Financial services

Financial services

Encrypted inference, cross-institution analytics, and supervisory reporting: without exposing customer records or moving data between banks.

The decryption gap is the moment data must be decrypted to be used. Institutional and government buyers.

Is this you?

Institutional financial compute environment

What this looks like in practice

Situation, how Umbra runs it, and what changes for the team that owns the risk.

01

Encrypted inference on customer records

Credit, fraud, or underwriting models must score features the institution cannot send to a third-party GPU cloud. Model refresh cycles are weekly; lattice FHE cannot keep pace. Regulators and internal audit ask where plaintext exists: today, the answer is everywhere.

How it runs

Customer feature tensors remain encrypted in the bank's key domain. Models run against ciphertext on Umbra U100 or N8 nodes co-located with the core banking tier. Prompts, activations, and scores stay encrypted until deliberate decryption inside the institution's HSM boundary.

What changes

Production ML without exporting identifiable rows to an external plaintext training or inference host. PCI and privacy assessments shrink because the compute tier never held customer records in the clear.

02

Cross-institution analytics without data sharing

Several institutions need joint AML, fraud-ring, or stress-test models without exchanging customer files. Legal agreements take months; a shared database is politically and regulatorily unacceptable.

How it runs

Each participant contributes encrypted datasets under contractual key governance. Joint models train and score in encrypted federated space on N8 nodes hosted at a neutral facility or rotated across participants. No party receives another's plaintext holdings; gradients and aggregates remain ciphertext throughout.

What changes

Sector-level detection quality without a shared customer database. Institutions gain network-effect model quality while legal and compliance teams retain a defensible no-pooling architecture.

03

Privacy-preserving supervisory reporting

A supervisor needs concentration, exposure, or systemic-risk aggregates that today force over-exposure of customer detail in regulatory extracts. Institutions resist granular submission; supervisors lack timely visibility.

How it runs

Encrypted aggregation produces capital, concentration, and counterparty statistics on Umbra. Supervisors receive ciphertext aggregates released through agreed key ceremony: not raw customer rows into a general-purpose analytics environment.

What changes

Regulatory visibility with a smaller plaintext scope for both institution and supervisor. Reporting cycles accelerate because aggregation runs continuously on encrypted holdings rather than on batch plaintext extracts.

04

Trading and market-data analytics under confidentiality

Desks and infrastructure providers need joint analytics on order flow and position data bound by Chinese walls and client confidentiality. Plaintext consolidation violates both; slow legal review blocks time-sensitive risk models.

How it runs

Counterparties contribute encrypted order and position features. Risk and surveillance models run on Umbra nodes inside each firm's trust boundary or at a jointly governed neutral node. Outputs are encrypted risk metrics, not raw tape.

What changes

Joint risk visibility without a consolidated plaintext tape. Compliance retains wall integrity because the compute path never required decryption at a shared analytics tier.

Constraint

Why plaintext fails here

Banks, insurers, and market infrastructures hold records under confidentiality, localisation, and contractual bans on sharing. Regulators need systemic visibility without a central plaintext honeypot. Partnerships stall when neither party may export identifiable data. Every plaintext hop: ETL, warehouse, GPU farm, vendor SaaS: expands audit scope and breach liability. Cross-border groups face overlapping GDPR, banking secrecy, and sector cloud guidance that plaintext analytics cannot satisfy at scale.

Approach

Ciphertext through the stack

Plaintext analytics expand audit scope at every hop. Cross-institution fraud and AML work traditionally demands pooling or a trusted third party that holds everyone's customer files. Lattice FHE is roughly 1000× too slow for production scoring and training; it remains a compliance slide, not a deployment. Umbra inverts the model: records stay on-premises or in sovereign enclaves; encrypted tensors and queries enter the compute path at 40M ops/s per U100 card. Umbra runtime keeps computation deterministic on ciphertext: no bootstrapping, no decrypt-at-the-GPU boundary. N4 and N8 nodes are the unit institutions procure when RainDB, encrypted inference, and SDK workloads must run at rack scale.

Why Umbra

Production FHE at rack scale

Financial buyers evaluating FHE face a speed cliff: software lattices cannot score or train at institution timelines; TEE and plaintext GPU paths still decrypt and re-expand PCI and privacy scope. Umbra hardware plus Umbra runtime offers a production path to full FHE that software lattices do not offer at rack scale: encrypted inference and cross-bank analytics at throughputs diligence teams can map to published card and node specs. Cards sell into existing bank estates; nodes are the commercial unit when acceptance testing and DR matter.

How you buy cards

Sized from one card to multi-card packs

Start on one U100 beside the core tier; grow RainDB / ZChat card packs in their chassis; take N4/N8 when support and DR matter.

Start

1 × U100 co-located with the core banking or data tier: RainDB against encrypted customer features, or a single-card ZChat path for private model scoring.

Scale pack

Scale with cards: RainDB concurrency across multiple U100s in the bank’s own chassis, or ZChat reference pack (6 × U100 + 2 × NVIDIA GPUs) for production private inference without a plaintext GPU boundary.

Institution path

N4 / N8 in primary and DR when the institution wants engineer-installed systems, not DIY rack integration.

Workflow

Bank encrypts features under institutional keys → RainDB / ZChat / SDK workloads run on Umbra → scores and aggregates decrypt only inside the bank’s HSM boundary.

Deployment

How it lands

Institutions usually evaluate on a U100 card co-located with an existing database tier, then place N4 or N8 nodes in primary and DR sites. N8 nodes draw roughly 1.4 kW wall power under load; deployment follows standard data-centre power and airflow practice: no rack redesign. Certified deployment covers survey, install, burn-in, and acceptance. Cards integrate into configured nodes; the node is what ships production-ready.

Regulatory

What buyers ask next

GDPR, PCI scope reduction, banking secrecy, and sector cloud guidance shape architecture. Ciphertext processing shrinks plaintext scope in privacy and PCI assessments. No FHE evaluation regime currently exists that can assess the scheme; formal certification is available customer-funded. ZipLogic is not the data controller for customer workloads.

Request a briefing

Bring the sector constraint. We respond within two business days.

Request a briefing Read the methodology

Integrate · Security

Also