Skip to content
Trivium Labs

Security & trust

Built to pass the vendor-risk committee.

Banks are right to be skeptical of software that touches customer data and the core. We start from the questions your examiners and vendor-risk team will ask, and build the answers into the platform.

How we build

Six commitments behind every platform.

Deployment that fits the risk

  • Loan operations run entirely on your infrastructure, as containers inside your network.
  • Identity can be self-hosted, federated across institutions or managed.
  • Audit evidence gets a dedicated database, sequencer and signing keys per institution.

Hold as little as possible

  • Loan documents and extracted terms never leave the institution.
  • Email verification keeps a recipient hash and message fingerprint, never addresses or message bodies.
  • Identity servers hold public keys and audit events only, never private keys or passwords, and are designed to be safe if leaked.

Separation of duties

  • Maker-checker approval on every consequential action.
  • Biometric step-up and transaction signing bound to the exact action being approved.
  • Every accept, override, escalation and approval is attributed to a person.

Evidence integrity

  • Append-only, hash-chained evidence records with RFC 6962 inclusion and consistency proofs.
  • Anchored to external witness logs and RFC 3161 timestamps, so no one, including us, can rewrite history.
  • Verifiable by an auditor or examiner without trusting the vendor.

Change you control

  • Signed releases you pull on your own schedule.
  • Versioned rules, so a decision can be reproduced against the rule set in force at the time.
  • Runbooks that ship with the product.

Ready for vendor due diligence

  • We expect your vendor-risk committee to ask hard questions, and we design for them.
  • Architecture and data-flow walkthroughs as part of every engagement.
  • A single point of contact for security questionnaires.

Security questions or a questionnaire to send? Email hello@triviumlabs.co. Product-specific documentation for Bookend is atusebookend.com/security.

Next step

Start with a workflow review

Forty-five minutes with the people who run the process. We map it end to end, count the touches and pull three recent exceptions. You leave with a one-page map, whether or not you go further.