How do I put guardrails on an AI trading agent (MCP)?
Keep the limits outside the agent, and give it tools that cannot break them. A prompt is not a limit: a model can misread a number, loop, or be talked out of an instruction.
The plan for Guard 1.0 is an MCP server (zunder-guard mcp). Its tools read the account and the limits, ask what Guard would allow for a trade, place, amend and close orders, and pull the kill switch. No tool can raise a limit, loosen a stop or resume after a halt, and every order the agent sends passes the same rules as any bot's. It is planned for MCP clients such as Claude Desktop, Claude Code and ChatGPT. None of it is released yet.
What is a Hyperliquid builder fee, and how does Guard use one?
A builder fee is a per-order fee that Hyperliquid lets an app attach to the orders it sends for a user. The user approves a maximum fee once with their main wallet and can revoke the approval at any time. Hyperliquid collects the fee with the trade and credits it to the app's builder address. Hyperliquid caps builder fees at 0.1% on perps and 1% on spot.
Guard will be self-hosted and source-available. The planned pricing: free to run · 0.02% per order on Hyperliquid · no subscription. The fee is a builder fee on the orders Guard sends, shown to you before you approve it, and Zunder Labs never holds your funds. Teams that want a fee-free licence: contact hello@zunderlabs.com.
Is Guard open source?
No: source-available. Guard will be published under the Elastic License 2.0. You can read the code, run it and change it for your own trading. You may not offer it to others as a hosted service, or remove or work around the per-order fee, which is built in as licence-key functionality.
Teams that want to run Guard without the fee can get a fee-free licence: contact hello@zunderlabs.com.
Does Guard give trading signals or investment advice?
No. Guard is a risk tool. It enforces limits you set on orders your bot or agent has already decided to send: it sizes them, adds a missing stop or refuses them. It gives no signals, no investment advice, and promises no returns.
Does Guard hold my keys or my funds?
No. Guard runs on your machine or your own server, not ours. Your funds stay in your Hyperliquid account. The only key Guard uses is an API wallet key that you create and that cannot withdraw. It stays on your machine, and we never see it.
Zunder Labs runs no service that holds a key or can place an order. This website reads public data only: no wallet connection, no signature, no key.
How much latency does Guard add?
Measured on AWS Graviton (c7g), release build, over 20,000 orders: checking every limit and computing the size takes 0.3 µs at the median. Building and signing the order takes 69 µs at the median and 74 µs at the 99th percentile.
For scale: an order from Frankfurt to Hyperliquid in Tokyo takes about 125 ms one way, half of the ~250 ms round trip we measured from our Frankfurt host, so roughly 1,800 times longer than Guard's 0.07 ms.
Not in these numbers yet: the local hop between your bot and Guard, and Guard's check of your bot's signature. We will publish both when the proxy ships, and the benchmark ships with Guard's source, so anyone can rerun it.
Which bots work with Guard?
Planned: anything that can point its Hyperliquid client at a custom URL. Guard will speak Hyperliquid's own API on your machine (for example http://127.0.0.1:8547), so your bot changes one setting and keeps its logic.
The plan covers ccxt and the bots built on it (such as Freqtrade), the official Hyperliquid Python and TypeScript SDKs, MCP clients, and your own scripts. Each integration gets a one-page guide once we have tested it. Until then, read this list as planned, not verified.
Is the backtest a promise of what Guard would have done?
No. It is a what-if. It replays an address's trades twice: once as they happened, once behind your rules.
- Skipping or shrinking a trade can change what the bot would have done next; the replay cannot know that.
- Prices, fees and funding after a skipped trade are taken from the real history.
- Losses are capped at the stop only where the bot actually had one.
- Results include fees and funding as Hyperliquid recorded them.
The backtest page replays the last 30 days of an address from Hyperliquid’s public data and lists what the replay had to assume.
Put a firewall in front of your bot.
Self-hosted and source-available. Hyperliquid first. Early access for the first bots that want hard limits.
Free to run · 0.02% per order on Hyperliquid · no subscription.