Built to stop, not just to trade.

Making money is the easy part to promise. Not losing it badly is the part that takes engineering. If you are thinking about giving a system access to your broker account, this is the page that should decide it for you.

In short. Eight named safeguards sit between an ordinary bad day and a bad outcome. Six of them are circuit breakers: specific conditions that trip a pre-set brake, with no discretion allowed in the moment. The seventh reads the broker's own books through the day and reconciles them against ours. The eighth means orders can leave by exactly one route and no other. Above all eight sits a kill switch that halts new buying in sixty seconds or less.

None of this is a feature list. Each item exists because a particular way of losing money was named first and the brake was built second. A crisis is exactly the moment human judgment is worst, so the response is decided in advance, written down, and applied without argument.

Where a trigger is a published number, it is printed below. Where it is not, we describe the condition in plain words rather than dress it up as precision we do not have.

Safeguards 1 to 6

Six circuit breakers, each with its own trigger.

A circuit breaker is not advice and not a suggestion. It is a condition that, once met, takes an option away from the system until the condition passes.

The safeguards, and what each one stops Consecutive losses a losing streak stops new entries Fast drawdown −7% in ten days, or −12% in thirty Stale data old prices mean no new orders Broker login fails no live session, no trading Rejected orders a cascade of rejects stops the queue Kill switch a full halt in 60 seconds or less Broker check the broker confirms, then the book moves One door out orders leave by one fixed route a named breaker, with its own trigger what makes a halt stick

Scroll sideways to see the whole diagram.

Consecutive losses, drawdown, stale data, broker login and rejected orders are the named circuit breakers, each with a numeric trigger. The drawdown breaker watches two windows: the ten-day one pauses trading for three days, the thirty-day one puts the whole system into its defensive setting. The kill switch, the broker check and the single route out are a different kind of thing: not breakers, but the mechanisms that make a breaker’s decision stick. All of them fail loud. None of them fail quietly.
BREAKER 01

Consecutive losses

Trips when losing trades stack up back to back, rather than scattering the way ordinary variance does.

Halts new buying. Positions already open keep their stops and targets at the broker.

Clears by rule, not by mood. The condition for resuming is set in advance rather than argued about on the day, and lifting the brake is itself recorded, so a brake can never be released quietly.

BREAKER 02

Fast drawdown

Trips when the book falls 7 percent over ten trading days.

Halts new buys for three days. Open positions continue to be managed and exited as normal.

Clears itself when the three days are served. Nobody has to remember to lift it.

BREAKER 03

Slow drawdown

Trips when the book falls 12 percent over thirty trading days.

Halts normal sizing. The system is forced into its most defensive posture for thirty days.

Clears when the thirty days are served, and only back into whatever mode performance then justifies.

BREAKER 04

Stale data

Trips when a price or an input is older than its freshness limit, or simply missing.

Halts the decision that depended on it. A stale number is never quietly substituted for a live one.

Clears when the feed comes back inside its limit.

BREAKER 05

Broker-login failure

Trips when the connection to your broker is not live and valid.

Halts order placement. Nothing can be sent without a working connection, so a dead login produces no orders rather than mystery ones.

Clears when the connection is restored. It is checked before the market opens each trading day, so a broken login is found early rather than at the moment an order matters.

BREAKER 06

Rejected-order cascade

Trips when the broker refuses an order and a bounded set of automatic retries does not clear it.

Halts that ticker for twenty-four hours. The rest of the book carries on. A rejection usually means something specific is wrong with that name, not with the market.

Clears when the twenty-four hours are up.

Safeguards 7 and 8

Two that are not brakes.

A brake stops the system from doing something. These two do a different job. One makes sure the system is not fooling itself about what already happened. The other makes sure there is only one way out.

7. It verifies the broker, not just itself

Through the trading day the system reads the broker's own books and reconciles them against its records. If a stop fired at the exchange, the journal learns it at the price the shares actually sold for, not the price we asked for. Nothing is assumed done because an order was sent.

This sounds obvious. It is not how most automated systems behave. The common failure is quieter than a crash: the software believes it still holds a position that was sold out from under it an hour ago, and every decision after that is made on a book that does not exist. Checking the broker's version is the only cure, and it has to be routine rather than something anyone remembers to do.

8. One door out

Orders can leave by one controlled, verified route and no other, which is what SEBI's algorithmic trading framework expects. Nothing reaches your broker any other way. One door, and one record of everything that walked through it.

The protection is in the narrowness. A system with several ways to reach your broker has several ways to be wrong about what it sent. This one has a single path and a single record, which is also why the audit trail can be complete rather than mostly complete.

One door out: how an order leaves the system ORO SAGE the system One route out one controlled, verified route Your broker your own account Exchange where the stop rests Any other address Any other machine the only route the broker accepts blocked: the broker refuses it

Scroll sideways to see the whole diagram.

Every order takes the same path, in the same direction: the system, one controlled route, the broker, then the exchange. No other machine and no other route can send an order in ORO SAGE’s name. Under the SEBI algorithmic trading framework, a broker is expected to accept algo orders only through identified, pre-verified routes. ORO SAGE is applying for registration under the applicable SEBI framework, and the routing is already built this way.

The kill switch

One command halts all new buying in sixty seconds or less, whether you pull it yourself or the system pulls it on itself. However the halt is called, there is one answer to the question of whether trading is stopped, not several opinions sitting in different places.

It is designed never to fail silently. A halt raises an alert, and the alert keeps trying until it has actually reached someone. If the brakes are pulled, they are pulled, and you will know it. A halt also stays a halt. Trading does not creep back on its own, it takes a deliberate decision to clear it, and that decision goes on the record. When Autopilot opens, the same switch is yours for your own account. (Autopilot opens after SEBI registration and broker algo-empanelment are in place.)

There is one more rung below the eight. A fall of 20 percent escalates to the founder directly. That rung is deliberately not automatic. It is the point at which a person is required to look.

Cash held back when the weather turns

ORO SAGE decides how much of the account may be deployed at all before it decides what to buy. That ceiling moves with the market regime and with the system's own recent performance: worse conditions, more cash held back, smaller positions. It refuses to be fully invested into a falling market.

The instinct most of us lack, stepping back when the weather turns, is written into the rules here rather than left to a mood on the day. The exact ceilings are governed policy, reviewed weekly, and they move as the review learns. Rather than print a number that could quietly drift out of date, this page commits to the behaviour, and the journal records the policy that applied on any given day.

Concentration caps

No single position may exceed the ceiling its conviction score earns. At the top band, a score of 9 or above, that ceiling is 20 percent of the portfolio. Between 7 and 9 it is 15 percent. Below 7 a candidate is not sized down, it is rejected outright. Each sector carries its own cap on top of that.

Diversification here is a rule the code enforces before an order exists, not an intention someone remembers on a good day.

Fail loud, never fake

A stale or fallback price is never allowed to masquerade as a live one. Every number the system uses carries where it came from and how fresh it is, so degraded data is either flagged as degraded or the work stops. Silence is treated as a failure, not as an all-clear.

Most quiet blow-ups in automated trading are not dramatic. A system keeps trading on numbers that stopped being true, and nobody notices for a week. This one is built to stop instead. The same discipline is what makes every claim on this page checkable rather than a matter of trust: see how we show our work.

The question nobody answers

What happens if ORO SAGE itself goes down.

Servers die. Code has bugs. Any honest answer to this question has to work on the day the system is not there to answer it.

Your stop and your target are not held in our software. They are placed with the broker at the moment of entry, which means they sit at the exchange. If our server dies at eleven in the morning, the thing that sells you out of a falling position is not our machine. The protection does not depend on us being awake.

What we still owe you is the truth about what happened while we were gone. When the system comes back up it reads the broker's books before it does anything else and reconciles them against its own. If a stop fired during the outage, the journal learns it at the price the shares actually sold for.

Until those two sets of books agree to the rupee, the system will not open anything new. Exits stay allowed, always. Entries wait. A system that is unsure what it owns has no business buying more of it.

The monitoring that notices the silence is kept deliberately separate from the system it watches, so it does not go down alongside it. And if the whole system ever has to be rolled back to hands-off, that is one deliberate decision, and your positions stay protected at the broker either way.

None of this removes risk. Trading loses money sometimes and no safeguard changes that. What these measures are built to do is make a catastrophic loss far less likely than an unguarded system would allow, and to make every stop that fires visible rather than discovered later. Read the honest version in the risk disclosure.