Skip to content
ORBITRAONE

Cortex intelligence

Automation with authority limits, evidence and an instant stop.

Cortex is the policy-bound AI trading and intelligence layer of ORBITRA ONE™. Its agents observe markets and portfolios, reason over approved data and propose actions — then act only within permissions you grant, explain every decision and stop on a single command.

  • Eight policy controls
  • Reason, risk and provenance
  • Verifiable action receipts
  • One-command kill

The governed loop

Six steps between a signal and an order.

No agent reaches the market directly. Every intent is simulated and authorized before it can execute.

Illustration: The governed agent loop: observe the market and portfolio, reason with a model ensemble, propose a trade intent, simulate it in Aegis, authorize it through the policy engine and execute it on ApexMatch. Eight policy gates surround the loop — capital, loss, leverage, markets, time, human confirmation, data sources and a one-command kill.
Cortex
  1. 01ObserveMarket and portfolio
  2. 02ReasonModel ensemble
  3. 03ProposeTrade intent
  4. 04SimulateAegis risk
  5. 05AuthorizePolicy engine
  6. 06ExecuteApexMatch
  • CapitalMaximum allocation
  • LossDaily and lifetime stop
  • LeverageInstrument ceiling
  • MarketsAllow / deny lists
  • TimeSession and expiry
  • ActionHuman confirmation
  • DataApproved sources
  • KillOne-command revoke

A governed loop in six steps: Observe (market and portfolio), Reason (a model ensemble), Propose (a trade intent), Simulate (Aegis risk), Authorize (the policy engine) and Execute (ApexMatch). Eight policy gates surround the loop — capital, loss, leverage, markets, time, action, data and kill. A proposal reaches execution only after clearing every gate that applies to it, and the kill control can stop the loop at any step.

Two modes of intelligence

Research is broad. Execution is governed.

Thinking and acting are separate paths in Cortex. An agent may explore any idea; turning one into an order takes authority you have granted.

Scope

Broad research
Any market, timeframe or scenario you ask about
Governed execution
Allow-listed markets, inside the active session

Inputs

Broad research
Any source you permit for research, with provenance recorded
Governed execution
Approved data sources only, plus current portfolio and Aegis state

Output

Broad research
Analysis, scenarios, hedge ideas and explanations
Governed execution
A signed trade intent with its limits attached

Authority

Broad research
None — research cannot move capital
Governed execution
Bounded by capital, loss, leverage and time limits

Evidence

Broad research
A reasoning trace you can review
Governed execution
A verifiable action receipt for every order

Policy controls

Eight controls define what an agent may do.

Policies are set per agent, versioned and enforced at the authorization step — outside the agent’s own code, so an agent cannot rewrite its limits.

Capital

Capital allocation

The most capital an agent may commit, in total and per market.

Loss

Daily and lifetime loss limits

Hard stops on loss per day and across the agent’s life. At either limit, trading stops.

Leverage

Leverage ceiling

A cap per instrument, set at or below what your account allows.

Markets

Market allow/deny lists

The instruments an agent may trade, and those it must never touch.

Time

Session and expiry

Trading windows, plus an end date after which authority lapses.

Action

Human confirmation

Which actions wait for your approval before they are sent.

Data

Approved data sources

Only approved feeds and datasets can inform an executable intent. Other sources stay in research.

Kill

One-command kill and revocation

A single command halts the agent and withdraws every permission it holds.

Explainable actions

Every action arrives with its reasons.

A Cortex proposal is never a bare instruction. It states why the agent wants to act, what Aegis expects the action to do to your portfolio and which data informed it — so you judge the reasoning, not only the outcome.

Every action, including one the policy rejects, produces a verifiable action receipt: a signed record of which agent acted, under which policy version, on what simulated risk and authorization, and with which orders and fills. A receipt can be checked without trusting the agent that produced it.

  • Reason: the signal and logic behind the proposal
  • Risk: the simulated post-trade state and any limits touched
  • Provenance: each data source and when it was read
  • Receipt: signed and linked to ApexMatch execution records
Illustration: A radial graph with Aegis at its center and six risk dimensions around it: collateral, volatility, liquidity, concentration, correlation and counterparty exposure. The shaded shape shows a portfolio’s current exposure; selecting a dimension shows how a change in it propagates to margin, limits and liquidation distance.

AEGIS

Unified risk graph

Select a risk dimension

Collateral · Volatility · Liquidity · Concentration · Correlation · Counterparty

Margin used
Liquidation distance

Human confirmation

You decide how much the agent decides.

Confirmation modes are set per agent and can differ by market and action type. Institutions can require four-eyes approval for any policy change.

  1. 01

    Propose only

    The agent prepares a complete intent with its reason, risk and sources. Nothing is sent until you place it yourself.

  2. 02

    Confirm each action

    Every intent waits for your approval on a signed-in device, and expires if its window closes first.

  3. 03

    Confirm above thresholds

    Small in-policy actions proceed. Anything above the size, leverage or loss impact you set waits for you.

  4. 04

    Autonomous within policy

    The agent acts without prompts inside its full policy. Every action still leaves a receipt for review.

Kill and revocation

One command stops the agent and revokes its authority.

The kill path does not depend on the agent’s cooperation. It halts new actions, withdraws the agent’s resting orders and revokes its permissions at the identity layer, so its signatures are no longer accepted for your account. Existing positions stay under your control and your Aegis protection policies.

Put intelligence to work on your terms.

Automation, including AI-assisted automation, can fail or behave unexpectedly, and you remain responsible for the permissions you grant. Cortex access depends on jurisdiction and eligibility.