Skip to content
Join the waitlistWaitlist

One-click templates

Templates that start Guard on your own account at Railway, Fly.io, Render, Hetzner, DigitalOcean or AWS (Tokyo). What each gives you and what it costs you in trust.

Every template deploys Guard on your own account at the platform. We never see the server, the config or the key: your key is typed on your server, never sent to us.

Use this alternative when you need a server as well as Guard. For comparing installation routes and the complete paper-first sequence, start with the setup journey.

Before you click: who else can read the key

Section titled “Before you click: who else can read the key”

A server you rent is run by someone else. On every platform below, the platform’s operators and anyone with access to your platform account could in principle read Guard’s state, including the API wallet key once you give it to Guard. The key cannot withdraw, but it can trade (API wallets).

So: use a sub-account or an account holding only what you are willing to lose, protect your platform account with two-factor authentication, and prefer a plain server you control (Hetzner, DigitalOcean, AWS) over a platform that builds and runs containers for you, if that matters to you.

PlatformWhat the template createsYour bot reaches Guard at
Railwaya service from Guard’s image with a volume, no public domainRailway’s private network
Fly.ioan app from Guard’s image with a volume, no public serviceFly’s private network (<app>.internal)
Rendera private service from Guard’s image with a diskRender’s private network
Hetzner Clouda server with cloud-init that runs the SSH install steps127.0.0.1:8547 on that server
DigitalOceana Droplet with the same cloud-init127.0.0.1:8547 on that Droplet
AWSa CloudFormation stack: one small instance, no inbound ports, access through Systems Manager, region ap-northeast-1 (Tokyo) by default127.0.0.1:8547 on that instance

Every template starts in paper mode and asks for no key. You create the API wallet in the Hyperliquid app yourself; no template generates a key. When you move to testnet, your key is typed on your server, never sent to us: you run the guided setup there (zunder-guard init --interactive), and then start Guard with the network named, for example by setting ZUNDER_GUARD_NETWORK=testnet in the platform’s environment for the service. Guard refuses to start a testnet setup without it, rather than quietly running paper.

Zunder’s research treats AWS Tokyo as the region next to Hyperliquid’s validators (docs/decisions.md, 5 Oct 2026, “Location is not a constraint for research”). For a bot that trades on closed bars, region hardly matters. For one that reacts within seconds, it can.

Guard does not listen on a public address. On Railway, Fly.io and Render, run your bot as a second service in the same project and point it at Guard’s private address. On a plain server, run the bot on the same machine.

This page as plain Markdown, for people and LLMs: /docs/deploy/one-click.md