AI Agentic Trading

A trading desk that
thinks for itself.

An AI agentic trading desk for macOS. Nineteen strategies competing for one pool of capital, under pre-trade risk checks and broker-resident protection.

Pre-trade risk Broker-resident stops Execution analytics Post-trade reconciliation SIP and OPRA market data

Judgment

A prosecutor stands between
the green light and your capital.

Clearing the entry rules is not permission to trade. It is permission to be argued with. Every surviving candidate is handed to an adversarial judge, which builds a case against it from evidence the desk already holds, and only the unconvicted are funded.

Prosecution one

Cross timeframe

The rest of the chart gets a vote.

The symbol’s other frames are polled on direction. Broad disagreement with the side the candidate wants to take, the daily frame included, is a conviction. A signal that only exists on the frame that produced it is not an edge, it is a coincidence with good timing.

Prosecution two

Recent record

This exact pairing has a history, and it is admissible.

Not the strategy in general, and not the symbol in general, but this precise pairing of the two. A pairing that has just been going wrong repeatedly does not get to try again at full conviction simply because a fresh bar arrived.

Prosecution three

Fill quality

The trade has to survive its own execution.

The strategy’s measured history of entry slippage is set against the edge this candidate is claiming. If the fills this strategy actually gets have been consuming edges of that size, the trade is unprofitable before it exists, and the judge says so.

Its accountability is structural, not aspirational.

Every veto is booked as a zero dollar shadow position and carried through the same lifecycle as a funded trade, so what each refusal actually saved or cost becomes a measured quantity rather than a claim. The judge reports that record, and if the record turns against it, its authority steps back until the evidence restores it.

Nothing here waits on a human.

There is no approval queue, no discretionary override and no setting that lets an operator wave a trade past the chain. You set the account and the risk limits. It runs the desk, whether you are watching or asleep.

Entry gauntletIdle
Signal on a completed bar·
Minimum edge cost filter·
Regime and event gates·
Data quality check·
Adversarial judge·
Allocator weight and caps·
Sizer, ramp and daily limits·
Router, stop rests at broker·
StandbyEvery candidate walks this path. The ones that clear it reach your account with a stop already resting at the broker, and every decision, either way, is recorded and later graded.

Schematic of the decision path. Not a live feed.

Intelligence

It knows
how much it knows.

Almost no trading system can tell you whether it is getting better, because nothing in it is keeping score of itself. This one carries a standing measure of its own competence, assembled from four components, and it keeps the history so that improvement is something you can see rather than something you argue about.

Competence, accumulating with every closed decision No scale shown. The shape is the point.
Component one

Evidence

How much closed experience actually stands behind the decisions being made right now. A desk that has not yet earned an opinion knows it, and says so, instead of trading like a veteran on its first morning.

Component two

Expectancy

Whether the capital is sitting in the strategies that are measurably earning, or merely in the ones that happen to be active. Being busy and being profitable are different states, and only one of them counts here.

Component three

Quality

How well the recent book is holding together, judged on the desk’s own closed trades rather than on a backtest that already knows the ending.

Component four

Adaptation

How many learned adjustments are currently in force: strategies benched, gates raised, allocations revived. A system that has learned nothing lately has a low reading here, and that is information too.

Every component is computed from the same tables the engine trades from. Nothing in it is a matter of opinion, nothing responds to how the last few days felt, and nothing moves the measure except outcomes that have actually been recorded.

The agent loop

Every trade earns its way
to your account.

This is what agentic actually means here: the software perceives, judges, acts, grades its own result and adjusts, without a human in the loop. No discretionary override, and no trade that skips a step. A chain of independent checks stands between a signal and your capital, each one recorded as it happens. Underneath runs a second loop, which measures how well those checks are performing and tunes them from what it finds.

  1. 01FeedsBars, top of book and regulatory filings.
  2. 02StrategyEvaluated once, on a bar that has closed.
  3. 03Cost filterThe edge must clear its own round trip.
  4. 04Gate chainRegime, events and data quality.
  5. 05JudgeArgues against the trade on the evidence.
  6. 06AllocatorWeight, size, ramp and concentration caps.
  7. 07RouterEntry and protection submitted together.
  8. 08BrokerThe stop rests here, not in the app.

Four of those eight can end a candidate. Every refusal is written down with the reason that ended it.

Decision ledgerEvery yes and every no it has ever made.
GradersEntries, exits and vetoes, scored against what the market then did.
OverseerReturns bounded adjustments, or a work order for a human.

Almost every self improving trading system learns only from what it took. This one also learns from what it declined, which is the great majority of what a disciplined desk does. Twice the evidence, from the same market.

Execution

The edge has to survive
the fill.

Expected edge is a claim. What the account receives after spread, fees and slippage is the result. The desk measures that gap continuously, from its own execution record, and prices it back into the next decision rather than discovering it at month end.

Its own transaction cost record
Top of book is spooled to disk for the whole session, so realised spreads by symbol and hour, maker fill validation and adverse-selection markouts are answered from what this account actually saw rather than from an assumption inside a cost model. Where the equity feed is a single venue rather than the consolidated tape, quoted spreads read wider than the national best bid and offer. That is stated plainly, and it errs in the conservative direction.
Slippage is a pre-trade veto, not a report
Each strategy’s measured entry slippage is set against the edge a new candidate is claiming. If the fills that strategy actually receives have been consuming edges of that size, the order is refused before it is sent. Execution quality is an input to the next decision, not a number reviewed after the quarter closes.
Order quantities in exact decimal
Sizes are computed in exact decimal arithmetic, never in floating point. A sub-penny crypto balance carries more significant digits than a float holds, and the rounding tail is enough for a broker to reject the protective stop on a position that already exists. A position that cannot be protected is not a rounding error, it is an unbounded one.
Books that reconcile to the brokerage
Realised profit, fees and round-trip history are reconstructed from the broker’s own fill activity and paired at running average cost, rather than from what the engine intended to do. Anything that happens while the software is not running, an overnight stop, a manual close, still lands in the record, because history that must match the brokerage has to come from the brokerage.
Pre-trade account checks
Account state is verified before the engine may trade and re-checked on a cycle while it runs: status, restrictions, and the regulatory minimum equity for margin under FINRA Rule 4210(b)(4). The guard either passes or it stops the engine and names the reason. There is no approval step in it.

The subsystems

Ten subsystems.
Every one of them scored.

They divide into what the desk decides, what it remembers, and what it changes about itself. Each is scored by the machinery it supervises, and each earns its authority from its own record.

Specific thresholds, weights and formulas are withheld throughout this page. Licensees receive them in full.

Judgment

What it decides, and what it refuses
I

Profit Hierarchy

One live ranking over everything actionable.

Inbound market events mark affected entries dirty in constant time, and a drain task re-scores them within milliseconds.

II

The Overseer

A second chair, on a short leash.

Only whitelisted controls inside hard bounds may apply themselves, and they do so with receipts. Everything else becomes a written work order for a human.

III

Health and Self Repair

It fixes its own plumbing, and writes down that it did.

Dead poll tasks, stale feeds and a wedged database are repaired automatically, and every attempt is written to the events log.

Memory

What it keeps, so that it can learn at all
IV

The Decision Ledger

Every yes and every no, kept forever.

Most systems record their trades. This one records its decisions, a far larger set, and that difference is what makes any of the learning possible.

V

The Grader

The cost of every refusal is measured, not assumed.

Declined candidates are replayed against the bars that followed, turning the ledger into matched pairs of decision and outcome.

VI

The Exit Grader

A report card on every goodbye.

Each close is replayed under a single counterfactual: the position keeps its original protection for the remainder of its hold clock.

Learning

What it changes about itself, and on what evidence
VII

The Allocator

Capital follows evidence, not opinion.

A Thompson sampling bandit over each strategy’s own posterior. The moment its evidence says it has stopped paying, its capital is withdrawn automatically.

VIII

Nightly Self Study

It re-fits its own priors after every close.

Rolling backtests re-run minutes after the close and blend into the priors, weighted toward the long baseline so recency can never compound drift them away.

IX

Style Autopilot

Each strategy gets the geometry its own record supports.

Gated by an evidence floor and damped by hysteresis, so a challenger must beat the incumbent repeatedly before anything moves.

X

The Forecaster

Machine learning that has to earn its influence.

Gradient boosted trees on pre-registered features, validated by purged walk forward. A model that fails its deploy gates ships disabled.

Research discipline

The easiest thing to find in
market data is a pattern
that is not there.

Search enough features across enough events and impressive results appear by chance alone, every time, in any data. A learning system without a defence against that does not get smarter, it gets confidently wrong. The research stack is built around the problem rather than around ignoring it.

Market adjusted outcomes
Every result is measured net of the benchmark over the identical window. Raw returns in a rising market flatter everything, including nonsense, and a study that skips this step will find edge in a coin toss.
A period the search never saw
Patterns are discovered on the training period only, then tested once against a later period held back from the search entirely. Surviving that is interesting. Failing it means the pattern was noise wearing a convincing shape.
False discovery control
Significance is controlled across the whole family of tests at once, not one test at a time, so the set of findings carries a bounded proportion of false positives instead of an unknown one.
Effect sizes, not just significance
A result can be statistically real and economically worthless. Both are reported, and it is the second that decides whether anything is done about it.
No lookahead, structurally
Features describing the moment before an event use only bars strictly earlier than the point the information became public, and events are timestamped at the filing date rather than the transaction date, because that is when the market could first have known.
Pre registration
The forecaster’s features and horizons are fixed before any outcome is seen, and pinned in the model manifest. A loaded model whose manifest disagrees with the running code is refused rather than trusted, because feature drift produces wrong answers with confident faces.

Bedrock

Seven things no intelligence
in this system may touch.

Under every autonomy mode, including full automatic. A finding that would require weakening any of these is skipped and explained rather than applied, and the list itself is one of the protected items, so nothing in the system can quietly shorten it.

Protective stops
They rest at the broker, never only inside this process. If the engine dies mid position, a stop already resting still fires. Equities enter as bracket orders so no window exists where the position is unprotected. Crypto gets a resting stop immediately after the fill, and if that stop cannot be placed the position is closed rather than held naked.
The kill switch
In the menu bar and on the dashboard. Cancels every order, closes every position. Nothing can gate it, defer it, or reason with it.
The daily loss stop
Trading halts at the limit you set for the day. Not a suggestion, not a soft warning, and not a control any AI layer may widen.
The profit target rule
A stopping rule, deliberately. Reaching the target ends the day. It never authorises larger size to chase more, and size never increases in response to a setback. Martingale logic fails the charter on sight, and there is none anywhere in this system.
Pre flight refusal
If the self test fails, trading is blocked and the app names the failing step. There is no override.
The sizing ramp and caps
New order routing code proves itself at reduced size before it trades at full size, and concentration caps bound how much of the account any single idea may become. Both are automatic and require nothing from the operator.
The implausible order guard
The last line between a bad number and a real order. An order that makes no sense against account state never reaches the broker.

Pre flight

Before it risks anything,
it risks a dollar.

The engine will not trade until an automatic self test passes. Nobody is asked to approve it. It simply runs, and takes about two minutes. The fourth step is the one that matters, because it proves stop orders genuinely reach the broker with real money before anything larger is at stake.

  1. Verify credentials, and confirm the account is active and unrestricted
  2. Confirm market data is genuinely streaming for each asset class
  3. Check the trading clock
  4. Place a real order of about a dollar in risk, confirm a protective stop is resting at the broker, close the position, and verify the fees booked correctly
  5. Reconcile the local database against real broker state

Then the ramp. Early trades run at a fraction of full size, stepping up only once the live order path has proven itself over a run of real fills.

The charter

A change that adds expected profit while weakening a loss bound fails this charter.

Governing document. Loaded verbatim into every audit the machine performs on itself.

Every judgment the system makes, whether a control change, a veto, an audit finding or a line of code it proposes, is tested against two hard goals and four questions. Which goal does this serve? What graded evidence supports it? How will success be measured? What is the damage if it is wrong, and what bounds that damage? A change that cannot answer all four is an observation, not an action.

The honesty requirements are enforced structurally rather than aspirationally. Claims are graded, and the grader’s verdicts outrank the rationale that produced them. Changes carry receipts: what changed, why, the value that was persisted, and the metric that will later prove or disprove it. The judge, the overseer and every strategy are held to the standard they apply to others.

Perception

Most of what a chart knows
is already in the price.

So the desk draws on sources that are not, and on shapes a chart cannot show you. Filings, disclosures, funding, calendars, the book itself, and the changing geometry of the market as a whole. Every feed is best effort by design: a dead feed gates nothing, and the engine keeps flying.

The shape of the market Cross asset geometry

Beyond price and volatility, the desk measures the market’s topology: how far apart assets are behaving from one another, treated as a point cloud under correlation distance. Assets dispersed and behaving independently is the normal state. The cloud collapsing, everything fusing into a single blob, is the documented shape that precedes a dislocation, and it is visible in the geometry before it is obvious in the prices.

Insider filings, in real time Edge

Corporate insiders must report open market purchases of their own stock within two business days, and the filing reaches the regulator within minutes. Several distinct insiders buying the same company inside a few weeks is hard to explain as anything but a shared view, and it is the only timely public source of informed trading there is. The desk parses filings itself, builds its own universe from live clusters, screens it for liquidity and tradeability, and takes its holding period from a fitted study rather than a hunch. If the current study validates no horizon, the strategy stands down and says so on screen.

Congressional disclosures Edge, neutral prior

Clusters of legislative purchase disclosures, entered with no prior advantage whatsoever. They must earn weight live against the same bandit as everything else, or they get benched like anything else.

Activist stakes Edge, neutral prior

Fresh activist filings, initial filings only. The same terms apply: neutral prior, live evidence, no exceptions made for a good story.

Perpetual funding Loss avoidance

Breakout longs are refused while perpetual funding sits crowded against its own trailing month, because the crowd paying to be long is not who you want to join. The premise ships with a study script, so a licensee can verify it rather than take it on faith.

Earnings blackout Loss avoidance

No new single name entries near a known print, and positions close the session before it. A stop cannot protect across a gap. Standing aside can.

Volatility stand down Loss avoidance

Above a configured volatility level, no new equity entries at all. A crisis brake, not a mood filter.

The quote tape Self measurement

Top of book is spooled to disk all session, so questions about real spreads by symbol and hour, maker fills and adverse selection are answered from the desk’s own record instead of an assumption buried in a cost model.

The application

A native Mac app.
Not a dashboard in a browser tab.

Sixteen screens in SwiftUI, resident in the menu bar, watching a Python engine that runs as its own supervised process. The two speak over a loopback interface bound to that machine alone. No inbound ports. Nothing listening to the internet.

Set two things, then leave it

Broker keys and risk limits. The keys go into the macOS Keychain and are never written to disk. After that the engine runs its pre flight and starts. On the next launch it resumes in whatever mode it last ran, and after a reboot the login item brings it back without anyone pressing anything.

It shows its reasoning, not just its results

Every row in the ledger is inspectable: what the strategy saw, which gate refused it, what the judge argued, and, days later, what the market did about that decision. The dashboard carries live market context derived from the same data the engine trades on, so the screen can never disagree with the trading logic.

Watch its mind change

The learning feed records every adjustment the desk makes to itself, with the evidence that caused it. Benches, revivals, raised gates, refreshed priors. It is the difference between a system that claims to adapt and one that shows you the receipt.

Bring your own signals

Alerts from charting platforms, or anything that can post JSON, enter as ideas and never as orders. They clear the same cost filter, sizing, ramp and caps as everything built in, and the allocator treats them as one more strategy with no prior, to be benched if they do not pay. An alert carrying a quantity is refused outright, because sizing is never the sender’s job.

The suite that guards all of this includes a check which drives a live regulatory filing the entire way through bars, strategy, sizing and routing into a protected order at the broker, with no human step anywhere in the path.

Tech Specs

What you take delivery of.

Platform
macOS 13 or later. Apple silicon and Intel
Engine
Python 3.12, asyncio, one supervised process
Interface
SwiftUI, menu bar resident, 16 screens
Brokers
Alpaca, in production · second broker adapter in migration
Asset classes
US equities · crypto, around the clock · US options, multi leg
Market data
SIP consolidated tape for equities, OPRA for options, gated on verified entitlements. Degrades to single-venue quotes and says so on screen
Strategies
19, competing for a single pool of capital
Allocation
Thompson sampling bandit over fee adjusted expectancy
Order protection
Broker resident. Bracket for equities, resting stop for crypto, defined risk for spreads
Order arithmetic
Exact decimal throughout. No floating point in any quantity that reaches the broker
Pre-trade risk
Account status, restrictions and FINRA Rule 4210(b)(4) margin minimum, checked before trading and on a cycle thereafter
Execution analytics
Own quote tape: realised spreads by symbol and hour, maker fill validation, adverse-selection markouts
Reconciliation
Realised P&L and fees reconstructed from broker fill activity at running average cost. Boot-time position and stop reconciliation before any new order
Research stack
Backtester with a real cost model, options repricing, purged walk forward validation, pattern studies with false discovery control
Prior depth
Equity index from 1993. Bitcoin from 2014
Storage
Local SQLite in WAL mode, parquet research store. Nothing leaves the machine
Local interface
58 endpoints, bound to 127.0.0.1
Credentials
macOS Keychain. Never written to disk
Network
Outbound to broker, regulator and public data only. No inbound ports
Codebase
75,246 lines across 198 modules, Python and Swift
Verification
518 checks in 54 suites. Backtests and a full year single account simulation reproducible from one command
Deployment
One Mac, login item. Resumes trading after a reboot unattended
Documentation
Owner’s guide, field manual, data flow reference and the governing charter

Licensing

Three ways in.

Sold to operators and firms who intend to run it, not to redistribute it. Every tier includes the charter, the owner’s guide and the reproducible research, because a system you cannot audit is one you should not run.

Evaluation

Fixed term, paper account only

  • The complete application, restricted to a paper account
  • Full pre flight, dashboards, decision ledger and learning feed
  • Run the backtests and the year simulation yourself
  • Owner’s guide and charter
Start an evaluation

Operator

Single operator, cleared for live

  • Everything in Evaluation, cleared for live trading
  • Signed application, with updates for the licence term
  • Your own broker credentials and your own account, always
  • Private support channel with the engineering team
  • Onboarding covering the risk settings that actually matter
Request terms

Source

Perpetual, with build rights

  • Full engine and application source, with build rights
  • The research stack, the priors and the study code
  • One broker adapter port included
  • White label naming and icon
  • Architecture handover with the engineering team
Inquire

Inquiries

Tell us what you
would run it on.

Account size, the asset classes you care about, and whether you intend to operate it or build on it. Terms follow from that.

The thresholds behind all of this are withheld for the same reason the desk refuses most of its own signals: the value is in the calibration, and calibration given away is calibration destroyed. Licensees receive it in full.

Answered by an engineer, not a queue

Goes straight to the team. Nothing is shared.

Questions

What agentic trading
actually means here.

What is AI agentic trading?
An agentic system does not wait to be told what to do at each step. It perceives the market, forms a judgment, acts on it, measures what happened, and adjusts its own behaviour from the result. TradeAgentic.ai runs that whole loop continuously across crypto, equities and options, with no human approving individual trades.
Does it really trade without approval?
Yes. There is no approval queue and no discretionary override. What you control are the boundaries: which account it uses, how much it may risk, and when it must stop for the day. Inside those boundaries it decides on its own, and every decision it makes, including every refusal, is recorded and later graded against what the market did.
How is this different from a trading bot?
A bot executes rules you give it and cannot tell whether those rules are still working. This desk runs an adversarial judge against its own candidates, scores the value of its own refusals, withdraws capital from strategies its evidence says have stopped paying, and re-studies its priors after every close. The rules are not the product. The judgment about the rules is.
Which broker does it connect to?
Alpaca in production, using your own account and your own API keys, which are held in the macOS Keychain and never written to disk. A second broker adapter is in migration, and a source licence includes one broker adapter port.
What happens if the software stops while a position is open?
Protective stops rest at the broker, never only inside the process, so a stop already placed still fires if the software is not running. On the next start the reconciler compares its records against the broker, adopts anything it does not recognise, and re-arms any missing stop before it is allowed to trade again.
Can I see why it did something?
Every row in the decision ledger is inspectable: what the strategy saw, which gate or prosecution answered it, what the judge argued, and, days later, what the market did about that decision. The learning feed separately records every adjustment the desk has made to itself, with the evidence that caused it.
Do I need to write code or pick strategies?
No. There are no strategy switches in the product. Nineteen strategies compete for one pool of capital and the allocator decides between them from their measured results. You set two things: your keys and your risk limits.
What does it run on?
A single Mac running macOS 13 or later, on Apple silicon or Intel. It installs as a login item and resumes trading after a reboot without anyone pressing anything. Nothing listens on an inbound port, and no market or account data leaves the machine.