Alto City Limits
The Insider Signal Board Verifies Every Insider Trade Against Its Exact SEC Filing
A service that watches company insiders' open-market stock purchases, verifies each one against the exact SEC filing it came from, and surfaces the rare moments when several insiders at the same company are buying at once — the signal worth paying attention to.
Overview
- Organization
- Alto City Limits
- Industry
- apps, Finance, SaaS, Technology
- Role
- Owner/Developer
- Timeline
- 2026
SEC-verified insider buying signals — every purchase checked against the exact Form 4 filing before it counts.
Role: Design & engineering
Stack: Python, FastAPI, SQLAlchemy, Alembic, PostgreSQL, vanilla-JS embeddable UI
Links: GitHub repo
What it is
A service that watches company insiders’ open-market stock purchases, verifies each one against the exact SEC filing it came from, and surfaces the rare moments when several insiders at the same company are buying at once — the signal worth paying attention to.
Why I built it
Insider buying is one of the few signals in markets that’s hard to fake: an executive spending their own money to buy their company’s stock on the open market is a costly, public vote of confidence. But the raw data is noisy. Most “insider transactions” are sales, stock-grant awards, option exercises, or tax withholding — not conviction buys. And data vendors will happily report a transaction that doesn’t actually match what the insider filed with the SEC.
I wanted a tool that did three things most feeds don’t:
- Separate real buys from noise — only open-market purchases count, nothing else.
- Prove each buy is real — verify it against the insider’s actual SEC Form 4 filing, row by row, before trusting it.
- Find the clusters — highlight when multiple insiders at one company buy in the same window, which is far more meaningful than a single purchase.
How it works
The pipeline runs in three stages.
1. Ingest & classify. Insider transactions are pulled from a market-data API and de-duplicated. Each is classified by SEC transaction code; only open-market purchases (code P, positive share change) are treated as discretionary buys. Everything else — sales, awards, exercises, gifts, tax withholding — is categorized but never scored as a buy. Each qualifying purchase gets a preliminary signal score based on size and the resulting change in the insider’s position.
2. Verify against the SEC. This is the core of the project. For each ranked purchase, the service queries SEC EDGAR: it finds the insider’s Form 4/4A filings near the transaction date, locates the actual ownership XML inside the filing (via the filing index, not a guessed filename), parses it, and matches it against the reported transaction — insider identity, issuer, date, share count, price, and direction. A transaction is marked verified only on an exact single-row match. Anything ambiguous, missing, or mismatched stays unverified, with a recorded reason. Nothing gets the benefit of the doubt.
3. Cluster. Verified purchases are aggregated per company over rolling 14/30/90-day windows into a cluster score. The scoring deliberately rewards breadth — several distinct insiders buying on separate dates — over a single insider repeating one purchase, so the signal can’t be inflated by one person or by amendments and duplicate filings.
The result is exposed through a JSON API and a self-contained, embeddable web board.
Engineering decisions I’m proud of
“Verified” means verified. The tempting shortcut is to trust the data vendor. I didn’t. The whole value of the tool is that a green “SEC VERIFIED” badge means the purchase was matched to an exact row in the insider’s real filing — so the verification logic is strict by design and fails closed. Correctness beat coverage every time there was a trade-off.
Financial data uses exact decimals, never floats. Share counts and prices are compared with Decimal and explicit tolerances, so a rounding artifact never causes a false match or a false rejection.
Resilient by default. External APIs are rate-limited and retried with backoff; the SEC client respects fair-access limits; verification runs in bounded, idempotent batches that commit per-transaction, so one failure can never roll back good results. Permanent non-matches aren’t retried forever.
Tested where it counts. The suite runs fully offline — every external call is mocked — and covers the semantics that matter most: non-purchases never score as buys; verified is true only on an exact SEC row match; ambiguous filings stay unverified; clusters exclude unverified and non-discretionary activity.
The interface
The board leads with the trust story. Each cluster expands to the underlying verified purchases, and every row links to the exact SEC filing it was matched against — so the claim is always one click from its proof. Tickers and filing accession numbers are set in monospace because they are codes; the verification seal is the one bold element, with everything else kept quiet around it.
(Insert screenshots here: the cluster leaderboard, an expanded company with verified rows + filing links, and the mobile view.)
What I’d do next
- Deploy a hosted demo with a scheduled worker so the board stays current.
- Broaden the tracked universe toward small- and mid-caps, where insider buying clusters actually appear.
- Add historical backtesting: do verified insider-buying clusters precede outperformance?
- Email/Slack alerts when a new cluster crosses a score threshold.
Running it in practice: data & subscription requirements
The tool relies on two external data sources, and it’s worth being upfront about what each requires:
SEC EDGAR (free). All verification runs against the SEC’s public filings, which are free to access. The client is rate-limited to stay within the SEC’s fair-access guidelines, so no subscription is needed here.
Market-data API (paid tier recommended). The insider-transaction feed comes from a third-party market-data API. The free tier is capped at roughly 60 requests per minute — and because the pipeline makes one request per tracked company, tracking more than a handful of tickers on the free tier hits that ceiling almost immediately. I built in request throttling and backoff so the system degrades gracefully instead of crashing when it’s rate-limited, but a paid subscription is required to track a meaningful universe of companies at a usable refresh rate. This is a deliberate design boundary, not a bug: the app is built to run correctly at any scale, but the breadth of what it can watch is gated by the data plan behind it.
Setup requires providing your own API credentials and a descriptive SEC contact string in an environment file — the repository ships with a documented template and never bundles secrets.
Honest limitations
Insider buying is genuinely rare — most windows, across most large companies, have none. That’s the point of the tool (it refuses to manufacture a signal), but it also means the board is quiet more often than not, and surfacing real clusters at scale needs a paid market-data subscription to get past free-tier API rate limits. The system is built to tell the truth, including when the truth is “nothing to see here.”