Market surveillance that explains itself
Catch market abuse the instant it happens, with an alert you can defend to the regulator line by line. AI-native from the first commit, not retrofitted like the rest.
Deploys on-premise or inside your own cloud account. Single-tenant. Your data never leaves your perimeter.
Every event flows through a deterministic core, then an advisory layer that decides what a human sees first.
The problem
Surveillance teams are drowning, and the abuse is getting smarter
Compliance desks at trading venues face the same four pressures, and most tooling makes at least one of them worse.
Alert fatigue
highToo much noise, not enough signal
Legacy tools fire thousands of bare alerts a day, so the real abuse hides in a backlog no desk can clear.
Cross-product manipulation
criticalBlind spots between products
Abuse now spans a future and its underlying, a bond and its CDS, and siloed surveillance never sees the pattern between them.
Defensibility
criticalScores you cannot explain
A black-box score is not an answer a regulator accepts, only the exact rule, the exact parameters, and the exact events.
Operational risk
highOutages mid-trading-day
Drop events during a failover and that unmonitored window becomes a reportable failure, not an inconvenience.
The solution
Rules surrounded by AI, not replaced by AI
A deterministic core is the system of record. An AI layer reads every alert like a senior analyst, and Sentri runs inside your perimeter. Speed and judgement, with an answer you can still defend line by line.
One event, end to end
live path
Market event
order · trade · quote · news · stats
Detection plane
23 rules · full evidence
Artificial Intelligence Layer
cluster · narrate · rank
Defensible case
rule + params + events
Report
MAR Art.16
Deterministic detection core
23 production rule types across five abuse families run on every event. Each alert names the rule, the parameters, and the underlying events. Fully reproducible, replayable, and defensible to the letter.
An advisory intelligence layer
AI reads each alert the way a senior analyst would: it explains why the alert fired, characterises the abuse pattern and the participant behind it, and clusters related alerts into a single ranked case. A built-in chat lets the analyst ask follow-up questions and dig into the evidence. It advises, it never overrides the rule.
A model runtime you control
Sentri runs entirely inside your perimeter. Models are pluggable: self-host them on hardware you control, or route to an external LLM if you choose. Either way your events, orders, and client data stay inside, and only what you opt to send ever leaves.
How it works
Two planes on one live event stream
A deterministic detection plane decides what is an alert. An intelligence plane of ML models and algorithms decides what a human should see first. Both read the same live stream, in real time.
SENTRI ▸ 23 rules on every event ▸ ML advisory layer ▸ deterministic system of record ▸ four-eyes to close
Detection plane
System of record- 123 deterministic rule types across five abuse families, evaluated on every single event
- 2Real-time pattern rules fire as abuse forms; scheduled sweeps catch marking-the-close and abnormal volume
- 3Same input, same alert, every time: reproducible and replayable to the exact orders and trades
- 4Every alert ships with the rule, its parameters, and the underlying events attached
Intelligence plane
ML · advisory- 1Unsupervised anomaly models flag behaviour no fixed threshold encodes, on the same raw stream
- 2Clustering and graph link-analysis fold related alerts into one case and connect participants across products
- 3NLP reads news and comms to tie trading to market-moving information and intent
- 4A risk model ranks cases by severity learned from what your analysts escalate and close; an LLM writes the narrative and answers questions
AI-embedded vs AI-retrofitted
The question every firm should ask their current vendor
Most surveillance platforms bolted AI onto alerts their rules engine had already produced. Sentri puts the intelligence plane on the same raw events the rules engine sees, before any alert is formed. That is the difference between an add-on and an architecture.
Platforms that retrofitted AI
Bolt-onevents the rules drop are never seen by the AI
- The AI sits after the rules engine, annotating alerts that already exist.
- It never sees the events the rules filtered out, only the ones that survived.
- A bolt-on: switch it off and the same product still ships.
Sentri: AI-native from the first commit
AI-nativeboth planes read the same raw stream, every event
- The intelligence plane reads the same raw stream as the rules, before any alert forms.
- Line of sight to every event, flagged or not, so novel abuse surfaces as a deviation.
- Detection and intelligence are one pipeline, not a feature you switch on.
Detection and intelligence run as one pipeline: the rules decide what is an alert, the AI decides what deserves attention first, and the human decides what to do about it. Not AI stitched onto yesterday's alert queue, but a surveillance platform built around it from the first commit.
The compliance copilot
Ask the compliance desk anything. In plain English.
Sentri ships a read-only copilot your analysts query in natural language. It calls the same audited tools the console exposes, reasons over what they return, and answers with the evidence attached. It reads your data. It never acts on it.
Read-only by design: the copilot explains, clusters, and drafts. Every four-eyes action stays with a human.
See it working
Not a roadmap slide. A platform that runs today.
The pipeline runs end to end on a live deployment right now: real feeds in, alerts out, cases triaged, reports drafted, and every step traced, reconciled, and searchable. The screenshots below are the running system.




Shipped and running
- Real-time ingestion of orders, trades, quotes, and news through FIX and gRPC adaptors into a durable, replayable log
- Deterministic detection running live: spoofing, layering, wash, ramping, marking the close, off-market, and more
- A case manager with severity and status triage, and two-officer four-eyes approval before any escalation
- MAR Article 16 STOR drafts generated straight from a case and its evidence trail
- Reconciliation that proves every ingested trade was accounted for, day by day
- Structured search across every order, trade, and quote, with a cold archive for multi-year retention
- Full observability: metrics, distributed traces, and correlated logs across every service
- Two read-only AI copilots you query in plain English, one for the case load, one for platform health
These are screenshots from a live, running deployment, not mockups. Ask us for a walkthrough on your own data.
Request a walkthroughCoverage
Twenty-three rule types, five abuse families, every asset class
Out-of-the-box detection tuned per asset class, from CDS and interest rate swaps to cash bonds, commodities, FX, and equities. Every rule is parameterised, suppression-aware, and audit-logged.
Price manipulation
- Ramping
- Marking the close
- Abnormal market share
- Abnormal volume turnover
Wash & circular trading
- Trade to trade
- Circular trading
- Circular trading, single party
- Wash trade
Order book manipulation
- Spoofing
- Layering
- Pinging
- Quote stuffing, performance
- Quote stuffing, spread
- Many trades in series
- Many order events in one book
Large & erroneous orders
- Large trade
- Large trade value
- Large order entry
- Mistaken order entry
- Off-market trade
Benchmarked & adaptive
- Large trade, benchmarked
- Trade to trade, benchmarked
- Per-participant rolling baselines
Why it matters
Fast enough for the tape, lean enough for the desk
Built for scale from the first commit: loss-free at volume, clustered for continuity, and light on the analysts and downstream teams who depend on the output.
Deploy
Runs where your data is allowed to live
Single-tenant by design. Sentri deploys into your environment and stays there. You keep custody of every event, every model, and every record.
self-hosted models run here, on hardware you control
only what you opt to send ever leaves
On-premise or your own cloud
Run Sentri in your data centre or inside your own cloud account. The same single-tenant build, deployed wherever your data is allowed to live.
Your data never leaves
On-premise can be fully air-gapped. In the cloud, it runs inside your VPC with no egress. Sentri operates no shared service and sees none of your traffic.
Models you control
Models are pluggable: self-host them in your perimeter by default, or route to an external LLM if you choose. Either way Sentri and your events stay inside, and only what you opt to send ever leaves.
Built for the regulator
Full transaction logs, history tracking, indexed search, and four-eyes approval before any case is closed or escalated. Reporting maps to FCA, SEC, MAS, ASIC, and more.
See Sentri on your own data
Walk through the detection core, the intelligence layer, and the deployment model with our team. We will run a tailored session against the asset classes and abuse patterns that matter to your venue.
Live wire
The market-abuse tape
Enforcement actions and regulatory shifts move constantly. This is the world Sentri is built for, from insider dealing and spoofing to MAR, MiFID II, and MiCA.
- 17d agoTechCrunch▸ Volkswagen engineers charged with insider trading tied to Rivian joint venture
- 1y agoESMA▸ MiCA: market-abuse rules for crypto-assets now apply across the EU
- 2y agoSEC▸ Archegos founder Bill Hwang convicted in sweeping market-manipulation and fraud case
- 2y agoEuropean Commission▸ EU AI Act enters into force; high-risk AI obligations phase in for surveillance systems
- 5y agoCFTC▸ JPMorgan to pay $920M to resolve spoofing across metals and Treasury futures
- 1y agoFCA▸ FCA reminds firms of their MAR Article 16 duty to detect and report market abuse
- 6y agoDOJ▸ 'Flash Crash' trader sentenced over spoofing that helped rattle US equity markets
- 3y agoSEC▸ SEC charges social-media 'pump-and-dump' ring for coordinated stock manipulation
- 1y agoESMA▸ ESMA reviews the market-manipulation indicators supervisors expect firms to monitor under MAR
- 6y agoCFTC▸ Global bank penalised for spoofing and layering in precious-metals futures
- 3y agoFCA▸ FCA secures convictions in insider-dealing ring trading ahead of takeover announcements
- 1y agoESMA▸ MiFID II transaction reporting back under supervisory focus as data-quality gaps persist
- 17d agoTechCrunch▸ Volkswagen engineers charged with insider trading tied to Rivian joint venture
- 1y agoESMA▸ MiCA: market-abuse rules for crypto-assets now apply across the EU
- 2y agoSEC▸ Archegos founder Bill Hwang convicted in sweeping market-manipulation and fraud case
- 2y agoEuropean Commission▸ EU AI Act enters into force; high-risk AI obligations phase in for surveillance systems
- 5y agoCFTC▸ JPMorgan to pay $920M to resolve spoofing across metals and Treasury futures
- 1y agoFCA▸ FCA reminds firms of their MAR Article 16 duty to detect and report market abuse
- 6y agoDOJ▸ 'Flash Crash' trader sentenced over spoofing that helped rattle US equity markets
- 3y agoSEC▸ SEC charges social-media 'pump-and-dump' ring for coordinated stock manipulation
- 1y agoESMA▸ ESMA reviews the market-manipulation indicators supervisors expect firms to monitor under MAR
- 6y agoCFTC▸ Global bank penalised for spoofing and layering in precious-metals futures
- 3y agoFCA▸ FCA secures convictions in insider-dealing ring trading ahead of takeover announcements
- 1y agoESMA▸ MiFID II transaction reporting back under supervisory focus as data-quality gaps persist
Designed for the frameworks your regulator holds you to