Two accounts open XAUUSD within 40 milliseconds of each other, same direction, same size ratio, from different registered identities. That is not a coincidence and it is not a strategy. It is either one person on two accounts or a copier fanning one signal across a group, and in an evaluation business both cases mean you are underwriting correlated risk you never priced.
The detection problem is a data problem before it is a rules problem. You cannot flag what your risk system never sees, and how much it sees is decided by the platform you launch on.
What the abuse patterns look like in the data
Three families cover most of it. Latency-sensitive entries are trades opened and closed inside a very short window, clustered around price movements the account seems to have anticipated, often at sizes that only make sense if the edge is execution rather than analysis. Cross-account replication is a set of accounts whose fills line up in time and direction closely enough that independence is not a credible explanation. Structural abuse is the grid and martingale family, where position sizing after a loss follows a mechanical pattern that the account's stated strategy does not.
None of the three is detectable from a daily summary. Latency patterns live in the millisecond field of the fill. Replication lives in the timing relationship between accounts that a per-account report never compares. Sizing sequences live in ordered trade history that survived every reset and migration. The detail your platform hands your risk system determines which of these you can even ask about, which is why prohibited strategy detection is a platform decision rather than a policy decision.
The polling gap, and why it is the real vulnerability
Most prop stacks assembled from a rented platform plus a separate risk tool read positions on a schedule. The tool asks the platform what is open, gets an answer, evaluates, and waits. Whatever happens between two questions is reconstructed later from history, if at all.
For drawdown enforcement the gap is a money problem: an account that breaches at second three keeps trading until second sixty. For abuse detection it is worse, because the patterns above are defined by timing, and a sampling interval wider than the pattern makes the pattern invisible. A trade opened and closed inside a polling window can be entirely absent from what your engine ever evaluated live.
eTrader's answer is to make the sync native rather than sampled at a distance: positions and closed trades reach the SINGUARD Prop Firm CRM rules engine every 500 milliseconds, and the engine evaluates the full rule library against them, applying the consequence you configured and writing the decision to an audit log. That covers drawdown, holding windows, consistency and the prohibited-strategy family including HFT, grid, martingale, hedging and cross-account patterns read from trade history. The architecture is described in the prop firm platform article.
A rule you cannot evidence is a rule you cannot enforce. Before writing a prohibited-strategy clause into your terms, confirm that the platform gives your engine the field you would need to prove a violation to an angry trader with a lawyer.
Where the rented platforms genuinely hold their own
The honest position: cTrader, DXtrade, Match-Trader and TradeLocker all expose trading data through APIs, and firms do build real detection on top of them. Some of those platforms carry their own risk tooling, and a well-built integration against a well-documented API can catch the cross-account and sizing patterns competently. MetaTrader's ecosystem has the deepest bench of third-party surveillance plugins in the industry for the firms that still have access to it, which is a genuine advantage of an old platform with a large developer economy.
The differences that survive are integration ownership and interval. On an assembled stack, the connection between platform and engine is a component you commissioned, and you own its failures, its rate limits and its upgrade path. Where the platform and engine ship as one system, that seam does not exist. Neither arrangement is magic, and a founder should compare specific intervals and specific fields rather than architectural adjectives.
What to do with a flag, which is where most firms go wrong
Detection without a decision process produces two failure modes, and firms usually pick one and suffer. Automatic failure on every flag punishes coincidences, and correlated entries between two traders in the same Discord are common enough that you will fail honest customers. Manual review of everything means the queue grows until reviews stop happening and the rule becomes theatre.
The workable shape is graded consequences configured per rule: flag for review on the ambiguous patterns, automatic suspension for the unambiguous ones, and a permanent log entry for both so the decision can be defended months later. That log is the asset. Payout disputes are the most corrosive events in a prop firm's life, and the firm that can show a timestamped rule evaluation wins them quietly. More on that in the audit log article.
Publish the rule before you enforce it
Detection capability is not a licence to invent rules after the fact. If minimum hold time matters to your model, publish a number. If you will not fund groups running one signal across accounts, say so in the terms a buyer accepts at checkout, not in the email refusing their payout. Firms that enforce unpublished rules generate exactly the public arguments they were trying to avoid, and no amount of platform-level surveillance repairs that.
For founders still choosing the stack, the surveillance question belongs in the same conversation as cost and vendor policy rather than after it, and the pricing breakdown shows what arrives bundled instead of quoted separately.
"You cannot enforce a rule you cannot evidence. Write the prohibited-strategy clause only after you know which field in the fill would prove it."
— Alex Onta, Executive Director, SINGUARD
Key Takeaways
- Latency, cross-account replication and grid or martingale sizing are all timing patterns, invisible in daily summaries and in any sampling interval wider than the pattern.
- A polling gap between platform and risk tool is both a drawdown exposure and a blind spot, because trades opened and closed inside the window were never evaluated live.
- eTrader syncs positions and closed trades into the Prop Firm CRM rules engine every 500 milliseconds, with configured consequences and a permanent audit entry.
- cTrader, DXtrade, Match-Trader and TradeLocker expose data through APIs and firms build real detection on them; the difference is who owns the integration seam.
Frequently Asked Questions
Can platform-level detection catch every form of prop firm abuse?
No. Platform data catches timing, sizing and correlation patterns well. It does not establish identity behind accounts, which needs KYC and payment-side signals, and it cannot decide intent. Detection produces evidence for a human decision, not a verdict.
Why does a 500 millisecond sync interval matter for abuse detection?
The patterns are defined by timing relationships between fills. If the risk engine samples positions less often than the pattern occurs, trades can open and close entirely inside a gap and never be evaluated live. A short native sync keeps the evidence in the engine rather than only in history.
Should a prop firm fail an account automatically when a pattern is flagged?
Grade the consequence per rule. Ambiguous patterns such as correlated entries between two traders belong in a review queue, unambiguous mechanical patterns can carry automatic suspension, and both should write a permanent audit entry. Enforce only rules that were published before the trader paid.
About the Author
Alex Onta is an Executive Director at SINGUARD. He built eTrader, the terminal, the mobile apps, eTrader Broker, Copytrading, Business and Community, along with the worldwide clustered-server infrastructure it all runs on, with his brother Roman Onta helping on the design, and he leads that division today. Together with Roman he builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals, and the two of them carry worldwide compliance, payment processing and international business structuring side by side. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.