Fromenance

Communication provenance

Make every customer communication verifiable.

Fromenance is a communication provenance platform for banks, credit unions, insurers, and utilities. Your customer asks "did you really send this?" and gets a definitive answer in seconds, from your domain, with no human on your side.

You register every outbound communication at send time. The customer forwards a suspicious message to verify@yourbank.com or pastes it at yourbank.com/verify. Fromenance matches it against the registry and replies in your voice: Verified, Not verified, or Known fraud.

Three steps, one answer

  1. Step 1: Register at send time

    Your application, ESP webhook, or a journal BCC tells Fromenance that a specific message went to a specific recipient. We store a verify code, a one way hash of the recipient address, and a content fingerprint. Never the address, never the body.

  2. Step 2: The customer asks

    They forward the message to verify@yourbank.com or paste it at yourbank.com/verify. No account, nothing to install, and the Fromenance name never appears. Screenshots work too.

  3. Step 3: A definitive answer in seconds

    Deterministic matching on the code, the recipient, and the fingerprint. The reply comes from your domain, in your branding, with the next step for that verdict. Every failed verification becomes threat intelligence.

Three verdicts, and the wording is locked

The verdict block in every reply is fixed text your fraud team cannot soften and your marketing team cannot inflate. It says what the institution can stand behind and nothing more.

Unregistered legitimate mail returns Not verified with the words "no record", never "fraudulent". Once your coverage is reviewed, Authoritative Mode changes that reply to "we did not send this".What Authoritative Mode requires.

Try it against the real API

This runs on a demo tenant on api.fromenance.com with a public site key. What you see is real latency and the real verdict path, with no model anywhere in it.

Northfield Bank (demo) verify page

Demo tenant: Northfield Bank (demo). Site key sk_pub_demo_northfield. Real API, real latency.

Registered message

This fraud alert was registered at send time to jane.doe@example.com. The footer carries the verify code twice on purpose.

Northfield Bank

We noticed a card transaction

Hi Jane,

A purchase of $412.90 at ACME ELECTRONICS was made with your Northfield Bank Visa ending in 4471 on September 24 at 10:42 AM.

If this was you, no action is needed. If you do not recognize this transaction, review it in the app or call the number on the back of your card.

Review this transaction: https://www.northfieldbank.com/app/alerts/tx/98812?utm=email

Thank you,
Northfield Bank Fraud Team

Not sure this email is from Northfield Bank? Forward it to verify@northfieldbank.com or enter code KX73-PQ9G at northfieldbank.com/verify. Reference: KX73-PQ9G

Northfield Bank, Member FDIC. 100 Main Street, Northfield, VT 05663. Privacy: https://www.northfieldbank.com/privacy

Verify

Codes are bound to the recipient: a code submitted without the address it was sent to resolves to Not verified as a replay by design, so change this address and watch the same code fail.

The reply never quotes the suspicious message or its links. It says only what the institution can stand behind: a registered communication matches, or no registered communication does.

What DMARC does not answer

SPF, DKIM, and DMARC are necessary and Fromenance depends on them. They answer a different question than the one your customer is asking.

Every failed verification is a phishing sample delivered by its target

A Not verified or Known fraud submission carries the attacker's domains, URLs, phone numbers, and QR payloads, sent in by the person the attack was written for. Fromenance extracts them deterministically, stores them per tenant, and exports them as CSV or STIX 2.1 today. Campaign clustering, IOC enrichment, and cross institution early warning are the intelligence tier on the roadmap.

Built for the people who own impersonation

Run a 60 to 90 day pilot on one communication stream.

Fraud alerts or transaction alerts are the best first stream. You get a written report of verification volume, verdict distribution, campaigns discovered, and intelligence yield.