A detection system built around your firm.
Off-the-shelf tools force a firm into the vendor's model of its risk. Runite engineers study how your firm actually operates and build detection against that reality, on infrastructure you control.
Four dimensions of risk, correlated into one evidentiary picture.
The four dimensions share one case model, so evidence from any source can corroborate or discount evidence from any other.
DIM-AMarket conduct
Runite correlates trading and communications evidence across sources — patterns consistent with MNPI misuse, allocation abuse, marking, and off-channel coordination — and assembles each finding into a case file counsel can take forward on the record.
DIM-BWorkforce integrity
Runite documents misconduct across sanctioned channels to an evidentiary standard, measures aggregated sentiment, and flags flight risk on critical desks using disengagement and access patterns from firm systems — never anyone's outside job search. Sentiment is disclosed to the people it covers, and no individual is scored.
DIM-CInformation integrity
Runite reconstructs escalation paths so management can see what was known below it and where the escalation stopped, while protected reporting channels remain invisible to the system by design. The same dimension watches proprietary code, models, and data moving toward the exit.
DIM-DExternal reputation
Runite monitors publicly available material from any source for activity that threatens the firm's name, and collection never extends beyond what is genuinely public. Positioning intelligence runs as a separate public-sources program.
The standard detection programs and what each one delivers.
Each program ships with a defined output, a named routing target, and benchmarks agreed during scoping. Deployments can extend the registry during scoping.
| Code | Program | Description | Output |
|---|---|---|---|
| SIG-01 | Insider-dealing indications | Trading and communications patterns consistent with the misuse of material non-public information. | Case file to compliance leadership and counsel. |
| SIG-02 | Trade misconduct | Allocation abuse, marking behavior, off-channel coordination, and execution patterns that deviate from mandate. | Case file to compliance. |
| SIG-03 | Employee misconduct | Policy-violating behavior evidenced across sanctioned channels and documented to an evidentiary standard. | Case file to the owner named in policy. |
| SIG-04 | Sentiment & morale | Aggregated, disclosed measurement of how teams regard projects, leadership, and the firm, with no individual scoring. | Standing report to management, disclosed to the teams it covers. |
| SIG-05 | Departure indicators | Flight-risk indications on critical desks, drawn solely from sanctioned firm systems. | Alert to management with continuity context. |
| SIG-06 | Escalation integrity | Reconstruction of what was known below management, when it was known, and where it stopped. | Escalation-integrity report to the executive committee. |
| SIG-07 | Code & IP exfiltration | Movement of proprietary code, models, and data toward the exit, including anomalous access and departure-correlated activity. | Immediate alert with the evidence preserved. |
| SIG-08 | Reputation threats | Publicly available online activity that endangers the firm's name. | Threat alert with response lead time. |
| SIG-09 | Positioning opportunities | Openings in the public conversation where the firm's standing can be advanced, run as a separate program on public sources only. | Periodic positioning brief to leadership. |
Everything runs inside the perimeter, and everything is logged.
Sources are read in place, detection runs where the data lives, and case files route to owners who are named in policy before the system is turned on. The consent registry gates collection against the written scope — outside it, collection is technically impossible — and the audit ledger logs every query append-only, including ours.
Every engagement is scoped with counsel and judged against benchmarks.
Engagements begin with scoping under NDA alongside your counsel, move through an embedded build-out on your premises, and mature into a standing capability your firm operates with our engineers alongside. Pilots run for a defined term — typically a quarter — against detection and false-positive benchmarks agreed in the scoping memo, with a documented walk-away.
Under NDA we provide the full diligence pack — principals, security architecture, engineer vetting standards, insurance, references — and we decline engagements where the governance framework cannot honestly be established.
Ask us what your firm cannot currently see.
Briefings are held under NDA with principals — compliance, legal, operating leadership, founders.
Request a technical briefing