<!-- https://zunderlabs.com/connect · Markdown version of the page -->

# Audit it. Watch it. Then guard it.

Start in your browser with nothing installed: replay your bot’s past, then watch its trades live against your rules. When you want Guard to block, not just warn, run it in front of your bot.

1. **Backtest** (in your browser · now): Replay your bot’s past under your rules.
2. **Watch** (in your browser · now): Judge every new trade live. Get warned.
3. **Guard** (with Guard 1.0 · waitlist): Run Guard in front of your bot. Block, not just warn.

## Step 1: Backtest

We started you off with a public vault that has traded on Hyperliquid since January 2025. Paste your own bot’s address: its public trade history is replayed right here, once as it happened and once behind your rules. The same replay as on [the backtest page](https://zunderlabs.com/backtest).

## Step 2: Watch your bot live

Enter its address. Every new trade is judged against your rules the moment it happens, right in this tab.

- read-only · public data · no keys, no signature
- runs while this tab is open
- warns, cannot block: blocking needs Guard (step 3)

Streams your address’s public trades from Hyperliquid and judges them with Guard’s engine in your browser.

## Step 3: Guard (With Guard 1.0 · planned, not released yet)

Nothing in this step exists yet. The commands below are the plan for Guard 1.0 and do not work today.

**Docker**

```
$ docker run -d --name zunder-guard -p 127.0.0.1:8547:8547 \
    -v ~/.zunder:/data ghcr.io/zunderlabs/guard:latest
# paper mode · pairing code: K7F-29Q
# point your bot at http://127.0.0.1:8547
```

**macOS**

```
$ brew install zunderlabs/tap/guard
$ zunder-guard init     # rules, API wallet, paper mode
$ zunder-guard run
# pairing code: K7F-29Q · listening on 127.0.0.1:8547
```

**Linux**

```
$ curl -fsSLO https://zunderlabs.com/guard/latest/guard-linux.tar.gz
$ zunder-verify guard-linux.tar.gz   # signature + checksum
$ ./zunder-guard init && ./zunder-guard run
# pairing code: K7F-29Q · listening on 127.0.0.1:8547
```

**Windows**

```
> winget install ZunderLabs.Guard
> zunder-guard init
> zunder-guard run
# pairing code: K7F-29Q · listening on 127.0.0.1:8547
```

**One-click cloud**

```
One click, your own server, your account:
  Railway · Fly.io · Hetzner · AWS Tokyo (closest to Hyperliquid)
# your key is generated on the server, never by us
# the monitor connects through an SSH tunnel you open
```

Planned properties: planned: signed release, checksum shown; starts in paper mode; listens on 127.0.0.1 only.

### Point your bot at Guard (planned)

One line changes. Your bot keeps its own logic.

**ccxt**

```diff
  exchange = ccxt.hyperliquid({
-     "privateKey": API_WALLET_KEY,
+     "privateKey": GUARD_CLIENT_KEY,
+     "urls": {"api": {"public": GUARD, "private": GUARD}},
  })
```

**Freqtrade**

```diff
  "exchange": { "name": "hyperliquid",
-   "secret": "<api wallet key>",
+   "secret": "<guard client key>",
+   "ccxt_config": {"urls": {"api": "http://127.0.0.1:8547"}}
  }
```

**Python SDK**

```diff
  from hyperliquid.exchange import Exchange
- ex = Exchange(wallet, constants.MAINNET_API_URL)
+ ex = Exchange(guard_client, "http://127.0.0.1:8547")
```

**AI agent (MCP)**

```diff
  // claude_desktop_config.json
+ "mcpServers": { "zunder-guard": {
+   "command": "zunder-guard", "args": ["mcp"] } }
  // the agent can trade, never loosen a limit
```

Your bot gets a key issued by Guard. The real trading key stays inside Guard, so a compromised bot can never trade past your limits.

### Then pair this page with your Guard (planned)

Type the code Guard printed. The monitor from step 2 then shows real decisions, and gains a kill switch. read-only by default · this site only; the page may pull the kill switch, never place an order.

Guard 1.0 is not out yet. Join the waitlist and we will tell you when the commands above work. [Join the waitlist](https://zunderlabs.com/#waitlist).
