Graduated drawdown ladder
Losses do not hit a single cliff. Risk is withdrawn in stages, so a bad morning narrows the book instead of ending it.
Pravrtti Elements · built with Codexonic
PRAMMIT runs your strategy, byte for byte, and wraps it in a risk layer that can only tighten — never widen. Loss mitigation outranks profit here. That is a rule the code enforces, not a value on a slide.
The ledger below is a recorded replay of the 2026-07-16 tape across the full F&O universe, with option chains approximated from candles — research grade, which is why not one of its rows is evidence-eligible. No live capital is deployed, and no return is claimed.
01 Why this exists
The system that came before PRAMMIT had a risk manager. It sat beside the engine — advisory, bypassable, and never a binding authority. An AI sat in the trade-approval path. No edge was ever measured before capital went in. Every one of those three facts is now structurally impossible.
02 The order path
This is the entire route from a signal to an order. There is no second route. A quantity can be reduced or refused anywhere along it, and increased nowhere — no gate, advisory, model or operator can widen a cap your strategy did not ask for.
Proposes
Your logic, unmodified and content-hashed. Immutable in CI — a bug we find is reported to you, never quietly patched.
May reduce
Six advisory domains — capacity, portfolio, stress, surveillance, treasury and mitigation — submit content-hashed constraints. Each is re-validated at the install boundary; one that widens is rejected outright.
May refuse
The sole enforced risk authority, scoped per tenant. No order path in the system may bypass it, and none is permitted to exist that does.
May refuse
Capability and margin, verified against the broker. If margin cannot be confirmed, the order is blocked — never assumed into existence.
Records
Only now does an intent exist. If the venue's answer is ambiguous it is reconciled and halted — never re-placed somewhere else on a guess.
Quantity surviving 1,200 at gate 01 · proposed
Reduction is the only direction of travel. A strategy that asks for 1,200 may leave with 500 — or with nothing. It can never leave with 1,201.
03 The loss stack
A supervised loop evaluates these on every tick. They act only by reducing a submitted quantity, tripping a kill switch, or halting the guard — never as a parallel enforcer competing with it.
Losses do not hit a single cliff. Risk is withdrawn in stages, so a bad morning narrows the book instead of ending it.
Three scopes. The widest one always wins.
Three venues behind one execution contract. When a venue's answer is ambiguous, the platform reconciles and halts — it does not re-place the order elsewhere and risk a double fill.
The dangerous state is not "low margin" — it is "margin unknown". If headroom cannot be verified, new risk is blocked, which is what keeps a broker's auto-square-off from making the decision for you.
Verified headroom · unverified region is blocked, not estimated
Notional, quantity and price sanity, applied before anything reaches a venue — including to the platform's own operators.
Every client runs in an isolated runtime with its own guard, capital, state namespace, decision log and kill switch. A crash or a halt is quarantined to that tenant — it is never allowed to propagate, and the platform-wide roll-up never nets a single tenant's breach away into an average.
04 The rulebook
Every rule below has an enforcement point in the source tree. A test asserts that each one is still enforced, so a rule cannot decay into a comment. There are no warnings — a rule either halts, refuses, or fails the build.
Rulebook fingerprint e060d375a84a8a60de59ffcb5cdad4ad38b1bc2350a3194e2e60ea36327875de
P1-paper-only Prime Halt P4-strategy-ip-immutable Prime Fail CI R1-single-enforced-authority Risk Halt R3-loss-mitigation-outranks-profit Risk Refuse D4-no-fabricated-values Data Refuse X1-no-lookahead Execution Refuse G4-no-exceptions-without-a-waiver Governance Halt 05 Evidence
Every setup a strategy sees is written to a ledger — including the ones it declined, which is what makes an honest comparison possible at all. The statistical gate then needs sixty independent sessions before it will even consider returning a verdict of EDGE.
We are at one. So the verdict is INCONCLUSIVE, and it will stay that way until the arithmetic says otherwise. A platform that would overstate its own results would overstate yours.
1 of 60 sessions recorded 59 short of quorum
The haircut for parameter search is applied before any verdict, so a strategy cannot pass by being tuned until it looks good. An INCONCLUSIVE result is the gate working, not the gate failing.
06 Claims we refuse to make
Guaranteed returns
No component may promise or imply a return. That is rule R3, and it is enforced in the tree — not a disclaimer bolted on at the end.
Proven backtested profit
A backtest is a hypothesis, not a result. Ours run point-in-time, fill at the next bar, and are priced for the parameter search that produced them. Most survive none of that.
AI that predicts the market
The learning layer has no live order path at all. It advises, and its advice can only tighten. The last system put a model in the approval path; that is precisely what we removed.
Profitable in paper, ready for live
A paper profit confers no live authority. Neither does a passing test, a backtest, or a successful mock. Go-live is a separate, human-gated decision against fresh evidence.
Production-ready today
It is not, and we publish the gap. Direct live onboarding is disabled, venue behaviour is not yet certified with credentials, and the option loss envelope is not economically complete. You will hear that from us before you hear it from your P&L.
07 Bringing a strategy
Your strategy is validated, never edited. Nothing advances a stage automatically, and the final stage does not advance without a person deciding it should.
A static safety scan rejects filesystem, network and dynamic-execution access. A behavioural sandbox then runs your code against bar context alone, checking it is deterministic, well-formed and bounded.
Validates · never edits
The accepted version is content-hashed into an immutable registry. Every production run afterwards re-verifies that hash against the bytes on disk, so no run can assert a strategy by name alone.
Hash-pinned · versioned
It runs in paper alongside the incumbent, writing every setup it sees to the ledger — refusals included. Drawdown, not return, is the primary comparison.
Paper · fully recorded
Promotion requires a fresh attestation and a human approval, recorded in a hash-chained ledger. A challenger that worsens drawdown is retired even when it has an edge.
Human decision · reversible
08 Engagement
Commercial terms are set per engagement against your capital, venue count and strategy complexity — so we quote after a walkthrough rather than pricing a risk envelope we have not seen.
For a desk that already trusts its strategy and wants it executed the same way every single session.
For capital where the downside matters more than the upside — the reason this platform exists.
For desks willing to contribute strategy behaviour to the training corpus on negotiated terms.
09 Straight answers
No. Every execution path is paper or dry-run, and direct live onboarding is disabled in the codebase. That is enforced by the first rule in the rulebook, which is not waivable. When it changes, it will change as a deliberate, ledgered decision — not as a configuration flag someone flips.
We will not answer that, and you should be wary of anyone who does. The honest statement is: expected return is unknown until an edge verdict is measured on your strategy; downside is structurally capped by the loss stack; and the catastrophic case — an unbounded, unattended drawdown — is what the architecture exists to exclude.
It is treated as immutable and owner-controlled. The platform validates it, hashes it and runs it — it never edits it. If we find a bug in your logic we report it to you; we do not fix it, because a silent fix would mean you are no longer running the strategy you approved. Corpus participation is a separate, explicitly negotiated agreement and never a default.
Upstox, Dhan and Zerodha sit behind a single execution contract, with official-source and catalog-identity boundaries implemented for all three. Credentialed venue and account behaviour is not yet certified, which is why the platform stays in paper — that certification is a prerequisite, not a follow-up.
SEBI's algorithmic trading framework has been mandatory since 1 April 2026. A written posture memo sets out the three classifications a platform like this could sit in, the bright lines for each, and the controls we hold against them. The classification decision itself sits with the board and SEBI counsel. We will not describe ourselves as registered or empanelled until we are.
The order is reconciled against broker truth and the path halts. It is never re-placed on another venue on the assumption that the first one failed — that assumption is how a hedge becomes a double position. Broker truth must also arrive scoped to your broker and account, even when the book is empty; an unscoped snapshot blocks callbacks and blind exits until an exact one is available.
Request access
A walkthrough is a working session, not a pitch: we run your strategy through ingestion, show you the ledger it produces — refusals and all — and tell you plainly where the platform is not yet ready for it.
Pravrtti Elements Pvt Ltd · built in partnership with Codexonic.