Instrument / 002 — Hermes
A research system that is built to refuse
> Hermes is a local, air-gapped pipeline that turns raw market data into candidate setups, forces each one through a deterministic evidence check and a locally hosted analyst, and refuses to call anything approved unless every gate independently consents. It never touches an exchange, and it is used here to teach process, never to hand anybody a decision.
Default answer
Wait
Absence of an approval file means no setup.
Exchange path
None
No execution code exists anywhere in it.
Deciding component
Code
A model can never set the permit flag.
I. Separation of powers
Nobody in the system is trusted twice
Arithmetic originates
Deterministic code generates and scores every candidate. The model is never allowed to discover a setup.
The model judges, narrowly
A locally hosted model answers one bounded question about a candidate that already exists, with the evidence handed to it.
Non-model code decides
The validator is the only component that can permit an alert, and it is code, not a model. Absence of the file means no setup. There is no soft 'probably fine' state.
II. The system, three ways
Arithmetic, then judgement, then proof, then authority
Each band hands the next one less freedom.
No exchange connection exists anywhere
III. The evidence packet
The contract that makes the auditor possible
The packet is assembled and frozen before the model is called. Every claim it makes must name a field in here and the value it read, which is what lets a deterministic auditor resolve the claim afterwards instead of taking the model's word for it. Some fields are withheld on purpose, so a bounded judgement cannot be argued from history or performance.
Loading sample packet…
IV. Layer by layer
- 01
Data ingestion
Read-only OHLCV and market context from several public venues across fourteen timeframes, deliberately more than one feed because a single feed going stale silently is the classic way a backtest starts lying.
Stale files are quarantined after ingestion so they cannot reach the feature engine.
- 02
Feature engine
Hand-rolled indicator computation with no third-party library: volatility, trend, dispersion, range structure, session context and regime labels.
Hand-rolled for provenance. Every number the analyst may cite traces to a readable line of code.
- 03
Candidate layer
Four orthogonal sleeves, each chosen because published evidence exists behind it: time-series momentum, breakout, carry from funding, and mean reversion that is structurally incapable of firing outside a range regime.
A regime module sets sleeve weights per bar. A breadth requirement means several sleeves must agree before anything triggers.
- 04
Evidence packet
A frozen snapshot of every fact the model is permitted to cite, assembled before it is called. The analyst must attach a reference to each claim, naming the field and the value it read.
The packet is the contract. That single choice is what makes the auditor possible.
- 05
Deterministic auditor
Every cited reference is resolved back into the packet and compared with a numeric tolerance. Geometry is checked. Levels must belong to the right timeframe and be used in the right role. Pass or fail, no opinion involved.
An earlier model-based auditor was demoted to advisory. Do not use a stochastic system to verify a stochastic system.
- 06
Validator
Three independent consents combined by code. Missing data blocks. An unavailable component blocks. Nothing defaults to permitted, and every refusal carries a machine-readable reason.
No overlay or ranking layer can upgrade a wait into an approval.
- 07
Lifecycle and memory
Every promoted candidate becomes a record with a status, an expiry, an invalidation condition and a block reason. Outcomes and lessons are appended to a ledger the system reloads into its own context.
So it can observe patterns like: asked twelve times this week, all blocked, same flaw recurring.
- 08
The lie detector
A triple-barrier evaluator with costs deducted before any result is printed, bootstrap intervals, a lookahead self-test on truncated history, a trials ledger keyed by config hash, and an adversarial QA suite checked against brute-force implementations.
Its first run on the new engine surfaced three real defects. Then the engine called its own rigged demo a loser.
V. Failures kept in
Ingestion opened its files in write mode every cycle, quietly truncating history and killing the deduplication path. Walk-forward validation was running on months of data while appearing to run on years. Well-formatted output, no information in it.
A model-based auditor started confirming a value matched the evidence and then listing it as contradicted anyway, inventing prior context it had never been given. It was replaced by deterministic checks and demoted to commentary that can never block.
Cycles launched with no obvious trigger because two diagnostic scripts were calling an endpoint they believed returned state. It did not return state, it spawned a cycle. The read path was made read-only and every control action now writes an audit line.
VI. What this is not
- The edge is unproven. The backtest evidence is thin and the ensemble engine's real test needs years of actual data with real funding before any claim means anything.
- There is no live record. The system has never executed anything, and no exchange connection exists anywhere in it.
- The default answer is wait, and for long stretches that was the only answer it produced.
- Two architectural eras exist in the codebase, and this page describes the design rather than a current read of every file.
- Nothing produced by this system appears on this site as an instruction. It is shown here as an example of process, not as guidance to act.
Education about trading process. Not investment advice. Nothing here is a recommendation to buy or sell anything. Most retail traders lose money.