Pricing & risk infrastructure for derivatives desks

Solve the model once
read everything else

Krylo computes the model’s transition operator — the exact solution operator of the pricing equation — directly and to high order, once per underlier set. Every product, Greek, scenario, maturity, and counterparty-exposure profile after that is a cheap, noise-free read of one solved object.

V(t) = e(T−t)ℒ g the object every incumbent method approximates around — computed directly
The problem

The autocallable loss cycle is computational

Worst-of and knock-in books broke their holders three times in six years — and the failure point is the same every cycle. The industry risk-manages these products by re-simulating them, and simulation-based risk numbers are at their noisiest exactly at the loss events: second differences across a payoff discontinuity amplify Monte-Carlo noise catastrophically. On a representative book of eight step-down notes, the industry-standard estimate of correlation risk came out at −0.06 ± 0.06 — the sign is unreadable on half the book, on the day it matters most.

€260M
Natixis, Korean worst-of books, 2018
€673M
SocGen + Natixis hedging losses, COVID quarter 2020
$4.6B
HSCEI knock-in wave, 2024 — plus $1.2B compensation reserves
$538B
callable / autocallable issuance in 2025 — a record, increasingly held outside dealers
How it works

The semigroup, computed — not approximated around

Monte-Carlo samples the transition operator one random path at a time. Finite differences re-step through it per product and per scenario. Neither ever constructs the reusable object itself. Krylo does — three components matter.

01

Analytic kernel

The short-time transition kernel is evaluated in closed form and moment-corrected to sixth order in space — with the correlation cross-term handled exactly, the term that forces operator-splitting compromises in ADI schemes. A one-year horizon is a handful of large, high-order steps.

02

Compression

The solved operator is projected to a small subspace where any horizon is a small-matrix computation: applying thirty years costs the same as applying one day, and a whole maturity surface comes from one build.

03

Products as projections

Autocall dates, memory coupons, and discrete knock-ins apply between marches as exact projections — discrete monitoring priced with no continuity correction. Run the same operator in reverse and it produces counterparty-exposure profiles with no nested simulation.

Krylo architecture: the model is solved once per underlier set; products, risk, scenarios, maturities and exposure are reads of the solved object.
The engine in one picture. The model is solved once per underlier set; the next product on the same underliers is a projection, not a re-solve.
The operator library: a lattice of solved models interpolated across market state, repricing the book intraday without a rebuild.
The operator library. A solved model is a reusable object: store a lattice of them, interpolate across market state intraday. One tangent step — “yesterday’s solution + a derivative” — reprices the book across an overnight move, no rebuild. No incumbent tool has this primitive.
Evidence

Exact where simulation is noisiest — and hundreds of times faster

Every number here regenerates from a provenance-stamped, gated benchmark: one command rebuilds the full evidence base, a numeric pass gate lives inside each benchmark, and a regression flips the report on its own. The comparisons run against closed forms, QuantLib, and 10M-path Monte-Carlo anchors — nulls published as prominently as the wins.

×
faster than full-path Monte-Carlo at T = 30y — unbiased, cost flat in maturity
bp
converged price of a real step-down term sheet at the coarsest production grid
/15
independently gated benchmarks vs closed forms, QuantLib, and 10M-path Monte-Carlo anchors
numerical failures across a 26-rung certification campaign on deployment-class hardware
Simulation cost grows with maturity; the solved-operator cost is flat — 306× at thirty years, without bias.
Cost flat in maturity. Simulation pays per path, per year — 306× slower at T = 30. One solved operator applies thirty years for the cost of one day, exactly and without bias; a whole maturity surface comes from one build.
Correlation risk of a real step-down autocall through the knock-in: exact profile vs noisy re-simulation estimates.
Through the breach. Correlation risk of a real step-down note (memory coupons, discrete knock-in, local vol + correlation + jumps) as the market slides toward the knock-in. Blue: the exact profile, read from one solved model. Red: re-simulation with nudged inputs, with its measured noise. The independent cross-check agrees: 4.68 ± 0.17 vs 4.78 at the knock-in.
Deterministic is not converged: ±3bp grid-dependent error removed by sixth-order contract loading.
Deterministic ≠ converged. The same term sheet on three production grids: standard contract loading carries ±3 bp that changes sign with the grid. With sixth-order loading: 0.04 bp at the coarsest grid — a two-second march.
Counterparty exposure profile of an autocall computed without nested simulation.
Exposure without the farm. The solved model run forward, paired with its backward values: EPE/PFE with the autocall runoff staircase, ≤ 0.12% of brute-force nested simulation at every date — in about four minutes on one GPU.
The living calibration

Calibration as state estimation, not snapshot fitting

Because the value flow of the pricing model is a linear semigroup, streaming quotes can be assimilated into the model’s coefficients continuously, with calibrated uncertainty — and every innovation decomposed into noise, drift, or an attributed shock. Validated on live exchange options: exactly silent through quiet weeks, 38 named and sized events through a real volatility episode. Every commercial surface product either fits snapshots or reprices fast; none tracks a model-consistent trajectory, carries calibrated uncertainty, or attributes its misfit.

Attributed shock detection on real exchange volatility data: silent on quiet weeks, named and sized events through a real episode.
Attributed shocks on real market data. The assimilation channel through a real volatility episode: discrete repricings detected, named, and sized — with the quiet-week null reported just as prominently.
Validation

A falsification program, with the nulls published

Claims about a pricing method should be cheap to check and expensive to fake. The comparisons run against closed forms, QuantLib, and converged Monte-Carlo — and the null results are published as prominently as the wins.

ClaimReferenceResult
Real step-down term sheet (memory, discrete KI)identical-logic Monte-Carlowithin MC noise (±0.02%)
Correlation risk through the breachmatched-seed MC bump4.78 vs 4.68 ± 0.17
2-asset worst-ofStulz (1982) closed form10⁻⁸
Whole implied-vol surface to 30yRichardson-extrapolated fine CN0.006 bp mean · 1.6 s
Counterparty exposure profilebrute-force nested simulation≤ 0.12% at every date
Bermudan exerciseQuantLib finite differences< 0.5%
vs Craig–Sneyd ADI / sparse CN, same gridStulz closed form~230× (price and corr. risk)

Published nulls, for the avoidance of doubt: in 1D on raw payoffs, tridiagonal Crank–Nicolson wins wall-clock at equal accuracy; and simulation deltas are fine — we do not sell better deltas. The value is in the numbers simulation cannot read.

Engagement

A four-to-six week pilot, on your book

Second-opinion risk engine — beside your stack, nothing ripped out.

What we run
  • 5–10 of your term sheets — public or synthetic equivalents acceptable, no MNPI required
  • Daily marks, breach risk profiles, the full per-note risk set
  • Optionally: counterparty-exposure profiles
  • On our hardware or a GPU box in your environment
Success criteria, agreed up front
  • Prices inside your own simulation noise
  • Risk numbers stable through knock-in scenarios
  • Full-book pack inside the daily window
  • The business test: the pack is in your morning risk meeting by week three

Fixed fee · week-two review · either side stops.