Understand trading incidents. Control the response.
Tusiro brings incident review and bounded protection into one product for trading execution. It is designed to help your team understand what happened and keep its response within agreed limits.
Current pilots review historical records and are read-only. Bounded protection during live incidents is designed, not built.
THE PROBLEM
An order goes wrong. Your team needs a clear next step.
Understanding the incident and controlling its consequences are part of the same operational problem.
A customer order
An order moves through the firm's systems, from a customer or from the firm's own trading desk.
Something looks wrong
It arrives late, gets rejected, shows a strange price, or fills unexpectedly. A dispute opens, or the desk asks for answers.
The hard question
What happened, did the system behave correctly, and what response is justified?
Answering takes hours to days of senior engineering time. Engineers open logs, match order IDs, and rebuild the timeline by hand while customers, risk, and management wait. Discovery interviews with brokerage engineering staff confirmed this pattern.
In 2012, Knight Capital routed unintended orders for roughly 45 minutes after a faulty deployment. The firm struggled to see what its systems were doing and lost over $460 million. Incident cost grows while a firm is blind.
SEC Exchange Act Release No. 70694
PROOF
Order-record correctness is not a solved problem anywhere.
In October 2024, FINRA fined Citadel Securities $1,000,000 and IMC Financial Markets $1,200,000 for inaccurate order-event reporting to the Consolidated Audit Trail. Citadel Securities misreported roughly 42.2 billion order events over two years. IMC misreported roughly 21.8 billion across 35 distinct error types. Software and system issues caused the errors, and the firms' own tooling did not catch them.
Even firms with deep infrastructure teams can lose track of their own order records. The problem remains unsolved, and fines follow.
WHAT YOUR TEAM RECEIVES
A shared incident record to support the next decision.
Order received at 10:04:11 · Risk check completed
No confirmation back from the exchange · No final message sent to the customer
Internal status says “OK” · Customer-facing status says “Rejected”
This is the report you can evaluate in a Tusiro pilot. Engineering, risk, and operations can review the same findings, see where evidence is missing, and explain the incident to customers or management.
THE PRODUCT IN CONTEXT
From understanding an incident to controlling its impact.
Tusiro connects two questions your team faces in the same incident: what can we establish from the records, and how should we keep the response within agreed limits? Evidence-backed review and bounded protection belong to that one product experience.
The goal is a clear account for engineering, risk, and operations, with protection during live incidents planned as part of Tusiro. Current pilots let you evaluate the incident-review experience on your own historical records.
Current pilots review historical records and are read-only. Bounded protection during live incidents is designed, not built.
WORKING INSIDE YOUR CONTROLS
Your execution data stays in your environment.
Agree the pilot's access and data-handling boundaries with your security team before work begins.
Deploy close to the data
Tusiro runs inside the customer's VPC or fully on-premises when required. Sensitive data does not pass through a vendor cloud.
A read-only pilot
Current pilots use historical records, with no live trading access or execution control.
Control what is shared
Your firm controls access to the report. Any sharing outside the environment is limited to a redacted report.
Deployment, access, and data handling are agreed before the pilot. Detailed security discussions take place with qualified customers through the agreed NDA process.
STATUS
Evaluate Tusiro on the evidence.
581,030
real NASDAQ order-book events processed end to end using LOBSTER academic data. This validates Tusiro's historical review on public data, not integration with a customer's records or live protection.
What this proves, and what it doesn’t
This proves the engine can run end to end on real market structure using public data. It does not prove integration with a customer's messy multi-system records. Pilots test that.
Additional data-source support
IBKR FX support is in implementation. Customer-specific data compatibility is assessed during pilot scoping.
WHY NOW
Regulators now penalize firms that cannot explain their own orders.
Citigroup fined £61.6M.
UK regulators fined Citi £61.6M after a $1.4B erroneous sell-off briefly hit European markets.
FINRA fines Citadel Securities and IMC.
FINRA fined Citadel Securities $1M and IMC $1.2M for inaccurate order records. Bad records block reconstruction of market events.
EU DORA takes effect.
ICT incident classification and reporting becomes a legal duty for about 20 categories of EU financial entities.
ESMA briefing on algorithmic trading.
The briefing sets expectations for governance, testing, and pre-trade controls. Firms must address AI used in trading algorithms in annual RTS 6 self-assessments.
Enforcement is widening from bad trades to bad trade records. Firms that cannot reconstruct order events face fines. Tusiro produces the evidence report.
NEXT STEP
Start with one incident.
Evaluate Tusiro with records from one past incident, under an agreed security process. Review the findings with your team and decide whether the product fits your operation.