Architecture & Security

Where the rules live decides whether they hold

This page is about trust: why Detent's enforcement doesn't ask your permission in the moment, and why running it never means handing anyone your keys, your data, or your edge.

Rules you can route around aren't rules

The whole trick is placement: Detent runs as its own process at the API layer, acting on the account itself — not a panel you can trade around.

Rules in a panel

A front-end rule is a suggestion. Trade around the panel once and every gate it carried — size caps, session windows, cooldowns — is gone the moment you need it.

Rules at the API layer

Detent runs as its own process against your broker's API and sees positions however they were opened. Bypassing a UI doesn't bypass the enforcement — it never lived in the UI.

One loop, four stages

Market data flows in, the engine evaluates, the gate layer decides, and only risk-reducing order actions flow out — no human in the hot path.

01
Your broker's feed
Live market data, on your credentials
FEED
02
Detent engine
Runs on your machine, watching your positions
ENGINE
03
Gate layer
Your rules, checked on every position
GATE
04
Risk-reducing actions
Tighten, close, or lock — never adds risk
ACT
Enforcement model

Lock-only, by construction

Every action the engine can take reduces risk: it tightens stops, locks profit, closes positions, and locks the account after a rule break. Stops only ever move toward safety — widening is refused at the same layer. In its first confirmed live save — a single logged instance, not a typical result — the lock converted a full-R loss into roughly half.

Route your orders through Detent and it can reject a rule-breaking order before it fills. Trade direct and it still catches the position and acts — it just can't un-send what you already sent.

CadenceEvery bar close
Stop directionLock-only, never widens
EntriesAlways yours — it never trades
Runs on your device
Risk-reducing actions only
Local audit log

Your keys, your machine, your rules

Detent is software you own and run — not a service you trust with your account. The security model is structural, not a promise.

You · your machine
Detent runs here — a local process
Your broker
Your account & API

Your keys, market data, and fills move only between you and your broker. No order and no trade of yours ever passes through a Detent server. The only thing that reaches us is a license check.

Credentials

Nothing passes through us

Your broker credentials are used on your own machine to reach your broker's API, and are never sent anywhere else. You enter them locally, and they never leave the device.

Configuration

Set at setup, locked in session

You define every threshold before the session starts. Once you're trading, the configuration is locked: no in-the-moment override, no "just this once." Changing your rules is a between-sessions act, on purpose.

Ownership

It holds nothing of yours

Not a managed service, not a signal service, not copy trading — Detent has no opinion on what you should trade and takes no custody of anything. Your audit log stays local and readable.

Fail-safe

It has to be running

Detent acts while it's running and connected to your broker. It leans on your broker's own stop — a real order that holds even if Detent or your connection drops — and reconciles your positions when it reconnects. That's the honest limit, and it's why your stop lives at the broker, not just in the app.

Compatibility

Works with the API your broker or prop firm already exposes

Detent connects on your own credentials, through the platform your broker or firm already runs on. Most funded-futures firms run on Rithmic, Tradovate, or ProjectX — if yours exposes API access, Detent connects on your own key.

Live today: ProjectX
Roadmap: Tradovate · Rithmic · TradeStation · Ironbeam · more
// What keeps it inside prop-firm rules
CredentialsYour own API key
Where it runsYour own device — no cloud
What it doesReduces risk only — it never trades for you

The ProjectX adapter is built and verified on a live account; the rest of the platform list is roadmap. And firms differ: confirm your firm's API access and automation terms before you buy. That call is yours.

The loop, on a real record

Run over 885 real trades

The same four-stage loop, against one funded futures trader's own history. No enforcement was running for it — so the record is a plain catalogue of the behaviors this architecture exists to block.

Revenge entries
451

Re-entries after a loss — the trade that turns a red day into a blown account.

Stop-widenings
312

The stop dragged wider mid-trade. The loop puts it back on the next bar close.

Worst day
−$6,336

The day the daily floor is built to end before it compounds.

Enforce your rules at the API layer

Works with major futures brokers through their own API — more on the roadmap. Runs on your own credentials, and can only ever reduce risk. Waitlist members get early access and founding-member pricing.