← Back to Bridge Trading

Execution Safety

What happens when something goes wrong  ·  Last Updated: 2026-10-07

Copy trading routes someone else's entries and exits into your own brokerage account. The interesting question is not what happens on a good day — it is what the engine does when a broker rejects an order, a feed lags, a position cannot be confirmed, or you simply lose more than you meant to. This page lists those cases, what the engine is built to do, and the audit record each one leaves behind.

None of this eliminates risk. Options and stock trading can lose your entire investment. Safety controls reduce the chance that a software or connectivity failure makes a bad trade worse; they do not make a losing trade a winning one, and they can fail. See the Copy-Trade Disclosure.

Principle: an exit is never silently skipped

The worst outcome in copy trading is an entry that fills and an exit that quietly does not. Bridge's exit path is built so that a trim or close either fills, escalates to a more aggressive order, or fails loudly with an alert — never a silent no-op.

Failure modes and what the engine does

1. The broker can't confirm you hold the position when it's time to exit

Broker position reads can be stale, partial, or formatted differently from what was sent. If the broker read does not match but Bridge's own record shows a confirmed fill, the engine attempts the exit anyway (fail-open). A truly uncovered sell is harmlessly rejected by the broker; a real position gets closed.

Audit record

exit_retry_broker_read_no_match_fail_open

2. A limit order isn't filling

Entries and exits are priced off the live options quote. If a marketable limit does not fill, the engine chases within a bounded ceiling and, as the final step, sends a market backstop so an exit crosses the spread rather than resting unfilled.

Audit record

entry_market_backstop · exit_market_backstop

3. A protective stop can't be placed at the broker

Every filled entry gets a protective stop. Some brokers reject resting stops in specific cases (cash-settled index options, stops too close to the bid, outside market hours). When the broker will not hold the stop, Bridge enforces it server-side and sends the exit itself if the stop level is breached.

Audit record

protective_stop_placed · protective_stop_failed · safety_stop_breach

4. You're down more than your daily limit

You set a daily-loss cap (and optionally a trailing drawdown) in your risk profile. A monitor evaluates it continuously during market hours. On breach, new copied entries are blocked and, unless you turned flattening off in your risk profile, open copied positions are flattened (on by default).

Audit record

daily_loss_monitor_breach · daily_loss_flatten_sent

5. A signal would break your risk limits

Per-trade size, max concurrent positions, and account-level caps are checked before anything is sent. A blocked entry is recorded with the reason. Exits are never blocked by a position cap — reducing risk is always allowed.

Audit record

risk_blocked

6. A same-day (0DTE) position is still open into the close

Contracts expiring today are flushed before the close with escalating order types so you are not left holding a position through expiration by accident.

Audit record

zero_dte_flush_escalated

7. You want everything to stop, now

Your dashboard kill switch halts all new copied orders for your account immediately. It does not depend on support being awake. Your broker's own app always works for closing positions.

Audit record

kill_switch_engaged · kill_switch_released

What is recorded, and for how long

What this does not cover

This page describes how the engine is designed to behave. It is not a guarantee of any specific outcome and is not part of any contract. If you believe a control did not act as described, that is an execution incident — see the support escalation path.