Skip to content
Join the waitlistWaitlist

One-click templates

Templates that start Guard on your own account at Railway, Fly.io, Render, Hetzner, DigitalOcean or AWS (Tokyo). What each gives you and what it costs you in trust.

Every template deploys Guard on your own account at the platform. We never see the server, the config or the key.

Before you click: who else can read the key

Section titled “Before you click: who else can read the key”

A server you rent is run by someone else. On every platform below, the platform’s operators and anyone with access to your platform account could in principle read Guard’s state, including the API wallet key once you give it to Guard. The key cannot withdraw, but it can trade (API wallets).

So: use a sub-account or an account holding only what you are willing to lose, protect your platform account with two-factor authentication, and prefer a plain server you control (Hetzner, DigitalOcean, AWS) over a platform that builds and runs containers for you, if that matters to you.

PlatformWhat the template createsYour bot reaches Guard at
Railwaya service from Guard’s image with a volume, no public domainRailway’s private network
Fly.ioan app from Guard’s image with a volume, no public serviceFly’s private network (<app>.internal)
Rendera private service from Guard’s image with a diskRender’s private network
Hetzner Clouda server with cloud-init that runs the SSH install steps127.0.0.1:8547 on that server
DigitalOceana Droplet with the same cloud-init127.0.0.1:8547 on that Droplet
AWSa CloudFormation stack: one small instance, no inbound ports, access through Systems Manager, region ap-northeast-1 (Tokyo) by default127.0.0.1:8547 on that instance

Every template starts in paper mode and asks for no key. You add the key on the server, by hand, when you move to testnet.

Zunder’s research treats AWS Tokyo as the region next to Hyperliquid’s validators (docs/decisions.md, 5 Oct 2026, “Location is not a constraint for research”). For a bot that trades on closed bars, region hardly matters. For one that reacts within seconds, it can.

Guard does not listen on a public address. On Railway, Fly.io and Render, run your bot as a second service in the same project and point it at Guard’s private address. On a plain server, run the bot on the same machine.

This page as plain Markdown, for people and LLMs: /docs/deploy/one-click.md