How the risk engine thinks
The risk engine covers what the Autonomous Risk Engine (ARE) does. This page covers how it actually works underneath, in more depth than most readers need, for anyone who wants to see the real machinery rather than take "it's automated" on faith.
Eight signals, not one number pretending to be simple
Every 15 minutes, the ARE recomputes a composite health score for each firm from eight separate signals, weighted by how much they actually matter:
| Signal | What it's really asking |
|---|---|
| Obligation coverage (33%) | Do current entitlements and pending payouts actually fit inside the treasury? |
| Burn velocity (15%) | How fast is the treasury draining, over the last day and the last week? |
| Payout cost pressure (15%) | Are incoming fees still funding outgoing payouts, or falling behind? |
| Concentration (10%) | Is exposure dangerously concentrated in one account or a small handful? |
| Open risk (12%) | If every open position went against the firm at once, how bad would it be? |
| Payout backlog (8%) | Is anything sitting unpaid past a reasonable service window? |
| Integrity pressure (4%) | Is abuse activity across traders elevated right now? |
| Market volatility (3%) | Is the broader market itself unusually turbulent? |
Two of these, obligation coverage's treasury figure and the payout backlog, are read directly from the blockchain rather than from an internal database an operator could quietly edit. Every score the engine ever publishes carries its full input vector, and there's a public endpoint that recomputes it independently, anyone can check that a firm's published score actually matches its published inputs, not just trust that it does.
It doesn't panic on noise, and it doesn't relax quickly either
A naive system would jump straight from "healthy" to "stressed" the instant a score crossed a line, then jump right back the moment it dipped under again, punishing a firm for a single bad hour and rewarding a firm for a single good one. This engine deliberately doesn't work that way.
Two protections do the work. First, terms scale continuously within a health band rather than jumping the moment a firm crosses into it, a firm one point into a stressed tier sees only a sliver of that tier's tightening, not the full weight of it all at once. Second, escalating into a worse tier happens fast, but relaxing back out is deliberately slower and requires the score to clear a real margin below the line, not just brush it, so a firm can't game the system by riding exactly on the edge. The one exception moves in the opposite, protective direction: a sudden, sharp treasury drop skips the gradual path entirely and escalates immediately.
The engine won't let a firm race to the bottom, or accidentally make an evaluation impossible
Two structural limits sit on top of everything else. A floor stops a firm's terms from ever becoming a genuinely zero-edge giveaway, even at the healthiest tier, there's a minimum built in. A ceiling stops the opposite: as a firm gets more stressed, several things tighten at once, and stacked together they could otherwise make an evaluation mathematically close to unwinnable. The ceiling caps how much combined tightening can ever apply, so a stressed firm's evaluations get meaningfully harder, never absurd.
When it does tighten, it tightens in a specific order
The engine doesn't reach for the harshest lever first. It defends a stressed firm in a fixed sequence: price moves first (which also naturally cools demand), then the rulebook itself, then execution conditions like spread and slippage, then exposure limits, and only as an actual last resort does it touch how fast a trader can be paid, and even then it drips payments rather than freezing them outright. Earned money is never cancelled at any point in this sequence.
A firm's growth changes its pricing on its own axis
Independent of risk health entirely, a firm's evaluation pricing and trader split shift automatically as its visible reserves grow, from an introductory price and the most generous trader split at launch, toward a higher price and a smaller (but still substantial) split once a firm has demonstrably built real reserves. A firm that stalls on paying out drops back a phase automatically, cheaper pricing and a better split, until it's earned its way back. The logic is simple: only a firm that's actually delivering gets to charge a premium for it.
The one dial an operator actually gets
At launch, an operator makes exactly one economic choice: a , tilted toward the firm's own margin, a balanced middle ground, or tilted toward trader-friendliness for volume. Everything past that single choice, the leverage baseline, the pricing curve, every tier transition, is the engine's job, not the operator's.
A public companion score built for the trader, not the firm
Alongside the risk score, the same 15-minute sweep computes a separate, public-facing for every firm, shown on every storefront. It reuses the same underlying signals but answers a different question on purpose: not "is this firm at risk," but "is this a good firm to trade for right now." It weighs real payout confidence, how reliably a firm has actually settled recent payouts, how attainable passing genuinely is against the firm's own numbers, and how generous the split is, into one comparable number a trader can use before ever reading a single other page on a firm's storefront.
