Give your clients automated crypto trading without rebuilding your stack.
We help crypto funds and white‑label businesses launch compliant, automated trading experiences. You bring the strategy and brand. We provide execution, risk controls, reporting, secure APIs, and fully tailored bots.
Illustrative values. Your caps are set in your Order Form and enforced in code.
Built for funds and white‑label platforms
If you want clients to automate trading, you need execution that is safe, auditable, and branded as your own. Axiom Finance is the control plane behind the experience.
Strategy-ready execution
Plug in your signals or models. We handle order lifecycle, retries, and multi‑exchange execution with idempotency.
Pre-trade risk controls
Enforce exposure caps, leverage rules, and account‑level kill‑switches before orders hit the market.
Audit-ready reporting
Every action is logged. Export trades, PnL, and audit trails in JSON or CSV for investors and compliance.
Ship a trading product, not a trading platform.
Axiom Finance is the entire backend a fund or fintech needs to put automated crypto trading in front of users — without burning 12+ months of engineering time.
Faster time-to-market
Replace a multi-quarter custom build with a deployment that ships in weeks. Risk, custody integrations, and reporting are already done.
Lower upfront engineering cost
Avoid hiring a quant infra team to write order routers, retry logic, exchange adapters, and audit pipelines. Subscribe to it instead.
Production-grade safety
Idempotent execution, kill-switches, and exposure caps prevent the catastrophic events that kill trading products and reputations.
Revenue you keep
White-label rights mean clients onboard, trade, and pay under your brand. We are infrastructure — never the customer-facing experience.
Time and cost figures are estimates for a comparable in-house build. We publish them as reasoning, not as measured customer results.
Infrastructure that fits your business model
Offer automated trading to your users with a white‑label platform or run it as a fund‑grade internal stack. We support SaaS, dedicated, and on‑prem deployments.
- Multi‑tenant orgs with operator / trader / viewer roles
- Encrypted credential vault with rotation and audit logs
- Unified execution across major exchanges
- Order lifecycle tracking with deterministic retries
REST endpoints + webhooks
All risk, execution, reporting, and credential actions are exposed via secure APIs.
Brand-ready deployments
Ship under your own domain with tenant‑specific configs and UI control.
Deterministic execution
No silent failures, no duplicate orders, full retry and failover logic.
Who we built this for
Crypto Funds
Offer automated strategies to LPs with strict risk limits and auditable execution.
White‑Label Platforms
Launch under your brand and let users invest via automated trading without building the core stack.
Brokerages & Fintechs
Add automated strategies as a premium user feature via API integration.
Signal Providers
Publish signals into a fully managed execution layer without touching custody.
Run client mandates without ever holding client assets.
Fund Manager is shipped and running in the platform today. A manager creates a fund, links client accounts, and deploys validated strategies across all of them in one action — while every asset stays in the client's own exchange account, behind a key the client can pull at any moment.
Non-custodial by construction
Trading happens inside each client's own exchange account, through that client's own API credentials. There is no pooled wallet, no omnibus account, and no deposit address — the platform is never in a position to hold, move, or lose client assets.
Scoped consent, revocable by either side
A client links their own credential and grants explicit, scoped consent before a manager can trade the account. Either the client or the manager can revoke it at any time; a revoked account leaves management and can no longer be targeted by a deployment.
Withdrawal-enabled keys are refused
Before consent is recorded, the platform asks the exchange what the key can actually do. If it can withdraw, the request is rejected outright and the account stays unmanaged until a trade-only key replaces it. An optional strict mode also rejects keys whose permissions the exchange will not confirm.
Fleet deployment from a gated strategy set
One strategy, deployed across many consented client accounts in a single action, sized equally, by AUM, or by risk. Only templates flagged fund-deployable in the curated library can be selected — the allow-list is closed in code, so nothing unvalidated reaches client money.
Fee accounting that is arithmetic, not assertion
Returns are time-weighted (Modified Dietz) so deposits and withdrawals cannot flatter performance. Management fee is annual basis points pro-rated on average capital; performance fee is charged only on gains above that client's own prior high-water mark, and the rate is capped at the database level.
Statements a client can check
Every ledgered period — start and end equity, flows, PnL, management fee, performance fee, high-water mark — exports per investor as JSON, CSV, or a printable HTML statement, alongside aggregate fund performance and per-investor summaries.
Fees that get billed, not just counted
Accrued fees are raised as an invoice covering exactly the periods it bills, and settlements are recorded against it — so accrued, invoiced, paid and outstanding stay separate figures instead of one lifetime accrual. Any given period can appear on only one invoice, enforced in the database. Axiom Finance records these settlements; it does not process them, because it never holds the money.
Fund Manager is a Fund-tier capability of the platform. The fund-deployable set is deliberately small — four strategies at the time of writing — because it is limited to templates that survived multi-fold walk-forward testing and the multiple-testing guard. That is a research standard, not a forecast: no strategy here is offered with a performance guarantee.
What it actually costs to do this in-house.
Most teams underestimate the long tail: exchange edge cases, idempotency, audit trails, and on-call. Build-side figures are our estimates for a comparable in-house build, not measured customer outcomes.
Integrate fast, scale safely
Use our SDKs or integrate directly with REST APIs. Stream order events into your data warehouse and monitoring stack.
POST /api/risk/limits
POST /api/credentials
GET /api/reports/trades.csvJavaScript / TypeScript
Fast client integration for fintech dashboards.
Python
Quant research + production automation pipeline.
Rust
Low-latency internal trading services.
One Business engagement. Priced for what you actually deploy.
No off-the-shelf SaaS plan, no seat-based tier ladder. Axiom Finance Business is a single offering, scoped on a discovery call and quoted as one annual contract. The cost reflects your team size, exchanges, deployment posture, and any custom work — and nothing else.
Everything below is shipped and running in the platform today — not a roadmap. Open a block for the full specification.
Execution & order safety
- Unified execution across 15+ CEX and DEX adapters
- Idempotent order submission · no duplicates on retry or restart
- Pre-trade exposure caps and a global kill-switch enforced at the engine
- Per-desk risk policies aggregated across every bot on the desk
Full specification
Adapters in production: Binance (spot + futures), Bybit, Bitget, BloFin, Coinbase, Kraken (spot + futures), KuCoin, OKX, MEXC, CoinEx, and CoinW, plus GMX v2, PancakeSwap, and SushiSwap on-chain. Orders carry client-side idempotency keys and are retried deterministically against exchange-side IDs, so an engine restart mid-flight reconciles state instead of duplicating orders. Named trading desks group sub-accounts into buckets with their own pre-trade caps — max position size, per-order and daily notional, daily loss, open orders, leverage, allowed margin types, kill switch, pause — aggregated across every bot assigned to the desk and editable in the dashboard.
Security & access control
- BYOK encrypted credential vault with rotation and per-action audit
- Role-based access control · Admin, Trader, Viewer · scoped per organization
- SAML 2.0 SSO with Single Logout, plus SCIM 2.0 user provisioning
- Multi-org structure with strict tenant isolation
Full specification
Exchange credentials are encrypted at rest under a per-tenant envelope key, rotatable without downtime, and every use is written to the action audit log. SSO covers the whole SAML 2.0 round trip: per-org IdP configuration (entity ID, SSO and SLO URLs, X.509 certificate, NameID format, JSON attribute mapping), public SP-metadata XML for your IdP team, AuthnRequest generation, an ACS endpoint that verifies the XMLDSig signature, just-in-time user provisioning, and SP-initiated Single Logout with session-cookie teardown. The login page auto-detects branded tenants and offers "Continue with SSO"; OAuth (Google) is available as the no-SAML fallback. SCIM 2.0 is the companion to SSO and closes the deprovisioning gap: your IdP (Okta, Azure AD, OneLogin) drives membership directly against /api/orgs/{org_id}/scim/v2/Users with an org API key as the bearer token — POST provisions a user and org membership with the same find-or-create-by-email semantics as SAML JIT, a userName filter answers the existence check IdPs run first, PATCH or PUT of active:false suspends the membership (both the Okta and Azure operation shapes are parsed), and DELETE removes the org relationship. The platform user account itself is never deleted, and your contracted seat cap is enforced atomically at provisioning time so concurrent creates cannot over-provision past it.
Compliance & reporting
- Every order, risk decision, and credential action logged
- JSON and CSV exports for trades, PnL, and audit trails
- Configurable audit-retention window, pruned hourly under policy
- Engine SLA measured from minute-bucketed heartbeats, exposed at /api/sla
Full specification
Exports are pulled on demand rather than requested through support, so your investors, auditors, and compliance team work from the same record you do. The retention window is set in your Order Form (minimum 7 days, no upper bound) and enforced by an hourly worker that prunes order, audit, and webhook history across every org-scoped table; the active policy is readable from the org-limits API. The SLA endpoint reports 1h, 24h, 7d, 30d, and 90d availability windows plus a current-status liveness signal, so the number is something you verify rather than take on trust. Contractual caps — bot count, connected exchanges, end-user and sub-account count, retention window — are enforced in code from the same Order Form values.
Integration & branding
- TypeScript, Python, and Rust SDKs with per-org API keys
- Signed outbound webhooks · HMAC-SHA256, idempotent enqueue, backoff retries
- Per-tenant white-label theming applied as live CSS overrides at boot
- Self-serve workspace for keys, branding, webhooks, SSO, and desks
Full specification
All three SDKs (@epochalquant/sdk, epochalquant on PyPI, epochalquant on crates.io) share one resource architecture: typed responses, automatic retry on 5xx and 429 with full-jitter backoff, a structured error hierarchy, a webhook signature verifier, and full coverage of the B2B surface — webhooks, desks, limits, branding, SAML, SLA, reports, audit, and API keys. Long-lived eq_live_* keys are issued per organization, Argon2id-hashed, prefix-indexed, revocable, and carry last-used plus usage audit. Branding (name, accent and secondary colors, logo, favicon, theme mode) is served from /api/public/branding and applied before first paint. The dashboard workspace covers all of it: issue and revoke keys, edit branding with live preview, create, test, and rotate webhooks with an inline recent-deliveries view, configure SAML, and manage desks with inline bot assignment. SaaS, Docker Compose, and Kubernetes deployment artifacts ship with the platform.
Everything above ships as standard. These are the items that genuinely vary between contracts, and the ones we scope on the discovery call.
Custom domain & white-label rollout
Per-tenant theming ships as standard. Your own domain, TLS, and mail sending are set up as deployment work, with commercial white-label rights granted in the contract.
Dedicated or on-prem cluster
Your own single-tenant deployment from our Kubernetes / Docker artifacts. Air-gapped option for regulated jurisdictions.
Custom bot strategies
Strategies designed and built for your signals, capital model, and risk envelope by our quant team.
Custom exchange adapters
Wire any venue beyond the 15+ we already support — CEX, DEX, or a prime broker bridge.
Retention & data residency
The audit-retention window and where the deployment lives are set per contract, sized to the jurisdiction you report into.
Custom integrations
OMS, PMS, custodian, or fund-administrator bridges — built once per engagement and maintained under the contract.
Platform fee
Sized to active bots, organizations, and sub-orgs. Bot count caps are enforced in code, so both sides know exactly what's included.
Usage component
Tied to order throughput across connected exchanges. Bands are agreed up front — no surprise overage invoices.
One-time setup
Deployment, the white-label domain rollout, custom adapters, and bespoke strategy work each appear as scoped line items.
Optional support tier
Dedicated response SLA, named technical owner, and incident playbooks are priced separately — you only pay if you need them.
Discovery call → scoped quote → signed Order Form. No PQL drip campaigns and no seat-counter pricing pages that don't apply to your model.
Request a tailored quoteSaaS
Fastest path to market. Multi‑tenant with enterprise‑grade isolation.
Dedicated single-tenant
Your own cluster with custom SLAs and governance controls.
On-prem / air-gapped
Deploy behind your firewall with compliance-grade audit trails.
A predictable rollout, scoped to your business.
Most pilots go from contract to a branded environment trading real flow in 2–6 weeks.
Discovery + scoping
Map strategies, exchanges, compliance posture, and target users. Decide between SaaS, dedicated, or on-prem.
Architecture + risk policies
Lock in exposure caps, leverage rules, kill-switch posture, key custody, and SLAs. Sign-off on the deployment plan.
Branded pilot
Stand up a branded environment, connect exchanges, ship a sandboxed pilot to a small operator group with full audit logs.
Production launch
Open to your users, with monitoring dashboards, governance panels, and incident playbooks ready from day one.
What buyers usually ask before signing.
Do you take custody of client funds?
No. Axiom Finance never holds end-user funds. Clients connect their own exchange accounts via encrypted API credentials, or you can integrate against a custodian of your choice.
Can we run this fully white-label?
Yes. Per-tenant theming — brand name, logo, accent and secondary colors, favicon — ships as standard and is applied before first paint. Your own domain, TLS, and the commercial white-label rights are set up per engagement. End users never see Axiom Finance.
What happens if an exchange is down or the engine restarts?
Order submission is idempotent. We retry deterministically with exchange-side IDs, never duplicate orders, and reconcile state on restart. The kill-switch can disarm new orders globally without affecting open positions.
How do you handle compliance and reporting?
Every order, position change, risk decision, and credential action is logged. We expose JSON and CSV exports for your investors, auditors, and internal compliance team — and provide retention controls for regulated jurisdictions.
What does pricing actually look like?
There is one Business engagement, not a tier ladder. Cost has four drivers: a platform fee sized to active bots and orgs, a usage component for order throughput, one-time setup line items (deployment, white-label, custom adapters, bespoke strategies), and an optional support tier. We share a fully-itemized quote after a discovery call — no seat math, no surprise overage invoices.
Can we deploy on-prem or in a regulated jurisdiction?
Yes. We support dedicated single-tenant clusters with custom SLAs and on-prem / air-gapped deployments behind your firewall, with audit trails sized to compliance requirements.
If a manager trades our clients' accounts, who holds the assets?
The client does, throughout. Fund Manager trades each client's own exchange account through that client's own API credential — there is no pooled wallet, no omnibus account, and no transfer of assets to us or to the manager. Consent is explicit, scoped, and recorded per account, and it is revocable by either the client or the manager. If the client's key carries withdrawal permission we refuse to manage the account at all until it is replaced with a trade-only key.
What happens when a client revokes access?
The account is marked revoked and leaves management immediately: no new strategy deployment can target it. Because the assets never left the client's exchange account and the key is theirs, the client can also disable or delete that key at the exchange without waiting on anyone. Statements and ledgered periods already produced stay exportable for the client's own records.
Bring your brand. We handle the trading infrastructure.
Book a demo and we will map your strategy, deployment, and compliance requirements.