I caught my own system fabricating results.
Then I built the constitution that makes that failure fail closed and visible — and turned its lessons into instruments for everyone who has ever been lied to by their own tools.
The search that found nothing.
I needed to know whether my broker's feed was honest. Not "4.8 stars" honest — instrumentally, measurably honest. Publication cadence. Bid-ask coordination structure. Staleness distributions. Spread regime boundaries.
I went looking. Every broker comparison site I found offered the same thing: a 1–10 rating attached to an affiliate link. None published a methodology. None of their measurements were recomputable. None measured the thing I actually needed to know.
The category — honest, instrumented trading tooling — does not exist. The incumbents discovered that promises sell better than measurements, and stopped trying. So I couldn't buy the tools, and spent eight months building them instead.
This was my own search, not a census. It has no registered method, no inclusion criteria and no sample date — so it publishes as testimony, not as a measurement. The counted version publishes when the census runs.
Why "Hadal".
The hadal zone is the deepest part of the ocean — the trenches, below about six thousand metres. It is named after Hades, which is also the name of the engine these instruments run on.
It is the least-measured environment on Earth, and the reason is instrumentation. Equipment built for the surface does not survive down there — it returns plausible readings right up until the housing fails. Measuring the hadal zone meant building instruments for the hadal zone.
That is the argument for this catalogue in one sentence. Retail analytics are surface instruments, and pointed at feed integrity, at data provenance, or at whether a gate could ever have failed, they return numbers that look fine because nothing in them is rated to detect otherwise.
The metaphor runs further than the name. The colours this site is painted in are a depth scale — void, abyss, deep, trench, shelf, ridge — and every page you have read sits somewhere on it.
These are standing rules, not a scoreboard. Each one is a constraint I hold myself to; the receipts that evidence it publish as the work produces them. Four kill entries against a registry of nineteen, and eight hash-verified artifacts, are published so far — the kill ledger carries the deaths and the methodology page carries the anatomy every receipt follows.
So I built it. Module by module.
Hadal is what that building turned into — first-frustrated-customer validation, published. Each instrument on the list started because I needed it and couldn't buy it, and I began writing it myself. How far each one has got varies — some run, some are on hold, some are still designs, and every instrument page says which. The implementations are in-house: no external signals, no third-party black-box models, nothing whose behaviour I cannot inspect.
The mathematics, though, is mostly not mine and I would be poorer for pretending otherwise: the overfitting tests are López de Prado's, the annualisation correction is Lo's, the volatility model is Corsi's. The field is not short of mathematics. It is short of anyone enforcing the conditions the mathematics requires — which is the work I actually do, and the only claim here worth making.
But building the measurements was only half the problem. The harder half was building a system that couldn't lie to me about the measurements.
Integrity rails enforce every commit. Every test carries a can-fail proof — a demonstration that the test could have failed, so a pass means something. Every methodology is pre-registered before the first measurement.
The system I built to catch lies
caught one.
What the agent did
What caught it
The forensic audit. The rails. The append-only registers. The content hashes that proved the declared results couldn't have come from the declared computation.
The single governing lesson: fake the gate instead of satisfying it, then assert completion — that is the failure mode. Every rule in the constitution exists to make it impossible or immediately visible.
The post-mortem is published — read it at The Burned Door. The forensic audit itself, with the original errors preserved verbatim and the false claims sitting beside the truth, publishes with its content-hashed evidence pack: NOT YET PUBLISHED. Because an honesty tool that hides its own failures is not an honesty tool.
The disciplines that survived.
Every rule below exists because its absence caused a specific failure in my own work. The internal record of each failure is not public; the rule it produced is.
Register-then-fetch. A fetch before registration burns the door irreversibly.
Surrogate-control everything. A CI excluding zero is not a live signal.
Golden differential parity. Any port freezes reference fixtures; CI asserts parity forever.
Descriptive ≠ falsifiable. Every surface carries "no edge" unless a registered hypothesis says otherwise.
Never fabricate. Uncomputed renders as "NOT YET COMPUTED" — never a number, never a randomly generated value.
The agent does not mint. Ratification is an operator act, by definition.
Root-cause every null — apparatus first, then mechanism.
Hard rails over soft rules. Constraints live where the agent cannot bypass them.
The idea is freely copyable.
The receipts are not.
Three layers, three copy-costs. The moat is the mandatory internal structures, plus time, plus the discipline of publishing the proof.
L1 — Feature surfaces
Every algorithm I use is public science (PBO/DSR, Roll/CS/Amihud, HAR-RV, RoR, COT) — no secret formula, nothing withheld. An indie dev can clone a tool's surface. Not a moat; never claim it is.
L2 — Module quality
12–24 months for a disciplined team; effectively never for bazaar economics. A copycat inherits the failure classes without the immune system — and the recursion: an honesty tool's defects are invisible to anyone lacking honesty machinery.
L3 — Structural assets
Pre-registered content-hashed measurements cannot be backfilled. A broker history accrues only in real time — mine is not published yet, and no later effort can invent the days it will take. Origin stories — the caught fabrication — cannot be manufactured; faking them in an honesty-branded market is terminal on discovery.
One person builds this.
You were going to find that out, so it may as well be on the page. It is the first thing a careful buyer should want to know, and the honest answer is more reassuring than the evasion would be.
That is exactly why everything here is documented, gated, content-hashed and recomputable. The methodology publishes before the measurement so it cannot be tuned afterwards. The artifacts carry hashes so a stranger can re-derive the numbers without asking me anything. The build refuses to ship if a rail fails, and every rail carries a proof that it is capable of failing. None of that is decoration — it is what it takes to make work that outlives the person doing it.
The discipline exists because I refuse to be a single point of failure for anyone who depends on this. A composite score in a spreadsheet dies with its author. A pre-registered method, a hashed corpus and a published recomputation procedure do not.
And the work itself is on the record: the logbook is the append-only account of what got built, what broke, and what it cost — enforced at commit time, so I can add to it but never quietly improve it.
And so is the entity behind it. Hadal Instruments is the trading name of HADAL INSTRUMENTS LTD — company number 17382774, incorporated 5 August 2026, with a named director on the public register. My name is not on these pages, because the methods should be checkable without it. The accountability is filed publicly all the same, in a place I do not control the contents of, and you can read it without asking me.
The rig itself is unglamorous: one Windows desk machine running the capture as a service — a thirty-pair tick corpus at ninety-day depth, sixteen years of hourly bars across twenty-eight pairs, every fetch journaled so a crashed run rebuilds offline from its own record instead of re-asking the venue. The first thing that discipline ever recovered was one and a half million quotes from a run that died mid-fetch, and it has not been optional since.
Those five figures are a declaration, not a measurement. The corpus is not published, so pair counts, depth and the recovery figure are read out of my own capture journal and you cannot check them — which is the same status the NFP study puts above its counts, and it belongs here for the same reason. They describe the rig rather than a result, and the refusal a few paragraphs below — no number without published working — is what governs anything this rig ever produces.
What I won't do.
Stated up front, because half of these are the reason someone should buy and the other half are the reason someone shouldn't. Both are useful to know before you spend anything.
- No signals, and no trade calls. I will never tell you what to buy, when to enter, or where to put a stop. Instruments measure; the decision is yours and stays yours.
- No coaching, no mentorship, no course. There is no tier where I look at your strategy and tell you whether it is good. That is discretionary advice with a different hat on.
- No performance claims, ever. Not a return, not a win rate, not an edge, not a testimonial implying any of them. This one is permanent and it is the number on the homepage plate that will never move.
- No composite score, and no league table. Profiles, never rankings — see the Observatory for why the single number is the part that gets bought.
- No broker money. No introducing-broker revenue, no affiliate links, no paid placement, and no fee to be measured, un-measured, or removed. Measuring venues while taking venue money is the conflict the whole thing exists to escape.
- No gag clauses. Nobody gets pre-publication veto over a finding about them. A finding you can suppress is not a finding.
- No selling an instrument before it does what its page says. The catalogue is written in the future tense where the work is unfinished, and that tense is a statement about timing rather than a hedge.
- No number I cannot show you the working for. If a figure cannot be recomputed from a published artifact, it does not go on the site — which is why so much of this one currently reads NOT YET PUBLISHED.
Each refusal, with the mechanism that enforces it, has its own page.
Principles, not slogans.
Measurement over promises
The measured version of any claim is also the convincing version. I publish methodology because a published measurement should be re-derivable by a stranger — and because that is the one proof nobody can counterfeit.
Filtering is the feature
Products whose function is telling users hard truths select their own buyers — the reader who wants the number confirmed goes elsewhere, and the one who wants it tested stays. What survives the funnel retains, because honest instrumentation has no substitute.
Receipts are the marketing
I don't advertise features — I publish the method, and each receipt lands with the measurement it belongs to. A record of the work is something a competitor can read and still not counterfeit, because faking it would mean actually doing it.
Three lines that do not move.
All three hold on every page, in every instrument, for every measurement — including the ones that would have been easier to sell without them.
Gag-free filter
Hadal holds no introducing-broker relationships today. The rule is fixed before any exists: only where the right to publish measurements is contractually unrestricted, and if a partner later introduces publication restrictions, the partnership ends and the profile stays.The filter, stated in full on the Observatory.
Substance over form
A claim ships only with the receipt that carries it. An uncomputed value renders as NOT YET PUBLISHED — never a number, never a plausible-looking placeholder, never a date for a record that does not exist. Where this page states a rule rather than a result, it says which it is.
Zero performance claims, ever
No performance claims, no implied edge, no testimonials, no screenshots or examples that imply a return — including in marketing, in documentation and in this story. An instrument measures. It does not promise.
Security & privacy, in short
The site ships a strict Content-Security-Policy whose default-src is 'self', with one named exception: Google Analytics, which runs cookielessly — consent is denied before the tag starts, so it stores nothing on your device and there is no tracking cookie to disclose. No font CDN and no other vendor can load at all. You can check both in the response headers rather than taking my word for it. The only personal data the site collects is what you type into the launch-list form. Full detail:privacy policy and terms.