Security boundary
Designed so a strategy cannot become an execution credential.
PromethIQ Markets treats trading infrastructure as security-sensitive software. The public deployment remains paper-only; the codebase isolates identity, risk, individual-order review, separately bounded mandates, deterministic execution, persistence, and provider lifecycle boundaries.
IdentityServer-managed access
- Salted password hashing and opaque hashed sessions
- HttpOnly, SameSite cookies and server-bound CSRF validation
- Protected routes, host validation, rate limits, and security headers
IsolationWorkspace-scoped data
- Session-derived workspace authorization
- Tenant filters on reports, exports, orders, and positions
- No browser-held brokerage private credentials
ExecutionExplicit authority by construction
- Exact terms and bounded mandates are immutable, fingerprint-bound, and expiring
- In the individual-review lane, proposal approval cannot submit; provider preflight and a password-backed second confirmation are required
- The public deployment injects no authenticated Robinhood/Kalshi write runtime
RiskIndependent hard gates
- 31 deterministic checks before paper execution
- Pause, stop, per-agent kill switch, and global paper halt
- Conservative sizing and hard exposure limits
RecoveryFail closed
- Transactional order and settlement persistence
- Restart recovery and renewable single-owner leases
- Unknown execution states block automatic retries
AuditReconstructable decisions
- Versioned strategies and probability models
- Structured explanations without hidden chain-of-thought
- Hash-chained audit records and readiness checks
Current public release boundary: PAPER_READY.Live execution remains disabled and unconfigured. Managed account inputs, authenticated evidence, lifecycle and protection certification, monitored recovery, independent security testing, compliance review, and a separately approved bounded beta remain required before any real-money use could be considered.