Skip to content
Trivium Labs

Operations · Audit · Security — for banks

Banking software that proves its work.

Trivium Labs designs, builds and delivers operations, audit, email security and identity platforms for banks. Each one produces results you can verify instead of trust, holds as little of your customers' data as possible, keeps a person on the approvals that matter, and leaves an evidence trail your examiners can follow.

evidence ledger · run 8b0c93ee
  1. 1
    RULE-RATE-AGREEOperations

    Rate, index and margin agree across note, agreement and approval

    NOTE · p.1LAR · p.2
    Agrees
  2. 2
    EVD-INCLUSIONAudit

    Event included in signed tree head; consistency proof verified

    RFC 6962tree 41,207RFC 3161
    Proven
  3. 3
    MSG-VERIFYEmail security

    Customer-forwarded "account locked" email was not sent by the bank

    lookalike domainSTIX 2.1 export
    Known fraud
  4. 4
    TXN-APPROVEIdentity

    Wire of $48,250.00 approved on the customer's phone

    biometricsigned · exact text
    Pending

2 verified · 1 fraud reported to your team · 1 awaiting the customer

RejectApprove
Illustrative. Every result cites its sources or carries its proof, and nothing consequential proceeds without a person's sign-off.

The practice

Three disciplines. Four platforms. One standard of proof.

Banks are run, audited and examined on the same question: can you show it was done right? We build the platforms that answer it, across operations, audit and security.

Operations

Loan operations

Available

Take the stare-and-compare out of the back office.

Loan closing, boarding and funding still run on people comparing documents by hand and re-keying values into the core. Our operations platform does the comparing and the keying, and leaves the judgement and the approvals with your staff.

Bookend →

Audit

Audit evidence

In development

Audit trails an examiner can verify without trusting anyone.

Most audit logs are only as trustworthy as the system that keeps them. Our audit platform records events as they happen and returns cryptographic proof that they existed, in that order, unaltered. An auditor or examiner can check that proof independently, without taking our word or yours for it. It is built for the systems banks now have to account for, including AI agents acting on the bank's behalf.

Learn more →

Security

Email security

In development

Let every customer check whether a message really came from you.

Impersonation fraud works because customers cannot tell a real bank email from a convincing fake. Domain authentication like DMARC proves which domain a message came from, not that your institution actually sent it. Our email security platform registers outbound messages as you send them. Customers forward anything suspicious, or paste a screenshot, and get a definitive answer from your own domain.

Learn more →

Security

Identity

In development

Sign in and approve with a phone. No passwords, no account to breach.

Passwords and shared identity accounts are what attackers go after. Our identity platform puts the identity on the customer's or employee's phone and unlocks it with their biometric. The phone derives a unique key for each site, so there is no master account to steal. The same approval covers sign-in, step-up checks and signed authorization of specific actions such as a wire transfer.

Learn more →

First to market

Bookend: Prove the loan is right. Then board it.

Bookend reads the executed closing package, reconciles every variable term against the credit approval, verifies execution, and stages boarding and funding for the bank's own maker-checker approval. It runs inside the bank's network and produces an examiner-ready evidence packet for every loan.

Community banks. Jack Henry cores first.

  1. 1

    Validate

    The package and the approval come in; every term is extracted with its page and position.

  2. 2

    Verify

    Rules reconcile the terms and check execution. A specialist accepts, overrides or escalates each exception.

  3. 3

    Board

    The staged core record is approved by a checker and committed once.

  4. 4

    Fund

    The wire request is staged from the disbursement authorization and approved by a second person.

  5. 5

    Evidence

    The loan is sealed. The packet proves what was checked, by whom, and that nothing changed since.

Operating principle

The model finds. The rules judge. A human approves.

Where we use models, they do what they are good at (reading documents, classifying them, locating values) and they run inside your deployment. Whether things agree is decided by deterministic, versioned rules and fixed verdicts that can be explained line by line to an examiner.

Every result passes a review screen where one of your people accepts, overrides or escalates it before anything reaches the core, and every step is recorded in an append-only, hash-chained evidence trail. The same principle runs through audit, email security and identity: prove it, then let a person decide.

How we work

Delivered as engagements, not downloads.

Every installation is a professional-services engagement, proven on your own data before it goes live.
  1. 01

    Discover

    We sit with the people who run the process, map it end to end, count the touches and pull real exceptions from recent work.

  2. 02

    Install

    We deploy where your risk team needs it, whether inside your network, self-hosted or on a dedicated tenant, and map the platform to your core, your records and your templates.

  3. 03

    Prove

    A parallel run on your own historical data is the acceptance test. You get an accuracy report against what your specialists found.

  4. 04

    Go live

    We train your team and go live with human approval on every item. Nothing forks the software for your bank.

  5. 05

    Support

    Signed releases you pull on your own schedule, runbooks that ship with the product, and a named engineer.

More on our approach →

Who we are

Built by people who have sat on both sides of the vendor table.

Our founders bring close to a century of combined experience in enterprise software, mid-market delivery and banking technology.
  • Product and engineering

    25+ years as an enterprise software architect and engineer

    Has designed and shipped enterprise systems for regulated industries, most recently in applied AI. Owns the platforms: pipelines, rules, evidence chains and on-premises delivery.

  • Go-to-market

    30+ years in mid-market enterprise sales

    Has spent a career selling and delivering software to mid-market companies, where the buyer is an operator and the proof has to happen on their own data. Owns the engagement model.

  • Banking technology

    40 years in banking technology

    Has worked with banks on modernization for four decades, across cores, lending operations and the vendor relationships that come with them. Owns what the products must be true to.

FAQ

Questions banks ask us

Something else? Ask us directly.

What does Trivium Labs do?

Trivium Labs is a professional services firm that designs, builds and delivers platforms for banks across three disciplines: operations, audit and security. Today that means four platforms: loan operations (Bookend, available now), verifiable audit evidence, email security against impersonation fraud, and passwordless identity. Every platform is delivered through an implementation engagement rather than sold as a download.

Who are Trivium Labs' customers?

Banks and credit unions, starting with community banks. Our first product, Bookend, serves commercial loan closing and boarding teams at community banks running Jack Henry cores.

What is Bookend?

Bookend is Trivium Labs' first product. It validates executed commercial loan closing packages against the credit approval, verifies signatures and execution, and stages core boarding and funding for the bank's maker-checker approval, with an examiner-ready evidence packet for every loan. Learn more at usebookend.com.

How can customers tell whether an email really came from their bank?

Our email security platform, now in development, registers each outbound message when the bank sends it. A customer forwards a suspicious message, or pastes a screenshot, and receives one of three fixed answers from the bank's own domain: Verified, Not verified or Known fraud. No account or app is needed, and the platform stores fingerprints and hashes rather than email addresses or message content.

How can a bank prove what its systems and AI agents did?

Our audit evidence platform, now in development, records events as they happen and returns cryptographic proof that they existed, in order and unaltered. The proofs follow RFC 6962 and are anchored to external witness logs and RFC 3161 timestamps, so an auditor or examiner can verify them independently. Agents can record events through a REST API, a CLI or an MCP server without code changes.

Can customers and staff sign in without passwords?

Yes. Our identity platform, now in development, lets people sign in and approve actions with their phone and biometric instead of a password. It issues standard OpenID Connect tokens, supports step-up checks for sensitive actions, and can sign a specific transaction, such as a wire, so the approval is bound to its exact details.

Does Trivium Labs software run in the cloud?

It depends on the platform and on what your risk team requires. Bookend runs entirely inside the bank's network. The identity platform can be self-hosted, federated or managed, and the audit platform gives each institution its own database and signing keys. Across all of them we hold as little data as possible: hashes and fingerprints instead of content, public keys instead of secrets.

How does Trivium Labs use AI?

The model finds; the rules judge; a human approves. Where we use models, for example to read and classify loan documents in Bookend, they run inside the deployment. Whether values agree is decided by deterministic, versioned rules that can be explained to an examiner, and a person approves before anything reaches the core.

Which core banking systems do you integrate with?

Bookend integrates with Jack Henry SilverLake, CIF 20/20 and Core Director through jXchange, and supports file export for any core. Additional core adapters are in development.

How long does an implementation take?

A typical Bookend engagement takes about four weeks: discovery, installation inside your network, a parallel run on twenty to thirty of your historical closings, training and go-live. Pilots of our in-development platforms start small, for example a single message stream such as fraud alerts.

How do we get started?

Start with a workflow review: forty-five minutes with the people who run the process. We map it, count the touches and pull three recent exceptions. You leave with a one-page map whether or not you go further.

Next step

Start with a workflow review

Forty-five minutes with the people who run the process. We map it end to end, count the touches and pull three recent exceptions. You leave with a one-page map, whether or not you go further.