Skip to content
Course contents
From analysis to automation

The rules you trade under

Since 2025 India has a SEBI framework for retail participation in algorithmic trading, and it governs what you may build and run. This chapter explains it plainly: what counts as an algo, the orders-per-second line, White Box versus Black Box, registration and the exchange order tag, the broker as the responsible principal, and the security rules such as static-IP whitelisting.

11 min readChapter 2 of 28
What you will learn
  • Explain when a retail strategy becomes a regulated algo (the order-rate threshold and third-party algos)
  • Describe White Box versus Black Box, registration, and the unique order-ID requirement
  • State the security obligations (static IP, API keys, kill switch) and why they exist

For most of its history, algorithmic trading in India sat behind a wall. It was something large institutions did, with direct exchange connections and compliance teams, and an ordinary retail trader could not take part in any formal way. That has changed. India's market regulator, SEBI, the Securities and Exchange Board of India, has put in place a framework for retail participation in algorithmic trading through registered brokers. If you plan to run a program that places orders, and this course assumes you might one day, these rules decide what you are allowed to build, how your orders are tracked, and who carries the responsibility when something goes wrong. So before you write a single line that touches a broker, learn the ground you are standing on.

One caution first. The details, thresholds, and dates in this chapter are the shape of the framework as it took form through 2025 and into 2026. Regulation changes, and the exact numbers will move. Treat the shape as real and confirm every specific with your broker and SEBI's own material before you build anything that trades. This is education, not legal or financial advice.

When your program becomes an "algo"

Automating your own trades through an approved broker API is fine; unauthorised or black-box algos, and selling unapproved strategies, are not.
Automating your own trades through an approved broker API is fine; unauthorised or black-box algos, and selling unapproved strategies, are not.

Start with the plain meaning. As soon as software places your orders through a broker's programming interface, its API (the channel a program uses instead of a human tapping the app), you have left ordinary manual trading. Whether that counts as regulated algorithmic trading depends mostly on two things: how fast, and whose logic.

The speed test is an order-rate threshold. Below a certain number of orders per second, you are treated as an ordinary trader who happens to use an API. At or above it, your activity is treated as algorithmic trading and must be registered through your broker. The exact figure is set by the exchanges and the brokers' industry body, and a number of around ten orders per second has been discussed. You can measure your own program's peak rate directly, which is the sort of check you should build in before you ever go near a live account.

ExampleMeasuring your program's peak order rate against the thresholdch02/order_rate_check.py
# India's framework treats a retail trader using a broker's API as a normal user
# below an order-rate threshold, and as an algo trader at or above it. The exact
# number is set by the exchanges and their industry forum; here we use an
# illustrative 10 orders per second to show how you would measure your own peak
# rate from the times at which your program sent orders.
# TODO(figure: confirm the current threshold and the body that sets it at publish).
from collections import deque

THRESHOLD_OPS = 10          # orders per second, ILLUSTRATIVE

# The times (in seconds) at which one program sent orders during a busy stretch.
order_times = [0.01, 0.05, 0.09, 0.12, 0.20,
               0.95, 0.97, 0.98, 0.99, 1.00,
               1.01, 1.02, 1.03, 1.04, 1.05, 1.06]


def peak_orders_per_second(times):
    """The most orders that fall inside any one-second window."""
    times = sorted(times)
    window = deque()
    peak = 0
    for t in times:
        window.append(t)
        while window and t - window[0] >= 1.0:
            window.popleft()
        peak = max(peak, len(window))
    return peak


peak = peak_orders_per_second(order_times)
print(f"Orders sent in this stretch:            {len(order_times)}")
print(f"Peak orders in any one-second window:   {peak}")
print(f"Illustrative threshold:                 {THRESHOLD_OPS} per second")
if peak >= THRESHOLD_OPS:
    print("At or above the line: this counts as algo trading, so registration applies.")
else:
    print("Below the line: treated as a normal API user.")
Output
Orders sent in this stretch:            16
Peak orders in any one-second window:   14
Illustrative threshold:                 10 per second
At or above the line: this counts as algo trading, so registration applies.

The code slides a one-second window across the times your program fired orders and reports the busiest second. Here the program hit 14 orders inside a single second, above the illustrative line of 10, so this activity would count as algo trading and trigger registration. A calmer strategy that acts once a minute would sit far below the line. The second test is authorship: if you run someone else's strategy or a ready-made algo product rather than your own, that generally counts as algo trading whatever the speed, because a third party's logic is now trading your account.

White box and black box

The framework splits algos by how visible their logic is, and treats the two very differently.

A white box algo is one whose logic is disclosed and can be understood and reproduced. You, and the exchange, can see the rules it follows. Because it is transparent, it carries the lighter registration path and can be offered to many traders once registered.

A black box algo is one whose logic is hidden, a proprietary strategy the user cannot see inside. Because nobody using it can inspect what it does, it is held to a stricter standard. The provider must register as a research analyst, keep detailed records, and report the strategy, so that an opaque, money-losing box cannot be sold without accountability.

For you, the practical lesson is a comfortable one. The strategies this course teaches are white box by nature. You write the rules, you can read them, and you can explain them in a sentence. That transparency is not just good compliance, it is good sense. You should never run a strategy, yours or anyone else's, whose logic you cannot state plainly.

The order tag, and who is responsible

Two more pillars hold the framework up, and both are about accountability.

The first is tagging. Every order an algo places carries a unique identifier assigned through the exchange, so each automated order can be traced back to the algo that sent it. This is the track-and-trace spine of the whole system. If a program floods the market or misfires, the exchange can see exactly which algo did it. Your manual taps and your algo's orders are not an anonymous blur; the automated ones are labelled.

The second is the chain of responsibility. In this framework the broker is the principal, the party the exchange holds responsible for what flows through its systems, and an algo provider acts as the broker's empanelled agent. In plain terms, your broker is accountable for the orders your program sends through it. That is exactly why brokers put controls around API access rather than handing out the keys freely. If you use a third-party algo provider, that provider sits in a defined, registered relationship with your broker, not off to one side in the dark.

The security rules, and why they protect you

Because a program trading your account is a serious thing, the framework and the brokers wrap it in security requirements. Learn them as habits now, because you will meet them again in the authentication chapter.

You will typically be required to use the API only from a static IP address, a fixed internet address that your broker has whitelisted, so your credentials cannot be used from anywhere else. You will sign in with API keys and access tokens rather than your ordinary password. Your broker logs the orders and monitors the flow, and the exchange can operate a kill switch to halt a malfunctioning algo. None of this is decoration. A leaked API key is not like a leaked password to a reading app. It is a key to something that can place trades with your money at machine speed. The security rules exist because the failure they prevent is expensive and fast.

What to carry forward

India now lets retail traders take part in algorithmic trading through their brokers, inside a SEBI framework you must design around. Software placing your orders edges you toward regulated algo trading, and an order rate above a set threshold, or the use of a third party's logic, pushes you across the line. Algos are split into transparent white box and opaque black box, with stricter rules for the latter. Every algo order is tagged and traceable, your broker is the responsible principal, and security rules such as static-IP whitelisting exist because a trading program is a dangerous thing to leave unguarded. The strategies you will build are white box, whose logic you can always state, which is the right way to trade. Next, the architecture: the parts an automated system is made of, and how they fit together.