Skip to content
ORBITRAONE

Institutions

Institutional by construction.

Brokers, funds, treasuries and market makers need more than an order book. ORBITRA ONE™ gives each duty its own permission, each action its own signed record and each system — execution, custody, risk and reporting — a deterministic interface.

  • FIX and native APIs
  • Four-eyes approvals
  • MPC and HSM signing
  • Independent kill controls

Control architecture

Six control domains. One evidence trail.

Each institutional control writes to the same signed record as the trades it governs, so trading, risk, operations and compliance read one version of events.

Illustration: Six institutional control groups arranged around one deterministic core: execution, governance, operations, risk, custody and compliance, each listing its principal controls.

01Execution

  • FIX and native APIs
  • Colocation-ready gateways
  • Drop copy and TCA

02Governance

  • Role-based permissions
  • Four-eyes approvals
  • Policy-as-code

03Operations

  • Subaccounts
  • Fee and rebate rules
  • Reconciliation exports
Settlement core

04Risk

  • Real-time limits
  • Stress and scenario APIs
  • Independent kill controls

05Custody

  • MPC and HSM signing
  • Qualified-custody links
  • Withdrawal governance

06Compliance

  • VaultID credentials
  • Market surveillance
  • Jurisdiction controls

Six control groups surround one deterministic core, together holding eighteen institutional controls. Execution: FIX and native APIs, regional and colocation-ready gateways, drop copy and TCA. Governance: role-based permissions, four-eyes approvals, policy-as-code. Operations: subaccounts, fee and rebate rules, reconciliation exports. Risk: real-time limits, stress and scenario APIs, independent kill controls. Custody: MPC and HSM signing patterns, qualified-custody integration points, withdrawal governance. Compliance: VaultID credentials, market surveillance, jurisdiction controls.

Execution

Connectivity for professional order flow.

FIX and native APIs
Industry-standard FIX connectivity alongside native APIs, with identical order semantics, limits and fill evidence whichever interface an order uses.
Regional gateways
Ingress points close to market participants verify signatures and timestamp orders before fair sequencing.
Colocation-ready gateways
Gateway architecture prepared for colocated connectivity, under the same sequencing rules as every other participant.
Drop copy
An independent real-time copy of execution reports for risk, operations and compliance systems.
Transaction-cost analysis
Fills measured against arrival, interval and benchmark prices, computed from the engine’s own signed records.

Session setup, message formats and integration guides are covered in the developer documentation.

Governance and operations

Duties separated, policies versioned, books reconciled.

GovernanceRole-based permissions
Trading, risk, operations and read-only roles, each scoped to accounts, subaccounts, markets and actions.
GovernanceFour-eyes approvals
Withdrawals, limit changes, policy edits and new agent permissions can require a second authorized approver before they take effect.
GovernancePolicy-as-code
Limits, allowlists and approval rules are versioned, machine-readable policies enforced by the protocol, with a complete change history.
OperationsSubaccounts
Separate strategies, desks or client flows into subaccounts with their own margin, limits and permissions.
OperationsFee and rebate rules
Fee schedules and maker rebates are configured per account tier and applied deterministically in clearing.
OperationsReconciliation exports
Trades, positions, balances, fees and funding in consistent export formats that tie back to signed records.

Risk

Limits that act before exposure exists.

Real-time limits on notional, position size, order rate and loss are evaluated by Aegis ahead of matching — for every account, subaccount, API key and agent.

Stress and scenario APIs run your own shocks against the current portfolio graph. Kill controls sit with the risk function, independent of trading: one action cancels open orders, blocks new ones and revokes API and agent permissions.

  • Pre-trade limits per account, subaccount, key and agent
  • Programmatic stress tests with custom scenarios
  • Kill controls held independently of the trading desk
  • A signed record of every limit change and intervention
Illustration: A radial graph with Aegis at its center and six risk dimensions around it: collateral, volatility, liquidity, concentration, correlation and counterparty exposure. The shaded shape shows a portfolio’s current exposure; selecting a dimension shows how a change in it propagates to margin, limits and liquidation distance.

AEGIS

Unified risk graph

Select a risk dimension

Collateral · Volatility · Liquidity · Concentration · Correlation · Counterparty

Margin used
Liquidation distance

Custody

Keys and withdrawals under governance.

MPC signing patterns
Signing authority split across independent key shares, so no single party or device can move assets alone.
HSM signing patterns
Keys generated and used inside hardware security modules, with signing policies enforced at the module.
Qualified-custody integration points
Interfaces for qualified custodians to hold assets, attest balances and release collateral under agreed rules.
Withdrawal governance
Destination allowlists, time delays, velocity limits and approval quorums applied before assets leave custody.

Custody arrangements are selected per account. See security for the full key-management and asset-security model.

Compliance

Eligibility and oversight inside the protocol.

01

VaultID credentials

Verifiable credentials for the institution, its users and its agents, disclosing only the attributes a market or issuer requires. See VaultID.

02

Market surveillance

Monitoring for manipulation patterns such as spoofing, layering and wash trading across markets, with alerts and case records.

03

Jurisdiction controls

Access to products and markets follows the institution’s credentials and is enforced before trading, not reviewed after the fact.

Institutional inquiry

Speak With the Institutional Team

Tell us about your institution, your role and the capabilities you want to evaluate. Please do not send identity documents, credentials or keys through this form.

  1. 01The institutional team reviews each inquiry and replies to your business email.
  2. 02Your requirements are mapped to execution, custody, risk and reporting capabilities.
  3. 03Where relevant, technical discussions cover API and FIX connectivity and integration with your existing controls.
  4. 04Eligibility and onboarding requirements are explained before any account step.

Never include passwords, private keys, seed phrases or identity documents.