Skip to content
777 Raptor

Platform · EMIL

Intelligence that lives inside the terminal.

EMIL is the evolving market intelligence layer. It adjusts its own inputs from what the market is actually doing, so nobody has to re-optimise it every quarter. Armed, it takes trades — strictly inside a mandate you wrote and confirmed. And it holds the capital boundaries you set, in the order path, where the intelligence layer cannot reach them.

Trading leveraged products carries a high level of risk to capital. Technology can improve analysis and controls; it cannot remove market risk.

What it is
A self-adjusting intelligence layer inside the platform. It observes market and account state, classifies the regime, re-scores its own inputs from live outcomes, enforces your capital boundaries, and — when armed — opens, closes, modifies and hedges positions inside an explicit mandate.
Who it is for
Traders who want context and controls rather than signals, and desks that need automation that adapts on its own but still has an audit trail and a hard stop a human can reach.
Why it matters
Markets change, strategies decay, relationships shift and risk moves. A fixed rule set is a snapshot of a market that has already gone — and a system that only adapts when someone retunes it is stale for most of its life.
How it connects
EMIL reads the terminal, the risk engine and the position book. Anything it proposes passes the same pre-trade checks as a human order — there is no privileged path to the market.
What happens next
Read how it re-ranks its own inputs, what it is permitted to do once armed, and how the capital architecture keeps protected capital out of reach. Then bring your own risk policy to a demo.

Self-adjusting

It learns without being retuned.

EMIL adjusts its own inputs from what the market is actually doing. Not on a quarterly schedule — continuously, as the normal operating state. Here are the four mechanisms, and the line they are not allowed to cross.

  1. 01

    It scores its own inputs

    EMIL tracks how well each input has been describing what subsequently happened. Informative inputs are weighted up; inputs that stop being informative are weighted down. Nobody edits a configuration file to make that happen.

  2. 02

    It notices when a relationship breaks

    A correlation that held for six months and inverted last week is not averaged into a comfortable middle. Stability is tracked across sub-windows, and a broken relationship is treated as broken.

  3. 03

    It classifies the regime first

    Trending, ranging, expanding, contracting. The same reading that is useful in one regime is useless in another, so the classification comes first and gates everything after it.

  4. 04

    It re-ranks continuously

    There is no quarterly retraining window during which the system is knowingly stale. Adaptation is the normal operating state, not a maintenance event.

Input weights, re-rankedIllustrative
  • Session behaviour0.220.41
    more informative this month
  • Volatility regime0.340.29
    stable
  • Cross-asset correlation0.310.11
    relationship unstable 9d
  • Spread dynamics0.130.19
    improving
Learning is not authority

Adaptation changes what EMIL thinks. It never changes what EMIL is allowed to do. Authority is a mandate you wrote and confirmed; enforcement happens outside the intelligence layer, in the risk engine, in the order path. So EMIL can conclude that a larger position is warranted and still be refused by the exposure limit — and the refusal is logged.

Adaptation reduces the chance of acting on a dead relationship. It does not make a system right more often, and it does not remove market risk.

Capital protection

It protects the capital you ring-fenced.

An account does not have to be one number. Declare a portion untouchable, set a floor that ratchets up as profit is banked, and automation is refused before it can reach either.

Capital architectureIllustrative · 14,261 USD total
Protected
10,000USDDeclared untouchable. EMIL may not put it at risk — an order that would draw on it is refused before it becomes an order.
Banked profit
2,841USDGains moved above the profit floor. Once banked they join the protected side rather than funding larger positions.
Working
1,420USDThe portion actually deployed. Exposure limits, loss budgets and drawdown guards all measure against this.
Profit floor11,400Equity may not fall below this while armed. Ratchets up as profit is banked, never down.
Drawdown guard8%Measured from the high-water mark, not from the start of the day. On breach EMIL disarms itself.
Daily loss budget2%Consumed for the session and EMIL stops acting, while continuing to observe and log.

Three controls at three horizons, because a bad hour, a bad fortnight and a structural decline are different problems. All three are enforced in the order path, outside the intelligence layer, so nothing EMIL concludes can widen them. None of it removes market risk: structure changes what automation can reach, not what the market can do.

Risk, enforced

Nine breakers, each with its action declared first.

Sizing starts at the stop and is cut to the exposure ceiling when the arithmetic exceeds it. Around that sit nine circuit breakers, each showing what it watches, the limit it watches against, and what it does when it trips — and a trip stops automation without touching a single open position.

Circuit breakers9 · each with its action declared in advance
  • Daily loss limitStops automationToday’s realised and floating loss against a share of the balance
  • Weekly loss limitStops automationThe same measure over the week, against its own budget
  • Drawdown from high-water markStops automationEquity below the account’s own high-water mark, not below the session open
  • Margin utilisationStops automationMargin used as a share of equity
  • Open positionsAlert onlyThe count against the profile maximum — at the cap, no new entries
  • Consecutive lossesStops automationClosed trades newest first, until the first winner
  • High-impact news windowStops automationA window either side of a scheduled high-impact event
  • Broker connectionStops automationWhether the venue link is up, and its latency
  • Market-data healthStops automationWhether the primary quote feed is healthy, including its rate budget

A tripped breaker stops automation and nothing else — open positions and broker-side stops are untouched. The trip is written to a history with the event that caused it, and re-arming goes back through activation with the acknowledgements again.

Sizing starts at the stop

  • The stop distance and the risk share are the inputs; the lot is the output, never the other way round
  • It shows the monetary risk permitted, the pip value, the raw calculated lot and the risk at the minimum lot
  • Where the calculation exceeds the aggregate ceiling the size is cut, and the panel says it was cut and by what
  • Risk is never a target: the percentage is an absolute ceiling, and raising the aggregate past its threshold needs a separate override workflow

Nine breakers, each with a stated action

  • Daily and weekly loss budgets, measured on realised plus floating loss
  • Drawdown from the account high-water mark, not from the session open
  • Margin utilisation, open-position count and consecutive losses
  • A high-impact news window either side of a scheduled event
  • Broker connection latency, and the health of the market-data feed itself

What tripping actually does

  • Every breaker states its action in advance — most stop automation, one only raises an alert
  • A trip stops automation and nothing else: open positions and broker-side stops are untouched
  • The trip is written to a history with the event that caused it, and stays there
  • Re-arming is not automatic; it goes back through activation with the acknowledgements again
  • The panel says when it was last evaluated, whether enforcement is on, and whether automation is armed

Capital in layers

  • Protected capital carries a floor it is never risked below
  • A profit floor locks banked gains, and unlocks only above the high-water mark
  • Progress toward a doubling milestone, at which it proposes trading only with profits
  • An equity curve with the drawdown laid over it, so a recovery cannot hide the hole it came out of
  • Drawdown events are named and dated, including the one where a strategy was downgraded and suspended

The breaker grid, and capital in layers

Risk-first sizing, where the calculated lot is cut to the exposure ceiling and says so — next to nine circuit breakers each showing its current value, its limit and what it does on trip.
Capital in layers: protected capital with a floor it is never risked below, a profit floor that locks banked gains, and an equity curve with the drawdown laid over it.

Evolving Market Intelligence Layer

Observe. Understand. Adapt. Protect. Act.

Five things EMIL does, in the order it does them. The fifth only happens once you have armed it.

01 · Observe

It watches what you cannot watch continuously.

EMIL streams price, spread, volatility, session state, exposure and cross-asset relationships. Not to predict them — to notice when they change.

02 · Understand

Conditions, stated as a reading.

Trending, ranging, expanding, contracting. A classification of what is happening now, with the inputs that produced it, and an explicit note when confidence is low.

03 · Adapt

A stale relationship stops driving the reading.

Input weighting is re-ranked as conditions change. A correlation that held for six months and broke last week is weighted as broken, not as history.

04 · Protect

The boundary is enforced outside the strategy.

Exposure limits, concentration limits and drawdown guards are evaluated in the order path. Nothing inside the intelligence layer can widen them.

05 · Act

Only through the permissions gate.

Only inside a mandate you wrote and confirmed by typing ARM, only with the trading permissions you granted, and only while armed. Every action passes the same pre-trade checks as an order you place yourself.

Not an EA. Not a bot. An intelligence layer.

A conventional expert advisor

  • Runs a fixed rule set until you turn it off.
  • Optimised on history, then deployed and hoped for.
  • Opaque: a number changes and you infer why.
  • Position sizing lives inside the strategy.
  • Stopping it means finding the setting that stops it.
  • Sold on a performance curve.

EMIL

  • Re-weights its inputs as conditions change, and says when a relationship has stopped holding.
  • Reports what it currently observes rather than what previously worked.
  • Logs every event in readable language with the inputs that produced it.
  • Bounded by the account risk limits, enforced outside it in the order path.
  • One always-visible control disarms it instantly, with no confirmation.
  • Described by what it observes and what it is forbidden from doing.

None of this makes EMIL a way to avoid losses. It is a way to see conditions earlier, to keep automation inside boundaries you wrote, and to be able to explain afterwards what happened and why.

The cockpit

One state under every surface.

The Control Cockpit is where EMIL is operated: research boards, the symbol layer everything resolves through, fundamentals from the filings, the book and what a shock would do to it. Every surface reads the same account, the same instrument master and the same limits.

The cockpit, running

The cockpit on arrival: the mode it is in, what the guardian has stopped, the morning brief with its own sourcing line, and the capital, exposure and risk-budget meters underneath.

Research boards

  • Nine exchange clocks with each venue’s local session state, and a note saying holiday calendars are not yet applied
  • Indices, metals and energy quoted together, with ETF proxies marked as proxies rather than passed off as the index
  • FX shown as central-bank reference rates, labelled a daily fixing and not a tradable price
  • Crypto straight from the venues: last, mark, funding, open interest and 24-hour volume per instrument
  • Breadth per group — how much advanced, the average move, the best and worst name — over 24 hours or seven days

One symbol layer under everything

  • A canonical symbol per instrument, plus what each data provider and charting vendor calls it
  • Any spelling resolves: EUR/USD, gold, SPX or nifty all land on the same instrument
  • Each row states whether it carries a research feed, a tradable venue, or both
  • Three counts kept honest and separate: instruments known, feeds live, and instruments actually tradable

Charting that admits what it is

  • Candles, line or area across nine timeframes, from one minute to monthly
  • SMA, EMA, Bollinger bands and RSI computed inside the cockpit rather than taken from a vendor
  • Compare mode against another symbol, and your own price levels saved per instrument
  • The footer states the bar count, the provider, the fetch time, and whether the data is stale

Fundamentals with the concept named

  • Filings pulled from SEC EDGAR directly — official, keyless, and cited on every figure
  • Eight fiscal quarters of revenue and net income, with trailing margins and diluted earnings
  • Balance sheet, cash, long-term debt and share count, each with the date it was reported
  • The XBRL concept used for revenue is printed under the table, and restatements replace earlier values
  • A screener across the same universe whose rows say what is missing rather than guessing

Context, and alerts that only watch

  • Headlines from open news indexes, with a fallback index when the primary one is unavailable
  • Each headline tagged with impact, risk-on or risk-off stance, and the instruments it touches
  • One line under each headline on why it matters, or plainly that it does not
  • Price alerts carry a condition, a threshold and a note on why the level matters
  • Alerts are research signals: they never place, modify or cancel anything

The book, and what would happen to it

  • Every linked account consolidated into one exposure map — gross, net, gross-to-equity, top-symbol concentration
  • An account that is not answering says so on its own row: a stale bridge, or an API key that is not whitelisted
  • Six macro factors on sliders — dollar, equities, crypto, gold, crude, ten-year yield — with presets for the obvious shocks
  • Linear profit and loss per position under the shock, then proxy hedges sized against the net factor exposure
  • Nothing in the simulator is sent anywhere: it is a calculated view, and it says so

Research, fundamentals and the symbol layer

Global Markets: nine exchange clocks, the watchlist, and boards for indices, metals, energy, FX reference rates and crypto — each stamped with its provider, its freshness and the time it was fetched.
The instrument master: one canonical symbol per instrument, what each provider calls it, and whether it carries a research feed, a venue, or both.
Heatmap and breadth: how much of each group advanced, its average move, and its best and worst name — FX against the dollar, crypto, and the research board.
Research charting: candles with SMA, EMA, Bollinger and RSI computed inside the cockpit, compare mode, and your own saved levels — labelled delayed research data, never an execution price.
Company intelligence straight from SEC XBRL: eight fiscal quarters of revenue and net income, the balance sheet, and the concept name used for every figure.
The equity screener, where a row says what it is still missing rather than guessing: ready, needs a filings scan, or needs a price.

Provenance

Nothing here is an execution price.

Every board prints its provider, its freshness and the time it was fetched. Delayed, a daily fixing and live from the venue are three different labels, and the cockpit uses them precisely — including when the honest label is stale.

Every board names its source

  • The provider, the freshness and the fetch time are printed on the board itself
  • Delayed, daily fixing and live from the venue are three different labels, used precisely
  • Where a free data plan forces an ETF proxy instead of the index, the row says proxy
  • When an upstream feed is unavailable the board says stale rather than showing the last value as current

Research data, never execution data

  • The research feed and the execution path are separate systems, stated as such on every research page
  • A quote used for analysis is never presented as a price you could have traded
  • Model output is labelled a model assessment, with the model named, and marked research rather than advice
  • The morning brief prints its own inputs: board rows, watchlist quotes, calendar events and headline count

What it declines to say

  • A brief with no calendar events says surprises may come from headlines instead of inventing a schedule
  • A screener row with no filing scanned stays empty rather than being estimated
  • A trade card with no survival simulation recorded says so, rather than omitting the field
  • A backtest with too few out-of-sample folds is labelled insufficient to judge, not promising

Context, alerts, the book and the shock

Headlines from open news indexes, each tagged with impact, stance and the instruments it touches, and each carrying one line on why it matters.
Price alerts: a condition, a threshold and a note saying why the level matters. Alerts are research signals — they never place, modify or cancel anything.
Every linked account in one exposure map, including the ones that are not answering — a stale bridge and a key that is not whitelisted both say so on the row.
The scenario and hedge simulator: six macro factors on sliders, the linear P&L of every position, and proxy hedges sized against the net factor exposure.

Every decision, in the open

Execution is step twenty-five of twenty-nine.

A proposal has to survive the whole pipeline before an order exists, and each step can stop it. Nothing here is a confidence score standing in for a check.

Read the market

Before there is an opinion, there is data that has to check out.

  1. 01Market data validation
  2. 02Instrument normalisation
  3. 03Regime classification
  4. 04Multi-timeframe analysis
  5. 05Strategy eligibility
  6. 06Signal generation

Test the conditions

A good signal in the wrong conditions is still a bad trade.

  1. 07Volatility check
  2. 08Liquidity check
  3. 09News check
  4. 10Correlation check
  5. 11Portfolio exposure check

Size it

The stop comes first, and the size follows from it.

  1. 12Stop-loss calculation
  2. 13Monetary risk calculation
  3. 14Position size calculation
  4. 15Minimum risk validation
  5. 16Aggregate exposure validation
  6. 17Margin check

Argue it

Four separate reviews, and the last of them holds a veto.

  1. 18Agent council
  2. 19Capital protection agent
  3. 20Independent risk engine
  4. 21Guardian

Permit it

Permission, human confirmation where required, then the broker’s own checks.

  1. 22Permission engine
  2. 23Confirmation layer
  3. 24Broker pre-trade validation

Send it, then live with it

Execution is step twenty-five of twenty-nine. Four of them come after.

  1. 25Execution
  2. 26Fill verification
  3. 27Live management
  4. 28Exit
  5. 29Post-trade analysis, memory and research learning
The council40 agents · 7 groups · one veto
  • 8Market analysisRegime, volatility, liquidity, correlation, session
  • 8Strategy and signalsOne agent per approach, arguing its own case
  • 6Risk and capital protectionSizing, exposure, drawdown, protected capital
  • 4Execution and brokerSpread, slippage, fills, venue behaviour
  • 7Learning and metacognitionScoring its own past calls and re-ranking inputs
  • 4Knowledge and teachingExplaining decisions in language, and being taught
  • 3Guardian layerOutside the council, holding the veto

A decision is the position the council reaches, not the output of one model. The guardian layer sits outside it, and EMIL cannot argue with a veto — there is no confidence score that overrides one.

The pipeline, and a proposal that did not pass

The decision pipeline: the twenty-nine steps a trade has to survive, with the current candidate’s position in it, and the forty agents grouped by what they are for.
A trade card: levels, size, monetary risk, the conditions it was read against, the reasons for and against, and every agent vote — including the ones that said no.

Inside the cockpit

A desk of forty, and one that can say no.

EMIL is not one model with a long prompt. It is a coordinated desk of specialists, and an independent risk engine that sits outside that desk holding a veto the desk cannot argue with.

The council

  • Forty specialist agents, each with one job, coordinated as a desk rather than a single model
  • A decision is a position the council reaches, not an output one agent emits
  • Observes what happened, reads what is happening, estimates what could happen next
  • Acts only inside a mandate that was written and confirmed before the session

The guardian

  • An independent risk engine sits outside the council and can veto any decision
  • The veto is absolute: there is no confidence score that overrides it
  • An aggregate exposure cap the council cannot raise, and a hard drawdown guard
  • Capital protection is the first rule, ahead of any view the council holds

Its own account of itself

  • Every decision carries the inputs it was made from and the agents that argued for it
  • Refusals are explained in the same detail as actions, because both are decisions
  • It adapts its own inputs from what the market is doing rather than on a retuning schedule
  • Nothing it learns can move the boundaries it was given

Operating modes

Nine modes. Five of them can act.

The mode determines what is possible at all. The mandate determines the boundaries within that. Both are yours to set, and one of the four that cannot act can still prepare a complete trade and then not send it.

Semi-AutonomousCan reach the market

EMIL can trade only within approved strategies, assets, sessions, risk and lot limits.

Permitted

  • Trading inside every one of those five limits

Not permitted

  • An unapproved strategy
  • An unselected asset
  • A session outside the allowed ones
  • Anything past the risk or lot limit

Activation

It cannot turn itself on.

Arming is a deliberate act with three parts: a disclosure of what the system cannot do, a review of every limit that will be in force, and acknowledgements that have to be ticked. Disarming is one button, always visible, and needs no confirmation at all.

The disclosure

EMIL is an AI-assisted trading system capable of analysing markets and, depending on the permissions you select, opening, modifying, hedging and closing trades.

Trading carries substantial financial risk.

EMIL cannot guarantee profit, eliminate losses, predict market movements with certainty, prevent gaps, prevent slippage, guarantee stop-loss execution, eliminate liquidity risk, eliminate broker risk, or eliminate technology failure.

Historical results, simulations, backtests, AI predictions, strategy confidence and previous profitable trades do not guarantee future performance.

Shown every time, before anything can be armed. It is not a footnote and it is not dismissible.

Then ticked · 4 acknowledgements

  • I understand that trading can produce substantial financial losses.
  • I understand EMIL may act automatically within the permissions shown above.
  • I understand the stated figure is the current default maximum EMIL-controlled exposure.
  • I understand hedging can introduce additional risk and costs.

Reviewed before it will arm · 15 fields

  • Mode

    Which of the nine, and therefore whether it can act at all

  • Base lot

    The unit every size is built from

  • Maximum aggregate exposure

    The ceiling across everything it holds at once

  • Maximum risk per trade

    As a share of the account, per position

  • Daily loss limit

    The budget for the session

  • Weekly loss limit

    The budget above that one

  • Maximum drawdown

    Measured from the high-water mark, not from the open

  • Maximum margin utilisation

    How much of the account may be committed

  • Maximum open positions

    A count, not a notional

  • Allowed assets

    The classes it may touch; everything else is refused

  • Allowed sessions

    The hours it may act in

  • Hedge permission

    Granted or not, as its own decision

  • News-event behaviour

    What it does as a high-impact event approaches

  • Profit capital mode

    Whether banked profit may be worked, or preserved

  • Emergency behaviour

    What happens the moment the stop is hit

The fields are the product. The values are whatever the operator set, which is why none are quoted here.

The activation screen

The activation screen: the disclosure, the nine operating modes with what each may and may not do, every limit that will apply, and the acknowledgements that have to be ticked.

Strategies

Nothing gains live permission automatically.

Twelve stages in the lab before a person looks at a candidate, then five promotion gates it has to earn. A challenger beats the champion across regimes in paper and restricted live, or it does not replace it — and while no historical engine is connected, the lab labels its own results as estimates.

In the lab · 12 stages before a person looks

  1. 01Learned idea
  2. 02Structured rules
  3. 03Data validation
  4. 04Backtest
  5. 05Out-of-sample
  6. 06Walk-forward
  7. 07Stress
  8. 08Regime
  9. 09Risk
  10. 10Score
  11. 11Paper
  12. 12Human review

A candidate missing a rule is marked incomplete and the missing rule is named. It is not filled in by guesswork, and the run does not proceed as though it had been.

Then promotion has to be earned
  1. 01ResearchAn idea with rules, not yet a candidate
  2. 02BacktestMeasured, and never sufficient on its own
  3. 03PaperForward, on live conditions, with no money at risk
  4. 04Restricted liveReal, and deliberately small
  5. 05ProductionChampion, until a challenger beats it

A challenger replaces a champion only after outperforming it across regimes in paper and restricted-live evaluation — never on backtest results alone, and never automatically. A strategy that degrades is downgraded, its live sizing halved, then suspended from new entries.

Promotion has to be earned

  • Five stages in order: research, backtest, paper, restricted live, production
  • A challenger replaces a champion only after outperforming across regimes in paper and restricted-live evaluation
  • Never on backtest results alone, and never automatically
  • Every strategy is versioned, health-scored out of a hundred, and watched for drift
  • A degraded strategy is downgraded, its live sizing halved, then suspended from new entries

Twelve stages before a human looks

  • Learned idea, structured rules, data validation, backtest, out-of-sample, walk-forward
  • Stress, regime analysis, risk analysis, a score, paper or forward test, then human review
  • A backtest is stated to be no proof of future profitability, in the surface itself
  • No strategy gains live permission automatically, at any score

It will not fill in a gap

  • A generated candidate is assembled only from components it has already validated — entries from one, a regime filter from another, a risk model from a third
  • Every candidate is traceable back to the knowledge it came from, rather than invented
  • A candidate missing a rule is marked incomplete and names the missing rule, and it will not guess the value
  • While no historical data engine is connected, runs are labelled estimates — conservative, cost-aware and penalised for overfitting
  • When one is connected, every surviving strategy re-runs the whole pipeline on real data before its results count

Champion against challenger, and the lab

Champion against challenger, and a promotion pipeline a strategy has to walk: research, backtest, paper, restricted live, production — never on backtest results alone.
The lab, with its data mode declared: estimates are labelled as estimates, a candidate missing a rule is marked incomplete rather than completed by guesswork, and every stage of the pipeline is its own tab.

Its own judgement

Confidence in a setup is not trust in the environment.

Two separate numbers, and a rule between them that only goes one way. It grades its own process rather than its outcomes, stores everything it reads as an untested hypothesis, and refuses a setup it rates highly when it does not trust the conditions around it.

The distinction · the application’s own example

Setup confidence

82%

“This pattern looks excellent.”

Environment trust

46%

“But I don’t trust these conditions.”

The rule

High setup confidence can never override low environment trust. On this example EMIL does not trade — it reduces risk, requires confirmation, or stands down entirely, and tells you which number was responsible.

What each trust band means

  • HighFull permitted autonomy

    Normal sizing, inside every cap that already applies

  • ModerateNormal operation, tighter filters

    Marginal setups are skipped rather than taken small

  • LowReduced or refused

    Risk cut, confirmation required, or it stands down and says why

  • Extreme noveltyCapital protection

    Regardless of how attractive any individual setup appears

Novelty, as its own input

A dedicated detector watches for behaviour that matches no learned regime — correlation breaking, a volatility signature it has not seen, price action outside the historical distribution. The penalty it raises pushes trust down on its own, without waiting for a loss to prove the point.

A journal that grades the process

  • Fills arrive from the paper desk and the agent pipeline on their own; manual entries are possible too
  • Each entry carries setup, tags, mistakes, exit, profit and loss, and notes on what you saw and how you felt
  • The review grades the process rather than the outcome, and says so under every grade
  • An entry too incomplete to assess is graded as such, told exactly which fields were missing, and flagged
  • Reporting no mistakes on a materially incomplete entry is itself called out as a process error

Reading is not knowing

  • Articles, research pages, central-bank publications and video captions, ingested by URL or uploaded as files
  • Only publicly available material is fetched: no paywall, login or platform restriction is bypassed
  • Every statement is classified — fact, opinion, prediction, trading rule or performance claim
  • Each is attributed to its exact source and location, and checked for contradictions against existing knowledge
  • It is then stored as an untested hypothesis until independently validated in the lab

Confidence is not trust

  • Confidence in a setup and trust in the environment are two separate scores, deliberately
  • High confidence can never override low trust: it reduces risk, asks for confirmation, or stands down
  • When it stands down it says which of the two numbers was responsible
  • A novelty detector raises a penalty when behaviour matches no learned regime, and trust falls automatically
  • On extreme novelty it enters capital-protection behaviour regardless of how good any single setup looks

Trust, the journal that grades process, and teaching it

Confidence in a setup and trust in the environment are separate numbers, and high confidence can never override low trust — the example shows an 82% setup declined at 46% trust.
The journal grades the process, not the outcome: an incomplete entry is reviewed, given a process grade, told exactly what was missing, and flagged — with the advice that an incomplete log is itself a process error.
Teaching it: public material only, every statement classified and attributed to its exact source, contradictions checked against what it already holds, and the result stored as an untested hypothesis.

Reaching a market

Paper first, and it says so.

Connect a broker you already have, or use the native terminal. Either way the same risk pipeline applies, the sandbox desks sit in front of the live ones, and the parts that are not finished are labelled rather than implied.

Two ways to reach a market

  • Connect a brokerage or exchange account you already have, through the API hub
  • Or use the native terminal, which needs no external broker account
  • Credentials stay server-side and isolated to the account that added them
  • Every selected market runs the same risk pipeline: the guardian, the exposure ceiling and monetary-risk validation apply unchanged

Markets, and what is honestly not ready

  • Forex, metals, global indices, energies and crypto run live on the native terminal
  • Global equities, country stock markets, ETFs, futures, options and fixed income are listed as coming, not as available
  • India is its own hub: equities, index derivatives and commodities, with holiday-aware sessions
  • Equity markets whose structure is ready but whose data feed is not say data coming soon on the tile
  • The native terminal states that it runs on a simulated feed while the liquidity integration is finished, and to treat it as paper

A ticket states its own protections

  • A quote older than ten seconds, or latency past three seconds, refuses the order
  • Spread and limit bounds checked before send; duplicates inside a five-second window rejected
  • A daily order cap, a slippage alert threshold, and a per-order monetary cap on live routes
  • Live orders are refused outright while a circuit breaker is tripped, or while the intelligence layer is disarmed

The council proposes; a human confirms

  • The agent desk convenes the council on one instrument and sizes the result deterministically
  • Gates before anything is offered: agreement, consensus and confidence floors, no high-impact event within thirty minutes, spread inside the router limit, no same-side position
  • Caps on size, on share of venue equity, and on agent executions per day; a proposal expires after fifteen minutes
  • Sandbox and testnet venues only — live venues are refused in code, not by configuration
  • Autopilot proposes and does not execute, and the screen lists every condition still standing in its way

The API hub, the terminal, and the two paper desks

The API hub: connect a broker you already have, or use the native terminal — and every market selected here runs through the same risk pipeline.
The terminal: chart, watchlist, order desk and open positions on one surface, with the account’s margin state along the bottom.
The paper desk: sandbox and testnet venues, a ticket that states its own protections — quote age, latency, spread, duplicate window, daily cap — and a journal of what was sent.
The agent paper desk, where the council proposes, the guardian checks and sizes deterministically, and a human confirms — to sandbox venues only, with live ones refused in code.

Evidence

A backtest that grades itself weak.

The engine runs on real public history with fees and slippage as inputs, reports the buy-and-hold it was measured against, and says plainly when there is not enough out-of-sample data to judge. Options analytics sit alongside it for reading volatility rather than predicting it.

Backtests that argue with themselves

  • Real public history, with the venue, instrument, timeframe, bar count, date range and fetch time printed
  • Fees and slippage in basis points per side are inputs, not omissions
  • Walk-forward across re-tuned folds plus a Monte Carlo path set, both optional and both reported
  • Return is shown next to buy-and-hold for the same period, including when buy-and-hold won
  • The verdict is a sentence, not a score: a thin result is called thin and a short fold count is called insufficient

The measures it reports

  • Trades, long and short split, win rate, profit factor and expectancy per trade after costs
  • Maximum drawdown, a Sharpe-like figure with Sortino beside it, exposure and average hold
  • An equity curve against the flat line, so a single winning stretch cannot hide behind a total

Options, for reading volatility

  • Listed contracts from the venue, with the count and the fetch time
  • At-the-money implied volatility by expiry as a term structure, from hours out to the following year
  • Put and call open interest, max pain, and ninety-to-one-ten skew as put minus call implied volatility
  • The chain itself: bid, ask, mark, implied volatility and open interest either side of each strike

The backtest verdict, and the volatility surface

A backtest that argues with itself: the verdict calls the result thin, names the buy-and-hold it failed to beat, and says the walk-forward has too few folds to judge.
Options analytics: ATM implied volatility by expiry, put/call open interest, max pain, skew, and the chain itself.

Around the trading

Scheduling, your own platform, the API, and who may do what.

Ten central banks with the series each rate came from, a read-only bridge that mirrors the platform you already trade on, a scoped API that reaches paper venues only, and permission grants that are individual switches with every change consent-logged.

What is scheduled, and what is not

  • Ten central banks with their current policy rate, the series it came from and the date of the observation
  • A bank with no decision in the two-week window shows no rate rather than a guess
  • Speakers and statements listed with their own impact rating, not folded into the rate
  • An economic calendar for this week and next, filterable by impact and currency, stamped with its fetch time

Bring the platform you already trade on

  • A read-only bridge mirrors a MetaTrader account: balance, positions and deals appear in the cockpit
  • Alerts from charting platforms or any other system arrive on a private webhook
  • Statements import into the journal from common broker exports, and re-importing the same file adds nothing twice
  • It never sends an order back to your terminal — when floating drawdown crosses your limit it warns you instead
  • Platforms without a native sync are named as such, with the webhook or statement path offered instead

An API with scopes, and your own data

  • Keys are scoped — read, market data, news, calendar, research, alerts, journal, portfolio, paper trade, webhooks, ingest, stream
  • A sandbox key cannot link a broker at all; keys take an optional IP allow-list and an expiry, and are shown once
  • Research data through the API is delayed and never an execution trigger, and the API reaches paper venues only
  • An OpenAPI document, a Postman collection and two SDKs, with quickstarts in three languages
  • Your own pushed rows stay isolated to your account and are never mixed with the research feeds

Running it as a desk

  • Organisations for advisories, trading firms, institutions and platforms, with roles and client books
  • A recommendation workflow with approvals, desk controls, and a tamper-evident archive
  • Permission grants are individual switches — emergency close, defensive hedges, learning updates, live promotion
  • Every permission change is consent-logged and auditable, and the risk profile is edited in one place
  • Export everything as one file; deletion purges credentials and keys and keeps invoices under an anonymised identifier

The operating surfaces

Central-bank state derived from the calendar feed and the latest FRED observations — and a bank with no decision in the window shows no rate rather than a guess.
Bringing your own platform in: MetaTrader mirrors read-only, alerts arrive by private webhook, statements import into the journal — and nothing is ever sent back to your terminal.
Keys with scopes, an optional IP allow-list and an expiry; sandbox keys that cannot link a broker at all; quickstarts in curl, JavaScript and Python.
The integration directory, labelled honestly: live means built and working here, and via REST means it works through the API today without a listing in that vendor’s marketplace.
Your own pushed data, isolated to your account and never mixed with the research feeds — quotes, orders and equity points in, summaries out.
Permission grants as switches with the risk profile beside them, an export of everything in one file, and a retention policy that says how long each kind of record is kept.
Running it as a team: roles, client books, a recommendation workflow, desk controls, approvals and a tamper-evident archive.

Bring your risk policy

The useful version of this conversation is the one where we configure EMIL's mandate against limits you actually enforce, then breach one deliberately and read the refusal together.