SAURON VISION

The All-Seeing Trading Intelligence Platform

Autonomous, multi-asset trading across stocks, forex, commodities, options, crypto, and CFDs — unified by a closed-loop intelligence engine that generates signals, gates risk across themes, executes through six brokers, grades every outcome, and feeds the result back into the next decision. Built end-to-end. 9979 tests green.

Institutional-Grade · Production-Hardened · Fully Auditable
Scroll
0
Asset Classes
0
Broker Adapters
0
Signal Evaluators
0
Tests Passing

A Closed-Loop Intelligence Engine

Sauron isn't a signal feed or a bot framework — it's the synthesis of both, plus everything that connects them. 36 evaluators fuse price, news, macro, COT, options flow and 13F filings into composite signals. A multi-dimensional risk gate prevents stacked exposure across asset classes. Six broker adapters route execution. Every trade is graded, every gate decision audited, every dollar tracked. Then the results feed back into how the next decision gets made.

Sauron's Eye Dashboard
Single real-time pane: live theme exposure (USD, equity, vol, currencies, sectors), open positions across every asset class, gate decisions, recent fills, bot health, 24h P&L. WebSocket push for instant updates — HTMX 10s poll as fallback.
Cross-Asset Orchestrator
A risk gate that thinks in themes, not just positions. Refuses new trades that stack USD-beta, equity-beta, vol-long, per-currency or per-sector exposure beyond your caps. Optionally size-weighted by notional. Closes never gated.
Self-Grading Loop
Every signal AND every bot trade is automatically graded in R-multiples, win rate, expectancy, holding period. A daily decay detector flags rules whose recent 7d underperforms their 30d baseline — before the drawdown gets real.
Strategy Evolution + AI Mutator
Decaying rules get mutated candidates; an opt-in Claude mutator proposes grounded changes given the recent track record. A walk-forward backtester (with transaction costs + slippage) confirms before anything deploys. See how a fork earns its capital →
Compliance & Audit Trail
Append-only sha256 hash-chained AuditLogEntry captures every trade open, close, and gate reject. Tamper detection via verify-chain. FIFO/LIFO/HIFO tax-lot bookkeeping with Form-8949-ready CSV export. Daily pg_dump with rolling retention.
Real-Time Notifications
Telegram, email, Discord, in-app bell — one toggle per channel. Fires on bot fills, orchestrator rejections, drawdown limits, track-record decay. Graceful degrade when credentials missing; Sentry catches what notifications can't.
EURUSD BUY 0.87
BTCUSD STRONG 0.94
XAUUSD HOLD 0.62
SPX SELL 0.81
SIGNAL RADAR

12 Evaluators.
One Composite Score.

The opportunity scanner fuses 36 evaluator kinds into multi-modal setups. Each setup is admin-editable, weighted, and emits an OpportunityFlag only when the composite score crosses your threshold. Every flag becomes a Signal that gets graded against its actual outcome — so the platform learns which evaluators carry weight in which regime.

  • ✓price_pattern · macro_regime · macro_trend · volatility_regime
  • ✓news_volume · news_sentiment · sentiment_snapshot · cot_report
  • ✓options_flow · correlation_pair · institutional_filings · calendar_event
  • ✓Apriori pattern miner auto-discovers high-lift combinations from history
  • ✓Self-grading: every signal scored in MFE/MAE/realized_r/duration
NEURAL ARCHITECTURE

Calibrated AI
You Can Override

Specialised agents powered by Claude with multi-model consensus, RAG-augmented memory, and Brier-score calibration tracking. Every agent prediction is scored against real outcomes — bad agents lose trust automatically. AI is a layer that adds confidence, never gates execution. Four autonomy levels from Observe to Full Auto — you choose.

  • ✓PreTradeSanity · SignalJournal · DecayInvestigator · AnomalyDetector
  • ✓StrategyAdvisor · StrategyMutator · MacroInterpreter · NewsAnalyst
  • ✓WeeklyReviewer · MarketCommentator · EarningsAnalyst · SpeechAnalyst
  • ✓RAG over historical signals + per-agent Brier-calibration scoring
  • ✓AI mutator (opt-in) proposes parameter tweaks grounded in track-record
ALPHA BENCH
EQUITY CURVE

Backtest the Bot,
Not Just the Rule.

Walk-forward backtester replays historical Signals through your AssetBotConfig — SL/TP %, cooldowns, sizing — and walks PriceData bars bar-by-bar to find each exit. With realistic transaction costs + slippage and an optional train/test split, you see how the bot would have done, not just whether the rule was profitable in theory. A config that wins on train but loses on test is overfit and not shippable. The Eye tells you that before any capital moves.

  • ✓Walk-forward train/test split with overfit-aware scoring
  • ✓Configurable transaction costs + entry/exit slippage
  • ✓Per-trade R, win rate, profit factor, Sharpe-R, max drawdown
  • ✓Auto-promotion: research → paper → live-small → live-full
  • ✓Auto-demotion when post-promotion performance degrades

From Tick to Trade to Truth

Every trade flows through five stages. Each stage's output is logged, audited, and fed back to make the next decision smarter. No black box — every step is inspectable from the Eye.

SIGNAL
12 evaluators
fuse → composite
RISK GATE
5-dimension
orchestrator
EXECUTE
6 broker adapters
idempotent orders
GRADE
R-multiple, win-rate,
holding period
LEARN
decay alerts +
auto-promote/demote

Closed-loop means a rule that wins for 30 days then drifts negative for 7 will fire a notification, get auto-demoted from live-full back to live-small, and surface in the audit log — without anyone watching.

What the Machine Does,
Every Day.

Drawn from the schedule the platform ships with, read when this page was served: 82 scheduled tasks on one beat, plus the price streams where they are enabled. Markets come in on the left, orders and words go out on the right, and the loop turns around one heartbeat. Hover a step, or tap it on a phone, to read what it runs and how often. Times are UTC.

Feel the Orchestrator

Synthetic trades stream in from the left. Each carries a random USD-beta, equity-beta and sector load. Drop the caps and watch which trades the gate refuses in real time. This is the same logic gate_new_entry() runs against your actual bots once you're inside.

▶ ORCHESTRATOR_GATE · LIVE_SIM
PASS 0 REJECT 0 RATE 0%
Live Exposure
USD +0.0
Equity +0.0
Top sector —
Bars centred on zero. Fill turns red when the next same-sign trade would breach your cap.
SIGNAL
ORDER
GATE
Decision Log ● LIVE
awaiting first trade…

Each row is a trade the gate just judged. Green = passed, red = refused, with the exact cap that tripped. Same logic as production gate_new_entry().

One Screen. Everything Moving.

The Operations Center is the home screen: what the system is doing right now. Live signals arrive on a rail that follows you across every page, fills and gate rejections land as banners the moment they happen, and the headband along the bottom keeps portfolio, exposure, bot state and drawdown in view without a click. Everything below is one page.

◉ OPERATIONS_CENTER · LIVE
◌ PAPER ⟂ WS PUSH UTC
TOKYO 00:00–06:00 LONDON 07:00–15:30 NEW YORK 13:30–20:00 SYDNEY 21:00–05:00
Signal Rail ● STREAMING
EURUSD LONG entry · stop · target
rule: macro_trend + cot_report · composite above threshold
TAKE TRADE PASS
NVDA SHORT entry · stop · target
rule: options_flow + volatility_regime · sized from your risk %
TAKE TRADE PASS
Inbox ● LIVE
◉Fill — bot opened a position and the rail card slid out
▣Gate reject — the orchestrator refused a stacked entry
◬New signal — composite crossed your threshold
▼Decay — a rule's 7d fell behind its 30d baseline
✦Critical news on an instrument you hold
Same events route to Telegram, email, Discord and WhatsApp — one toggle per channel.
Portfolio—
Exposure—
Open R—
Bot state—
Unread—
Drawdown—
1 CLICK
Take Trade
A signal becomes a position from the rail itself — sized from your risk settings, then graded, reconciled, kill-switchable and audited exactly like a bot's. Executes on the paper venue: the bots are what trade live, once they have earned it.
0
Instruments Watched
Every one clickable through to its own page — candlesticks down to the minute, the signals that fired on it, and the news that moved it.
0
Headlines · 24h
Ingested, scored and attached to the instruments they touch. A dash in the headband always means “not measured yet” — never a zero dressed up as data.

Nothing Reaches Live
Without Earning It.

One bot per asset class, each with its own entry logic, sizing, cooldowns and skip reasons — all of them starting on the paper venue. A strategy climbs the ladder only on evidence, and falls back down the moment the evidence stops. Nobody has to be watching.

STOCKS
sector-aware · earnings blackout
FOREX
per-currency exposure caps
COMMODITIES
metals · energy · agriculture
CRYPTO
24/7 · funding + liquidation aware
OPTIONS
flow-driven · defined risk
MANUAL
your Take-Trade book, same rails
STAGE 01
RESEARCH
signals recorded
and graded, no capital
STAGE 02
PAPER
executes on the
simulated venue
STAGE 03
LIVE · SMALL
real money,
scaled-down sizing
STAGE 04
LIVE · FULL
full sizing,
still under the gate

▼ and back down again — a decayed rule is demoted automatically, with 0 strategies currently on the ladder.

BACKTEST
The Bot, Not the Rule
Replay historical signals through the exact bot config — SL/TP, cooldowns, sizing — walking bars to find each real exit. A config that wins on train and loses on test is overfit, and says so before any capital moves.
FORENSICS
Why Did It Do That?
One timeline per fill: the rule that fired, the signals that voted, the gate decision, the brain's advisory, the sizing multipliers in force, and the audit rows. No archaeology across five pages.
0
Configured Bots
Every one of them disabled and flattened in a single action by the kill switch — which itself needs your PIN.

Three Ways to Hold a Thesis.

A personality is not a new engine. It is a coherent preset of the knobs that already decide how a bot behaves — the bar it reads, the volatility its stop and target are cut from, how long a thesis may live, how many bets run at once, how much one stop-out costs. Those knobs used to be set one at a time, and nothing in the platform said which combination was a trading style and which was a typo. Three of them are named now: each graded over a window that matches its own holding period, each with its own band in the account allocator.

Scalp — Hours, Not Days
Many small bets on the hourly frame, with the stop and the target cut from hourly volatility rather than the four-hour default — a tight stop the bar can actually reach inside a session. A thesis that has not moved by the end of that session is closed. Graded over the shortest window, because a run of scalps is a sample.
  • Framehourly
  • Hold ceilinghours
  • Bets at oncemany, each small
  • Horizon priornone — nothing to say
Swing — What Sauron Is Today
The four-hour trend, held across sessions rather than across weeks. This is the behaviour every existing bot already has, written down as a preset instead of living as the accident of whichever defaults shipped — so the other two personalities are a choice against a named baseline, not against a blank.
  • Framefour-hour
  • Hold ceilingdays
  • Bets at oncea handful
  • Horizon priorlight
Position — The Long View
Daily bars, few bets, each one allowed a wide stop because it is meant to survive ordinary noise. The personality the five-to-ten-year view actually moves — swing feels it at half weight, and the scalp book not at all — and even here the tilt is capped: a structural opinion must never out-vote a measured one.
  • Framedaily
  • Hold ceilingweeks
  • Bets at oncefew, each larger
  • Horizon priorits own lane

No personality borrows to fund a position. None of the three sets a leverage or a margin knob — the preset is timeframes, stop and target multiples, a hold ceiling, a concurrency limit and a risk fraction, and that is the whole list. What the short-term one actually gets is how much position one fixed risk budget buys when the stop is tight, plus how many bets may run at once. Both are cash. Where leverage exists at all it is the broker's, on the venues that are built that way, and this platform reports it back to you as a fact at the confirm step instead of offering it as a dial to turn up. And a personality moves no capital by itself: it changes no account share, enables no config, and applying one to a bot that is already trading live re-sizes real risk — so that one asks for your PIN.

Every Candidate Seen
Before Any Order.

The entry path is cut in two: every bot proposes before anything executes. Turn the fleet pass on — it ships off, like every switch here that can reach an order — and one layer finally sees the whole tick at once. The desk ranks the candidates each bot has already cleared through its own gates, grades what that rule has really paid across five lanes of evidence, and prices every candidate by its marginal risk — what it adds to a book that already holds correlated positions, not what it would cost standing alone. Then it fills a risk budget the drawdown governor is allowed to cut. Its only power over a size is to shrink one.

◈ CAPITAL_DESK · PROPOSE → RANK → FILL
◌ SHADOW ⟂ MARGINAL RISK PER USER · PER VENUE
Candidate Ladder — one pass ● RANKED
01 FOREX · cleared by its bot TAKEN
02 COMMODITY · uncorrelated with the book TAKEN
03 STOCK · higher R, but correlated DISPLACED
04 CRYPTO · small, diversifying TAKEN
05 STOCK · budget exhausted DISPLACED
Risk budget · this venue Governor cut
The budget is a share of the venue's capital, less the risk already standing at stop in the open book, and the drawdown governor shrinks it as the curve falls away from its high-water mark. Paper and live never share a budget, a book, or a correlation penalty.
Ranked onEXPECTED R
Costed byMARGINAL RISK
Unmeasured pair—
Size mayONLY SHRINK
Orders the desk sendsNONE

Displaced is not discarded. The desk walks the bars the entry it refused would have lived through, prices the exit it would have found, and books the R it would have paid — so the desk is graded against the fleet it overruled, with the tie-breaks in that counterfactual deliberately set against the desk. A correlation it could not measure enters the arithmetic as zero and is written down as unmeasured, never quietly assumed away.

0
Desk Passes Recorded
One row per user, per venue, per tick — how many times the desk has thought. Not how many times it acted: in shadow the fleet executes exactly as it always has, and the plan is the counterfactual being graded beside it.
0
Decisions With an R
A taken candidate inherits its trade's realised R; a displaced one is graded on the bar-walk it never got. A decision no bar could price stays ungraded rather than being counted as evidence that the desk measures itself.
NO ORDERS
Placed by the Desk
The desk sends nothing itself, in either mode: its whole power is to shrink a size or skip an entry. Every pass above was written in SHADOW: the switch that would let the plan be obeyed is off, and it turns on the way everything else here does — on graded evidence, by a person, behind the PIN. Why that is the point →

One Account.
Re-Split on Evidence.

With its pipeline running, the allocator proposes every few hours what share of the broker account each live pool should take — that switch ships off too, and none of this starts until somebody turns it on. The proposal comes from graded evidence, the brain's regime read, how many opportunities the scanner is actually finding, news risk, and the horizon prior — the last one capped low, because a structural view must never out-vote a measured one. A floor keeps a pool that is doing badly alive at a size that still produces evidence: a pool at nothing can never earn its way back. A ceiling stops one good week handing the account to one bot. A cap on daily movement stops the whole book chasing the morning.

◇ SHARE_ALLOCATOR · PROPOSED
◌ SHADOW ⟂ GRADED NEXT DAY PIN TO APPLY
Three market states, and they are not symmetric on purpose: it de-risks in a single plan on a shock and re-risks slowly afterwards. The bars above are the shape of the mechanism, not this deployment's book — what any account actually holds is nobody's business but its operator's, and it is not on a public page.
0
Share Plans Written
Every plan, in every state — not only the applied ones. The claim is that the allocator proposes on a schedule and is graded whether or not anybody clicks; counting applies would tell the story of the operator instead of the engine.
PROPOSED
Nothing Moves
A plan is a proposal. It moves a share only when an admin applies it behind the PIN, and only with the live switch on. None has ever been applied here. This module never writes a pool's capital and never touches the broker: the share is the only thing it decides.
GRADED
A Day Later
Each plan is scored against what the live book actually paid — positive when it leaned toward the pools that then earned R. Every input that went into a target is stored on the plan, including the readers that degraded and why.
PARENT DECAY MUTANTS FORK
MUTATION LINEAGE

Decay Is the Trigger.
Evidence Is the Judge.

Rules opt in by declaring a parameter schema. When the nightly investigator confirms decay on one of them, mutation proposals are generated that same night — creation is a reflex to evidence, not a calendar appointment. Each candidate perturbs one to three parameters inside their declared bounds, and every one of them has to prove itself on data the parent never saw before an operator is even asked.

  • ✓Confirmed decay fires proposals immediately; nothing waits for a weekly sweep
  • ✓Adaptive cadence: mid-week runs skip when the fleet closed too little to learn from
  • ✓Walk-forward evidence packet: train/test split, mutant vs parent on both halves
  • ✓Overfit candidates are penalised by their worse half — good train, bad test never wins
  • ✓Approved mutants fork into research and trade beside the parent, which is never overwritten
  • ✓Undecided proposals expire — an unanswered question does not pile up into noise

A Machine That Argues
With Itself.

Above the signal engine sits a layer whose only job is to understand. It reads the platform's own state on a loop, writes down what it believes, invites its own agents to attack those beliefs, keeps what survives, and forgets the rest. Every claim carries a deadline, and every deadline is graded.

Brain Synthesis
Every thirty minutes a structured world snapshot — observations, portfolio state, exposure, rule track records, regime probes — becomes one report with a regime call, a confidence and a handful of falsifiable predictions. If synthesis fails it says so; downstream agents degrade instead of guessing.
Knowledge Graph
Settled facts — regimes, theme states, rule states, persistent anomalies, narrative threads — get promoted out of the raw observation queue into durable nodes with a history you can walk. What the graph holds is what the agents are allowed to treat as known.
Hypothesis Market
Any agent may post a claim — with a confidence and a deadline. Other agents vote to co-sign, refine or dissent. When the deadline passes the claim is resolved against what actually happened, and the result flows straight into the poster's calibration.
The Critic
A red-team agent whose job is to argue against Sauron's own ideas. It reviews claims from low-trust agents, sanity-checks every high-confidence one, and samples the rest. When it dissents strongly it must post its own counter-claim — so the quality of the dissent is measured too.
Consolidation & Forgetting
Once a night the day's observations are compacted: load-bearing facts move into the graph, everything that led nowhere is pruned. Without a forgetting mechanism the queue grows without bound and every agent drowns in noise. Pure, deterministic, cheap.
Generated Strategies · Journal · Trust
The Mind also writes candidate strategies of its own — and they enter the same ladder as everything else, with no shortcut for being AI-authored. The AI journal records what each agent said, what it cost, and how it aged; Brier-scored calibration turns that history into per-agent trust, and low trust means less weight downstream.
SIX MONTHS TWELVE MONTHS TODAY FIVE TO TEN YEARS
SECTOR HORIZON

The Only Agent
Looking Past Friday.

Switched on — it ships off, and costs a frontier-model pass when it runs — Horizon writes, once a month, a five-to-ten-year view of every sector this platform can trade: what structurally changes, what it would take to be wrong, and which risks are worth guarding against years before they arrive. Every other agent on this platform looks hours to weeks ahead. This one is held to exactly the same bar as the rest: prose with no gradable claim in it does not count, so each thesis ends in direction calls at six and twelve months, resolved against the first bar at or after the deadline by the same calibration ledger that scores every other agent.

  • ✓The first of those calls come due in 2027 — until then this page claims nothing about how right they were
  • ✓Its sector tilts reach the allocator as a weak prior, capped by construction
  • ✓It moves the long-horizon book most and the mid-horizon one at half weight; a book that is flat by lunchtime never sees it at all
  • ✓The row is written before the model is called, so a provider outage is an error row, never a silent gap
  • ✓A garbled answer is kept and marked rejected — you paid for it and you get to read it — but it is never treated as a view
◬ ASK_SAURON · RESEARCH READ-ONLY
What's your current read on the dollar?
Reading the last 72h of reports, graph nodes and open hypotheses — here is the posture, what changed, and the two claims that would falsify it.
Why did you pause that momentum rule?
Its recent window fell behind its own baseline; the decay investigator confirmed it, the actuator paused it, and the audit row is linked below.
Where did our recent dissents come from?

Interrogate Your
Own Machine.

A conversation with the platform about the platform. It reads Sauron's own accumulated state — brain reports, knowledge nodes, hypotheses, rule track records, your book — and answers in plain English with the rows it used. It has no tools to change anything: the research agent can only look. Press Ctrl+K on any page, or open the full conversation from AI Agents.

  • ✓Retrieval over your real history — not a general-purpose chatbot with a ticker
  • ✓Intelligence hub: reports, graph, hypotheses and dissents in one reading room
  • ✓Daily strategist briefing: outlook, posture, watchlist and three actionable ideas
  • ✓Each briefing idea is posted as a hypothesis — the strategist gets graded too
  • ✓Earnings reviews on the names you hold, written before the print and read after it

Six Brokers. One Adapter Pattern.

Every broker speaks the same duck-typed interface (ping · ticker · klines · order_book · market_order · account · balance). Routing per-symbol via the broker_router based on the instrument's asset_class. Encrypted credentials at rest (Fernet). Paper-mode default.

BINANCE
spot · futures · crypto
ALPACA
stocks · ETFs · paper/live
OANDA
forex · 28 pairs · practice
IBKR
options · futures · CFDs · stocks
PAPER
simulated · always-on default
+ MORE
add via duck-typed adapter
15min
Reconcile
Open positions checked vs broker every 15 min during market hours. Manual closes and liquidations are detected, not lost.
SHA-256
client_order_id
Deterministic order IDs prevent double-fills if a worker dies mid-call. Binance, Alpaca and OANDA dedup server-side.
23:30
UTC Snapshot
Daily portfolio snapshot at 23:30 UTC, decay scan at 06:15 UTC. Backups run from the deploy's own container on their own clock. The platform looks after itself.

Every Decision.
Hashed. Forever.

The audit log is append-only and hash-chained. Every trade open, trade close, and gate rejection produces a row whose payload_hash = sha256(prev_hash · kind · canonical(data)). Mutating any past row breaks the chain — verify exposes the tamper. Combined with FIFO/LIFO/HIFO tax-lot bookkeeping and Form-8949 CSV export, the platform is ready for taxable-account live deployment.

  • ✓save() refuses to update existing rows; delete() raises
  • ✓verify_chain() walks forward, recomputes, flags any breaks
  • ✓Tax lots: open on every BUY · consume on close · ST/LT (≥365d) auto-classified
  • ✓Encrypted broker credentials (Fernet); paper-mode is the default
  • ✓Sentry-instrumented; structured Celery + Django integration
kindtrade_open
preva1c4…
hash7e2b…
→
kindgate_reject
prev7e2b…
hash9f1d…
→
kindtrade_close
prev9f1d…
hashb34c…
AUDIT CHAIN

The Audit Trail Guards the Past.
The PIN Guards the Present.

A password gets you a session. It does not get you money. Every action that can move capital sits behind a second factor you hold, and a screen left unattended stops being a screen anyone can use.

0
Audit Chain
Append-only entries, each hashed onto the last. Editing any past row breaks every hash after it, and verification names the break.
2ND GATE
PIN on Login
Credentials accepted is not signed in. A 4-to-8 digit PIN stands between the password and the terminal, throttled against guessing, with a password-verified reset as the only way back.
ARMED
PIN to Go Live
Bots run on paper until you arm them — and arming live takes the PIN, every time. The emergency kill switch that disables every bot and flattens the book is behind the same gate.
IDLE
Auto-Lock
After your chosen quiet period the session locks itself to a bare PIN screen — no shell, no data, no admin, no report. An unattended desk stops being an open terminal.

Nothing Here Grades
Itself Kindly.

One rule runs under all of it. Every proposal is a gradable call with a deadline on it. Every plan is scored against the counterfactual — what actually happened, or what the trade it displaced would have paid. Anything unmeasured renders as an em dash, never as a zero dressed up as data. And every switch that can move money is off until a person turns it on, behind the PIN, with an audit row to show for it.

0
Agent Calls Resolved
Predictions the resolver has marked right or wrong. Both directions, summed — publishing only the correct ones would be a hit rate dressed up as a volume, on the page whose whole pitch is that this platform grades itself in both.
0
Components on a Switch
Scrapers, engines, pipelines — each one something an admin can stop from the cockpit. Counted whether it is running or paused: the number says how much of the platform answers to a switch at all.
0
Commands Catalogued
Every operator command with its exact usage, held against the framework's own command list by a test — so the catalogue in the cockpit cannot drift away from what the shell will actually accept.
0
Rules Under Control
The same rules the promotion ladder counts, seen from the other side: each carries an enforcement state, and nothing sizes money without one. Two labels over one population — said plainly, because it is not extra coverage.

So here is the honest position, which is the better story anyway. The desk places no orders. It ranks, and its only power over a size is to shrink it; the allocator moves no share by itself. Both are built to run on every tick and every schedule, behind switches that ship off like every other switch here that can reach the money, and both are graded against what would have happened without them. Neither has been trusted with the account on this deployment. When one is, it will be because a human read the evidence and turned a switch — not because a landing page said they were ready.

Production-Hardened

Battle-tested OSS. Multi-stage Docker build, non-root runtime, ASGI worker for Channels. gunicorn + uvicorn serving HTTP and WebSockets; Sentry-instrumented; Celery beat for the recurring tasks; Channels for the per-user Eye push; a pg_dump nightly with rolling retention. The platform looks after itself.

Python 3.12 Django Channels HTMX PostgreSQL Redis Celery + Beat gunicorn + uvicorn Anthropic Claude Fernet Sentry SDK ib_insync pandas / numpy Docker cryptography pytest / Django test

Many Lenses. One Eye.

Each evaluator pulls from real data feeds (SEC, CFTC, FRED, news APIs, broker depth, etc.) and outputs a normalised score the scanner can compose. Add a new evaluator with one register_kind() call — the scanner picks it up automatically.

USD beta
Equity
Vol-long
▲ live theme exposure pulse from the orchestrator gate
SEC EDGAR
13F · insider · 10-Q
CFTC / COT
commitments of traders
FRED Macro
CPI · GDP · rates · DXY
News APIs
volume + sentiment
Options Flow
unusual activity scanner
Economic Calendar
earnings + central bank
Reddit / StockTwits
social sentiment snapshot
IBKR / Twelve Data
price + volatility regime

Ready to See
Everything?

Sauron starts in paper mode. Wire up your brokers when you've watched it run. Flip the orchestrator on when you're ready. Promote rules from research to live-full when their walk-forward backtest agrees with their live track record. Cautious by default — aggressive when you ask.

PAPER
Default Mode
No live trades until you flip mode="live" per config. Everything visible without a single broker key.
OPT-IN
Orchestrator
Risk gate is OFF by default. Enable on profile, set caps, watch the Eye. Flip off if it's too tight.
REVERSIBLE
Every Action
Rule pauses, allocator changes, stage promotions — all have propose/apply/rollback flows in the actuator.

SAURON VISION

Sauron Vision

SECOND GATE

ENTER PIN CODE

OPERATOR
PIN forgotten?