Most prop firm risk systems were built around a simple question: is this account behaving badly?
It's a reasonable question. It catches the obvious stuff — the trader who opens fifty positions in ninety seconds, the martingale ladder that doubles down until the drawdown limit bites, the news scalper who only ever trades the thirty seconds around NFP. If your book is four hundred accounts and your risk team knows most of them by name, account-level rules will hold the line.
The trouble starts somewhere north of a thousand accounts, and it isn't a volume problem. It's a shape problem.
The abuse that actually costs firms money at scale doesn't look bad at the account level. It looks fine at the account level. That's the entire point of it.
The Failure Mode Nobody's Rules Catch
Picture six accounts, funded across three weeks, each passing its challenge cleanly. No HFT. No martingale. Drawdowns well inside limits. Every one of them would sail through a per-account rule engine without triggering a single flag.
Now look at them together. Three are long EURUSD at the same moment; three are short the same size. Whichever side wins, the firm pays out. Whichever side loses, the accounts blow and the challenge fees were sunk costs the group already priced in. The expected value is positive for the group and negative for the firm — and no individual account ever did anything against the rules.
Copy-trading rings work on the same logic. One skilled operator, twelve funded accounts under twelve different names, identical entries within a few hundred milliseconds. Each account looks like a competent discretionary trader. Collectively it's a single strategy drawing twelve payouts from a firm that thinks it's diversified across twelve independent traders.
Then there's plain multi-accounting: one person, several identities, several bites at the challenge. Cheap to attempt, and the failed attempts are invisible because failures are supposed to be common.
None of this is exotic. It's the standard playbook, and it's why so many firms discover the problem in the same place — during a payout review, after the capital is already out the door.
What "Network-Based" Actually Means
The shift happening across risk tooling right now is from evaluating accounts to evaluating relationships between accounts. Instead of scoring each account against a rulebook, the system builds a graph: accounts are nodes, and the edges are the things that suggest two accounts aren't really independent.
QuantSentry — an AI-native risk platform Quant Technology Group launched in early 2026 — is a fairly clean illustration of the category, so it's a useful one to walk through. Its own framing is "see what account-level tools can't," which is a blunt way of naming the gap above.
The platform describes its network layer as mapping hidden relationships across thousands of accounts, not just individual behaviour, built on four signal types:
- A cross-account graph built in real time. The relationship map isn't a nightly batch job. It updates as trades land, which matters because the window between a coordinated group forming and a payout request is often days, not months.
- Device fingerprint clustering. Browser, OS, screen, timezone and hardware signals combine into an identifier that survives a new email address and a fresh KYC document. Two accounts registered to different names in different countries, both trading from the same device fingerprint, is not a coincidence you should have to argue about.
- Shared payout network mapping. Coordination is expensive to hide at the point of settlement, because eventually the money has to land somewhere. Wallets, bank details and payment rails cluster in ways that trading behaviour alone won't reveal. This is usually where a hedge group stops looking like a hedge group and starts looking like one person.
- P&L correlation scoring. The statistical backbone. If two accounts' equity curves move together far more than chance allows — especially inversely, which is the hedging signature — that correlation is evidence regardless of whether the accounts share any infrastructure at all. This is what catches the careful operators who use separate devices, separate VPNs and separate payout rails but can't disguise the fact that their positions are mirror images.
Why the overlap is the product: any one of these signals produces false positives on its own. Two traders in the same city on the same ISP share an IP. Two momentum traders in the same session correlate. The value is in the intersection — when device clustering, payout linkage and inverse P&L correlation all point at the same six accounts, you're no longer looking at coincidence. You're looking at a group.
The Rest of the Stack
The network graph sits alongside seven pattern engines that score for the behaviours you'd expect — HFT abuse, martingale scaling, copy-trading rings, hedge groups and others — with alerts generated in under sixty seconds and surfaced in a prioritised queue where the highest-exposure cases come first. There's also geo-risk scoring across 179 countries and firm-wide exposure analytics.
The piece that deserves attention beyond the detection itself is what the platform calls Evidence Kits: AI-generated PDF dossiers built per case, generated in under ninety seconds.
This sounds like a minor convenience feature. It isn't. Detection is only half of a risk workflow — the other half is being able to act on it. Declining a payout on the grounds of coordinated abuse means telling a trader their account is being closed under your terms of service, and that trader has every incentive to dispute it publicly, loudly and sometimes legally. A risk team that can't produce a clear document showing the linked accounts, the shared signals, the correlated positions and the timeline is a risk team that will quietly approve marginal payouts rather than fight. Enforcement capacity is bounded by evidence capacity, and most firms discover this the first time a flagged trader pushes back hard — the same reason audit trails matter at the account level.
What It Costs
Pricing is published, which is refreshingly rare in this corner of the market:
| Accounts | Monthly | Evidence Kits |
|---|---|---|
| Up to 1,000 (Launch) | €750 | 30 / month |
| 1,000–3,000 | €1,449 | Included, tiered |
| 3,000–5,000 | €2,449 | Included, tiered |
| 5,000–8,000 (Scale) | €3,997 | 600 / month |
| 8,000+ (Enterprise) | Custom | Unlimited |
Detection engines and Slack support come with every tier; higher tiers add integrations and dedicated account management.
Whether that's expensive depends entirely on what payout leakage is costing you now — which, if you're running account-level rules only, is a number you don't currently have. That's not a rhetorical point. Firms that add network detection frequently find historical coordination they never billed to anyone, and the honest version of the ROI calculation starts there rather than with the subscription line.
The Part Worth Thinking About
The specific vendor matters less than the shift underneath it. Coordinated abuse is a relational phenomenon, and relational phenomena are structurally invisible to systems that evaluate one entity at a time. You cannot fix that with better per-account thresholds, more rules or a stricter drawdown policy. Tightening account-level rules mostly punishes legitimate aggressive traders — the people whose challenge fees and eventual payouts are the business — while the coordinated groups adjust and carry on.
Graph analysis is the structurally correct answer, and the tooling has now reached the point where firms in the low thousands of accounts can buy it rather than build it. That's the real change. Two years ago this was in-house engineering that only the largest operators could justify.
If you're running a prop firm today, the question isn't really whether to adopt a specific platform. It's narrower and more uncomfortable than that: do you currently know whether any of your funded accounts are related to each other? If the honest answer is that you'd have no way to tell, that gap is worth closing — with QuantSentry, with a competitor, or with something you build. But it's worth closing before the next payout run, not after it.
"Per-account rules answer 'is this trader cheating?' The expensive question is 'are these twelve traders one person?' — and only a graph can answer it."
— The Singuard Team
Singuard builds software for prop firms and brokers, including risk, CRM and trading platform infrastructure. This article is an independent explainer; we have no commercial relationship with Quant Technology Group.
Key Takeaways
- Coordinated abuse — hedge groups, copy-trading rings, multi-accounting — looks clean at the account level by design. Per-account rules structurally cannot see it; only relationships between accounts reveal it.
- Network detection builds a real-time graph from four signal types — device fingerprint clustering, shared payout mapping, P&L correlation and the cross-account graph itself. No single signal convicts; the overlap does.
- Detection without evidence is unenforceable — QuantSentry's per-case Evidence Kits matter because enforcement capacity is bounded by evidence capacity, especially when a flagged trader disputes publicly.
- Published tiers run €750–€3,997/month by account count. The honest ROI comparison isn't the subscription line — it's the payout leakage you currently have no way to measure.
Frequently Asked Questions
What Is Network-Based Risk Detection for Prop Firms?
Instead of scoring each account against a rulebook, the system builds a graph: accounts are nodes, and the edges are signals that two accounts are not really independent — shared device fingerprints, shared payout destinations, and P&L curves that correlate far more than chance allows. Coordinated abuse like hedge groups and copy-trading rings looks clean at the account level and only becomes visible in the relationships between accounts.
Why Don't Account-Level Rules Catch Hedge Groups and Copy-Trading Rings?
Because no individual account breaks a rule. Six accounts hedging each other each pass their challenge cleanly with drawdowns inside limits; whichever side wins, the firm pays out. The abuse is a property of the group, not of any account in it — which makes it structurally invisible to systems that evaluate one entity at a time. Account-level detection is still necessary for HFT, grid and martingale patterns; it just cannot see coordination.
What Does QuantSentry Cost?
Pricing is published on its site: tiers run from €750/month at Launch (up to 1,000 accounts, 30 Evidence Kits monthly) through €1,449 for 1,000–3,000 accounts, €2,449 for 3,000–5,000, and €3,997 at Scale for 5,000–8,000 accounts with 600 kits. Above 8,000 accounts it is custom Enterprise pricing with unlimited kits. Singuard has no commercial relationship with Quant Technology Group — this article is an independent explainer.