Portfolio
LIVEYour true net exposure across every connected venue — spot, perps, options in one book.
Your true net exposure across every connected venue — spot, perps, options in one book.
Every venue you've linked — connection type, permissions, and live margin. Vala can never withdraw from any of them.
Track any Hyperliquid wallet — live positions from the public API, flip alerts while the tab is open. Hyperliquid only — this lens reads Hyperliquid's public data; wallets on other venues aren't covered here.
Real activity from connected accounts · estimated rewards. Programs publish no APIs — every estimate is editable, and your numbers win.
Put idle balances to work — pick from the Yield menu in the top nav. Each lens is labelled honestly: stablecoin & lending rates are live (DefiLlama, key-less), covered calls are a DEMO product preview, and CeFi rates are sampled.
Pick a price you'd be happy to sell your ETH at. Get the premium now — in your wallet, instantly. Your coin sits in an on-chain vault, so there's nothing to liquidate.
Pay a premium once. That's the most you can ever lose. If you're right, the upside is entirely yours — no liquidations, no margin calls, no surprises.
Work in progress — agents are early and still being refined; treat them as a preview. Automated strategies on your connected venues, inside limits you set.
What every tab does, where your data lives, and exactly what Vala can — and can never — do with your accounts.
Vala is a non-custodial cockpit that sits on top of the trading accounts you already have. Connect venues with least-privilege credentials and Vala shows one book: your true net exposure with spot netted against perps and option delta folded in, live margin per venue, funding, liquidation distance and price-shock stress.
Your funds never move. Every balance stays on its own venue, and withdrawal permission is never requested — on any venue, in any mode.
Stuck? Hit ✦ Ask Vala in the top bar (⌘K from anywhere; type / in the chat for the command palette) — it reads your live snapshot and answers in plain English. Every answer takes a 👍/👎, and the 👎 asks what to fix — that feedback drives the roadmap directly.
Whole-book risk across every connected venue: net exposure per asset (spot vs perp vs option delta), account leverage — total directional delta including option delta, over account value — unrealised P&L, funding/day, nearest liquidation, a standalone price-shock card, and — when options are detected — greeks, expiries, a spot×vol stress matrix and a P&L-vs-spot curve with full price and P&L axes.
Connect exchanges and wallets. Every connector states its permission level before you paste anything; live venues show real margin, preview venues are clearly badged. Connect wallet reads any address across Ethereum, Arbitrum, Base, Optimism & Polygon — MetaMask or any browser wallet supplies your address only (nothing signed), and a batch add inside it takes a whole pasted list, one address per line, each added as its own read-only wallet. Kraken connects with either a spot or futures key — Vala auto-detects which. Hyperliquid reads cover Unified Accounts (spot collateral counted when the perps wallet reads $0) and every perp DEX — validator-run and HIP-3 markets alike — so no position hides on a secondary book. Each venue card has Remove (deletes its key from this device) and Hide (keeps it here with full margin detail but excludes it from the Portfolio page); a tickbox hides all spot-only wallets at once.
One dropdown, seven lenses — only one renders at a time. Movers & Shakers (the landing lens) leads the menu now. News: recent headlines from twelve public news RSS feeds (CoinDesk, Cointelegraph, Decrypt, Bitcoin Magazine, The Block, Blockworks, The Defiant, DL News, CryptoSlate, NewsBTC, U.Today, Protos) plus CryptoPanic's coin-tagged wire — and the same tape is readable from the chat: ask “summarise the news”, “what happened overnight” or “any news on HYPE” for a sourced digest tied to your book, with anything touching your held assets tagged YOUR BOOK and floated up — each refresh is AI-scored for market impact (headline text only, never your book): Top ranks by impact, Newest is pure chronology — read-only, it links out and never trades on news. Movers & Shakers: 24h / 1w / 1m / 3m price moves for the coins you hold plus the highest-volume majors — with open interest and its ~24h change (from Binance perp open-interest history) — and the biggest 24h movers on Hyperliquid with a matching headline from the same tape where one exists; a blank driver means no obvious story. Funding Rates: the cross-venue funding matrix, annualized — Hyperliquid / Binance / Bybit from HL predicted fundings, OKX / dYdX / Paradex from their public APIs, held assets first, plus the widest venue spread a delta-neutral pair would collect and a highest/lowest funding board across every listed coin. Vol: the Deribit vol market, drawn — DVOL for BTC and ETH with its 30-day range, the ATM term structure as a curve with the 90/110 put/call wing band around it (the band's asymmetry is the skew), per-expiry skew bars, and your own option expiries marked on the curve. All Deribit's own mark IV — nothing modeled or interpolated. Risk Mgmt Signals: a chronological feed of what matters on your book (thin liq distance, tight margin, funding drag, watched-whale flips), each line with one button that stages the Execute ticket — you always confirm. Whales: watch any Hyperliquid wallet — public data, flip alerts, the live leaderboard. Points: the farm tracker — an API points column read live from the venue where a feed exists (Paradex XP today; Extended's documented points endpoints currently return no data and Lighter has no points API, so enter those yourself; more as venues publish), 30-day volume from connected venues, and a Your points column that defaults to the API figure but is yours to override; Value is always your number × your $/point. History WIP: the cross-exchange replay — account value summed across your DeFi venues only (wallet-based venues add together cleanly; CeFi is excluded), plus whole-book net delta across every venue. Recording-only for now: Vala saves one real snapshot per day from when you start using it and never backfills or invents history from before that — so the chart is sparse at first and fills in over time. Hyperliquid's venue-native history shows as a LIVE comparison when connected.
Currently hidden from the top nav — a deliberate call while the cockpit stays focused on risk (non-custodial, no fund movement). The view still works: ask Vala or type /yield. Four lenses, each labelled by what its data really is: Stablecoins and Lending are live (DefiLlama's key-less API, filtered to reputable protocols and major assets with TVL floors and sanity bounds, APY-spike flags included); Covered calls is a DEMO product preview (indicative Black–Scholes on live spot, waitlist); CeFi rates are clearly-badged SAMPLE figures — no CeFi venue publishes a rates API. Read-only rate screens — funds never move through Vala.
Four agents — the Liquidation Guard (watches liquidation distance and margin; alerts, or places reduce-only orders once armed), Copycat (mirrors a wallet at your size), the Delta Auto Hedger (keeps whole-book delta inside your band), and the Points Farmer (advises where your existing flow earns most — never trades). Every executing agent starts in Simulate. Real orders need a Hyperliquid trade key plus a two-click arm per session, capped per order, with a kill switch always visible. Only you can start or arm an agent — Ask Vala fills in forms but never runs one.
Four risk alerts you toggle on the Portfolio page, delivered as native browser notifications: net exposure crossing your ±$ threshold (default $25k), nearest liquidation dropping under your % threshold (default 15%), funding flipping against you on a held perp (from collecting to paying, once it's material), and any watched whale flipping side. Enabling a toggle asks your browser for notification permission; Send test notification confirms it works. Conditions are re-checked about every 30 seconds, and each alert is de-duplicated for 10 minutes — so a persistent condition pings you at most once per 10 min, never in a stream. Alerts are in-browser only: they fire from an open Vala tab, not a server. Close the tab (or sleep the machine) and nothing runs — no server watches your book while Vala isn't open. Thresholds and toggles are saved on this device. Server-side and Telegram delivery are on the roadmap. The same four conditions also surface as in-app cards under Intelligence → Risk Mgmt Signals, which need no notification permission and show whenever Vala is open.
The copilot in the top bar (⌘K anywhere; type / in the chat box for the slash-command palette — /risk, /funding, /news, /history, /scenario, /reduce, /watch, /feedback and more). It reads a sanitized snapshot of your book, explains any number, and drives the app on command — jumps tabs, runs what-ifs, stages tickets, proposes risk reductions, pre-fills agent forms, changes which metrics show. Answers come back numbers-first — a one-line read, labeled figures, a short takeaway — and you can restyle them permanently by just saying so ("keep it short", "always flag my nearest liq"). Everything that acts ends in the human-confirmed Execute ticket — you review the staged order and one click sends it — which stages perps by default (say "spot" explicitly and it flips the ticket's Spot flag — plain buys and sells only); asked to trade an option, it stages a Deribit options ticket in-app (BTC & ETH, single-leg — you confirm) and hands off options listed elsewhere rather than substituting; asked to fix a liquidation on a read-only venue, it says so plainly instead of staging a hedge that can't help. Rate any answer 👍/👎 — the 👎 asks what to fix and feeds the roadmap.
Withdrawal is never possible. Every supported credential type is structurally unable to move funds:
| Venue | You provide | Vala can | Vala can never |
|---|---|---|---|
| Hyperliquid | wallet address, or agent-wallet key | read · sign orders locally | withdraw — agent wallets can't, by protocol design |
| Binance / OKX / Bybit / Kraken / Gemini | API key you create with withdrawal OFF | read (+ trade if you enable it) | withdraw — you never grant the permission |
| Deribit | scoped API key | account/trade read (or read-write) | wallet write — scope stays off |
| Paradex | read-only token, or L2 key for in-app orders | read · sign orders locally (L2 key) | withdraw — the L2 key can trade but not withdraw |
| Lighter / Drift | public wallet address | read public state | anything else — there is no key |
| Derive | scoped session key | read (or trade with account scope) | withdraw — needs your main wallet |
| Aster / Backpack / Extended | withdrawal-off API key | live balance & position reads · orders hand off to the venue | withdraw — never granted |
| Pacifica | public Solana address | read public account state | anything else — there is no key |
In your browser's localStorage, on this device, full stop. Vala has no database and no user accounts. Removing a venue (or clearing site data) deletes the key. The honest consequence: anything with access to this browser profile — malware, rogue extensions — could read stored keys. Use a clean profile and least-privilege keys.
Work in progress. Agents are an early preview and still being refined — expect rough edges, and keep them in Simulate until you've watched one behave. Execution agents are Hyperliquid-only for now.
Agents run on live data — whale positions, your book delta, your per-venue margin. In Simulate (the default), fills are modeled in your browser at the mark price; no order ever leaves the page. In Live — only after you arm a session — they place real, capped orders on your Hyperliquid agent key and read the resulting positions back from your account. Arming is deliberate friction: two clicks, per session, gone on reload, with a Stop-all kill switch on screen the whole time.
What it watches. Venues margin you in two different ways, so the guard tracks two different numbers. On isolated-margin positions (Hyperliquid perps), every position has its own liquidation price, and the guard watches each one's price distance to liquidation — how far the market must move against you before that leg is liquidated. On cross- and portfolio-margined venues (Deribit portfolio margin, Paradex, Derive, CeFi cross), no single position has a liq price — the whole account liquidates when equity falls to the venue's maintenance margin. There the guard watches the venue's own reported maintenance margin as a % of equity. Vala never re-invents a venue's margin model — portfolio-margin maths (vol shocks, hedge offsets) belongs to the venue, so the guard trusts the venue's number and watches the ratio.
When it fires. You set two thresholds: an isolated liq-distance floor (default 15%) and a margin-ratio ceiling (default 80% of equity used as maintenance). A single price wick isn't enough — a breach must hold for a number of consecutive checks (default 2, checked every 30 seconds against live marks) before the guard acts, and after acting it leaves that position alone for a cooldown (default 30 min) so it never chews a position to nothing. If several things breach at once it deals with the closest risk first, one action per check. It refuses to act on stale data: if a venue hasn't refreshed in 5 minutes, it tells you it's blind there instead of guessing.
What it does. In Alert-only mode (the default): a browser notification plus a pre-filled reduce-only ticket — correct side derived from your actual position, sized to your reduce % and dollar cap — one click to review, and you press Execute. In Auto-reduce mode, after you explicitly arm a session: the guard sends that same reduce-only order itself, on the venue holding the risk — any connected venue with a trade key, through the same per-venue execution path as the Execute ticket. On a cross-margined venue it trims the largest perp position (deterministic; note a hedged book can be an exception — trimming one leg can raise margin usage, which is why the order is always capped and reduce-only). Reduce-only is enforced by the exchange — the order can shrink an existing position but can mathematically never open, add to, or flip one. That is why the guard's arm is a standing grant — it stays armed until you press Stop, surviving page reloads — while Copycat and the Hedger arm for only 30 minutes: the guard's orders can only ever take risk off.
What it honestly can't do. A liquidation belongs to the venue holding the position. Reducing on another venue, or hedging elsewhere, does not move a liq price or free maintenance margin where the risk lives — so the guard never pretends it does. On venues where Vala can't execute (read-only keys, hand-off venues), it alerts and tells you exactly what to do on that venue: trim the position there or add collateral. On a portfolio-margined options book (e.g. Deribit PM) it names the venue and the buffer, because choosing which option leg to unwind is a judgment call the venue's margin model drives — not something to automate blindly.
Arming & the kill switch. Auto-reduce needs three explicit steps: switch the guard to Auto-reduce, arm the session (a two-click confirm), and run it. An armed session lasts 4 hours, is held in memory only (a reload disarms it), is capped per action in dollars, and shows a permanent Stop all kill switch. If the session lapses, the guard keeps watching and alerting — it just stops sending orders until you re-arm.
Keeping it watching. The guard runs in your open browser tab. An open tab keeps working, including in the background: the guard holds a keep-alive lock that exempts it from Chrome's aggressive background throttling, and if the browser still pauses it (or the machine sleeps), it detects the gap, logs exactly how long it was blind, and runs an immediate catch-up check when the tab wakes. Three things genuinely stop it: closing the tab, the browser's Memory Saver discarding the tab (exempt askvala.ai in Chrome's Memory Saver settings, or keep Vala in its own window), and the machine sleeping. For a book that needs true 24/7 cover, keep a machine awake with the tab open — server-side monitoring is on the roadmap.
One honest trade-off. An auto-reducer closes into weakness — that is precisely what prevents a cascade, but it also realises losses at bad prices by design. If you'd rather make the final call yourself at 3am, run it in Alert-only; the staged ticket is one press away.
Copycat and the Delta Hedger trade only Hyperliquid. The Liquidation Guard places reduce-only orders on any connected venue with a trade key (through that venue's own in-app execution path); venues connected read-only get alerts, clearly labeled. All of it runs inside the limits you set, capped per order, and only while this tab is open and armed — a web page can't run a 24/7 keeper. Copycat and the Hedger arm for 30 minutes at a $250-per-order cap, in-memory — a reload disarms them; a Copycat stop-loss also disarms the session. The Liquidation Guard is different by explicit design: its arm is a standing grant that survives reloads and lasts until you press the Stop-all kill switch — justified because its orders are strictly reduce-only (they can only ever shrink risk). The kill switch is always on screen. No withdrawal permission, ever — agent keys can't withdraw by protocol design. Start every agent in Simulate and watch it behave before arming. Nothing on this site is investment advice.
Prices & funding: Hyperliquid public API — including every Hyperliquid perp DEX (validator-run and HIP-3 markets), not just the default book, and Unified Account balances where spot collateral is the source of truth. Whale data: Hyperliquid public clearinghouse state and leaderboard. Headlines (News): public news RSS feeds, cached 10 minutes. Movers & Shakers: Hyperliquid public day stats and daily candles. Funding Rates matrix: HL predicted fundings plus OKX / dYdX / Paradex public APIs. Yield rates: DefiLlama's key-less API. History: one blended daily snapshot recorded to this browser's localStorage while a tab is open, plus Hyperliquid's own account-value history where connected. Your balances: the read scopes of the keys you connect. Everything refreshes every 30–60 seconds while the tab is open — Vala does not run in the background or on a server.
That's the whole list. There is nothing else to leak.
Ask Vala is powered by Claude, Anthropic's language model, called through a single stateless serverless function. Understanding exactly what crosses that boundary — and what never does — matters, so here it is in full.
What is sent per message. Your question, your recent chat history (held only in this browser; the ⟲ Clear button erases it), and a snapshot your browser assembles at that moment: position sizes, per-venue margin and equity, funding, option legs and greeks, watchlist entries, and agent states. The snapshot is constructed to exclude credentials by design — API keys, secrets, and signing keys are never part of it, so they cannot reach the model under any circumstance.
Computation versus phrasing. Every risk number — net exposure, margin ratios, liquidation distances, stress grids — is computed deterministically in code, in your browser, before the model is involved. Claude's role is to put those numbers into words and decide which are relevant to your question. A model error can phrase something poorly; it cannot alter your margin math.
What is stored. Nothing, server-side. The function forwards your message and returns the reply; it writes no databases and keeps no logs of your book. Conversation history lives exclusively in your browser's local storage. On Anthropic's side, API traffic is governed by their commercial terms — inputs and outputs are not used for model training by default, with limited retention for trust-and-safety purposes; see Anthropic's commercial terms for the current policy.
The honest boundary. Using any cloud AI copilot means your position sizes transit two infrastructure providers (Netlify, which hosts the relay, and Anthropic, which serves the model) as an anonymous snapshot — sizes and venue names, no identity, no addresses beyond truncated watch entries, no credentials. Nothing that crosses that boundary can act: every action the model proposes ends in a ticket that only you can send, and the keys that could sign it never leave this device. If you prefer zero model exposure, simply don't open the chat — every screen in the cockpit works without it.
In one line: the model sees sizes, never keys; it phrases, never computes; it stages, never sends.
The fine print: Terms of Service · Privacy Policy
Feedback, a venue you want connected, or an agent idea — hit 👎 on any Ask Vala answer or type /feedback in the chat, or use a waitlist button on the Yield previews. The roadmap is genuinely driven by these.