Path A
Replace the core
Core and Switch become the bank’s foundation, with the modules it chooses on top.
- A complete platform from one vendor
- Suits banks renewing their core system
Core banking, card and ATM switching and thirteen standalone modules, with a control plane that builds them and keeps changing them — white-label software installed in the bank’s own data centre.
The problem
A bank doesn’t buy software that stays frozen. It buys the ability to change it — new products, new regulations, new channels.
Today every change is a negotiation. So banks stop asking, and their systems freeze.
Features, an implementation project and a maintenance contract.
Every change after go-live becomes a new request, a new quote and a new wait.
Speed of change
The ability to change a banking system safely, whenever the bank needs to. That is what Bank in a Box is built around.
The licence is paid once. Change is paid for the life of the system.
Forge, the control plane
Forge is not a code factory. Every change request runs through a pipeline: it is staged on a copy, compiled and tested automatically, and reaches the source only if it passes.
Step 1
Reads the change request and plans the work, keeping it within the scope that was asked for.
Step 2
Decides where the change belongs in the existing system and which parts it may touch.
Step 3 · only when needed
Prepares database changes, only when the request needs them.
Step 4
Writes the code for the change, following the system’s existing patterns.
Step 5
Compiles for real and runs the automated tests. If the build fails, the compiler errors go to Repair and the result comes back here.
Loop with Verify
Receives the real compiler errors, fixes the code and sends it back to Verify until it builds and the tests pass.
Step 6
Reviews the change before it is accepted, including whether the documentation was updated.
Result
The change is promoted to the source and a release package is prepared.
Work happens on a copy. If a change fails, the source is exactly as it was.
A baseline is taken before any change, so only problems the change introduces can block it.
What went wrong in one change is kept and used in the next.
A change to core logic is rejected if the documentation was not updated with it.
Work happens on a copy. If a change fails, the source is exactly as it was.
A baseline is taken before any change, so only problems the change introduces can block it.
What went wrong in one change is kept and used in the next.
A change to core logic is rejected if the documentation was not updated with it.
A small, real change, from the first check to a ready release package in about a minute.
Spring Boot · Go · Node / Express · FastAPI · Web · React Native · Flutter · Android
Forge runs entirely inside the bank, language model included — nothing leaves the data centre.
| 01 | Starting state recorded | Done |
|---|---|---|
| 02 | Prepared on a copy | Done |
| 03 | Compile | Succeeded |
| 04 | Automated tests | Passed |
| 05 | Applied to the system | Done |
| 06 | Release package | Ready |
Three files changed, none outside the request’s scope. Compare that with months.
The portfolio
A core layer, standalone modules around it, and the control plane that builds and changes all of them. Each product can be bought and run on its own.
Control plane
Forge Builds and changes every product
Banking products, installed in the bank’s data centre
Module layer — each one standalone
Core layer
Each product has its own database, its own release and its own pipeline, so one can change without touching another.
When Shield freezes an account, it calls the core over its API — and if that call fails, the account stays frozen.
Built to run on-premise, even without an internet connection.
The fifteen products
Open any product to see the problems it solves, what it already does and who it is for.
Banks replacing their core: commercial banks, BPR and BPRS, and new digital banks.
Go microservices · REST · gRPC · events · Conventional + sharia · Kubernetes-ready, on-premise
Issuers and acquirers with card and ATM estates, and switching providers.
Rust core + Go services · ISO 8583 · EMV · NDC · GPN · Visa · Mastercard · PCI DSS 4.0.1 mapping
Banks and multifinance companies.
9 credit products · 15-stage workflow · On-premise OCR, 19 document types · POJK 22
Banks with a growing loan book.
10 amortisation methods · Daily batch, safe to rerun · Real-time APIs
Banks and multifinance companies reducing bad loans without adding collectors.
Per-contact compliance check · Approved templates per channel · Linked to Lend
Every bank — AML is mandatory spend.
DTTOT · OFAC · UN lists · PPATK typologies · GRIPS reports, HSM-signed
Banks with rising digital volume that need declines they can explain.
13 fraud types · Score 0–1000 · 15 starter rules · 11-feature store
Banks still preparing regulatory reports in spreadsheets.
24 reports, 6 regulators · XBRL · CSV · XML · HSM signature · 10-year archive
Treasury teams working from spreadsheets.
LCR · CAR · NOP intraday · IFRS 9 / PSAK 71 · FX · PUAB · SBN · IRRBB
Banks and financial groups running ERP and HRIS separately from the core.
Corporate GL · Procure-to-pay · Payroll: PPh 21 · BPJS · Multi-entity
Banks assembling management reports by hand that cannot use a cloud warehouse.
Bronze → silver → gold · 10 data-quality rule types · Questions in Indonesian · On-premise
Banks with an app whose decisions are hard-coded.
Risk-based authentication · A/B and bandit tests · UU PDP consent
Usually comes with other Bank in a Box products rather than bought on its own.
JWT + JWKS · Default-deny policies · PKCS#11 to a hardware HSM
Banks meeting the SNAP BI mandate or opening Open APIs.
SNAP BI · JSON Schema · Avro · Protobuf · OpenAPI · Zero trust · UU PDP masking
Banks or vendors that want their own capacity for change in a closed environment.
Python · LangGraph · FastAPI · Web control centre · Local language model · 8 target stacks
Two ways to start
The two paths don’t compete. A bank can start with one module on its current core and move further later.
Path A
Core and Switch become the bank’s foundation, with the modules it chooses on top.
Path B
Keep the existing core and attach the modules you need — Report, Shield, Collect, Treasury and others — through APIs.
Under the hood
Writing code is no longer the hard part. Running change safely in systems that hold people’s money is.
Card messaging, chip cryptography, hardware key management, double-entry accounting and OJK compliance are built in from the start.
Staging on a copy, real compilation, baselines and automatic rollback decide whether a change is accepted — not a model’s confidence.
Forge builds and changes every other product in the portfolio, so each change it makes feeds back into how it works.
Everything, including the language model behind Forge, runs inside the bank’s own data centre.
Card messaging, chip cryptography, hardware key management, double-entry accounting and OJK compliance are built in from the start. ISO 8583 · EMV · HSM · Double-entry · OJK.
Staging on a copy, real compilation, baselines and automatic rollback decide whether a change is accepted — not a model’s confidence.
Forge builds and changes every other product in the portfolio, so each change it makes feeds back into how it works.
Everything, including the language model behind Forge, runs inside the bank’s own data centre.
Today’s language models can write banking code. What nobody has is the layer that makes those changes safe to run in systems that hold people’s money.
Everything you need to know about Bank in a Box.