Platform · Risk engine
Prop firm risk management software built for enforcement and investigation.
The PropXO risk engine enforces your challenge rules in real time — targets, drawdown, consistency, news windows, leverage — and watches for the abuse patterns that actually cost prop firms money. Every pattern alert lands in an investigation queue for a human decision, with a full audit trail behind it.
Enforced across trading platforms
Rule enforcement
Every rule you sell, enforced as it happens.
A rule that is checked overnight is a rule that leaks money all day. The engine evaluates account state as trading happens, against the precise rule set each trader purchased.
Profit targets
Per-phase targets are tracked continuously against live account state. A pass is recognized the moment it is earned — not at an end-of-day reconciliation job.
Every drawdown variant
Daily, overall, and trailing drawdown, each computed equity-based or balance-based. The engine enforces the exact definition each trader bought, because the difference between equity and balance drawdown is the difference between a breach and a payout dispute.
Consistency rules
Profit-concentration and behavior checks that keep one outsized session from masquerading as a repeatable edge. Configurable per challenge, visible to the trader, enforced without exception.
News and weekend restrictions
No-trade windows around scheduled events — FOMC, NFP, CPI, central-bank decisions — and weekend holding rules. Futures firms get exchange session and holiday calendars; crypto firms get weekend rules that are real configuration, not an afterthought.
Leverage caps
Position sizing is checked as exposure changes, so an oversized position is caught when it opens — not discovered later when it has already blown through the drawdown.
Rules locked at purchase
When you revise a challenge, existing participants keep the rules they bought. The engine always enforces the terms on file for that specific account, so a config change never rewrites a live evaluation.
Rules are defined once, in the challenge builder, and enforced here. One definition means no drift between what your marketing page promised, what your terms say, and what the engine actually checks.
Abuse detection
The patterns that actually cost prop firms money.
Most losses don't come from good traders passing. They come from coordinated exploitation of the evaluation model — and each scheme leaves a signature. The engine watches for the known playbook across identity, coordination, and execution.
Pick rejected
Pre-tradestake 400.00 > max 250.00
rule: max_stake_per_pick
logged · visible to bettor
Identity
Multi-accounting
One person operating a stack of accounts to farm evaluations — passing on some, burning others, and treating your fee structure as the cost of a lottery ticket.
Identity
KYC duplication
The same identity documents or verification details appearing behind supposedly separate customers. Caught by cross-referencing KYC records, not by hoping support notices.
Identity
IP and device conflicts
Device fingerprints and network history that contradict the account's claimed identity — separate customers who share hardware, sessions, or connection patterns.
Coordination
Hedging across accounts
Opposite positions opened across accounts so that one side passes no matter what the market does. Invisible per account; obvious once accounts are compared.
Coordination
Copy-trade rings
Clusters of accounts mirroring entries, exits, and sizing within shared sessions — a coordinated group presenting itself as independent traders.
Execution
News-window abuse
Trades timed into restricted news windows to exploit volatility and pricing gaps around scheduled releases — the exact behavior your news rules exist to exclude.
Execution
HFT-style bursts
Rapid-fire order bursts characteristic of automated exploitation of evaluation pricing rather than trading. The pattern looks nothing like discretionary execution, and the engine knows the difference.
Philosophy
Alerts are signals for investigation, not automatic punishments.
Pattern detection is probabilistic, and pretending otherwise punishes innocent traders. So the engine draws a hard line between rules and signals.
Deterministic rules act on their own
A drawdown breach is arithmetic, not judgment. Hard rule violations are enforced automatically the moment they occur, and the record shows exactly which rule fired and why.
Pattern alerts open a case
Correlation is not proof. Multi-account and coordination signals queue for human review with the evidence attached — no account is punished by a probability score.
We're direct about the limits, because vendors rarely are: no risk engine can read intent. Two traders on a shared household network are not automatically a ring. A vendor promising fully automatic fraud elimination is describing a system that bans real customers and calls it accuracy. What software can honestly do is surface the evidence quickly, keep related accounts in one view, and leave the decision — and its permanent record — with your team.
ALERT copy_trade_ring
accounts acc_ktzq · acc_mhrv · acc_pldn
evidence correlated entries within shared sessions
matching device fingerprint
overlapping IP history
state queued_for_review // no action taken yet
reviewer unassigned
available actions
approve → clear the flag, note the reason
suspend → pause trading pending review
refund → return the evaluation fee
extend → give the evaluation time back
audit every decision logged: actor, evidence, outcomeInvestigation queue
From alert to decision, with the receipts kept.
An alert is only useful if it ends in a defensible decision. The queue is built around that ending.
- 01
Detect
The engine raises an alert with its evidence attached: the trades, sessions, device fingerprints, and related accounts that triggered it.
- 02
Correlate
Related alerts group into a single case. Linked accounts surface together, so your team judges a ring as a ring — not as a scatter of unrelated anomalies.
- 03
Decide
A person reviews the case and takes an action: approve and clear the flag, suspend the account, refund the fee, or extend the evaluation. The engine recommends nothing it can't show evidence for.
- 04
Record
Every decision is written to the audit trail — who acted, what they reviewed, what they chose. When a trader disputes an outcome, you answer with the record, not a recollection.
Outcomes feed analytics and reporting, where confirmed-abuse patterns sit next to pass rates and payout exposure — so when passes spike, you can tell a marketing win from a leak before you pay out either way.
Coverage
One risk engine across every vertical.
Trading, futures, crypto, and sports betting firms run on the same enforcement and investigation core — with the market-specific rules each vertical actually needs layered on top.
FAQ
Frequently asked questions
PropXO · Demo
See the risk engine on a live account.
A walkthrough of real-time enforcement, the investigation queue, and the audit trail, configured for your vertical. Commercial terms are scoped privately for the deployment.