# Zunder Labs > Zunder Guard is a risk firewall for trading bots and AI agents on Hyperliquid: it runs on your own machine, sizes every order from its stop and refuses anything that breaks your rules (leverage cap, required stop, distance to liquidation, open risk, daily loss stop, drawdown halt, position size, loss at the stop, market allowlist). Self-hosted and source-available (Elastic License 2.0); free to run · 0.02% per order on Hyperliquid · no subscription. A risk tool: no signals, no investment advice. In development, with a waitlist. Zunder Labs is a brand of orcastrate UG (haftungsbeschränkt). Status, honestly: Guard is being built and is not released. The site's market view, backtest and watch steps run in the browser on public Hyperliquid data. Anything planned is marked "planned". Measured: Guard's risk check takes 0.3 µs (p50) and building plus signing an order 69 µs (p50), 74 µs (p99), on AWS Graviton. ## Pages - [Zunder Guard](https://zunderlabs.com/index.md): What Guard is, the nine rules, the measured latency, the Zunder stack with honest statuses, and the FAQ. - [Backtest](https://zunderlabs.com/backtest.md): Replay a Hyperliquid address under your rules, in the browser; what the replay can and cannot tell you. - [Connect](https://zunderlabs.com/connect.md): Audit, watch, guard: what works in the browser today and what ships with Guard 1.0. - [FAQ](https://zunderlabs.com/faq.md): Straight answers to the questions people ask about bot risk limits on Hyperliquid. ## Docs - [What Zunder Guard is](https://zunderlabs.com/docs/index.md): A self-hosted risk firewall between any trading bot or AI agent and Hyperliquid. What it does, what it does not do, and how an order flows through it. - [API wallets](https://zunderlabs.com/docs/concepts/api-wallets.md): What a Hyperliquid API wallet (agent wallet) can and cannot do, why a trade-only key is not harmless, and how Guard keeps it away from your bot. - [Builder fees](https://zunderlabs.com/docs/concepts/builder-fees.md): What a Hyperliquid builder fee is, how you approve and revoke one, and the fee Guard plans to charge. - [Daily loss stop and drawdown halt](https://zunderlabs.com/docs/concepts/circuit-breakers.md): The two circuit breakers of the risk engine, how they are measured, when they fire and clear, and why only a person can resume after a drawdown halt. - [The equity cap](https://zunderlabs.com/docs/concepts/equity-cap.md): Size and measure losses from a fixed sleeve instead of the whole account. How the cap works, why it measures losses against the smaller base, and what it cannot do. - [The journal](https://zunderlabs.com/docs/concepts/journal.md): The risk engine's append-only, checksum-chained journal, what each line holds, when a line is written, and what it can and cannot detect. - [The kill switch](https://zunderlabs.com/docs/concepts/kill-switch.md): What the kill switch does, in which order, why it latches, and how to trade again. - [Paper, testnet and mainnet](https://zunderlabs.com/docs/concepts/networks.md): The three modes Guard runs in, what each one sends where, and why mainnet needs you to type it. - [The nine rules](https://zunderlabs.com/docs/concepts/rules.md): Exact definitions, formulas, defaults and bounds of Guard's nine rules, where each lives in the code, and what Backtest and Watch can and cannot judge. - [Sizing from the stop](https://zunderlabs.com/docs/concepts/sizing.md): How Guard turns a stop price into a position size, with the exact formula from zunder-risk and hand-worked examples. - [Stops only tighten](https://zunderlabs.com/docs/concepts/stops-only-tighten.md): Why a stop can move towards the price but never away from it, and how a stop is replaced without a moment unprotected. - [Deploy Guard](https://zunderlabs.com/docs/deploy.md): Where Guard can run, what every install has in common, and which page to read for your platform. - [Docker](https://zunderlabs.com/docs/deploy/docker.md): Run Guard from its container image, bound to localhost, with its state on a volume. - [Network footprint and the firewall rule](https://zunderlabs.com/docs/deploy/network-footprint.md): Every connection Guard makes, which ones are optional, how to see them, and a firewall rule that enforces them. - [One-click templates](https://zunderlabs.com/docs/deploy/one-click.md): Templates that start Guard on your own account at Railway, Fly.io, Render, Hetzner, DigitalOcean or AWS (Tokyo). What each gives you and what it costs you in trust. - [Homebrew and winget](https://zunderlabs.com/docs/deploy/packages.md): Install Guard on macOS with Homebrew or on Windows with winget. - [One SSH command](https://zunderlabs.com/docs/deploy/ssh.md): Install Guard on a Linux server with one SSH command, after verifying the installer on your own machine. - [Verify a release](https://zunderlabs.com/docs/deploy/verify.md): Check that a Guard release is the one our public build produced, from public source, using checksums, Sigstore signatures, SLSA provenance and a reproducible build. - [FAQ](https://zunderlabs.com/docs/faq.md): The questions from the homepage, answered in full, with links to the details. - [How integrations work](https://zunderlabs.com/docs/integrations.md): Guard speaks Hyperliquid's own API on your machine. Point your bot's API URL at it and sign with a Guard client key. What passes, what is checked, what is refused. - [ccxt](https://zunderlabs.com/docs/integrations/ccxt.md): Put Guard in front of a ccxt Hyperliquid client by overriding its API URLs. The exact config keys, and two ccxt defaults to switch off. - [Freqtrade](https://zunderlabs.com/docs/integrations/freqtrade.md): Put Guard in front of Freqtrade's Hyperliquid exchange through ccxt_config. The exact config keys. - [MCP for Claude, ChatGPT and Cursor](https://zunderlabs.com/docs/integrations/mcp.md): Give an AI agent guarded trading tools through Guard's MCP server. The exact config for Claude Desktop, Claude Code, Cursor and the OpenAI Agents SDK, and why ChatGPT is different. - [Hyperliquid Python SDK](https://zunderlabs.com/docs/integrations/python-sdk.md): Put Guard in front of the official Hyperliquid Python SDK with base_url. The exact arguments. - [TradingView alerts through the relay](https://zunderlabs.com/docs/integrations/tradingview.md): Turn TradingView alerts into guarded Hyperliquid orders. Why a relay is needed, the alert format, and what the relay can and cannot do. - [TypeScript SDK](https://zunderlabs.com/docs/integrations/typescript-sdk.md): Put Guard in front of the @nktkas/hyperliquid TypeScript SDK with the transport's apiUrl. The exact options. - [Anonymisation](https://zunderlabs.com/docs/methods/anonymisation.md): How the live market hides trader addresses, what that protects against, and what it does not. - [The heat score](https://zunderlabs.com/docs/methods/heat-score.md): How the 0 to 100 heat score of a trade is computed, from which facts, and what it does not mean. - [How the honest backtest works](https://zunderlabs.com/docs/methods/honest-backtest.md): Why the browser Backtest replays real fills instead of simulating a strategy, the exact replay rules, and the honesty rules Zunder applies to every backtest. - [The latency benchmark](https://zunderlabs.com/docs/methods/latency.md): How much time Guard's risk check and order signing add, how it was measured, what is not included, and how to rerun it. - [Request budget](https://zunderlabs.com/docs/methods/request-budget.md): How the browser tools stay within Hyperliquid's rate limits, using half of your IP's allowance. - [CLI](https://zunderlabs.com/docs/reference/cli.md): The zunder-guard commands, and the zunder-runner commands they are modelled on. - [Config keys](https://zunderlabs.com/docs/reference/config.md): Every key of guard.toml with its default and bounds. Generated from the code at release; this skeleton lists the keys that exist in code today. - [Event schema for the monitor](https://zunderlabs.com/docs/reference/events.md): The events a running Guard publishes on its local API, for the monitor page, Telegram alerts and your own tools. Draft. - [Rules codes (shared rules schema v1)](https://zunderlabs.com/docs/reference/rules-schema.md): The one format for a set of Guard rules, shared by the website, the docs and `zunder-guard init --rules`. Fields, units, defaults, bounds, the zr1_ encoding, and examples. - [Veto and reason codes](https://zunderlabs.com/docs/reference/veto-codes.md): Every code Guard, the risk engine and the browser tools use to say why an entry was refused or resized. - [Reporting a vulnerability](https://zunderlabs.com/docs/security/reporting.md): How to report a security problem in Guard, the relay or the website, and what happens next. - [Threat model](https://zunderlabs.com/docs/security/threat-model.md): What each part of the Zunder stack can and cannot do, and what happens when the bot, the relay, the website or a key is compromised, or a request is replayed. - [Quickstart in paper mode](https://zunderlabs.com/docs/start/quickstart.md): Install Guard, load your rules, and point a bot at it in paper mode. Paper mode uses Hyperliquid's real prices and sends no orders. - [Backtest](https://zunderlabs.com/docs/tools/backtest.md): Replay any Hyperliquid address under your rules in the browser. How the replay works, what it reads, and what it cannot know. - [Live market](https://zunderlabs.com/docs/tools/live-market.md): Hyperliquid's public trades, judged by your rules and anonymised, in your browser. What is sampled, how traders are anonymised, and the request budget. - [The relay](https://zunderlabs.com/docs/tools/relay.md): How the Zunder Relay carries TradingView alerts and bot requests to a Guard that cannot be reached from outside, why it is not custody, and its limits. - [Watch](https://zunderlabs.com/docs/tools/watch.md): Your bot's trades judged live in a browser tab. What Watch reads, how it judges, and why it can warn but never block. ## Optional - [Contact](https://zunderlabs.com/contact.md): How to reach Zunder Labs. - [Licences](https://zunderlabs.com/licenses.md): Third-party licences for this website. - [Impressum](https://zunderlabs.com/impressum.md): Legal notice (Impressum). - [Privacy](https://zunderlabs.com/privacy.md): Privacy policy: what this site does and does not collect. - [Everything in one file](https://zunderlabs.com/llms-full.txt): all pages and docs above as Markdown.