AADC Tracer

Do you know what your model actually computed?

Model documentation describes what a pricing model is meant to do. Validation has to establish what the code actually does, and today that means people reading source code by hand. The AADC Tracer records the calculation as it runs in your production binary, ties every step to the source line that performed it, and hands that record to an AI agent. The agent builds the validation evidence from what was computed, and every claim it makes can be checked.

The toolchain moved from gcc 12 to gcc 13 last quarter. Can anyone say which numbers changed? We measured it.
The documentation says the pricer draws 2,040 random numbers. On one run we traced, it drew 21,658.
A coding agent wrote the pricer; an assistant wrote its documentation from the source. Both read well. What did the code compute?

What it is

The AADC Tracer records a pricing calculation as it runs in the production binary: every arithmetic step, comparison and input. It attributes each recorded step to the source file, line and function that produced it, across the pricer and the libraries it calls. It reports every hard-coded number that reaches the price, every market-dependent branch with its distance to switching, which inputs each output depends on, and a validation report drafted from that record for a person to check. It runs on Linux x86-64 with Python 3.10 to 3.14, installed as pip install aadc-quantlib-tracing (QuantLib 1.41 with tracing built in); the engine traces C++ and Python code. It is made by MatLogica Ltd, London. The package ships under the AADC Community Edition licence: non-commercial and academic use only, with commercial and full-performance academic licences from info@matlogica.com.

One switch, no code changes

Set AADC_TRACE=1 and run your normal pricing program. The run produces the same prices as always, plus a complete record of the calculation: every arithmetic step, comparison and input, each attributed to its file, line and function. Without the switch the program runs exactly as before; with it off, pricing speed is unchanged. C++ and Python.

What the record gives you

Source attribution for every step

Any number in the result can be traced back across classes and libraries to the market quotes and constants it came from, and the record proves which inputs it does not depend on.

Every input identified and documented automatically

Market data, calibrated parameters and every hard-coded number buried in the code, from tolerances and cut-offs to day-count conventions and solver brackets, listed with their value and the exact line that set them.

Every branch found and explored

Each market-dependent decision is listed with its distance to switching. For each one, the agent finds the inputs that flip it, re-records the unmodified program there, and documents how the model behaves on the other side. Branches that cannot be reached within the agreed input ranges are reported, not assumed safe.

An agent that works from evidence, not from reasoning

Asked to read source code, a language model infers what the code probably does, the way a person does mental arithmetic, and it can be confidently wrong. Given the record, the agent reads what the code did: the record is its calculator. The output is a validation report in which:

  • every claim is verifiable: each statement cites the file and line it rests on, and each formula links to the source lines that compute it;
  • every result is reproducible: the record and the re-recordings are kept as an audit trail, so a reviewer or a regulator can re-run any finding;
  • people keep the decisions: the tool produces the evidence; validators judge model fitness and sign off.

On real code

One QuantLib swaption price: 74,428 recorded steps across about 40 source files, every step attributed to its source line; 140 hard-coded numbers that reach the price, three day-count conventions in one valuation, and 85 market-dependent branches, all found automatically from a single 17 ms recording. The lines that come back:

74,428 tape entries, 74,428 attributed (100%)

jamshidianswaptionengine.cpp:102   minStrike = -10
jamshidianswaptionengine.cpp:103   maxStrike = 10
vasicek.cpp:51                     B = 1.4901e-08    (x240)
errorfunction.cpp:209              0.84375           (x10)
actual365fixed.hpp:57              / 365.0           (x5157)

85 frozen-branch sites, e.g. brent.hpp:106, brent.hpp:110 ...

QuantLib 1.41, pip install aadc-quantlib-tracing. Every figure on this page reproduces from the scripts that ship with it.

Not new inside the platforms. New on your library.

Inside the largest in-house platforms this record has existed for thirty years as the dependency graph. Goldman Sachs built SecDB in 1993 and calls it the backbone of its risk analytics for securities. Its former core engineers describe it publicly as a lazily evaluated, backward-propagating dataflow graph with automatic dependency tracking. Beacon, founded by two of the engineers behind SecDB, Athena and Quartz, took that architecture to other firms as a platform.

In every case the graph comes with the platform. To ask where a number came from, a bank had to adopt the whole system and move its models onto it. The AADC Tracer records the dependency structure of a valuation from the library you already run, in C++ or Python, with one environment variable and no migration.

What you receive

A validation report on the model, generated from the record and reviewed by a person: summary with tier, lifecycle and outcome; regulatory framework; methodology; model inventory entry; feeding models; input classification; engine configurations; pricing methodology per engine, with every formula linked to the tape lines that compute it; cross-engine benchmarks; sensitivity ladders; frozen-branch analysis; convergence, parity and materiality tests; findings, each explainable to a file and line, with a severity and a recommendation; and the validation outcome.

Sample validation report, barrier option, 15 pages (PDF) ↓

Who it is for

Model validation and audit teams

Evidence from the binary that runs in production, the focus of PRA SS1/23, Fed SR 26-2 and the ECB guide.

Model documentation

Generated from what the code computed, so it cannot drift.

Quant developers

Trace a wrong number to its source. See exactly what a code change did to the calculation.

Run it on your models

Tell us the firm, a work email and what you want to run it on, and we come back with a commercial licence. Personal and academic use needs no key: pip install aadc-quantlib-tracing.

AADC Tracer FAQ

What is the AADC Tracer?

A recording of a pricing calculation as it runs in the production binary, tied to the source line that performed each step, handed to an AI agent that builds validation evidence from what was computed. Model documentation describes what a model is meant to do; the record shows what the code actually did.

What exactly does the record contain?

Every arithmetic step, comparison and input of the run, each attributed to its file, line and function. From it, any number in the result can be traced back across classes and libraries to the market quotes and constants it came from, and the record shows which inputs it does not depend on.

What is in the validation report?

A specification of what ran, an input classification (market data, calibrated parameters, hard-coded constants with their values and lines), a dependency map, a branch map with each market-dependent decision and its distance to switching, cross-engine benchmarks, AAD sensitivities, findings with severity, file and line and a recommendation, and the explored input box with the sites that were not reached. The sample report on this page is a 15-page example on a barrier option across three engines.

Does tracing change the prices or the speed?

With the switch off the program runs exactly as before: same tape, bit-identical prices, pricing speed unchanged. Recording is 11 to 13 percent slower than a plain run (single runs 9 to 24 percent). With tracing on, which is audit time only, recording is about twice as slow and prices are still bit-identical.

Do I have to change my code?

No code changes. The library is built once with the AADC compiler, production grade at -O2, and tracing is the runtime switch AADC_TRACE=1 on your normal pricing program.

Which languages and libraries does it work with?

C++ and Python. QuantLib 1.41 ships ready to trace as pip install aadc-quantlib-tracing; an in-house library is built once with the compiler. Because the library has to be built with the compiler, tracing a closed vendor binary without its source is not something it does.

What does the AI agent do, and how do I know it is not making things up?

Asked to read source code, a language model infers what the code probably does and can be confidently wrong. Given the record, the agent reads what the code did: the record is its calculator. Every claim in the report cites the file and line it rests on, every formula links to the source lines that compute it, and every result is reproducible because the recordings and re-recordings are kept.

Can a reviewer or a regulator re-run a finding?

Yes. The record and the re-recordings are kept with the report, so any finding can be re-run by a validator, an internal auditor or a supervisor.

What about the branches a single run did not take?

Each market-dependent decision is listed with its distance to switching. For each one the agent finds the inputs that flip it, re-records the unmodified program there, and documents how the model behaves on the other side. Exploration is bounded by the input ranges it is given; branches that cannot be reached within them are reported, not assumed safe.

What does it not do?

It does not replace governance: tiering, approval authority, risk appetite, the question of whether this is the right model for the product, market data for back-testing, calibration quality assessment, and the validation outcome decision all stay with people. A flagged difference is not always material; re-recording decides. Agreement between engines that share curve and library code cannot catch common-mode errors.

Why not use a debugger?

A debugger usually means a -O0 build, so you debug a binary that is not the one in production, one stop at a time, and values that cross classes arrive as plain numbers with their origin lost. The record is taken from the -O2 production binary, holds the whole calculation as data that an agent can query without stepping, keeps the origin of every value, and replays at new inputs in milliseconds.

Is this not what SecDB-style platforms already have?

Inside the largest in-house platforms the dependency graph has existed for decades, and it comes with the platform: to ask where a number came from, a bank had to adopt the whole system and move its models onto it. The Tracer records the dependency structure of a valuation from the library you already run, with one environment variable and no migration.

What does a prospect receive, and does it run without MatLogica software?

The validation report, the record, the re-recordings, and readable source reconstructed from the recording. The reconstructed code compiles on its own, with none of our software present at the deployment site, so the evidence can be inspected and run without us.

How long does a recording take?

One QuantLib swaption price gave 74,428 recorded steps across about 40 source files, 140 hard-coded numbers that reach the price, three day-count conventions in one valuation and 85 market-dependent branches, all from a single 17 ms recording.

Which regulatory expectations does the evidence speak to?

Evidence from the binary that runs in production is the focus of PRA SS1/23, Federal Reserve SR 26-2 and the ECB guide to internal models; the report is organised so that validation and audit teams can map its sections to those expectations.

Can it generate model documentation?

Yes. Documentation generated from what the code computed cannot drift from the code, because it is produced from the record of the run rather than from a description of the design.

Is it useful to quant developers outside validation?

Yes: trace a wrong number to its source, and see exactly what a code change did to the calculation by comparing the records of the two runs.

What if an agent wrote the pricer?

The Tracer validates what the code computed, not what its author says it computes, so it applies equally to code written by people, by a coding agent, or by both; the documentation an assistant wrote from the source is checked against the record of the run.

Can I run it myself?

Yes. pip install aadc-quantlib-tracing on Linux x86-64 with Python 3.10 to 3.14 gives QuantLib 1.41 with tracing built in, and the scripts that reproduce every figure on this page ship with it.

What does it cost?

The package ships under the AADC Community Edition licence: free for non-commercial and academic use. Commercial use and full-performance academic use are licensed by MatLogica; the form on this page starts that conversation.

Who makes it?

MatLogica Ltd, London, the company behind the AADC compiler. The Tracer was presented at the 22nd WBS Quantitative Finance Conference in Valletta in October 2026.