From the first live model to a financial ecosystem — every milestone with its date, its capacity, what ships inside it, and the condition it has to satisfy before it ships at all.
Chapter 1 is four dates and a hard seat limit. Chapter 2 is what those four dates were built to make possible.
A seat is the scarcest thing Oktombo has. This is the complete rulebook: what a seat is, how you get one, how you keep it, and how you lose it.
An account is free, unlimited and open to anyone. It gives you the roadmap, the knowledge and legal library, the public proof pages, and a place in the queue.
A seat is finite. It is the right to have the system work for you: the capacity behind copying — Sterling and above — and, from Chapter 2, autonomous execution on your own exchange account. Watching the lists takes no capacity and needs no seat; a seat is consumed only by being served. Watching is free for everyone, always. The seat prices only the work: €50 a month plus five percent of gains once the SaaS Trader is live — except for Black OKTO, which pays nothing. Free is not the same as unlimited, and the seat is where the limit lives.
Seats are non-transferable and bound to a verified person. One person, one seat. There is no secondary market in seats, and there never will be.
A trading system that publishes its entries has a capacity limit built into the arithmetic. When many accounts mirror the same entry within the same minutes, they compete for the same liquidity at the same price. Slippage rises, fills degrade, and the edge that made the signal worth following thins out — for everyone, including the people who arrived first.
The seat count is therefore not a scarcity tactic. It is the honest answer to the question how many people can this actually serve well right now. It rises when three things improve together: the depth of the markets we trade, the number of instruments we trade across, and the execution logic that spreads entries rather than stacking them.
One thousand, total and final. Reached in five steps across six months, and not exceeded under any circumstances, for any tier, for any price.
Opens only once the regulatory authorisation required to manage client capital is in place. Ten thousand is also a ceiling, not a waypoint on the road to unlimited — and it opens in tranches, on the same gate logic as every other milestone.
When seats are free, they are filled from the queue in a fixed order. When none are free, the queue holds and everyone can see their position in it.
| Priority | Who | Why |
|---|---|---|
| 1 | Holders of one of The 999 | Permanent standing granted by the collection. |
| 2 | Highest OKTO tier first | Standing in the membership system. |
| 3 | Longest anchor standing | Tenure breaks ties, so duration beats a single large purchase. |
| 4 | Queue position | Time of request decides the rest. |
A seat carries three duties. Two of them are suspended permanently for holders above the immunity threshold in §2.8.
Fourteen consecutive qualifying days without activity releases the seat. A qualifying day is a day on which the system published at least one actionable signal. Days when the system was silent, paused or under maintenance do not count against you — the clock measures your inactivity, never ours.
Activity means one of: a trade marked as copied in the cockpit, or an active managed connection that meets the minimum in §2.6. Simply logging in is not activity, and it is not meant to be.
From the end of Chapter 1, a seat held with a managed connection requires a minimum of €2,500 under management. That capital never leaves your own exchange account and Oktombo never holds it — the minimum is read from your account, not deposited with us.
A seat held without a managed connection carries no minimum. That is what standby is for.
SaaS invoices that are due are paid. A failed payment triggers a notice, then a second notice, then release on day fourteen. Access is suspended but the seat is held throughout that window, so an expired card costs you nothing but the inconvenience of replacing it.
Life happens. Rather than forcing you to trade to keep something you paid attention to earn, standby lets you hold the seat while you are not using it.
| Price | free |
| You keep | The seat, and your place in the order of things. Sight follows your tier as always. |
| You pause | The inactivity clock, the minimum under management — and all charges. A parked seat lends its capacity to the queue. |
| Duration | Unlimited. Your parked capacity serves the queue while you are away, and that is payment enough. |
| Switching | One click, either direction, effective immediately. |
Standby is offered at every point in the release process, including in the final notice. Nobody loses a seat without being shown the button that keeps it.
You are never released for a shortfall you did not cause.
If your managed capital falls below the minimum because the system lost money, nothing happens to your seat. You receive a notice and a ninety-day window in which you may top up if you want to keep a managed connection. If you do not, the seat converts to standby automatically — it is never released. A drawdown is our result, not your failure, and the rules reflect that.
If you withdraw capital yourself below the minimum, you have fourteen days to restore it or to convert to standby. Same outcome, shorter window, because it was your decision.
Holding 0.5% or more of circulating OKTO — the Sterling tier — suspends obligations one and two for as long as the holding is maintained:
Obligation three remains. Immunity is immunity from the capacity rules, not from a bill you have incurred — no holding entitles anyone to a service they have chosen to use and not pay for.
The threshold is measured on a seven-day average, so a momentary dip changes nothing, and a fall below it enters a thirty-day grace period extended by anchor standing before immunity lapses. Because circulating supply falls as the platform is used, a holding that never moves grows as a percentage over time: immunity becomes easier to keep, never harder.
A released seat returns to the queue and goes to the next person in the order set out in §2.4. The person released keeps their account, their copy ledger, their anchor standing and their tier — nothing is deleted, and they rejoin the queue with all of it intact. There is no penalty and no cooling-off period beyond the queue itself.
What is always visible, live in the cockpit: whether a seat is free, and how long the queue is. The chapter ceilings — 1,000 and 10,000 — are public commitments and stay public. The live capacity behind the door is not: it is a measurement that moves with the edge, and publishing a moving number would only be wrong tomorrow. You always know if you can enter. You never have to ask.
Chapter 1 runs as three feedback rounds and then a live launch. A round is not a waiting list with a nicer name — it is a working relationship with a defined job on both sides.
A round closes when its seats are filled or when the next milestone ships, whichever comes first. Nobody is removed when a round closes — seats accumulate. The cap describes how many new accounts open, not how many stay.
Six months, four dates, from a model that has never touched a user's screen to a platform with a thousand seats, a token, a collection and its own execution infrastructure.
The system goes live on real capital — ours, not yours — and everything it does becomes visible in the cockpit in the same second it happens.
The three figures above are the conditions under which the model goes live, measured before it does. They are the entry test, not a forecast: the model trades when it meets them, and it waits when it does not.
The live cockpit. Open positions with stop, target and a running scale between them. Closed trades with realised outcomes. The daily digest. Nothing curated, nothing delayed.
Copy trades for user accounts. Every signal carries the numbers you need to mirror it on your own exchange account — and a calculator that converts them to your position size, your levels, your risk in euros.
Simulated trading capital. Set the amount you would realistically invest, and the cockpit answers one question every day from then on: how would the system have performed with your capital? Real signal outcomes, your number.
The copy ledger. Your decisions recorded against the system's, from day one. It shows where you did better and where you did worse, and it does not flatter you.
The model meets all three thresholds on out-of-sample data, and the execution path has been verified end to end with real orders. Live capital is ours alone at this stage — no user capital is involved in any form.
The platform gets its membership layer. Launch runs on First Ledger, and every parameter is published before a single token moves.
OKTO turns users into members. Tiers, anchor standing, advisory governance and priority in every capacity decision from this point onward are all read from the ledger. The full economy is specified in the OKTO whitepaper; this section covers what changes in the product on the day.
Tier system live. Sand, Aqua, Sterling, Pearl and Black OKTO — read from your wallet at every sign-in, with anchor standing accruing from the first day you hold. From launch day, sight follows standing: Sand and Aqua watch the trade lists, Sterling opens H360 rows to copy, Pearl reads every detail on both engines with a live copy-worthiness verdict. Black OKTO says only: Private.
Wallet sign-in. Sign in with an XRPL address instead of an account. Wallet sign-in burns a small amount of OKTO every session — verified or not: the signed burn is the proof the wallet is yours, and choosing that door is choosing its price. Email sign-in never burns anything.
The OTC desk — OKTO and The 999 inside the cockpit. Acquiring and transferring both happens in the product, without sending anyone to an external interface and hoping they come back. It is the difference between a token you have to go and find and one that is part of the thing you already use.
Governance. Advisory voting from Aqua upward, in the cockpit, with results and reasoned decisions published.
Genesis is 70 / 30. Seventy percent belongs to the market — five hundred million released by delivered adoption, two hundred million as locked liquidity depth. Thirty percent works in four on-chain escrows — founder, community programs, HYPE conversion, trading capital — with every schedule enforced by the ledger and every address public before the first token moves.
The tokenomics page. Every flow, every burn, every parameter — live, with the running totals, not a static PDF.
Round 1 execution data shows the system carried twenty concurrent accounts without measurable degradation, the token infrastructure has been rehearsed on testnet end to end, and the parameter book is published and hashed.
A token launch is the first thing a project does that cannot be undone. Ours runs in five acts across sixty days, and each act leaves behind an artefact anyone can check.
Every address is created, labelled and published before it holds anything: the four working-escrow locks (founder, community programs, HYPE, trading capital), liquidity, burn destination, the Reactor route. The trustline guide and a short explainer go live in the cockpit so that nobody has to learn XRPL mechanics under time pressure on launch day.
The complete parameter book is published — distribution, vesting schedules, burn bands, every flow — together with a hash over it. From that moment, any later change is detectable by anyone who kept the hash. The whitepaper goes live in the legal area of the platform in the same step.
Trust-line locking (XLS-85) is enabled on the issuer first, then issuance to the published addresses in the published order, then the four working-escrow locks are created on-chain — deliberately in that sequence, because escrow capability must exist before the key that could grant it is destroyed at T+1. Listing on First Ledger with initial depth from the liquidity allocation. The registration and session burn flow goes live in the cockpit with the current band visible. Liquidity is provided in announced tranches, and there are no allocations outside the parameter book — including for us.
The issuing account is blackholed, live and publicly linked. Supply becomes a fact of the ledger rather than a promise in a document. It is deliberately a separate event after full distribution, because that is the order in which it means something.
The first Proof-of-Flywheel report, including the first on-chain attestation anchor, plus a review of the launch window — what was said would happen, what happened, with transaction links for both — and the opening entry of the monthly pendulum balance: treasury OKTO sold versus bought back and burned, cumulative from day one.
999 unique pieces at five XRP, allocated at random, with fairness proved before the first mint rather than asserted after it.
One octopus, identical to the pixel in all 999 pieces — the constant, because the system is one. Everything around it is state: nine material families from a single Obsidian Genesis piece through gold, sterling, aurora, blueprint and pearl to the four hundred of the standard edition, and within each family a combination of ink, ground, ring, pattern, iris, gaze, aura and highlight that exists exactly once.
Provable fairness. A single hash over the complete metadata of all 999 pieces is published before minting opens. Every property of every piece was fixed beforehand, and nobody — including us — can shift rarity afterwards.
Mint in waves. Higher tiers first, then all members, then public. The price is identical in every wave; the privilege is the order, not a discount. Early waves carry a per-wallet limit so the collection reaches the community rather than three addresses.
Thirty percent to liquidity. Straight into OKTO/XRP depth, at a published address, verifiable on-chain from the first mint.
Sealed utility. Future utility chapters are written, hashed and published as sealed hashes. A seal opens only when its function has shipped — at which point anyone can verify it was written from the start. An opened seal is delivered reality, never a promise.
Prototype access. Sterling plus one of The 999 unlocks the SaaS prototype throughout the build era — the first seats on autonomous execution that exist at all.
The metadata root hash is published, the mint contract is rehearsed on testnet, and the OKTO/XRP pool exists with sufficient depth for the proceeds to be deployed without moving the market.
A second engine on a shorter horizon, the first users trading through Oktombo rather than alongside it, and the Reactor beginning to work.
Until now the platform has published what one engine does. From November it runs a second, faster one — and starts doing something fundamentally different for a small group: executing on their behalf, on their own accounts.
The H60 engine. A shorter-horizon model running alongside the base engine, with its own feed, its own channel and its own record. The H60 list joins the cockpit from day one — unlabelled at Sand, named from Aqua, and every verified account holds Aqua. Closed H60 rows open at Pearl; the running ones open only at Black OKTO.
The SaaS prototype, 10 to 20 users. Oktombo executes on your own exchange account. Your capital never leaves your control, withdrawal permission is never granted, and the connection is revocable in one action. Entry during the build era: Sterling holding one of The 999, in queue order — the first autonomous execution that exists at all.
The HYPE Reserve goes active. The HYPE conversion escrow begins selling in gated monthly tranches; proceeds become HYPE, staked natively, lowering the fee tier on every trade the system makes. Staking rewards split in half — one half compounds the reserve, the other buys OKTO and burns it. From here the pendulum swings back daily.
The account stays public. Every trade the system takes is visible on-chain at the published address — copy it raw if you like, with the lag and the slippage that come free of charge. What the chain cannot show is which engine ran a trade: attribution lives in the cockpit, priced by the tier ladder. What the chain cannot give is simultaneous execution on your own account — that is the SaaS Trader, and it is the only thing that will ever cost money. Watching stays free for everyone, permanently.
Campaign 1. The first marketing effort aimed outside the XRP community — reaching people who have never held a token and do not intend to, because the product has to stand on its own before its economy does.
H60 passes the same live entry test the base model passed, on out-of-sample data. The prototype opens only with the non-custodial permission model verified: trade permission granted, withdrawal permission technically impossible. The fee flow and the wallet check at sign-in are live before the first invoice exists.
The end of the prototype era. A thousand seats, execution across multiple venues, and the investor-facing product that turns the platform into a business.
V1 is the version we would be happy to be judged by. Everything before it is explicitly a prototype with users in the room; from here the platform is a product with a track record behind it and a company around it.
Multi-venue platform. Execution is no longer tied to a single exchange. Orders route across venues, which improves fills, reduces concentration risk, and is the structural precondition for every seat increase after this one.
Oktombo SaaS Investor. The full product: autonomous trading on your own account across supported venues, with a performance fee on realised gains and nothing else. No custody, no deposits, no lock-up. €50 a month plus five percent of realised gains above your high-water mark — and nothing else. Black OKTO members pay nothing at all. Seats are limited; the exact number is announced at launch, within the chapter ceilings.
A thousand seats. The final capacity step of Chapter 1, opened only because multi-venue execution makes it carryable.
The company. Oktombo GmbH operating with the regulatory framework in place — the unglamorous milestone that separates a project from an institution, and the one that makes everything in Chapter 2 legally possible.
Multi-venue routing verified in production. SaaS beta results from Round 3 show execution quality holding across accounts. The regulatory framework is in place before any fee is charged to any user.
Dates are intentions. Gates are commitments. When the two conflict, the gate wins and the date moves.
| Before | The gate |
|---|---|
| First Model live | All three entry thresholds met out of sample; execution path verified with real orders. |
| Token launch | Round 1 carried twenty accounts without degradation; token infrastructure rehearsed end to end; parameter book published and hashed. |
| The 999 | Metadata root hash published; mint rehearsed; pool depth sufficient to absorb proceeds. |
| H60 model | H60 passes the same live entry test as the base model; non-custodial permission model verified. |
| Oktombo V1 | Multi-venue routing verified in production; SaaS beta execution quality holds across accounts; regulatory framework in place. |
Chapter 1 builds one system that trades well and a platform that shows it honestly. Chapter 2 turns that into infrastructure other people build on.
The name is not marketing. V2 is a different class of thing.
Everything in Chapter 1 is a single engine family, on one asset class, executing on venues we chose, serving a capped number of seats. That is a product. V2 is the version where the constraints come off in every direction at once: more engines running in parallel across uncorrelated approaches, more asset classes, more venues, and an execution layer that is no longer the bottleneck.
The reason it can only come second is that each of those expansions multiplies the number of ways to be wrong. A system trading one asset class on one venue with a hundred accounts can be verified by hand. The same system across four asset classes, six venues and ten thousand accounts cannot — it needs the proof infrastructure, the operational discipline and the track record that Chapter 1 exists to build.
Chapter 1 earns the right to attempt Chapter 2. Nothing else does.
Ten thousand seats, and not one more. Chapter 2 opens the platform to ten times the people of Chapter 1 — once the regulatory authorisation to manage client capital is in place, and in tranches rather than at once. The ceiling remains real: the same arithmetic that capped Chapter 1 at a thousand caps Chapter 2 at ten thousand, and multi-venue routing is what moves the number rather than ambition.
The SaaS product moves from a beta of twenty to the default way most people use Oktombo. Your capital stays on your own exchange account, under your own keys, at every point. Oktombo holds trade permission and nothing else — withdrawal is not a permission we ask for, because it is not one we ever want. Fees are charged on realised gains, so the alignment is structural rather than promised.
Crypto perpetuals are where the system began because the data is continuous, the venues are open and the costs are transparent. Tokenised equities come next — the foundation for that has been growing quietly since 2026 as a five-second-resolution equity dataset. Beyond that: foreign exchange and commodities, in each case only when the data quality and the venue economics justify it. The engine is asset-agnostic by construction; the constraint has always been data, never ambition.
Multi-venue execution begins in V1 and becomes the core of V2: smart routing across centralised and decentralised venues, choosing the venue per order rather than per strategy. This is what turns capacity from a hard ceiling into an engineering problem — and it is why the seat ladder can eventually stop being the defining constraint of the business.
The system reads the news stream of every asset it trades, learns which events actually move markets rather than which ones generate headlines, and recognises relationships between sectors that look unconnected. Signals stop being pure price reactions and start carrying context. This is the layer that changes what the system can see, rather than how fast it can act.
Other firms run their own front end, their own brand and their own client relationships on top of the Oktombo engine. It is the point where the company stops being a product for individuals and becomes infrastructure for institutions — the same architecture, sold to a different customer, with the non-custodial model intact because it was never bolted on.
OKTO and The 999 stop being platform-specific and become the identity layer of everything in the ecosystem: which products you can reach, which capacity you hold, which standing you have accrued. The final sealed chapters of the collection live here — where your piece is not just a badge in a cockpit but the identity you carry across the whole system, including in physical form.
Three axes expand across the two chapters. Each one multiplies the others, which is why they are sequenced rather than attempted at once.
A roadmap is only worth the constraints its author accepts. These are ours.
Every shipped milestone remains in the roadmap permanently, with its original date next to the date it actually shipped. The record of kept and missed commitments is the most useful thing we can give a prospective member.
No hypothetical performance figure, no back-tested curve presented as a result, no cherry-picked window. Where a number does not exist yet, the interface says so rather than filling the space.
In every milestone of both chapters, by architecture rather than by policy. Oktombo never takes custody, and withdrawal permission is never requested at any stage of the product.
The fee model is public long before the first invoice exists: watching free forever, the SaaS Trader at €50 a month plus five percent of gains — and Black OKTO at zero. The trades themselves are public on-chain: we sell the lens and the hand, never the feed. Honoured exactly as written.
When a gate does not pass, the date moves and the reason is published with the data behind it. We would rather move a date than ship a milestone that has not earned its way through.
Capacity rises when the execution data says it can, not when the growth target says it should. This is the commitment most likely to cost us money and the one least likely to be broken.