Pricing & risk infrastructure for derivatives desks

Solve the model once
read everything else

Krylo is a pricing and risk engine for the structured products that keep blowing up desks — autocallables, worst-of and knock-in books. It reads risk exactly where today’s tools go blind, delivers a full-book risk pack hundreds of times faster, and runs entirely on hardware inside your own perimeter. The idea underneath is simple: solve the model once, then read every price, Greek, scenario and exposure off that one solved object.

V(t) = e(T−t)ℒ g the object every incumbent method approximates around — computed directly
The problem

The autocallable loss cycle is computational

Worst-of and knock-in books broke their holders three times in six years — and the failure point is the same every cycle. The industry risk-manages these products by re-simulating them, and simulation-based risk numbers are at their noisiest exactly at the loss events: second differences across a payoff discontinuity amplify Monte-Carlo noise catastrophically. On a representative book of eight step-down notes, the industry-standard estimate of correlation risk came out at −0.06 ± 0.06 — the sign is unreadable on half the book, on the day it matters most.

€260M
Natixis, Korean worst-of books, 2018
€673M
SocGen + Natixis hedging losses, COVID quarter 2020
$4.6B
HSCEI knock-in wave, 2024 — plus $1.2B compensation reserves
$538B
callable / autocallable issuance in 2025 — a record, increasingly held outside dealers
What it changes for the desk

Three things your current stack can’t give you

The technical detail is below and in the brief. In business terms, a pilot puts three capabilities on the desk that a simulation stack structurally cannot.

01

See the risk you’re blind to today

The correlation and knock-in numbers that go unreadable on a simulation desk — noise swamping the signal on the exact day a book breaks — come out here as a clean, exact profile you can actually hedge on.

02

A full-book risk cycle on one GPU

Daily marks, breach profiles and counterparty exposure for the whole book inside the risk window — hundreds of times less compute than a Monte-Carlo farm. No new data centre, no overnight batch that misses the morning meeting.

03

An independent, auditable second opinion

It sits beside your existing stack as a check on the dealer’s marks — nothing ripped out — and every number reproduces from a gated benchmark your model-risk team can rerun, not just read.

How it works

One solved model, then everything is a read

For the quants: Monte-Carlo samples the transition operator one random path at a time, and finite differences re-step through it per product and per scenario — neither ever builds the reusable object itself. Krylo does. Three components matter.

01

Analytic kernel

The short-time transition kernel is evaluated in closed form and moment-corrected to sixth order in space — with the correlation cross-term handled exactly, the term that forces operator-splitting compromises in ADI schemes. A one-year horizon is a handful of large, high-order steps.

02

Compression

The solved operator is projected to a small subspace where any horizon is a small-matrix computation: applying thirty years costs the same as applying one day, and a whole maturity surface comes from one build.

03

Products as projections

Autocall dates, memory coupons, and discrete knock-ins apply between marches as exact projections — discrete monitoring priced with no continuity correction. Run the same operator in reverse and it produces counterparty-exposure profiles with no nested simulation.

Krylo architecture: the model is solved once per underlier set; products, risk, scenarios, maturities and exposure are reads of the solved object.
The engine in one picture. The model is solved once per underlier set; the next product on the same underliers is a projection, not a re-solve.
The operator library: a lattice of solved models interpolated across market state, repricing the book intraday without a rebuild.
The operator library. A solved model is a reusable object: store a lattice of them, interpolate across market state intraday. One tangent step — “yesterday’s solution + a derivative” — reprices the book across an overnight move, no rebuild. No incumbent tool has this primitive.
Evidence

Exact where simulation is noisiest — and hundreds of times faster

Every number here regenerates from a provenance-stamped, gated benchmark: one command rebuilds the full evidence base, a numeric pass gate lives inside each benchmark, and a regression flips the report on its own. The comparisons run against closed forms, QuantLib, and 10M-path Monte-Carlo anchors — nulls published as prominently as the wins.

×
faster than full-path Monte-Carlo at T = 30y — unbiased, cost flat in maturity
bp
converged price of a real step-down term sheet at the coarsest production grid
/15
independently gated benchmarks vs closed forms, QuantLib, and 10M-path Monte-Carlo anchors
numerical failures across a 26-rung certification campaign on deployment-class hardware
Simulation cost grows with maturity; the solved-operator cost is flat — 306× at thirty years, without bias.
Cost flat in maturity. Simulation pays per path, per year — 306× slower at T = 30. One solved operator applies thirty years for the cost of one day, exactly and without bias; a whole maturity surface comes from one build.
Correlation risk of a real step-down autocall through the knock-in: exact profile vs noisy re-simulation estimates.
Through the breach. Correlation risk of a real step-down note (memory coupons, discrete knock-in, local vol + correlation + jumps) as the market slides toward the knock-in. Blue: the exact profile, read from one solved model. Red: re-simulation with nudged inputs, with its measured noise. The independent cross-check agrees: 4.68 ± 0.17 vs 4.78 at the knock-in.
Deterministic is not converged: ±3bp grid-dependent error removed by sixth-order contract loading.
Deterministic ≠ converged. The same term sheet on three production grids: standard contract loading carries ±3 bp that changes sign with the grid. With sixth-order loading: 0.04 bp at the coarsest grid — a two-second march.
Counterparty exposure profile of an autocall computed without nested simulation.
Exposure without the farm. The solved model run forward, paired with its backward values: EPE/PFE with the autocall runoff staircase, ≤ 0.12% of brute-force nested simulation at every date — in about four minutes on one GPU.
The living calibration

The model re-calibrates itself intraday — and flags when the market really moved

Because the value flow of the pricing model is a linear semigroup, streaming quotes can be assimilated into the model’s coefficients continuously, with calibrated uncertainty ��� and every innovation decomposed into noise, drift, or an attributed shock. Validated on live exchange options: exactly silent through quiet weeks, 38 named and sized events through a real volatility episode. Every commercial surface product either fits snapshots or reprices fast; none tracks a model-consistent trajectory, carries calibrated uncertainty, or attributes its misfit.

Attributed shock detection on real exchange volatility data: silent on quiet weeks, named and sized events through a real episode.
Attributed shocks on real market data. The assimilation channel through a real volatility episode: discrete repricings detected, named, and sized — with the quiet-week null reported just as prominently.
Coverage & scope

What it prices today — stated plainly

Scope claims here stay inside what the gates actually certify. If your book lives outside this list, we tell you before a pilot, not during one.

Asset classes
  • Equity and FX-style exotics, 1–3 factors
  • Not covered: credit
Model families
  • Local volatility
  • Stochastic-local volatility (SLV)
  • Jump-diffusion (Merton)
  • 3-factor SLV + Hull–White stochastic-rates hybrid — supported, certified existence-proof grade, API-routed
Payoffs shipped & gated
  • Vanillas · digitals
  • Barrier options (knock-in / knock-out)
  • Autocallables — single, step-down, worst-of
  • Asians · lookbacks
  • American exercise (semilinear / penalty route)
  • Worst-of-3 baskets
Beyond single prices
  • Book-level revaluation · scenario / risk cubes
  • Online (“living”) calibration — tracks the pricing operator intraday from quote streams
Roadmap
  • Full rates-exotics coverage
  • Regime-switching model family
Validation & model risk

Validation-ready by construction

Built for the group that has to approve it. A 15/15 gated benchmark ladder runs against independent referees — QuantLib and Monte-Carlo with common-random-number controls — and a 158-test gate suite ships with the distribution, running on the exact binaries we deliver. Certified on enterprise GPU hardware, with published null results and a written scope-and-limitations statement. Claims about a pricing method should be cheap to check and expensive to fake.

ClaimReferenceResult
Real step-down term sheet (memory, discrete KI)identical-logic Monte-Carlowithin MC noise (±0.02%)
Correlation risk through the breachmatched-seed MC bump4.78 vs 4.68 ± 0.17
2-asset worst-ofStulz (1982) closed form10⁻⁸
Whole implied-vol surface to 30yRichardson-extrapolated fine CN0.006 bp mean · 1.6 s
Counterparty exposure profilebrute-force nested simulation≤ 0.12% at every date
Bermudan exerciseQuantLib finite differences< 0.5%
vs Craig–Sneyd ADI / sparse CN, same gridStulz closed form~230× (price and corr. risk)

Published nulls, for the avoidance of doubt: in 1D on raw payoffs, tridiagonal Crank–Nicolson wins wall-clock at equal accuracy; and simulation deltas are fine — we do not sell better deltas. The value is in the numbers simulation cannot read.

For model-risk teams: SR 11-7-style vendor-model documentation ��� full whitepaper, gate inventory, and a written model scope-and-limitations statement — is available under NDA for independent validation. The falsification program is designed so your MRM team can rerun the evidence on the delivered binaries, not just read it.

Deployment

On-prem, inside your perimeter

Your positions and market data never leave your infrastructure. There is no vendor cloud, and nothing about an evaluation requires you to send us a book.

How it ships
  • Compiled Python library — Linux x86_64, pinned Python, no source in the artifact
  • Runs on a single NVIDIA-GPU server
  • Air-gapped installs supported (offline dependency bundle)
How you use it
  • Import-and-price in notebooks or batch jobs
  • gRPC service wrapper for legacy C++/Java risk stacks — on the roadmap
  • Ships with its own verification suite — rerun our gates against the exact binaries we delivered
Who built this

One quant, accountable end to end

I’m Andrew. I built Krylo — the numerical methods, the gates, and the distribution. I’m completing a PhD in applied mathematics at BYU (Phi Kappa Phi), I hold two patents as named inventor, and I spent four years as a data scientist in industrial R&D building diagnostic medical technology. You deal with one person, and the accountability is undivided.

Ownership & licensing
  • Independently developed and wholly owned
  • Production licenses: source-code escrow available
  • Support terms defined in the license agreement
Continuity — independent of the vendor
  • Third-party validation engagements supported as an alternative to source access
  • The shipped verification suite lets you confirm the artifact works as documented at any time — with or without us in the room
Engagement

A four-to-six week pilot, on your book

Second-opinion risk engine — beside your stack, nothing ripped out.

What we run
  • 5–10 of your term sheets — public or synthetic equivalents acceptable, no MNPI required
  • Daily marks, breach risk profiles, the full per-note risk set
  • Optionally: counterparty-exposure profiles
  • On our hardware or a GPU box in your environment
Success criteria, agreed up front
  • Prices inside your own simulation noise
  • Risk numbers stable through knock-in scenarios
  • Full-book pack inside the daily window
  • The business test: the pack is in your morning risk meeting by week three

Fixed fee · week-two review · either side stops.