AI Agentic Trading

A trading desk that
thinks for itself.

An AI agentic trading desk for macOS. Nineteen strategies across crypto, equities and options. A prosecutor that argues against every trade before your capital moves, a memory of every decision it has ever made, and a standing measure of how much it has learned from them. You supply the account and the risk limits. It does the rest, around the clock, without you.

Judgment

A prosecutor stands between
the green light and your capital.

Clearing the entry rules is not permission to trade. It is permission to be argued with. Every surviving candidate is handed to an adversarial judge, which builds a case against it from evidence the desk already holds, and only the unconvicted are funded.

Prosecution one

Cross timeframe

The rest of the chart gets a vote.

The symbol’s other frames are polled on direction. Broad disagreement with the side the candidate wants to take, the daily frame included, is a conviction. A signal that only exists on the frame that produced it is not an edge, it is a coincidence with good timing.

Prosecution two

Recent record

This exact pairing has a history, and it is admissible.

Not the strategy in general, and not the symbol in general, but this precise pairing of the two. A pairing that has just been going wrong repeatedly does not get to try again at full conviction simply because a fresh bar arrived.

Prosecution three

Fill quality

The trade has to survive its own execution.

The strategy’s measured history of entry slippage is set against the edge this candidate is claiming. If the fills this strategy actually gets have been consuming edges of that size, the trade is unprofitable before it exists, and the judge says so.

Its accountability is structural, not aspirational.

Every veto is booked as a zero dollar shadow position and carried through the same lifecycle as a funded trade, so what each refusal actually saved or cost becomes a measured quantity rather than a claim. The judge reports that record, and if the record turns against it, its authority steps back until the evidence restores it.

Nothing here waits on a human.

There is no approval queue, no discretionary override and no setting that lets an operator wave a trade past the chain. The controls you get are the ones that bound risk. The judgment itself is the product, and it runs whether you are watching or asleep.

Conviction logic withheld

Entry gauntletIdle
Signal on a completed bar·
Minimum edge cost filter·
Regime and event gates·
Data quality check·
Adversarial judge·
Allocator weight and caps·
Sizer, ramp and daily limits·
Router, stop rests at broker·
StandbyEvery candidate walks this path. The ones that clear it reach your account with a stop already resting at the broker, and every decision, either way, is recorded and later graded.

Schematic of the decision path. Not a live feed.

Intelligence

It knows
how much it knows.

Almost no trading system can tell you whether it is getting better, because nothing in it is keeping score of itself. This one carries a standing measure of its own competence, assembled from four components, and it keeps the history so that improvement is something you can see rather than something you argue about.

Competence, accumulating with every closed decision No scale shown. The shape is the point.
Component one

Evidence

How much closed experience actually stands behind the decisions being made right now. A desk that has not yet earned an opinion knows it, and says so, instead of trading like a veteran on its first morning.

Component two

Expectancy

Whether the capital is sitting in the strategies that are measurably earning, or merely in the ones that happen to be active. Being busy and being profitable are different states, and only one of them counts here.

Component three

Quality

How well the recent book is holding together, judged on the desk’s own closed trades rather than on a backtest that already knows the ending.

Component four

Adaptation

How many learned adjustments are currently in force: strategies benched, gates raised, allocations revived. A system that has learned nothing lately has a low reading here, and that is information too.

Every component is computed from the same tables the engine trades from. Nothing in it is a matter of opinion, nothing responds to how the last few days felt, and nothing moves the measure except outcomes that have actually been recorded.

The agent loop

Every trade earns its way
to your account.

This is what agentic actually means here: the software perceives, judges, acts, grades its own result and adjusts, without a human in the loop. No discretionary override, and no trade that skips a step. A chain of independent checks stands between a signal and your capital, each one recorded as it happens. Underneath runs a second loop, which measures how well those checks are performing and tunes them from what it finds.

Feeds bars · filings Strategy once per bar Cost filter edge vs cost Gate chain regime · events Judge 3 prosecutions Allocator weight · size Router bracket · mleg Broker stop rests here Refused booked as a zero-dollar shadow position · reason recorded Taken filled · protected · marked Decision ledger every yes and every no, replayed against the bars that followed Graders entries · exits · vetoes Overseer slow cortex · AI Work orders filed · a human decides Bounded knobs only · receipts written · out of range demotes to a finding

Almost every self improving trading system learns only from what it took. This one also learns from what it declined, which is the great majority of what a disciplined desk does. Twice the evidence, from the same market.

The subsystems

Ten organs.
Every one of them measured.

They divide into what the desk decides, what it remembers, and what it changes about itself. Each is scored by the machinery it supervises, and each earns its authority from its own record.

Judgment

What it decides, and what it refuses
I

Profit Hierarchy

One live ranking over everything actionable.

At any moment a great many setups stand gated behind a named blocking condition. They live in a single ranking that promotes an entry the instant its gate clears and evicts it the instant it degrades. Inbound market events mark affected entries dirty in constant time, a drain task rescores them in bounded micro batches within milliseconds, and serving reads are cached snapshots, so nothing aggregates on the read path. It reorders attention and capital contention. It never places, exits, or bypasses.

Scoring function withheld
II

The Overseer

A second chair, on a short leash.

A frontier model layer reads graded decisions and the live regime on a rolling cadence and returns findings. Only whitelisted controls inside hard bounded ranges may apply themselves, and they do so with receipts. Everything else becomes a written work order for a human. The fast path never waits on it, and no key, no budget, a timeout or a dead network all degrade to the engine behaving exactly as it does without an AI layer.

Control whitelist withheld
III

Health and Self Repair

It fixes its own plumbing, and writes down that it did.

A monitor runs beside the trading loop and answers one question honestly, on a short cycle: is every organ working right now, and if not, can it be fixed without a human? Dead poll tasks, stale feeds, a wedged database, all repaired automatically, throttled per fix, every attempt written to the events log so that fixing itself overnight is an auditable claim rather than folklore. Repairs restore plumbing only. Nothing there can place, size or close a trade.

Repair matrix withheld

Memory

What it keeps, so that it can learn at all
IV

The Decision Ledger

Every yes and every no, kept forever.

Most systems record their trades. This one records its decisions, which is a much larger set, and the difference is the whole basis of its learning. Each row carries what the strategy saw, which gate or prosecution answered it, and what the market subsequently did about that answer. The ledger is the memory the rest of the machine reasons over.

Schema withheld
V

The Grader

The cost of every refusal is measured, not assumed.

Declined candidates, whether gated, vetoed, outranked or rejected, are replayed against the bars that followed. Did the claimed edge pay before an equal move against it? The ledger stops being a record of intentions and becomes matched pairs of decision and outcome, which is the only honest input a system is allowed to rewrite itself from. The approximation used for declined rows is labelled as one, everywhere it appears.

Replay policy withheld
VI

The Exit Grader

A report card on every goodbye.

Each close is replayed forward under a single counterfactual, in which the position keeps its original protection for the remainder of its hold clock, and asked whether leaving when it did cost money or saved it. A tightened trail, a harvest and a timeout are the same question wearing three labels, so one policy answers all of them, continuously, rather than in one audit a quarter.

Counterfactual basis withheld

Learning

What it changes about itself, and on what evidence
VII

The Allocator

Capital follows evidence, not opinion.

Every strategy carries a posterior over its own net expectancy, seeded from decades of backtests and updated by each closed trade. A Thompson sampling bandit draws from all of them at every rebalance, so a strategy the desk is merely uncertain about still gets explored rather than starved by an unlucky start. The moment a strategy’s own evidence says it is no longer paying, its capital is withdrawn automatically. It keeps trading on paper, and a sustained recovery earns the allocation back.

Bench thresholds withheld
VIII

Nightly Self Study

It goes back to school after every close.

Minutes after the session ends, the engine reruns rolling backtests for every strategy that trades on daily bars and blends the result into its own priors, weighted toward the long baseline so that recent history can tilt a prior but can never compound drift it away. The original baseline is preserved and every blend starts from it. The allocator hot reloads the result, and the whole event is written to the learning feed the app displays, so you can watch it change its mind.

Blend weights withheld
IX

Style Autopilot

Each strategy gets the geometry its own record supports.

A single global risk dial applies one hold clock and one reward geometry to every strategy at once, when the evidence says each has its own best setting. The autopilot computes, per strategy, the setting that strategy’s own evidence would choose, gated by an evidence floor so that a winner cannot rest on a handful of trades, and damped by hysteresis so a challenger must beat the incumbent repeatedly before anything moves.

Ring matrix withheld
X

The Forecaster

Machine learning that has to earn its influence.

Gradient boosted trees over a feature set pre registered before any outcome was seen, trained nightly in a separate process and validated by purged walk forward with deploy gates written into the model manifest. A model that fails its gates ships disabled and the engine flies without it. Predictions are observed from the first day and carry no weight at all in the ranking until graded evidence funds them.

Features and horizons withheld

Research discipline

The easiest thing to find in
market data is a pattern
that is not there.

Search enough features across enough events and impressive results appear by chance alone, every time, in any data. A learning system without a defence against that does not get smarter, it gets confidently wrong. The research stack is built around the problem rather than around ignoring it.

Market adjusted outcomes
Every result is measured net of the benchmark over the identical window. Raw returns in a rising market flatter everything, including nonsense, and a study that skips this step will find edge in a coin toss.
A period the search never saw
Patterns are discovered on the training period only, then tested once against a later period held back from the search entirely. Surviving that is interesting. Failing it means the pattern was noise wearing a convincing shape.
False discovery control
Significance is controlled across the whole family of tests at once, not one test at a time, so the set of findings carries a bounded proportion of false positives instead of an unknown one.
Effect sizes, not just significance
A result can be statistically real and economically worthless. Both are reported, and it is the second that decides whether anything is done about it.
No lookahead, structurally
Features describing the moment before an event use only bars strictly earlier than the point the information became public, and events are timestamped at the filing date rather than the transaction date, because that is when the market could first have known.
Pre registration
The forecaster’s features and horizons are fixed before any outcome is seen, and pinned in the model manifest. A loaded model whose manifest disagrees with the running code is refused rather than trusted, because feature drift produces wrong answers with confident faces.

Study parameters withheld

Bedrock

Seven things no intelligence
in this system may touch.

Under every autonomy mode, including full automatic. A finding that would require weakening any of these is skipped and explained rather than applied, and the list itself is one of the protected items, so nothing in the system can quietly shorten it.

Protective stops
They rest at the broker, never only inside this process. If the engine dies mid position, a stop already resting still fires. Equities enter as bracket orders so no window exists where the position is unprotected. Crypto gets a resting stop immediately after the fill, and if that stop cannot be placed the position is closed rather than held naked.
The kill switch
In the menu bar and on the dashboard. Cancels every order, closes every position. Nothing can gate it, defer it, or reason with it.
The daily loss stop
Trading halts at the limit you set for the day. Not a suggestion, not a soft warning, and not a control any AI layer may widen.
The profit target rule
A stopping rule, deliberately. Reaching the target ends the day. It never authorises larger size to chase more, and size never increases in response to a setback. Martingale logic fails the charter on sight, and there is none anywhere in this system.
Pre flight refusal
If the self test fails, trading is blocked and the app names the failing step. There is no override.
The sizing ramp and caps
New order routing code proves itself at reduced size before it trades at full size, and concentration caps bound how much of the account any single idea may become. Both are automatic and require nothing from the operator.
The implausible order guard
The last line between a bad number and a real order. An order that makes no sense against account state never reaches the broker.

Pre flight

Before it risks anything,
it risks a dollar.

The engine will not trade until an automatic self test passes. Nobody is asked to approve it. It simply runs, and takes about two minutes. The fourth step is the one that matters, because it proves stop orders genuinely reach the broker with real money before anything larger is at stake.

  1. Verify credentials, and confirm the account is active and unrestricted
  2. Confirm market data is genuinely streaming for each asset class
  3. Check the trading clock
  4. Place a real order of about a dollar in risk, confirm a protective stop is resting at the broker, close the position, and verify the fees booked correctly
  5. Reconcile the local database against real broker state

Then the ramp. Early trades run at a fraction of full size, stepping up only once the live order path has proven itself over a run of real fills.

The charter

A change that adds expected profit while weakening a loss bound fails this charter.

Governing document. Loaded verbatim into every audit the machine performs on itself.

Every judgment the system makes, whether a control change, a veto, an audit finding or a line of code it proposes, is tested against two hard goals and four questions. Which goal does this serve? What graded evidence supports it? How will success be measured? What is the damage if it is wrong, and what bounds that damage? A change that cannot answer all four is an observation, not an action.

The honesty requirements are enforced structurally rather than aspirationally. Claims are graded, and the grader’s verdicts outrank the rationale that produced them. Changes carry receipts: what changed, why, the value that was persisted, and the metric that will later prove or disprove it. The judge, the overseer and every strategy are held to the standard they apply to others.

Perception

Most of what a chart knows
is already in the price.

So the desk draws on sources that are not, and on shapes a chart cannot show you. Filings, disclosures, funding, calendars, the book itself, and the changing geometry of the market as a whole. Every feed is best effort by design: a dead feed gates nothing, and the engine keeps flying.

The shape of the market Cross asset geometry

Beyond price and volatility, the desk measures the market’s topology: how far apart assets are behaving from one another, treated as a point cloud under correlation distance. Assets dispersed and behaving independently is the normal state. The cloud collapsing, everything fusing into a single blob, is the documented shape that precedes a dislocation, and it is visible in the geometry before it is obvious in the prices.

Insider filings, in real time Edge

Corporate insiders must report open market purchases of their own stock within two business days, and the filing reaches the regulator within minutes. Several distinct insiders buying the same company inside a few weeks is hard to explain as anything but a shared view, and it is the only timely public source of informed trading there is. The desk parses filings itself, builds its own universe from live clusters, screens it for liquidity and tradeability, and takes its holding period from a fitted study rather than a hunch. If the current study validates no horizon, the strategy stands down and says so on screen.

Congressional disclosures Edge, neutral prior

Clusters of legislative purchase disclosures, entered with no prior advantage whatsoever. They must earn weight live against the same bandit as everything else, or they get benched like anything else.

Activist stakes Edge, neutral prior

Fresh activist filings, initial filings only. The same terms apply: neutral prior, live evidence, no exceptions made for a good story.

Perpetual funding Loss avoidance

Breakout longs are refused while perpetual funding sits crowded against its own trailing month, because the crowd paying to be long is not who you want to join. The premise ships with a study script, so a licensee can verify it rather than take it on faith.

Earnings blackout Loss avoidance

No new single name entries near a known print, and positions close the session before it. A stop cannot protect across a gap. Standing aside can.

Volatility stand down Loss avoidance

Above a configured volatility level, no new equity entries at all. A crisis brake, not a mood filter.

The quote tape Self measurement

Top of book is spooled to disk all session, so questions about real spreads by symbol and hour, maker fills and adverse selection are answered from the desk’s own record instead of an assumption buried in a cost model.

The application

A native Mac app.
Not a dashboard in a browser tab.

Sixteen screens in SwiftUI, resident in the menu bar, watching a Python engine that runs as its own supervised process. The two speak over a loopback interface bound to that machine alone. No inbound ports. Nothing listening to the internet.

Set two things, then leave it

Broker keys and risk limits. The keys go into the macOS Keychain and are never written to disk. After that the engine runs its pre flight and starts. On the next launch it resumes in whatever mode it last ran, and after a reboot the login item brings it back without anyone pressing anything.

It shows its reasoning, not just its results

Every row in the ledger is inspectable: what the strategy saw, which gate refused it, what the judge argued, and, days later, what the market did about that decision. The dashboard carries live market context derived from the same data the engine trades on, so the screen can never disagree with the trading logic.

Watch its mind change

The learning feed records every adjustment the desk makes to itself, with the evidence that caused it. Benches, revivals, raised gates, refreshed priors. It is the difference between a system that claims to adapt and one that shows you the receipt.

Bring your own signals

Alerts from charting platforms, or anything that can post JSON, enter as ideas and never as orders. They clear the same cost filter, sizing, ramp and caps as everything built in, and the allocator treats them as one more strategy with no prior, to be benched if they do not pay. An alert carrying a quantity is refused outright, because sizing is never the sender’s job.

The suite that guards all of this includes a check which drives a live regulatory filing the entire way through bars, strategy, sizing and routing into a protected order at the broker, with no human step anywhere in the path.

Tech Specs

What you take delivery of.

Platform
macOS 13 or later. Apple silicon and Intel
Engine
Python 3.12, asyncio, one supervised process
Interface
SwiftUI, menu bar resident, 16 screens
Brokers
Alpaca, in production · second broker adapter in migration
Asset classes
US equities · crypto, around the clock · US options, multi leg
Strategies
19, competing for a single pool of capital
Allocation
Thompson sampling bandit over fee adjusted expectancy
Order protection
Broker resident. Bracket for equities, resting stop for crypto, defined risk for spreads
Research stack
Backtester with a real cost model, options repricing, purged walk forward validation, pattern studies with false discovery control
Prior depth
Equity index from 1993. Bitcoin from 2014
Storage
Local SQLite in WAL mode, parquet research store. Nothing leaves the machine
Local interface
58 endpoints, bound to 127.0.0.1
Credentials
macOS Keychain. Never written to disk
Network
Outbound to broker, regulator and public data only. No inbound ports
Codebase
75,246 lines across 198 modules, Python and Swift
Verification
518 checks in 54 suites. Backtests and a full year single account simulation reproducible from one command
Deployment
One Mac, login item. Resumes trading after a reboot unattended
Documentation
Owner’s guide, field manual, data flow reference and the governing charter

Licensing

Three ways in.

Sold to operators and firms who intend to run it, not to redistribute it. Every tier includes the charter, the owner’s guide and the reproducible research, because a system you cannot audit is one you should not run.

Evaluation

Fixed term, paper account only

  • The complete application, restricted to a paper account
  • Full pre flight, dashboards, decision ledger and learning feed
  • Run the backtests and the year simulation yourself
  • Owner’s guide and charter
Start an evaluation

Operator

Single operator, cleared for live

  • Everything in Evaluation, cleared for live trading
  • Signed application, with updates for the licence term
  • Your own broker credentials and your own account, always
  • Private support channel with the engineering team
  • Onboarding covering the risk settings that actually matter
Request terms

Source

Perpetual, with build rights

  • Full engine and application source, with build rights
  • The research stack, the priors and the study code
  • One broker adapter port included
  • White label naming and icon
  • Architecture handover with the engineering team
Inquire

Inquiries

Tell us what you
would run it on.

Account size, the asset classes you care about, and whether you intend to operate it or build on it. Terms follow from that.

Every threshold marked withheld on this page is withheld for the same reason the desk refuses most of its own signals: the value is in the calibration, and calibration given away is calibration destroyed. Licensees receive it in full.

Answered by an engineer, not a queue

Goes straight to the team. Nothing is shared.

Questions

What agentic trading
actually means here.

What is AI agentic trading?
An agentic system does not wait to be told what to do at each step. It perceives the market, forms a judgment, acts on it, measures what happened, and adjusts its own behaviour from the result. Line For Capital runs that whole loop continuously across crypto, equities and options, with no human approving individual trades.
Does it really trade without approval?
Yes. There is no approval queue and no discretionary override. What you control are the boundaries: which account it uses, how much it may risk, and when it must stop for the day. Inside those boundaries it decides on its own, and every decision it makes, including every refusal, is recorded and later graded against what the market did.
How is this different from a trading bot?
A bot executes rules you give it and cannot tell whether those rules are still working. This desk runs an adversarial judge against its own candidates, scores the value of its own refusals, withdraws capital from strategies its evidence says have stopped paying, and re-studies its priors after every close. The rules are not the product. The judgment about the rules is.
Which broker does it connect to?
Alpaca in production, using your own account and your own API keys, which are held in the macOS Keychain and never written to disk. A second broker adapter is in migration, and a source licence includes one broker adapter port.
What happens if the software stops while a position is open?
Protective stops rest at the broker, never only inside the process, so a stop already placed still fires if the software is not running. On the next start the reconciler compares its records against the broker, adopts anything it does not recognise, and re-arms any missing stop before it is allowed to trade again.
Can I see why it did something?
Every row in the decision ledger is inspectable: what the strategy saw, which gate or prosecution answered it, what the judge argued, and, days later, what the market did about that decision. The learning feed separately records every adjustment the desk has made to itself, with the evidence that caused it.
Do I need to write code or pick strategies?
No. There are no strategy switches in the product. Nineteen strategies compete for one pool of capital and the allocator decides between them from their measured results. You set two things: your keys and your risk limits.
What does it run on?
A single Mac running macOS 13 or later, on Apple silicon or Intel. It installs as a login item and resumes trading after a reboot without anyone pressing anything. Nothing listens on an inbound port, and no market or account data leaves the machine.