Architecture & Security
LiquidONE separates the execution engine from the web application. The database acts as the immutable contract between the two.
The four moving parts
The web application
A Next.js 16 application hosted on Vercel. It provides the user interface across three subdomains: Marketing, Authentication, and the Product Dashboard. Nothing you click places an order directly: the interface reads data and writes configuration, and a separate scheduled route in the same deployment is what ticks bots and routes orders.
The Postgres contract
Supabase Postgres sits between the web app and the engine. The web app writes bot configurations to the database. The engine reads these configurations, executes trades, and writes results back to the database.
The trading engine
A TypeScript engine, ticked on a schedule. Each tick loads active bots, evaluates market conditions for their instruments, applies the ORB logic and every risk check, and routes any resulting order to the broker. Exactly one ticking path runs against a given set of bots at a time, and heartbeats detect it if that is ever violated.
Data isolation (RLS)
Live updates to the dashboard (agent feed, live P&L) are powered by Supabase Realtime. To ensure security, Row-Level Security (RLS) policies are enforced at the database level, using the authenticated session to guarantee that users can only subscribe to their own data streams.