Trade Surveillance Software: Custom Build vs SMARTS, Actimize and Eventus
Keep the vendor and build alongside it. Nasdaq SMARTS, NICE Actimize, Eventus Validus and SteelEye carry years of regulatory pattern work you should not recreate, and a single asset class firm on one or two venues should simply buy and tune.
On this page
Keep the vendor and build alongside it. Nasdaq SMARTS, NICE Actimize, Eventus Validus and SteelEye carry years of regulatory pattern work you should not recreate, and a single asset class firm on one or two venues should simply buy and tune. What you build is the layer they cannot see: order lineage, identity resolution across entities, and case quality.
What SMARTS, Actimize, Eventus and SteelEye actually do well
Monday morning, the market abuse queue holds 1,840 alerts from Friday. Two analysts have the day. They will sort by score, work the top hundred, and mass close the rest with a reason code that says no further action. Nobody chose that. It is what happens when a threshold scenario fires on every large order near the close in a thin name, when one event generates alerts in four scenarios, and when the queue has no memory of the fact that this trader was reviewed for the same pattern three times this quarter and cleared each time for the same reason.
The vendors are not why that happens. Nasdaq SMARTS, NICE Actimize, Eventus Validus, SteelEye and Behavox all ship detection libraries representing years of regulatory pattern work, and they maintain those scenarios as rules shift, which is real ongoing value you would otherwise fund yourself. Scila, b-next and Trapets serve their own segments credibly. If you trade one asset class on one or two venues at moderate volume with a small number of desks, and your alert queue is genuinely reviewed rather than triaged, buy Eventus or SteelEye, tune it properly and put nothing into a build. That is the right answer for most firms searching this term.
Say the awkward part too. The detection library is the least differentiated part of a surveillance programme. Recreating it is the most common way a firm spends a year of engineering and ends up with less coverage than it started with.
Where they stop: a vendor scenario sees the market, not your order book
The workflow no packaged platform models is the one that separates a real case from a false positive, and it depends on facts that live inside your order management system rather than in market data.
- Your own algorithms look like manipulation. A desk running an algorithm whose child order behaviour involves rapid repricing produces a footprint that a generic layering scenario cannot distinguish from the real thing. Only your parent to child linkage and your algorithm identifiers explain it.
- One beneficial owner appears as several participants. Two legal entities routing to the same venue through different memberships produce two participant identities for one person. Cross venue and cross product patterns are invisible until identity is resolved.
- Order lifecycle is stored badly. Most firms hold executions well and lifecycle poorly. Amendments and cancels sit as separate records with no reliable parent linkage, timestamps come from three clocks at different granularity, and the venue message sequence was never retained. Spoofing, layering and momentum ignition are arguments about intent, and intent is only visible in sequence.
- Tuning is capacity management wearing a compliance label. Raising a threshold until the queue is survivable silently removes coverage in exactly the range where manipulation is economical, and firms do it because the scenario ships as a black box with a handful of parameters.
The last one is the quiet failure. Surveillance programmes are examined on review quality far more often than on detection coverage. An alert that existed and was dismissed in eleven seconds alongside four hundred others is worse to explain than an alert that never fired.
The review record itself is usually thinner than firms realise. In many desks it consists of an alert status and a free text comment, with no measurement of whether two analysts closed comparable patterns for comparable reasons. Consistency across a team is the thing an examiner can test and a firm rarely has, and it is not a detection problem at all.
The arithmetic: alerts per day against analyst headcount
Surveillance is not priced per seat in a way that decides this, so do the arithmetic on review capacity, which is the constraint that actually binds.
A meaningful first pass on an alert, meaning the analyst opens the evidence and forms a view rather than reads a title, takes eight to ten minutes. That is roughly fifty alerts per analyst per day at best. Two analysts give you a genuine capacity of about a hundred alerts a day. Anything above that is triage, whatever your closure statistics say.
Now price both sides. A fully loaded surveillance analyst runs around $110,000 a year in most markets, so the third and fourth analyst you would need at 200 alerts a day costs $220,000 annually and recurs forever. The build over five years, at a first release of $175,000 plus integration at 15 percent plus support at 18 percent a year from year two, comes to roughly $327,000, or $65,450 a year.
The crossover sits at about 120 alerts a day sustained. Above that with two analysts, you are already not reviewing your queue, and the layer costs less per year than the headcount that would fix it and does a job headcount cannot do. Below it, tune what you own and spend the money on scenario coverage instead.
What a custom build actually costs
A focused first release covering normalised capture of order and execution data from your order management systems and venues, full lifecycle reconstruction with replay, two or three firm specific scenarios and a proper case workflow runs $110,000 to $240,000 and ships in 16 to 22 weeks.
A full platform adding cross venue and cross product detection, identity resolution across entities, trader behaviour baselining, alert scoring, linkage to communications surveillance and regulator ready case export runs $300,000 to $850,000 phased across 10 to 18 months.
Integration and data migration runs 10 to 25 percent of build cost, and surveillance sits at the ceiling for one reason: a firm running three order management platforms plus a vendor algorithm container has four dialects of the same event, and each venue drop copy or market data feed is its own ingestion project. Year two onward runs 15 to 20 percent of build cost annually, and in this category a meaningful share of that is storage, because holding several years of full order lifecycle messages at native timestamp precision so an analyst can query a five minute window in seconds is a genuine engineering commitment. Decide it at the start, because retrofitting replay depth is close to a rebuild.
The four situations where building wins
- Regulatory fit. Your obligations attach to records you do not currently hold in a queryable form. Suspicious order and transaction reporting under the market abuse rules, supervisory obligations under FINRA Rule 3110, market access controls under SEC Rule 15c3-5, clock synchronisation requirements under MiFID II, and Consolidated Audit Trail linkage all depend on order level data with defensible timestamps. If proving what you reviewed means searching two systems and taking screenshots, that is the gap.
- Scale economics. You are past roughly 120 alerts a day with a review team that cannot honestly work them, and adding analysts is the only lever you currently have.
- A workflow that is your competitive advantage. Encoding your own account taxonomy, desk mandates, algorithm identifiers and parent to child order relationships lets you suppress structurally explainable behaviour without lowering coverage. In the surveillance work we have delivered, that is where alert volume falls by a large multiple while the number of cases reaching a genuine investigation rises, which is the only pair of numbers worth quoting to a regulator.
- Integration sprawl across three or more systems. Several order management platforms, venue feeds, a communications archive from Global Relay or Smarsh, reference and instrument data, and case management. The identity and instrument graph that joins them is exactly the layer packaged tools expect you to supply, and nobody sells it.
How to decide in a week
Sample your own closures. Pull last month's closed alerts, take thirty at random weighted toward the ones closed fastest, and ask the analyst who closed each one to reproduce the evidence they reviewed and the reasoning. Time it, and count how many were closed in under a minute.
Then run one investigation cold. Pick a five minute window on a busy day and ask someone to reconstruct what a single trader displayed, amended and cancelled across venues in sequence, with timestamps you would put in front of an examiner. Time that too.
If thirty closures each come with reproducible evidence and the reconstruction takes an hour, your programme is sound and your money belongs in scenario tuning. If a meaningful share closed in seconds, or the reconstruction takes three days of manual assembly, the order lineage layer is the thing to build and the case for it writes itself.
The next step is a paid discovery phase. At Digital Heroes that ends with a signed product requirements document covering the order lifecycle model, timestamp and sequencing treatment across sources, the identity resolution approach, replay storage depth and the acceptance criteria, before any code is written. You keep it either way. We are wrong for you if you want the vendor library replaced, because we will tell you to keep it and build only what it structurally cannot see. We contract through Indian LLP, US LLC and UK LTD entities so intellectual property assigns under your own law, more than fifty specialists have delivered over 2,000 projects, and you meet the named team before signing. Clutch, Trustpilot, Fiverr Vetted Pro and our D-U-N-S record all answer the diligence question your risk committee will ask.
Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- The average developer spends more than 17 hours a week dealing with maintenance issues such as debugging and refactoring, and about four of those hours on 'bad code' - waste that equates to nearly $85 billion annually worldwide in opportunity cost. Source: Stripe (2018) →
- McKinsey argues software developer productivity can be measured by combining system-level metrics (DORA and SPACE) with its own outcome-oriented approach, which it reports deploying across nearly 20 tech, finance, and pharmaceutical companies - a claim that sparked significant debate in the engineering community. Source: McKinsey & Company (2023) →
- A study (led by Prof. Pak-Lok Poon, published in Frontiers of Computer Science, 2024) reviewing decades of spreadsheet-quality research found that about 94% of spreadsheets used in business decision-making contain errors, illustrating the hidden risk of manual spreadsheet workarounds that custom software is built to replace. Source: Central Queensland University / phys.org (Prof. Pak-Lok Poon et al.) (2024) →
- Grand View Research valued the global field service management market at USD 4.43 billion in 2022 and projects it to reach USD 11.78 billion by 2030, a 13.3% CAGR, driven by growing field operations in telecom, utilities, construction and energy. Source: Grand View Research (2023) →
Frequently asked questions
How much does custom trade surveillance software cost?
A focused first release covering normalised order and execution capture, lifecycle reconstruction with replay, two or three firm specific scenarios and a case workflow runs $110,000 to $240,000 over 16 to 22 weeks. A full platform adding cross venue detection, identity resolution, alert scoring, communications linkage and case export runs $300,000 to $850,000 across 10 to 18 months, with 15 to 20 percent of build cost annually from year two.
How do you reduce false positives without reducing coverage?
By adding context rather than raising thresholds. The same aggressive order near the close is unremarkable from a client facilitation desk closing a hedge and highly interesting from a proprietary account that has been accumulating all week. Encoding account taxonomy, desk mandates, algorithm identifiers and parent to child order relationships lets you suppress structurally explainable behaviour. Raising a threshold removes coverage exactly where manipulation is economical, which is the opposite outcome.
Who owns the scenario logic if an agency builds our surveillance system?
You should own the repository, the scenario definitions, the cloud accounts and the right to bring in another firm, agreed in writing before kickoff. At Digital Heroes the client owns all of it from the first commit. Scenario logic is compliance policy expressed in code, and policy you cannot read, explain to a regulator or change without raising a vendor change request is not policy your firm actually controls.
How long should we retain full order lifecycle data?
Long enough to cover your longest applicable record keeping obligation and your own investigation lookback, which for most firms means several years rather than months. Decide the retention depth before the first line of code, because storing years of lifecycle messages at native timestamp precision in a form that answers a five minute query in seconds is an architecture decision. Retrofitting that depth later is close to rebuilding the capture layer.
What role should artificial intelligence play in surveillance alerts?
Drafting and consistency checking, never disposition. A model can assemble the case narrative from structured evidence the system already gathered, and flag where a proposed closure is inconsistent with how similar cases were closed by other analysts. It suggests and a human decides. Any system where a model closes alerts creates exactly the review quality problem that examinations focus on, with less explanation available than the manual process it replaced.
What is the difference between trade surveillance and communications surveillance?
Trade surveillance watches orders and executions for patterns such as spoofing, layering, wash trading, marking the close and insider dealing. Communications surveillance watches email, chat and voice for intent, disclosure and collusion, typically through an archive from a specialist provider. They answer different halves of the same question. Linking them so a case file carries both the order sequence and the surrounding messages is where investigations become conclusive rather than suggestive.
Can custom software detect manipulation that crosses venues and products?
Only after two prerequisites exist. You need one trader and beneficial owner identity that survives multiple entity memberships, and an instrument relationship graph that knows this option references that underlying and this depositary receipt references that foreign line. Once those exist, cross product scenarios are straightforward to express. Without them, no amount of scenario sophistication helps, and this is precisely the layer packaged tools expect the firm to supply.
How long does it take before analysts see a difference?
Sixteen to twenty two weeks to a first release, with the visible change usually arriving at replay rather than at detection. Once an analyst can watch a five minute window reconstruct itself, investigations that took three days take an hour, because the evidence assembles instead of being gathered. Firm specific scenarios follow, and alert volume typically takes another two months of tuning against real dispositions before it settles.
Should we build the case management or use what the vendor provides?
Build it, because the case file is the artefact you will actually be examined on. It should carry the evidence snapshot as it stood at review time, the analyst reasoning against structured factors rather than a free text box, the escalation path, the approval and links to prior cases involving the same trader or pattern. That makes disposition consistency measurable internally, which is far better than having it measured for you.
We trade one asset class on two venues. Should we build anything?
No. At that shape the vendor products are pragmatic, deploy quickly and carry scenario maintenance as rules change, which is real value you would otherwise fund. Spend the effort on tuning against your actual desk behaviour and on making sure every alert closure carries reproducible evidence. Revisit when you add venues or asset classes, run in house algorithms, or find your queue exceeding what your analysts can honestly review.
Is a solo freelancer enough for my project, or do I really need an agency?
A solo freelancer is a fine choice for a well-defined build under roughly $15,000 to $20,000 with a limited lifespan: an internal calculator, a scripted integration, a prototype. Above $50,000, or for any system your business will depend on for years, you are buying continuity as much as code: enforced code review, cover when someone is ill, and support that outlasts one person's career plans. Price the risk of a single point of failure, not just the hourly rate.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
How much should a small business expect to pay for custom software?
Across 2,000+ Digital Heroes projects, a small business system that replaces spreadsheets or one core workflow typically lands between $40,000 and $80,000, with more complex first versions running up to $150,000. The two levers that move the number most are integrations and user roles, not the team's hourly rate. Any quote under $15,000 for a full production system means the vendor has not understood your scope yet.
What happens if I stop paying for maintenance after launch?
Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.
Is it cheaper to customize Salesforce than to build a custom CRM from scratch?
If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .