Solutions · Institutional Trading Desks
Controls your procurement team can verify, not just read about.
Desk technology gets bought twice — once by the traders and once by the people who answer for it: risk, compliance, security, audit. VegaTrade was designed for the second purchase. The properties a control attestation needs are implemented as architectural invariants, each one observable in the product and evidenced in the audit chain.
Control Plane
One order path. One halt authority. No exceptions.
Every order on the platform passes the pre-trade risk gateway in the C++ hot path — position-size caps, daily-drawdown stops, order-rate ceilings, and per-tenant symbol whitelists, evaluated deterministically before any order can reach a broker. The gateway is the only path; the architecture has no bypass for administrators, models, or maintenance modes.
The kill switch propagates over a dedicated, ECDSA-P256-signed control channel with epoch, scope, and heartbeat — a spoofed engage or a suppressed disengage is rejected at the subscriber. An operator-issued global halt reaches every fast-loop component in under 100 milliseconds, survives process restarts via a state-file fallback, and records the issuing operator, the engagement's geolocation, and the chain-of-custody of every in-flight order.
Forensic Attribution
"Show me everything this user did" — answered byte-identically.
Privileged actions — authentications, trade executions, administrative and configuration changes — are designed to be geo-attributable through the audit chain: originating IP and derived geolocation are captured on the action event, with downstream events joined by chain reference, and events that fail attribution are quarantined rather than silently dropped. Capture-time anomaly flags (VPN, Tor exit, datacenter IP, impossible travel) are specified in the same security-telemetry slice, on the roadmap.
The chain those events live in is hash-linked per tenant, signed daily in a hardware security module, archived to WORM storage with seven-year retention, and replayable byte-identical. When an internal-audit request or a regulator inquiry arrives, the desk's answer is a verified export, not a log-stitching project.
Desk Workflow
A working surface, fast enough to live in.
The console is keyboard-first and live: a draggable, symbol-linked trader workspace; an orders blotter streaming over server-sent events; positions, P&L, margin, drawdown, correlation, and exposure-concentration views; execution-plan and performance-attribution surfaces; and a command palette for navigation. Risk-limit utilization renders against the desk's own configured gates, so the trader and the risk officer are reading the same number.
On the roadmap for institutional deployments: a signed thick-native desktop client running local C++ compute against the regulated backbone, FIX drop-copy ingress, and a pluggable broker-adapter SDK for multi-broker execution. Each is specified in the platform's architecture records; the contact form is the entry point to discuss timing.
Send us the security questionnaire first.
The platform is pre-launch; the architectural evidence map — audit-chain integrity, HSM signing discipline, tenant isolation, encryption posture, RBAC — is ready for the procurement conversation now.
Request Access