Security & certifications
Liquary is a self-custodial trading frontend for Hyperliquid: your keys stay with you. Below are independent checks of its security posture, each one publicly re-verifiable, none self-awarded.
HTTP Security Headers: Grade A
Scanned by securityheaders.com (Snyk). All six protective headers are set: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
Last checked: August 8, 2026. The link opens the current, live result.
ImmuniWeb SSL Security Test: Grade A
Scanned by ImmuniWeb's SSL Security Test: Grade A. TLS 1.2 and 1.3 only, every supported cipher suite PCI DSS compliant, a fully trusted certificate chain, and hybrid ML-KEM post-quantum key exchange already enabled (the NIST-recommended transition setup).
Last checked: August 8, 2026. The link opens the latest report, with a one-click refresh to re-run it.
Last checked: August 8, 2026. The link opens the latest report, with a one-click refresh to re-run it.
Mozilla HTTP Observatory: Grade B+
Scanned by MDN's HTTP Observatory (Mozilla): 80/100, 9 of 10 tests passed. The one flagged item is the CSP 'unsafe-inline'/'unsafe-eval' allowance we keep deliberately for performance: documented, and compensated by a build-time security lint that blocks the code patterns it would expose.
Last checked: August 8, 2026. The link opens the current, live result.
Sucuri SiteCheck: Low Security Risk
Scanned by Sucuri SiteCheck (GoDaddy), rated Low Security Risk: no malware detected, and the domain is absent from all 9 blacklists the scanner monitors. A reputation check that complements the header scans: it attests the site serves nothing harmful and is flagged nowhere.
Last checked: August 8, 2026. The link opens the current, live result.
Google Safe Browsing: No suspicious content detected
Checked against Google's Safe Browsing database (Transparency Report): no suspicious content detected. This is the database Chrome, Firefox and Safari all consult, so a clean status here means no browser warning stands between a visitor and the app.
Last checked: August 8, 2026. The link opens the current, live result.
Email anti-spoofing: DMARC enforced
SPF and DMARC are live on liquary.xyz with a quarantine policy applied to 100% of mail: a fraudulent email impersonating our domain lands in spam, not in your inbox. All five MXToolbox DMARC checks pass, and this protects users directly against the number-one crypto attack, phishing from a spoofed sender.
Last checked: August 8, 2026. The link opens the current, live result.
Found something off? Security reports are read first: tell us through the feedback form.