Anomaly Detection
| Date | Sessions ago | Detector | Event | z | Severity | Confidence | Score contrib. |
|---|---|---|---|---|---|---|---|
| 07-May-2026 | 74 | Correlation Break | Correlation break vs XLY | -2.44 | Low | 100% | – |
Rolling 20-session correlation to XLY fell to 0.36 against a 120-session norm of 0.74 (2.4 sigma). AMZN has stopped trading on the same driver as its benchmark — idiosyncratic news, not market beta. 0.74Expected 0.36Actual -2.44σZ-score 120Baseline obs. -1.39%Return that day 271.17Close 14-session context (correlation) | |||||||
Each detector z-scores one series against the symbol's own recent history and fires on the session the threshold is first crossed — a transition, not a state, with a 3-session cooldown, so one three-week volatility regime is one event rather than fifteen identical rows. Every rolling statistic is ex-ante.
| Detector | Series scored | Baseline | Fires at | Weight | Status for AMZN |
|---|---|---|---|---|---|
| Price Gap | 1-day % return | 20 sessions | |z| ≥ 2.5 | 1.00 | active |
| Volume Surge | log volume (adjusted) | 20 sessions | z ≥ 2.0 | 0.90 | active |
| Volatility Spike | log 5-session realized vol, annualized | 60 sessions | z ≥ 2.0 | 1.00 | active |
| Options Flow | put/call volume, IV30, IV30/IV90 | 60 sessions | |z| ≥ 2.0 | 0.90 | unavailable — Options history for this symbol is 6 sessions; the detector needs 20 to form a baseline. |
| Correlation Break | 20-session correlation to benchmark | 120 sessions | z ≤ -2.0 | 0.80 | active |
| Liquidity Drop | log traded value (price × volume) | 60 sessions | z ≤ -2.5 | 0.70 | active |
| Model-based | 8-feature joint vector | up to 500 sessions | both models agree | 0.60 | active — Nightly batch, last run 23-Aug-2026. |
Severity comes from |z| alone, so the same number means the same thing in every detector: Critical ≥ 4.0σ (base 40), High ≥ 3.0σ (28), Medium ≥ 2.5σ (18), Low below that (10). Confidence scales with how deep the baseline actually was, which is why options events on a thin history are discounted rather than trusted at face value.
The composite is contribution = base × weight × confidence × 0.5^(sessions_ago / 10), summed over events in the last 60 sessions, then squashed with score = 100 × (1 − e^(−sum/60)) so it saturates instead of running away. Bands: Nominal < 20, Watch 20–44, Elevated 45–69, Critical ≥ 70. This symbol's raw sum is 30.35. Engine v1.0.
Known limits — read before trading off this
Liquidity is a tape proxy. KA has no order-book depth, so the Liquidity Drop detector scores traded value (price × volume). Read it as "harder to get size done", not as a measured spread or book thinning.
Options history is shallow. options_iv_history is a forward-only nightly snapshot; for most of the universe the baseline is weeks rather than years, so options events carry low confidence and will strengthen on their own as the snapshot accumulates.
Correlation is US-session only. A same-dated close on a non-US venue is a different trading day, so benchmarking it against SPY or a sector ETF would measure the time zone rather than the decoupling. Non-US symbols simply do not run that detector.
The model-based detector asks a different question. The six univariate detectors are rolling — each session is judged against the 20 to 120 sessions immediately before it, so they fire throughout a window. The model is fitted once over the symbol’s whole stored history and marks the most extreme sessions in it, so a symbol whose violent period was eighteen months ago can legitimately show zero model events in a six-month window. A count of zero here means “nothing in this window ranks among the symbol’s most extreme sessions”, not that the detector failed.
The model-based detector cannot explain itself. The other six each score one series, so every flag decomposes into expected vs actual. IsolationForest and LocalOutlierFactor return a score over the joint vector and nothing decomposable; the drill-down shows the standardised features they saw, which is the nearest honest substitute. It is weighted below the six for that reason, it runs from a nightly batch rather than live, and a flag landing on a day another detector already explained contributes nothing to the score.
Detection is not prediction. A high score says the symbol is behaving unlike itself, not which way it goes next. The detectors have not been validated against a hand-labelled event set, and the score has not been tested for correlation with subsequent realized volatility.
Ask the market a question. Get a calculated answer.
The AI is not a chatbot bolted onto a document store. It calls the same analytics engine that powers every screen on this platform — so what comes back is a number it computed from raw history, with the command that produced it.
86,000+ instruments
Global equities, ETFs, funds, options, FX, commodities, crypto, economics, filings, transcripts and news — one normalised symbol universe with adjusted history.
A real analytics engine
Screening, backtesting, technicals, options analytics, correlations, seasonality and factor models — computed on demand from raw prices, never a stale cache.
It shows its working
Answers arrive with the charts, tables and tool calls behind them, so you can check the number instead of trusting a paraphrase.
Your own documents
Upload filings, decks and research. Ask across them and the answer cites the page it came from.
Agents and workflows
Multi-step research that runs the platform's tools for you — screen, pull the history, compute, compare, then write it up.
MCP, CLI and API
The same command catalogue from Claude, your own agent, a shell or your pipeline. The answer on screen is the answer your job gets at 4am.
You ask
“How does NVDA usually trade through earnings?”
It calls
→ ka.options_expected_move(NVDA)
It answers
NVDA has averaged a 9.2% absolute move on the day after earnings and closed higher 67% of the time. Two in three reactions land between −4.2% and +16.3% — the distribution is skewed right, not symmetric.
Every figure computed live from our own history — not scraped, not summarised.
Or start with