Onboarding a counterparty still means a shared call, test scripts walked by hand, and logs read line by line — one client at a time. Tag35 replaces that. Point its AI at your rules of engagement: it plans the tests, drives every session, explains any failure in plain English, and issues a signed, auditable certificate. Hours, not weeks.
No hand-written scripts, no scheduled analyst, no reading logs line by line. Point Tag35's AI at a spec and a venue and it initiates the flows, runs the test cases, adapts, analyzes every response, and produces the deliverables — you review and approve.
The venue's rules of engagement — PDF, Word, even an existing FIX dictionary — plus the connection to test against. That's the whole ask.
It plans the test surface, opens and drives every session, injects the negative and resilience cases, watches each response, and diagnoses anything that breaks — autonomously, around the clock.
A signed pass/fail certificate, the full message log both ways — reproducible for any auditor — and machine-readable results your CI or ticketing can pick up.
| The AI runs everything except the grade. Every pass or fail is the deterministic core's — signed, and reproducible byte-for-byte.
A counterparty gets certified one at a time, over a shared call — an analyst walking the test script message by message while both sides read the logs. Specs live in PDFs; every retest waits for the next open window across time zones. And every venue upgrade, new order type, or FIX version bump starts the whole thing over.
Human-gated sessions dominate the calendar. Each fix-and-retest cycle costs days, not minutes.
A venue with quarterly releases faces an enormous certification surface. Analysts don't scale linearly.
Recordkeeping expectations mean logs, sign-offs, and chat trails must be retained and retrievable for years.
A SaaS control plane that orchestrates, and a run-anywhere data plane that executes FIX where the network demands it — often inside your DMZ or a colo near the venue.
Publish specs, generate scenario packs, run certification programs, and review signed evidence — from one place. Your analysts orchestrate; they no longer babysit sessions.
Speaks FIX natively and executes scenario packs deterministically. Runs in our cloud, your cloud, your DMZ, or fully air-gapped — and connects outbound-only over mTLS.
Four stages, and the AI drives all four — you approve and collect the output. A compiled state machine still owns every verdict.
Upload the RoE as PDF, Word, HTML, or an existing FIX dictionary. Tag35 Copilot extracts every message, field, enum, and conditional rule into a machine-readable Orchestra spec — each rule cited back to its source clause with a confidence score. You review and approve; nothing goes live without a human.
From the approved spec, Tag35 compiles versioned Scenario Packs: session-layer conformance, order lifecycle, negative and fuzz cases, resilience, and throttle limits. Every enum, every conditionally-required field, every "send X → expect Y" workflow. The model proposes; the compiler and schema validation dispose.
Counterparties self-serve through a guided portal with a live message console and instant verdicts. When a run fails, Copilot explains which tag and rule were violated, cites the clause, and suggests the candidate-side fix — so the retry doesn't wait for an analyst's email.
Every run produces a signed Evidence Bundle: raw wire logs in both directions, verdicts, timestamps, and spec/pack hashes — hash-chained for tamper evidence and reproducible from the bundle alone. Retained to your policy and handed to your auditor without a scramble.
A false PASS on a revenue-bearing connection is existential. So Tag35 holds a hard line: the AI plans the tests, drives every session, and explains what breaks — but it never decides pass or fail. Every verdict comes from a compiled state machine with exact assertions, reproducible byte-for-byte from signed evidence.
Certification is slow because a person sits at three choke points — reading the spec, writing the tests, and explaining every failure. Tag35 Copilot takes all three. And unlike a claim, it shows its work.
Members connect over FIX 4.4. SecurityIDSource (22) must be 8 (Exchange Symbol) for listed instruments.
On any partial or full fill, the ExecutionReport (35=8) must carry LastPx (31) and LastQty (32). Orders received during a halted phase are rejected with a session-level Reject (35=3).
Heartbeat interval is 30s; the venue issues a TestRequest after 1.5× the elapsed interval.
<fixr:message name="ExecutionReport" msgType="8"> <fixr:fieldRef id="31" name="LastPx" presence="required"> <fixr:rule when="150 in {1,2}"/> </fixr:fieldRef> <fixr:fieldRef id="32" name="LastQty" presence="required"/> </fixr:message>
Every rule cited to its source clause with a confidence score. You approve — nothing goes live without a human.
8=FIX.4.4|35=8|150=1|39=1|11=ORD-001|14=200|6=189.44✗ tag 31 (LastPx) absent — required when 150=1
This partial fill is missing LastPx (31). Your rules of engagement mark LastPx and LastQty required whenever ExecType reports a trade (150 = 1 or 2). Add both tags to partial and full fills.
… 39=1|31=189.44|32=200|14=200 …retry PASSRevise a spec and Tag35 diffs the Orchestra versions, regenerating only the scenarios that changed — and flags every candidate whose certification just went stale.
orchestra_broker v7 → v8 + OL-14 DoneForDay required by 17:00 ET + enum 40=P (pegged) now accepted - OL-03 superseded by OL-14 → 2 scenarios regenerated · 4 candidates re-flagged
Point Tag35 at historical FIX logs and it reports where real behavior diverges from the documented spec — a way to land with an operator before a single test runs.
prod logs ⟂ active spec ! 35=8 carries 58 (Text) on rejects — undocumented ! 40=3 (stop) observed in flow — absent from RoE → 2 drift findings surfaced for review
The tools in this category run on test scripts written and maintained by hand, visual script builders, or a managed team that certifies your counterparties for you — on a scheduled call, in business hours. Tag35 starts from the spec and lets an AI do the work.
| And where it counts most, Tag35 is stricter, not looser: the AI plans and explains, but every pass or fail is decided by a deterministic engine — signed, and reproducible byte-for-byte.
The same signed container certifies from our SaaS pool or from deep inside a regulated network — managed from the Platform either way.
Hosted, elastic, zero-ops. The fastest path to a first certification.
↑ outbound mTLSAWS, GCP, or Azure inside your own VPC and controls.
↑ outbound mTLSNext to the venue gateway. No inbound firewall rules required.
↑ outbound mTLSSigned bundle in, signed evidence out. Same formats, sneakernet transport.
⇄ offline bundleEngines dial home on 443 with mutual TLS. The control plane never opens a connection into your network — zero inbound rules to manage.
Scheduled runs keep executing when the control plane is unreachable. Evidence spools locally and syncs on reconnect, oldest-first.
The engine verifies signature and hash on every config bundle and binary, and refuses unsigned or unpinned artifacts. Regulated customers pin exact versions.
Venue credentials and TLS material are held engine-side or in your KMS. The control plane stores references, never the secrets themselves.
Tag35 owns its FIX session state machine so it can send the bad checksum, abuse the sequence numbers, and drop the session at the worst possible moment — the things a normal engine is built to refuse. That's not a workaround; it's the point.
AI ingestion of RoE into reviewable Orchestra, with versioning, semantic diff, and drift detection against live logs.
Compile specs into signed Scenario Packs; natural-language authoring; a coverage report that shows exactly which spec rules are exercised.
Invite → connectivity wizard → guided 24/7 runs → Copilot diagnosis → PDF report, shareable badge, and operator sign-off.
Enroll engines with one-time tokens, push signed config, canary and roll back, tail sessions, and pin versions across the fleet.
Signed, hash-chained bundles; configurable retention and legal hold; full audit trail; API and webhooks into Jira, Salesforce, ServiceNow.
Multi-tenant orgs and workspaces, RBAC, SSO (SAML/OIDC), SCIM, per-program environments, and metered billing.
Exchanges, ATSs and MTFs, brokers, and OMS/EMS vendors running certification programs at scale. Cut analyst hours, activate member revenue faster, and stay audit-ready by construction.
Buy-side desks, prop firms, and vendors integrating one system with a dozen counterparties. Rehearse against published venue profiles before the formal run — no waiting for an analyst to free up.
Retention and recordkeeping obligations should be validated with your counsel and auditors — Tag35 is engineered to meet them, not to opine on them.
Type II on the roadmap from day one, with controls designed in rather than bolted on.
TLS 1.2+ and mTLS in transit; encryption at rest; signed artifacts end to end.
Strict multi-tenant boundaries. No candidate wire data leaves the tenant without explicit opt-in.
Private keys and venue credentials never transit the control plane — references only.
WORM-style retention with object lock, legal hold, and per-tenant export.
SBOM and provenance attestations; sigstore-style signing on binaries and bundles.
EU and US data-residency options for regulated deployments.
Fully offline mode via signed bundle import and evidence export — identical formats.
We'll ingest a real rules-of-engagement document, generate the pack, and run a live certification with you — deliberate failure and all.
Thanks — the Tag35 team will be in touch at the email you gave. Have your rules-of-engagement doc ready when we talk.