// the find
OpenByteInc/QuantDinger
Open-source AI Trading OS, agent trading, and vibe trading, with Jev System One integration. Research, build Python strategies, backtest, and paper/live trade across crypto, stocks, and forex. Launch your own multi-tenant trading SaaS with built-in user management, billing, payments, and settlement.
QuantDinger is a self-hosted, open-source trading OS for writing Python strategies, backtesting them with proper statistical rigor, and running paper or live execution across crypto exchanges and traditional brokers like IBKR and Alpaca. It's aimed at independent quant traders and small teams who want to own their infrastructure and credentials instead of subscribing to a black-box signal service.
The architecture is a real distributed system, not a monolith pretending to be one — trading loops, Celery jobs, Kafka event processing, and scheduling are explicitly separated into different processes with documented ownership rules. Strategy evolution includes walk-forward validation, PBO, Deflated Sharpe, and block-bootstrap Monte Carlo, which is more overfitting-awareness than most retail bot repos bother with. Production hardening is actually implemented (non-root containers, read-only root filesystem, dropped capabilities, strict file permission checks) rather than just claimed in a README. The MCP/Agent Gateway uses scoped, rate-limited, audit-logged tokens and fails open on AI-provider outages so a dead LLM can't trap an open position.
Putting an LLM or JEV call in front of live order entry is a risky pattern regardless of how it's framed — a slow or flaky provider sits in the execution critical path, and 'fail open' quietly removes the filter exactly when something's already gone wrong upstream. The operational surface is enormous for a 'self-hosted' tool: two Redis instances, Kafka, Postgres, Celery, and a dozen-plus exchange/broker adapters, with the docs themselves warning not to reuse cache Redis as the Celery broker — that's a lot of ways to misconfigure this alone. It's not cleanly open source: the backend is Apache 2.0, but the web and mobile clients live in separate source-available repos, and branding/trademark use is governed separately. Manual Docker deployments still default to a known admin/password pair (quantdinger/123456) for backward compatibility, which is a real exposure for anyone who skips the hardening docs before exposing a port.