<!-- https://zunderlabs.com/ · Markdown version of the page -->

# Your bot can be wrong. Your limits can’t.

Zunder guard — a risk firewall for bots and AI agents.

Guard runs on your machine, between your bot and Hyperliquid. It sizes every order from its stop and says no to anything that breaks your rules. Quietly, until it matters.

- 0.3 µs risk check · 69 µs sized and signed ([how it was measured](https://zunderlabs.com/#speed))
- [Join the waitlist](https://zunderlabs.com/#waitlist) · [Backtest your rules](https://zunderlabs.com/backtest) · [Connect your bot](https://zunderlabs.com/connect) · [FAQ](https://zunderlabs.com/faq)

## The market, judged by your rules.

Every dot is a real trade on Hyperliquid, as it happens. Guard reads the trader’s public account and asks one question: would your limits have let it through?

The page shows a river of the last 48 seconds of trades (one lane per market: BTC, ETH, SOL, HYPE, alts; dot size is notional, colour is heat), the share refused and resized under your rules, why Guard said no, refusals by market, and a table of the latest decisions. Traders are anonymised in your browser. Trades stream from Hyperliquid’s public data and are judged on this page.

Guard's default rules: 5× max · 2.0% at stop · no stop: Guard sets one · liq. ≥ 10% · size ≤ 200% · open ≤ 6% · daily 6% · drawdown 25% · 5/5 markets.

## Faster than lightning. Literally.

A lightning stroke lasts tens of microseconds. Guard checks every limit in 0.3. In that time, light travels about 90 metres. Your order never waits on Guard; it waits on the wire.

- **0.3 µs**: every limit checked, size computed
- **69 µs**: order built and signed, p50
- **74 µs**: p99, over 20,000 orders
- **1 hop**: the only extra stop is your own machine

One order's trip, bot in Frankfurt and Hyperliquid in Tokyo: Guard: check + sign 0.07 ms; network to the exchange ~125 ms.

*Method:* Measured on AWS Graviton (c7g), release build, 20,000 orders: risk sizing p50 0.3 µs; order build and signature p50 69 µs, p99 74 µs. Network is one-way, Frankfurt to Tokyo: about 125 ms, half of the ~250 ms round trip we measured from our Frankfurt host. The local hop and signature check of the Guard proxy are not in these numbers yet; we publish them when it ships. The benchmark ships with Guard’s source, so anyone can rerun it.

## Four checks. 0.3 microseconds. Every order.

1. **Read the account.** Equity, open positions and their stops, from the venue and from Guard’s own record. The riskier view wins.
2. **Size from the stop.** Your bot names a stop. Guard turns your risk limit, fees and the venue’s rounding into a quantity.
3. **Check every limit.** Leverage, open risk, the daily loss stop, the drawdown halt. One fails, the order never leaves.
4. **Send, stop, record.** The order goes out with its stop resting on the venue, and the decision lands in a journal no restart can rewrite.

### The nine rules

Four refuse an order, two halt new entries, two shrink it, and one adds the stop your bot forgot. You set each one; the defaults are Guard’s policy.

- **Market allowlist** (default all markets; refuses): Only markets on your list can be traded.
- **Required stop** (default Guard sets one; adds a stop): No stop? Guard sets one, sized to your max loss at the stop. (Or refuses, if you choose.)
- **Max leverage** (default 5×; refuses): Refuses an order that would take the position above your leverage cap.
- **Min distance to liquidation** (default 10%; refuses): Refuses an order whose position would sit closer than this to its liquidation price.
- **Max open risk** (default 6%; refuses): Refuses a new trade when the loss at all stops, open positions plus this one, would pass this share of the account.
- **Daily loss stop** (default 6%; halts): Once the account is down this much since the start of the UTC day, new entries stop until the day is over.
- **Drawdown halt** (default 25%; halts): Once the account is this far below its peak, new entries stop until a human resumes.
- **Max position** (default 200%; resizes): Shrinks an order whose position would be larger than this share of the account.
- **Max loss at the stop** (default 2%; resizes): Shrinks the order until the loss at its stop, fees included, is at most this share of the account.

Always, whatever you set: stops only tighten, a restart never resets a stop, and a drawdown halt waits for a human.

## The Zunder stack.

Guard is the first product. Around it, the tools we use ourselves, each with an honest status.

| Product | What it is | Status |
|---|---|---|
| Guard | Risk firewall between any bot or AI agent and Hyperliquid. | Building |
| Backtest | Replay any address under your rules. | Live |
| Watch | Your bot’s trades judged live in the browser. | Live |
| Live market | Hyperliquid’s trades judged by your rules, anonymised. | Live |
| Agent kit (MCP) | Guarded trading tools for Claude, ChatGPT and agent frameworks. | With Guard 1.0 |
| Monitor | Pair the browser with your local Guard: decisions and kill switch. | With Guard 1.0 |
| Data | Point-in-time Hyperliquid data: trades, books, node gossip. | Planned (recorded since Oct 2026) |
| Labs | Research notes: honest backtesting, the signal lab. | Planned |
| Guarded Arena | AI agents trading in public, every veto visible. | Planned |
| Mint | Toolkit for HIP-3 market deployers. | Exploring |
| Terminal | Guard in the browser for manual traders. | Exploring |

Live: works today. Building: in progress. With Guard 1.0: ships with Guard. Planned: decided, not started. Exploring: an idea we are testing.

## Questions, answered straight

### Is Zunder Guard available today?

Not yet. Guard is being built. Its risk engine, the sizing from the stop, the daily loss stop and the drawdown halt already run in Zunder's own trading system; the proxy that puts them in front of your bot is in progress. You can [join the waitlist](https://zunderlabs.com/#waitlist) for early access.

On this site today: the [backtest](https://zunderlabs.com/backtest) and the [watch](https://zunderlabs.com/connect#watch) steps run in your browser, and the live market section shows how Guard judges trades. All three read Hyperliquid’s public data and judge it with Guard’s risk engine, compiled to WebAssembly, in your browser.

### How do I add a daily loss limit or a kill switch to my Hyperliquid bot?

Put the check outside the bot's own logic. A limit written into the strategy fails together with it: a restart resets counters kept in memory, and a bug can skip the check entirely.

A daily loss limit needs three things: the account's equity at the start of the UTC day, a check before every new order that refuses it once the day's loss reaches your limit, and a halt that survives restarts. A kill switch is the same mechanism pulled by hand: it refuses every new order at once.

That is what Guard is built to do in front of your bot (planned for Guard 1.0). It reads equity from Hyperliquid and from its own record and uses the riskier of the two, and refuses new entries once the day's loss reaches your daily loss stop (default 6%). A restart never resets a stop. The daily stop clears at the next UTC day; a drawdown halt (default 25% below the peak) waits for a human.

Until Guard ships, [Watch](https://zunderlabs.com/connect#watch) can warn you in the browser when one of your bot's trades breaks a rule. It cannot block anything.

### Is a Hyperliquid API wallet (agent wallet) safe? What can it do and not do?

Safer than your main key, but not harmless. An API wallet is a separate key that your main wallet approves to trade for the account. It can place and cancel orders; it cannot withdraw or transfer funds.

So a leaked API wallet key cannot take your funds out directly, but whoever holds it can still trade your account into losses: open oversized positions, or buy an illiquid market at a bad price from themselves.

Keep it away from code you do not fully trust. With Guard (planned), the API wallet key stays inside Guard on your machine. Your bot gets a separate client key issued by Guard, which Hyperliquid does not accept on its own, and every order still has to pass your limits. If you think a key has leaked, replace that API wallet.

### How do I put guardrails on an AI trading agent (MCP)?

Keep the limits outside the agent, and give it tools that cannot break them. A prompt is not a limit: a model can misread a number, loop, or be talked out of an instruction.

The plan for Guard 1.0 is an MCP server (`zunder-guard mcp`). Its tools read the account and the limits, ask what Guard would allow for a trade, place, amend and close orders, and pull the kill switch. No tool can raise a limit, loosen a stop or resume after a halt, and every order the agent sends passes the same rules as any bot's. It is planned for MCP clients such as Claude Desktop, Claude Code and ChatGPT. None of it is released yet.

### What is a Hyperliquid builder fee, and how does Guard use one?

A builder fee is a per-order fee that Hyperliquid lets an app attach to the orders it sends for a user. The user approves a maximum fee once with their main wallet and can revoke the approval at any time. Hyperliquid collects the fee with the trade and credits it to the app's builder address. Hyperliquid caps builder fees at 0.1% on perps and 1% on spot.

Guard will be self-hosted and source-available. The planned pricing: free to run · 0.02% per order on Hyperliquid · no subscription. The fee is a builder fee on the orders Guard sends, shown to you before you approve it, and Zunder Labs never holds your funds. Teams that want a fee-free licence: contact hello@zunderlabs.com.

### Is Guard open source?

No: source-available. Guard will be published under the Elastic License 2.0. You can read the code, run it and change it for your own trading. You may not offer it to others as a hosted service, or remove or work around the per-order fee, which is built in as licence-key functionality.

Teams that want to run Guard without the fee can get a fee-free licence: contact hello@zunderlabs.com.

### Does Guard give trading signals or investment advice?

No. Guard is a risk tool. It enforces limits you set on orders your bot or agent has already decided to send: it sizes them, adds a missing stop or refuses them. It gives no signals, no investment advice, and promises no returns.

### Does Guard hold my keys or my funds?

No. Guard runs on your machine or your own server, not ours. Your funds stay in your Hyperliquid account. The only key Guard uses is an API wallet key that you create and that cannot withdraw. It stays on your machine, and we never see it.

Zunder Labs runs no service that holds a key or can place an order. This website reads public data only: no wallet connection, no signature, no key.

### How much latency does Guard add?

Measured on AWS Graviton (c7g), release build, over 20,000 orders: checking every limit and computing the size takes 0.3 µs at the median. Building and signing the order takes 69 µs at the median and 74 µs at the 99th percentile.

For scale: an order from Frankfurt to Hyperliquid in Tokyo takes about 125 ms one way, half of the ~250 ms round trip we measured from our Frankfurt host, so roughly 1,800 times longer than Guard's 0.07 ms.

Not in these numbers yet: the local hop between your bot and Guard, and Guard's check of your bot's signature. We will publish both when the proxy ships, and the benchmark ships with Guard's source, so anyone can rerun it.

### Which bots work with Guard?

Planned: anything that can point its Hyperliquid client at a custom URL. Guard will speak Hyperliquid's own API on your machine (for example `http://127.0.0.1:8547`), so your bot changes one setting and keeps its logic.

The plan covers ccxt and the bots built on it (such as Freqtrade), the official Hyperliquid Python and TypeScript SDKs, MCP clients, and your own scripts. Each integration gets a one-page guide once we have tested it. Until then, read this list as planned, not verified.

### Is the backtest a promise of what Guard would have done?

No. It is a what-if. It replays an address's trades twice: once as they happened, once behind your rules.

- Skipping or shrinking a trade can change what the bot would have done next; the replay cannot know that.
- Prices, fees and funding after a skipped trade are taken from the real history.
- Losses are capped at the stop only where the bot actually had one.
- Results include fees and funding as Hyperliquid recorded them.

The [backtest page](https://zunderlabs.com/backtest) replays the last 30 days of an address from Hyperliquid’s public data and lists what the replay had to assume.

## Put a firewall in front of your bot.

Self-hosted and source-available. Hyperliquid first. Early access for the first bots that want hard limits. [Join the waitlist](https://zunderlabs.com/#waitlist).
