Built to pass your security review.
One URL for security teams and procurement: how the service is secured, what we log, who processes data on our behalf, and the documents your review needs, without a sales call in between.
The posture, in plain terms.
What is actually in place today, stated so your reviewer can quote it. If a control isn't listed here, don't assume it; ask us through the document request form.
Encryption in transit
TLS on every surface. Streams run over gRPC (HTTP/2 + TLS) at stream.hyperliquidrpc.com:443; RPC, /info, and historical queries are HTTPS-only. There are no plaintext listeners.
API-key authentication
Every request authenticates with an x-api-key credential. Keys are issued per account, rate-limited individually, and can be rotated or revoked from the console at any time without a support ticket.
No credential publication
A hard rule enforced in review: no credentials, server IPs, or internal hostnames appear on this site or in our docs. The only addresses we publish are the four public service endpoints.
Logging policy
We log operational metadata (request counts, egress volume, error rates, connection lifecycle) to run and bill the service. We do not retain strategy-revealing payloads such as your filters, queries, or subscription patterns beyond what operating the service requires.
Self-operated fleet with failover
We run our own Hyperliquid node fleet with automated failover and redundancy. No resold third-party infrastructure sits between your subscription and the chain. Live availability is published on the status page.
Responsible disclosure
Found a vulnerability? Mail security@hyperliquidrpc.com. We acknowledge reports within two business days, keep reporters informed through the fix, and credit good-faith research. No legal action for good-faith testing within scope.
SOC 2, stated honestly.
Claims carry receipts here, and compliance status is a claim like any other. We publish the true state of the audit, not a badge, and we keep this page current as it changes.
In the meantime, we complete security questionnaires and share our written policies under NDA through the document request form below.
Subprocessors
Third parties that process service data on our behalf. The named vendor list, with regions, is available via document request.
| Subprocessor | Function | Data involved |
|---|---|---|
| Cloud infrastructure provider | Hosting for the API gateway, console, and historical archive | Service and account data |
| Transactional email provider | Account, billing, and incident notification email | Name and account email |
| Hosted status-page provider | status.hyperliquidrpc.com, operated off our main infrastructure | Subscriber email, if you subscribe to updates |
Get the paperwork your review needs.
Four fields, no sales sequence. Requests go straight to the engineers who own the controls; we reply from security@hyperliquidrpc.com within two business days.
NDA-gated documents come with the NDA attached. Sign and we send the document back on the same thread.
Mid-review and need a human?
The first call is technical scoping with the engineers who run the fleet. Bring your questionnaire.