A researcher who built your best strategy can walk out with it tonight, and every tool you own will record the move as approved. Her access is not a hole in the wall. It is the wall. She needs full read on the signal, the model, the parameter set, the backtest outputs, the production configs that turn a model into orders. That is the job. Take the access away and she cannot do it.
So the question your security stack asks of each move, was this permitted, comes back "yes" every time. It keeps saying yes right up to the moment the edge is gone and a competitor is running it.
The move is permitted; the pattern is the breach
She copies a production model over two weeks. Small chunks, off-hours, down an approved transfer path the desk uses for real work a hundred times a day. No policy breaks. No credential is stolen. No alert fires. Pull up any single action and it looks like Tuesday.
The breach lives in the sequence, not the action. This identity, reading these high-value paths, at this hour, in this volume, toward this destination, in a combination that has never been hers before. A tool that scores moves one at a time is structurally blind to a pattern that only exists across them. At a quant firm that blind spot sits on top of the one asset that matters.
Predictive tools guess the bad move before it happens, flood the desk with false alarms, and still wave the permitted one through. Forensics name what left after it has already left, which on a trading desk means after the edge is in someone else's production. Neither watches the move as it forms. The pattern is only visible in one place: at runtime, on the movement itself.
The wall nobody else clears: latency
The quant desk adds a second constraint that disqualifies most of the security market before a single feature gets evaluated.
Microseconds are the product. The trading infrastructure team will not let a security agent sit in the order path and add overhead, and they are right. Security does not get to overrule them. So latency-sensitive firms run thin: they deploy the controls they can afford to run and leave the production trading hosts under-covered, because the agents that would cover them cost too much where it counts. The blind spot persists not because nobody built a tool. It persists because the tools that exist stand in the path, and in-the-path is a non-starter on a desk where the path is the edge.
Hilt sits off the path. The collector watches data movement at the kernel, metadata only by default, and never sits inline. It does not block, drop, queue, or alter a packet. Footprint runs around 0.1% of one core and 4 to 8 megabytes of memory per host. It watches the move instead of standing in it, so there is no inline hop to add to order processing.
We have measured it. On real production trading infrastructure, controlled against the same hosts without the collector, p99 latency improved by roughly five percent with Hilt running. The mechanism is plain: the kernel-level collector displaced heavier in-path monitoring the firm was already carrying, and pulling that work out of the path was a net win on the tail. A security tool does not make trading faster by magic. The claim is narrower and checkable: off the path is real and measured, and it inverts the tradeoff a desk braces for whenever it adds coverage.
What it does on a research desk
Hilt resolves each move to a probabilistic, source-dependent identity: which researcher, which job behind it, which destination, and whether this fits how that identity normally moves data. It learns that picture from months of real movement, not a rule you had to predict and write in advance.
When she copies the model, the deviation surfaces on several layers at once. The job is off for her identity. The access is a bulk read of high-value research paths in a tight window. The destination volume is off even though the channel is approved. Any one signal is noise on a busy desk. Stacked, they are a pattern, and a pattern is a case, not an alert. Hilt writes the case with the narrative of what moved and why it does not fit, then isolates the host at the network from the control plane. It quarantines without ever reaching into the path.
None of this reads your strategy. Metadata only is the default, so Hilt sees that a pattern is wrong without opening a research notebook or a model file. Content-aware inspection is there when you want it; it is never the price of admission. For a firm whose entire value is the data it would rather no tool ever read, that default is the point.
Where this sits next to what you run
Hilt can stand in for the endpoint sensor on these hosts, and many firms retire their EDR once it is in place; keep an EDR alongside only if you also want the malware and live-intrusion layer it covers. Your network controls govern access at the perimeter. Your DLP catches the obvious application-layer paths, the customer record emailed to a personal account. Those are good at what they cover.
None of them was built to judge the pattern of movement across permitted actions, run through approved channels, by the one legitimate user who is supposed to have access. That is the quant blind spot, and it sits exactly where the strategy lives. Runtime data movement governance closes it without asking the trading team to eat latency it cannot afford, whether it stands in for your endpoint sensor or runs next to one you keep for the malware layer.
If your stack cannot answer "what did this researcher's data actually do, resolved to the job behind it and scored against how it normally moves, in the small hours across these three nights," then the most valuable thing in the building is the one thing you cannot watch leave.
If that is the gap, the quickest way to size it is a 30-minute call, engineer to engineer. No deck. Just where the collector would sit on your hosts, what it would see, and the off-the-path architecture and latency numbers, with whoever owns your trading infrastructure in the room.