Fromenance

Fromenance for banks

Your customers ask "did my bank send this?" Give them an answer.

Fromenance is a communication provenance platform for regional banks: you register every fraud alert, transaction alert, and wire notice at send time, and a customer who forwards a suspicious one to verify@yourbank.com gets Verified, Not verified, or Known fraud in seconds. It is the layer above DMARC that the customer can actually see, and every lure they forward becomes an indicator for your fraud team.

What your customers are receiving

The impersonation scenarios banks fraud teams see every week, and what a Fromenance verdict does to each one.

Register these streams first

Coverage is the whole game. Start with the communications customers already scrutinize, because those are the ones they will forward.

  1. 01

    Fraud alerts

    The stream customers scrutinize most and forward most. The best first stream for a pilot, and where footer replay is most likely to be observed.

  2. 02

    Transaction and card alerts

    High volume, template driven, easy to register from the ESP webhook. Customers already know what a real one looks like, so a lure stands out when it fails.

  3. 03

    Wire and ACH notifications

    Lower volume, highest value per message. Register through the API or the journal path from the core banking or treasury platform.

  4. 04

    Statements and account notices

    Batch runs from a statement vendor. Use the batch endpoint (up to 1,000 per call) or add journal-{slug}@ingest.fromenance.com as a BCC on the vendor's sending system.

Outcomes you can put in front of the board

Every metric below is captured by the product itself, so the pilot report is a dashboard export.

Compliance framing

Fromenance is a customer facing fraud control with an audit trail: every verdict is immutable, every analyst action is logged, and every registered communication has a record of when it was sent and to whom (as a one way hash). That maps to what examiners ask for under FFIEC guidance on customer authentication and fraud response, and it gives your incident reports a timestamped source of truth. We do not claim regulatory certification; we give you the evidence.

The pilot, week by week

60 to 90 days on one stream, fixed fee credited to the first annual contract, with onboarding help and a written report.

  1. Step 1: Week 0

    Contract and DPA, tenant created, TXT record published, redirect rule live, forwarding test passed.

  2. Step 2: Week 1

    One stream registered, footer deployed to that template, reply identity live on your domain.

  3. Step 3: Weeks 2 to 12

    Run. Weekly 30 minute review of Submissions and Indicators with your fraud lead. Reports at day 30, 60, and 90.

Questions evaluators ask

Do we have to route customer mail through Fromenance?
Only the messages customers choose to forward to verify@yourbank.com, and only after the forwarding hop passes DKIM or ARC for your domain and your TXT record checks out. If your security review prefers to start smaller, the web verify page needs no mail routing at all.
What does the customer see?
A reply from verify@verify.yourbank.com (or a subdomain you choose) in your branding, with the locked verdict and a next step. The Fromenance name never appears. On the web page, the same template renders in place.
How does this fit our existing DMARC, gateway, and brand protection?
It sits above them. DMARC authenticates your domain, the gateway filters inbound mail to your staff, brand protection takes down lookalikes. None of them answer the customer holding the phone. Fromenance does, and it feeds indicators to all three.
Which stream should a bank pilot first?
Fraud alerts and transaction alerts. Customers already scrutinize them, they are template driven, and the ESP webhook or a single API call registers them without touching the core.
What if our core banking vendor cannot call an API?
Add journal-{slug}@ingest.fromenance.com as a BCC or journaling target on the vendor's sending system. We receive the full message, hash the recipient, fingerprint the body, and register it. Pair it with a static per template code or the reserve flow for the footer.

Run a 60 to 90 day pilot on one communication stream.

Fraud alerts or transaction alerts are the best first stream. You get a written report of verification volume, verdict distribution, campaigns discovered, and intelligence yield.