One-click templates
Every template deploys Guard on your own account at the platform. We never see the server, the config or the key.
Before you click: who else can read the key
Section titled “Before you click: who else can read the key”A server you rent is run by someone else. On every platform below, the platform’s operators and anyone with access to your platform account could in principle read Guard’s state, including the API wallet key once you give it to Guard. The key cannot withdraw, but it can trade (API wallets).
So: use a sub-account or an account holding only what you are willing to lose, protect your platform account with two-factor authentication, and prefer a plain server you control (Hetzner, DigitalOcean, AWS) over a platform that builds and runs containers for you, if that matters to you.
The templates
Section titled “The templates”| Platform | What the template creates | Your bot reaches Guard at |
|---|---|---|
| Railway | a service from Guard’s image with a volume, no public domain | Railway’s private network |
| Fly.io | an app from Guard’s image with a volume, no public service | Fly’s private network (<app>.internal) |
| Render | a private service from Guard’s image with a disk | Render’s private network |
| Hetzner Cloud | a server with cloud-init that runs the SSH install steps | 127.0.0.1:8547 on that server |
| DigitalOcean | a Droplet with the same cloud-init | 127.0.0.1:8547 on that Droplet |
| AWS | a CloudFormation stack: one small instance, no inbound ports, access through Systems Manager, region ap-northeast-1 (Tokyo) by default | 127.0.0.1:8547 on that instance |
Every template starts in paper mode and asks for no key. You add the key on the server, by hand, when you move to testnet.
Why Tokyo for AWS
Section titled “Why Tokyo for AWS”Zunder’s research treats AWS Tokyo as the region next to Hyperliquid’s validators (docs/decisions.md, 5 Oct 2026, “Location is not a constraint for research”). For a bot that trades on closed bars, region hardly matters. For one that reacts within seconds, it can.
On a platform, the bot must be there too
Section titled “On a platform, the bot must be there too”Guard does not listen on a public address. On Railway, Fly.io and Render, run your bot as a second service in the same project and point it at Guard’s private address. On a plain server, run the bot on the same machine.