Equities allocation rose above strategic ceiling for the first time.
Coverage 38.07% against a 30.00% ceiling — headroom −€131.4m. First non-benign observation with no prior acknowledgement.
PortfoliFLOW is a complete investment office in software. Your book lives in it, front office to investor report; agents watch it on a schedule — limits, quotas, valuations, cash coverage — and speak only when something is material. Ask, and they answer with figures — computed, never guessed. Every decision closes in writing.
Coverage 38.07% against a 30.00% ceiling — headroom −€131.4m. First non-benign observation with no prior acknowledgement.
CASE-0001 Equities allocation rose above strategic ceiling for the first time.
Closing note: €140m rotation out of listed equities approved by the IC; SAA ceiling unchanged; secondary review in Q4. Journal · JRN-0018
This is how small teams run large books today — not by choice, but because nothing was built for them.
PortfoliFLOW is built to take that list off the desk — into software and agents — so the hours go back to the part that is actually the job. A structural problem doesn't vanish overnight; but every line above is one the platform already addresses, and the sections that follow show how.
Chat assistants answer questions. A book needs something else: a system that re-reads it on a schedule, notices what changed — and stays silent when nothing did. Reactive on demand. Proactive by default.
Chat, voice or Telegram — or a photo of a term sheet. She answers with a view, and with the numbers to back it: computed by the platform, not by the model.
A scheduled pass over the whole book: limits, quotas, valuation freshness, cash coverage, the press. Urgency set by deterministic rules, not by the model; the immaterial filtered out; a finding only when there is one.
The whole book lives here: every holding with its cash flows, NAV, multiples and returns — private funds and listed lines alike — priced from the live feed and kept current without anyone re-keying a thing. Most systems show you the book. This one helps you run it.
The part of the day that isn't investing — that part is handled now.
One case from one week on the demo book — what the platform did on its own, and where it stopped.
The Watch Desk surfaces one finding: equities above their ceiling, the computed figure beside it. On a quiet day it surfaces nothing — silence is a deliberate state, not an empty screen.
The finding becomes a file: notes, a consultation, a scenario tested against the live plan — without touching the book.
The file closes with a decision of record and a journal line. When the committee asks how the decision was made, you open the file, not your memory.
Opened from finding saa:equities. Coverage 38.07% against a 30.00% ceiling; headroom −131,423,394 EUR. Materiality frozen at opening.
IC meets Thursday. Two paths to prepare: rotate ~€140m out of listed equities, or revise the ceiling.
Shirley on the two paths:
A €140m rotation into government bonds DM and IG credit closes the breach with about €8m to spare and opens no new one — both classes hold well over that in headroom. Raising the ceiling is defensible only if the overweight is a deliberate position, and the current SAA inputs don't support that.
Planning Desk, hypothetical trade −€140m listed equities:
Closing note recorded. Journal · JRN-0018
One finding, one file, one line in the journal. Nobody had to remember to check.
This is the part most "autonomous" systems get wrong. It doesn't decide.
It brings you the question with the numbers attached — possible moves phrased as support, never as instruction; urgency set by deterministic rules, not by the model.
Every figure is computed by auditable code. A language model, asked the same question twice, can drift — even in the number. An institutional book cannot rest on that. Changing the model does not change the numbers.
Elsewhere, the model is the calculator. Here, the model is the colleague who knows which calculator to reach for.
And every decision closes in the journal — append-only, gap-free by construction: the page the auditor reads first.
The efficient frontier on the live book — a standing view, not a one-off study. Every class against its cap, projected forward, so a breach is forecast rather than discovered.
The investor review computed rather than assembled — current on any day. Incoming manager reports read for you, every value cited to its page.
Institutional coverage for a small team. Scale judgment, not headcount.
Call her and talk, type to her, or send her a photo — at your desk or on your phone, in your language, around the clock. She answers like a professional: with a view, and with the numbers behind it.
Here: a term sheet photographed on a conference floor, weighed against the live book in one turn.
She orchestrates. The code computes.
A full desk session — in the data room →PortfoliFLOW is open source under the AGPL-3.0. The code that produces every figure — the analytics core, the limit engine, the scenario overlay — can be read line by line before an institution relies on it. And it runs on your own machines, behind your own firewall — so the first book it watches can be the real one.
The business model is just as simple: the software is free. Institutions whose policies need a commercial licence, or who want a hosted instance, pay for that.
Built to be reviewed — the standards, the decision log and the isolation model are in the data room.
Built for the small teams that run large books — pension funds, boutique and mid-size asset managers, family offices and allocators.
Prefer to see the code first? It's public — or have your technical people stand it up in an afternoon.
If the front page made you curious, this is where you verify it. Six exhibits from the running application — synthetic demo data throughout — and the answers a diligence process asks first: where it runs, what it is built to, and why nothing locks you in.
Every screenshot is taken from the running application; the animated pieces are rebuilt from it. Anything shown here can be reproduced on a local instance in an afternoon.
One session from the demo book: the PM asks which fund is earning its fee; Shirley resolves it herself, answers with computed figures and the caveats a careful colleague would add, renders the chart on request — and when asked for a verdict, pulls the limits state unprompted, reports the sleeve is over its cap, and leaves the decision where it belongs: with the PM.
Best-performing PE fund: Investment U — Sample US Buyout Fund II (2024 vintage, USD, North America).
Performance/risk profile
Ann. return: 60.71% · Sharpe: 1.42 · Sortino: 8.82 · Max drawdown: −6.63%
That Sharpe and drawdown combination is the strongest in the entire book, PE or otherwise — only Investment T (a cash-proxy overnight-rate ETF) and the cash sleeves show comparable ratios, and those are trivially low-vol instruments, not a fair comparison.
Essentially zero correlation to everything, including your listed-equity sleeve and the rest of the PE book. That's the answer to your framing: this is not a beta substitute. If it were just repackaged listed-equity beta with a fee wrapper, you'd expect it to track Investment A/B/H reasonably closely — it doesn't, at all. It's behaving as a genuinely idiosyncratic return driver, and it's mildly diversifying against your private debt book too.
The caveat you should carry into the review
Bottom line: on the numbers available, it looks like alpha, not disguised beta. But with a 21-month track record and zero distributions, I'd frame it in the review as "promising, unproven" rather than "vindicated," and revisit once you have a realization or two to anchor the DPI.
Chart's up — rolling IRR since inception, on its own axis. The shape tells the story: a noisy first few months, where small denominators swing early IRR hard, including a brief dip below zero; then it settles into a 25–40% band through 2025; and the recent markups have pushed it above 50%.
Read the level with the same caution as everything else on this fund: it's computed on GP-marked NAV, with no realisations behind it yet.
Let me know if you want the same view for another fund, to compare across vintages.
Good performance so far, but a few things temper how much weight I'd put on that number, plus a limits wrinkle worth flagging.
What the data shows
The part that actually matters for a decision: your limits
At the July Stichtag, your private_equity SAA bucket is in breach — 13.76% coverage against a 12.00% cap, headroom −€23.2m. The corresponding AnlV bucket (anlv_13) is at WARN, 13.76% vs 15% cap. Investment U sits inside this sleeve.
That doesn't mean this specific fund is a problem — it's performing better than most of the book, by a wide margin — but it does mean:
I'll leave the "hold, trim the sleeve elsewhere, or flag to IC" call to you — that's a portfolio construction decision, not something I'll pronounce on — but the two facts to carry into that discussion are: strong unrealised performance on thin evidence, sitting inside a sleeve that's currently over cap.
The SAA weights held passively — applied to benchmarks, and applied to the tenant's own composites — plotted against the actual portfolio. The shaded band is the allocation effect. The board question, answered as a chart.
A tangency portfolio against your current position — a standing view you can act on, not a one-off study, with cashflow-adjusted returns underneath.
Stretch a drawdown, repace a fund's capital calls, insert a hypothetical trade, shock a market or a currency — the engines recompute over the live plan world, and the book itself is never touched. A result worth keeping is pinned to a case, frozen as it stood.
Funds without a manager plan are paced by the Takahashi–Alexander model — published, deterministic — so the projection covers the whole book.
A scheduled pass over the whole book: limits, quotas, valuation freshness, cash coverage. A finding surfaces only on material change — on a day without one, it surfaces nothing.
Below: the calibration that governs the desk, per tenant — thresholds, re-trigger deltas and urgency floors, with the value in force shown next to each field.
Equities have breached the 30.0% SAA ceiling, now at 38.07% of the portfolio, creating a headroom deficit of €131.4 million. This is a structural overweight against the strategic asset allocation limit — not a one-day mark.
The ceiling is class-specific, so trimming elsewhere creates no room under it. Realistic paths: rotate listed equities into classes with headroom (government bonds DM, IG credit), or revise the ceiling with a documented IC rationale — defensible only if the overweight is deliberate.
limit_coverage · saa:equities · ceiling 30.00% · observed 38.07% · first non-benign observation, no prior acknowledgement · re-trigger Δ 0.5pp
NAV, IRR, TVPI and DPI at portfolio level; region, vintage and sector splits; then the same anatomy per investment. Because it is computed from the live book, it is current on any day — the written commentary is the only part produced by hand.
On a single workstation, for evaluation or a one-person desk. Containers, migrations, browser.
Inside your own infrastructure, under your own network policy and controls. The same containers, your database.
Hosted on EU servers under EU and German law, in ISO-certified data centres. No setup on your side.
Routine operation of the platform, including by its operator, provides no incidental read access to tenant data.
Every architectural decision is recorded before code is written — after Nygard — in an immutable log of more than 110 ADRs that ships with the repository. Layer boundaries are enforced by regression tests rather than by convention; tenants are separated inside the database with row-level security; every action lands in an append-only audit log.
The build is aligned to ISO 25010, arc42 and CERT Python, and designed to comply with and support DORA resilience principles. Together, these let a reviewer establish how the system produces its outputs before reading the business logic.
Any model behind an OpenAI-compatible endpoint — Anthropic, OpenAI, Google, aggregators such as OpenRouter, or local via Ollama, in which case no prompt leaves your infrastructure. Configured per tenant and per purpose — and changing the model does not change the numbers.
PostgreSQL and Python — your data in your own database, exportable at any time. A market feed never overwrites the imported record, and a data licence belongs to the tenant, not to the platform.
The code is yours to run, read and keep — independent of any vendor, ourselves included. For institutions whose policies don't fit the AGPL's terms, a commercial licence is available: same code, covering different use cases.
A complete synthetic demo book is included, so everything shown on this site can be reproduced without production data — and without talking to us first.
The repository holds the code, the decision log and the install path. Issues and discussions are open; contributions run under a CLA and follow the same ADR-first discipline as the project itself — with or without coding agents.
Linux or macOS · Python 3.11+ · Podman or Docker with a Compose provider · Windows via WSL2
bash -c "$(curl -fsSL https://portfoliflow.com/install.sh)"
The installer checks prerequisites, asks for an owner e-mail and password, and ends with a verified status report and the URL to open. Update the platform anytime with a simple command: git pull.
The README on GitHub documents this and two further installation paths — download-inspect-run with a published checksum, and the full manual sequence.