The All-Seeing Trading Intelligence Platform
Autonomous, multi-asset trading across stocks, forex, commodities, options, crypto, and CFDs — unified by a closed-loop intelligence engine that generates signals, gates risk across themes, executes through six brokers, grades every outcome, and feeds the result back into the next decision. Built end-to-end. 9979 tests green.
Sauron isn't a signal feed or a bot framework — it's the synthesis of both, plus everything that connects them. 36 evaluators fuse price, news, macro, COT, options flow and 13F filings into composite signals. A multi-dimensional risk gate prevents stacked exposure across asset classes. Six broker adapters route execution. Every trade is graded, every gate decision audited, every dollar tracked. Then the results feed back into how the next decision gets made.
AuditLogEntry captures every trade open,
close, and gate reject. Tamper detection via verify-chain. FIFO/LIFO/HIFO tax-lot
bookkeeping with Form-8949-ready CSV export. Daily pg_dump with rolling retention.
The opportunity scanner fuses 36 evaluator kinds into multi-modal setups.
Each setup is admin-editable, weighted, and emits an
OpportunityFlag only when the composite score crosses your threshold.
Every flag becomes a Signal that gets graded against its actual outcome —
so the platform learns which evaluators carry weight in which regime.
Specialised agents powered by Claude with multi-model consensus, RAG-augmented memory, and Brier-score calibration tracking. Every agent prediction is scored against real outcomes — bad agents lose trust automatically. AI is a layer that adds confidence, never gates execution. Four autonomy levels from Observe to Full Auto — you choose.
Walk-forward backtester replays historical Signals through your
AssetBotConfig — SL/TP %, cooldowns, sizing — and walks PriceData bars
bar-by-bar to find each exit. With realistic transaction costs + slippage and an optional
train/test split, you see how the bot would have done, not just whether the
rule was profitable in theory. A config that wins on train but loses on test is overfit
and not shippable. The Eye tells you that before any capital moves.
Every trade flows through five stages. Each stage's output is logged, audited, and fed back to make the next decision smarter. No black box — every step is inspectable from the Eye.
Closed-loop means a rule that wins for 30 days then drifts negative for 7 will fire a notification, get auto-demoted from live-full back to live-small, and surface in the audit log — without anyone watching.
Drawn from the schedule the platform ships with, read when this page was served: 82 scheduled tasks on one beat, plus the price streams where they are enabled. Markets come in on the left, orders and words go out on the right, and the loop turns around one heartbeat. Hover a step, or tap it on a phone, to read what it runs and how often. Times are UTC.
Synthetic trades stream in from the left. Each carries a random USD-beta,
equity-beta and sector load. Drop the caps and watch which trades the gate refuses
in real time. This is the same logic gate_new_entry() runs against your
actual bots once you're inside.
Each row is a trade the gate just judged. Green = passed,
red = refused, with the
exact cap that tripped. Same logic as production
gate_new_entry().
The Operations Center is the home screen: what the system is doing right now. Live signals arrive on a rail that follows you across every page, fills and gate rejections land as banners the moment they happen, and the headband along the bottom keeps portfolio, exposure, bot state and drawdown in view without a click. Everything below is one page.
One bot per asset class, each with its own entry logic, sizing, cooldowns and skip reasons — all of them starting on the paper venue. A strategy climbs the ladder only on evidence, and falls back down the moment the evidence stops. Nobody has to be watching.
▼ and back down again — a decayed rule is demoted automatically, with 0 strategies currently on the ladder.
A personality is not a new engine. It is a coherent preset of the knobs that already decide how a bot behaves — the bar it reads, the volatility its stop and target are cut from, how long a thesis may live, how many bets run at once, how much one stop-out costs. Those knobs used to be set one at a time, and nothing in the platform said which combination was a trading style and which was a typo. Three of them are named now: each graded over a window that matches its own holding period, each with its own band in the account allocator.
No personality borrows to fund a position. None of the three sets a leverage or a margin knob — the preset is timeframes, stop and target multiples, a hold ceiling, a concurrency limit and a risk fraction, and that is the whole list. What the short-term one actually gets is how much position one fixed risk budget buys when the stop is tight, plus how many bets may run at once. Both are cash. Where leverage exists at all it is the broker's, on the venues that are built that way, and this platform reports it back to you as a fact at the confirm step instead of offering it as a dial to turn up. And a personality moves no capital by itself: it changes no account share, enables no config, and applying one to a bot that is already trading live re-sizes real risk — so that one asks for your PIN.
The entry path is cut in two: every bot proposes before anything executes. Turn the fleet pass on — it ships off, like every switch here that can reach an order — and one layer finally sees the whole tick at once. The desk ranks the candidates each bot has already cleared through its own gates, grades what that rule has really paid across five lanes of evidence, and prices every candidate by its marginal risk — what it adds to a book that already holds correlated positions, not what it would cost standing alone. Then it fills a risk budget the drawdown governor is allowed to cut. Its only power over a size is to shrink one.
Displaced is not discarded. The desk walks the bars the entry it refused would have lived through, prices the exit it would have found, and books the R it would have paid — so the desk is graded against the fleet it overruled, with the tie-breaks in that counterfactual deliberately set against the desk. A correlation it could not measure enters the arithmetic as zero and is written down as unmeasured, never quietly assumed away.
Rules opt in by declaring a parameter schema. When the nightly investigator confirms decay on one of them, mutation proposals are generated that same night — creation is a reflex to evidence, not a calendar appointment. Each candidate perturbs one to three parameters inside their declared bounds, and every one of them has to prove itself on data the parent never saw before an operator is even asked.
Above the signal engine sits a layer whose only job is to understand. It reads the platform's own state on a loop, writes down what it believes, invites its own agents to attack those beliefs, keeps what survives, and forgets the rest. Every claim carries a deadline, and every deadline is graded.
Switched on — it ships off, and costs a frontier-model pass when it runs — Horizon writes, once a month, a five-to-ten-year view of every sector this platform can trade: what structurally changes, what it would take to be wrong, and which risks are worth guarding against years before they arrive. Every other agent on this platform looks hours to weeks ahead. This one is held to exactly the same bar as the rest: prose with no gradable claim in it does not count, so each thesis ends in direction calls at six and twelve months, resolved against the first bar at or after the deadline by the same calibration ledger that scores every other agent.
A conversation with the platform about the platform. It reads Sauron's own accumulated state — brain reports, knowledge nodes, hypotheses, rule track records, your book — and answers in plain English with the rows it used. It has no tools to change anything: the research agent can only look. Press Ctrl+K on any page, or open the full conversation from AI Agents.
Every broker speaks the same duck-typed interface (ping · ticker · klines · order_book ·
market_order · account · balance). Routing per-symbol via the broker_router based on
the instrument's asset_class. Encrypted credentials at rest (Fernet). Paper-mode default.
The audit log is append-only and hash-chained. Every trade open, trade close,
and gate rejection produces a row whose payload_hash =
sha256(prev_hash · kind · canonical(data)). Mutating any past row breaks the
chain — verify exposes the tamper. Combined with FIFO/LIFO/HIFO tax-lot bookkeeping
and Form-8949 CSV export, the platform is ready for taxable-account live deployment.
save() refuses to update existing rows; delete() raisesverify_chain() walks forward, recomputes, flags any breaksA password gets you a session. It does not get you money. Every action that can move capital sits behind a second factor you hold, and a screen left unattended stops being a screen anyone can use.
One rule runs under all of it. Every proposal is a gradable call with a deadline on it. Every plan is scored against the counterfactual — what actually happened, or what the trade it displaced would have paid. Anything unmeasured renders as an em dash, never as a zero dressed up as data. And every switch that can move money is off until a person turns it on, behind the PIN, with an audit row to show for it.
So here is the honest position, which is the better story anyway. The desk places no orders. It ranks, and its only power over a size is to shrink it; the allocator moves no share by itself. Both are built to run on every tick and every schedule, behind switches that ship off like every other switch here that can reach the money, and both are graded against what would have happened without them. Neither has been trusted with the account on this deployment. When one is, it will be because a human read the evidence and turned a switch — not because a landing page said they were ready.
Battle-tested OSS. Multi-stage Docker build, non-root runtime, ASGI worker
for Channels. gunicorn + uvicorn serving HTTP and WebSockets;
Sentry-instrumented; Celery beat for the recurring tasks; Channels for the per-user Eye push;
a pg_dump nightly with rolling retention. The platform looks after itself.
Each evaluator pulls from real data feeds (SEC, CFTC, FRED, news APIs, broker depth, etc.)
and outputs a normalised score the scanner can compose. Add a new evaluator with one
register_kind() call — the scanner picks it up automatically.
Sauron starts in paper mode. Wire up your brokers when you've watched it run. Flip the orchestrator on when you're ready. Promote rules from research to live-full when their walk-forward backtest agrees with their live track record. Cautious by default — aggressive when you ask.
mode="live" per config.
Everything visible without a single broker key.