Operations · Audit · Security — for banks
Banking software that proves its work.
Trivium Labs designs, builds and delivers operations, audit, email security and identity platforms for banks. Each one produces results you can verify instead of trust, holds as little of your customers' data as possible, keeps a person on the approvals that matter, and leaves an evidence trail your examiners can follow.
- 1RULE-RATE-AGREEOperations
Rate, index and margin agree across note, agreement and approval
NOTE · p.1LAR · p.2Agrees - 2EVD-INCLUSIONAudit
Event included in signed tree head; consistency proof verified
RFC 6962tree 41,207RFC 3161Proven - 3MSG-VERIFYEmail security
Customer-forwarded "account locked" email was not sent by the bank
lookalike domainSTIX 2.1 exportKnown fraud - 4TXN-APPROVEIdentity
Wire of $48,250.00 approved on the customer's phone
biometricsigned · exact textPending
2 verified · 1 fraud reported to your team · 1 awaiting the customer
Proof, not assurances
Every result can be checked: cited sources, signed records and cryptographic proofs a third party can verify without trusting us.
Minimal data by design
On-premises where documents are sensitive; hashes, fingerprints and public keys everywhere else. We hold as little as we can.
A human approves
Maker-checker sign-off in operations, biometric approval in identity. Nothing consequential happens silently.
Open standards
OpenID Connect, RFC 6962 transparency proofs, RFC 3161 timestamps and STIX 2.1. No proprietary lock-in.
The practice
Three disciplines. Four platforms. One standard of proof.
Operations
Loan operations
AvailableTake the stare-and-compare out of the back office.
Loan closing, boarding and funding still run on people comparing documents by hand and re-keying values into the core. Our operations platform does the comparing and the keying, and leaves the judgement and the approvals with your staff.
Bookend →Audit
Audit evidence
In developmentAudit trails an examiner can verify without trusting anyone.
Most audit logs are only as trustworthy as the system that keeps them. Our audit platform records events as they happen and returns cryptographic proof that they existed, in that order, unaltered. An auditor or examiner can check that proof independently, without taking our word or yours for it. It is built for the systems banks now have to account for, including AI agents acting on the bank's behalf.
Learn more →Security
Email security
In developmentLet every customer check whether a message really came from you.
Impersonation fraud works because customers cannot tell a real bank email from a convincing fake. Domain authentication like DMARC proves which domain a message came from, not that your institution actually sent it. Our email security platform registers outbound messages as you send them. Customers forward anything suspicious, or paste a screenshot, and get a definitive answer from your own domain.
Learn more →Security
Identity
In developmentSign in and approve with a phone. No passwords, no account to breach.
Passwords and shared identity accounts are what attackers go after. Our identity platform puts the identity on the customer's or employee's phone and unlocks it with their biometric. The phone derives a unique key for each site, so there is no master account to steal. The same approval covers sign-in, step-up checks and signed authorization of specific actions such as a wire transfer.
Learn more →First to market
Bookend: Prove the loan is right. Then board it.
Bookend reads the executed closing package, reconciles every variable term against the credit approval, verifies execution, and stages boarding and funding for the bank's own maker-checker approval. It runs inside the bank's network and produces an examiner-ready evidence packet for every loan.
Community banks. Jack Henry cores first.
- 1
Validate
The package and the approval come in; every term is extracted with its page and position.
- 2
Verify
Rules reconcile the terms and check execution. A specialist accepts, overrides or escalates each exception.
- 3
Board
The staged core record is approved by a checker and committed once.
- 4
Fund
The wire request is staged from the disbursement authorization and approved by a second person.
- 5
Evidence
The loan is sealed. The packet proves what was checked, by whom, and that nothing changed since.
Operating principle
The model finds. The rules judge. A human approves.
Where we use models, they do what they are good at (reading documents, classifying them, locating values) and they run inside your deployment. Whether things agree is decided by deterministic, versioned rules and fixed verdicts that can be explained line by line to an examiner.
Every result passes a review screen where one of your people accepts, overrides or escalates it before anything reaches the core, and every step is recorded in an append-only, hash-chained evidence trail. The same principle runs through audit, email security and identity: prove it, then let a person decide.
How we work
Delivered as engagements, not downloads.
- 01
Discover
We sit with the people who run the process, map it end to end, count the touches and pull real exceptions from recent work.
- 02
Install
We deploy where your risk team needs it, whether inside your network, self-hosted or on a dedicated tenant, and map the platform to your core, your records and your templates.
- 03
Prove
A parallel run on your own historical data is the acceptance test. You get an accuracy report against what your specialists found.
- 04
Go live
We train your team and go live with human approval on every item. Nothing forks the software for your bank.
- 05
Support
Signed releases you pull on your own schedule, runbooks that ship with the product, and a named engineer.
Who we are
Built by people who have sat on both sides of the vendor table.
Product and engineering
25+ years as an enterprise software architect and engineer
Has designed and shipped enterprise systems for regulated industries, most recently in applied AI. Owns the platforms: pipelines, rules, evidence chains and on-premises delivery.
Go-to-market
30+ years in mid-market enterprise sales
Has spent a career selling and delivering software to mid-market companies, where the buyer is an operator and the proof has to happen on their own data. Owns the engagement model.
Banking technology
40 years in banking technology
Has worked with banks on modernization for four decades, across cores, lending operations and the vendor relationships that come with them. Owns what the products must be true to.
What does Trivium Labs do?
Trivium Labs is a professional services firm that designs, builds and delivers platforms for banks across three disciplines: operations, audit and security. Today that means four platforms: loan operations (Bookend, available now), verifiable audit evidence, email security against impersonation fraud, and passwordless identity. Every platform is delivered through an implementation engagement rather than sold as a download.
Who are Trivium Labs' customers?
Banks and credit unions, starting with community banks. Our first product, Bookend, serves commercial loan closing and boarding teams at community banks running Jack Henry cores.
What is Bookend?
Bookend is Trivium Labs' first product. It validates executed commercial loan closing packages against the credit approval, verifies signatures and execution, and stages core boarding and funding for the bank's maker-checker approval, with an examiner-ready evidence packet for every loan. Learn more at usebookend.com.
How can customers tell whether an email really came from their bank?
Our email security platform, now in development, registers each outbound message when the bank sends it. A customer forwards a suspicious message, or pastes a screenshot, and receives one of three fixed answers from the bank's own domain: Verified, Not verified or Known fraud. No account or app is needed, and the platform stores fingerprints and hashes rather than email addresses or message content.
How can a bank prove what its systems and AI agents did?
Our audit evidence platform, now in development, records events as they happen and returns cryptographic proof that they existed, in order and unaltered. The proofs follow RFC 6962 and are anchored to external witness logs and RFC 3161 timestamps, so an auditor or examiner can verify them independently. Agents can record events through a REST API, a CLI or an MCP server without code changes.
Can customers and staff sign in without passwords?
Yes. Our identity platform, now in development, lets people sign in and approve actions with their phone and biometric instead of a password. It issues standard OpenID Connect tokens, supports step-up checks for sensitive actions, and can sign a specific transaction, such as a wire, so the approval is bound to its exact details.
Does Trivium Labs software run in the cloud?
It depends on the platform and on what your risk team requires. Bookend runs entirely inside the bank's network. The identity platform can be self-hosted, federated or managed, and the audit platform gives each institution its own database and signing keys. Across all of them we hold as little data as possible: hashes and fingerprints instead of content, public keys instead of secrets.
How does Trivium Labs use AI?
The model finds; the rules judge; a human approves. Where we use models, for example to read and classify loan documents in Bookend, they run inside the deployment. Whether values agree is decided by deterministic, versioned rules that can be explained to an examiner, and a person approves before anything reaches the core.
Which core banking systems do you integrate with?
Bookend integrates with Jack Henry SilverLake, CIF 20/20 and Core Director through jXchange, and supports file export for any core. Additional core adapters are in development.
How long does an implementation take?
A typical Bookend engagement takes about four weeks: discovery, installation inside your network, a parallel run on twenty to thirty of your historical closings, training and go-live. Pilots of our in-development platforms start small, for example a single message stream such as fraud alerts.
How do we get started?
Start with a workflow review: forty-five minutes with the people who run the process. We map it, count the touches and pull three recent exceptions. You leave with a one-page map whether or not you go further.
Next step
Start with a workflow review
Forty-five minutes with the people who run the process. We map it end to end, count the touches and pull three recent exceptions. You leave with a one-page map, whether or not you go further.