Veritrax
Three products  ·  one register

The data between your systems decides the numbers.

Mappings, reference data, lineage and the movement between systems: every report depends on this layer, and no function owns it. Veritrax governs it. We start with the mapping and reference data, because that is where the failures begin and it can be brought under control without changing a single existing process.

Three questions Answerable today, or a project?

Who decided which line this belongs on?

TesseraMapping & reference data

Where did this number come from?

ArgusLineage & traceability

How many systems changed it on the way?

PortusCollection & modelling

Most institutions cannot answer any of the three without commissioning work to find out. We start with the mappings and reference data, because that is where the errors originate — and it needs no change to any existing process.

The problem

The tables that decide your numbers are the ones nobody owns.

A general ledger account becomes a regulatory line item. A product code becomes an asset class. A cost centre becomes a legal entity. Each of those is a decision that changes what gets reported, and in most institutions they sit in spreadsheets and configuration screens with no owner, no approval trail and no review date. When a number turns out to be wrong, this is usually where it went wrong.

Added without approval

A new code appears, someone adds a line so the process will run, and it goes live during close. It is never reviewed, because nobody outside that team knows it exists.

Changed without a trail

Edits made straight into production with no second pair of eyes and no version history. When a prior period has to be restated, the version that produced the original number no longer exists.

Wrong without warning

Values that no longer map fall into a catch-all bucket. The process completes, the number looks plausible, and nothing alerts. This is the most common route to a misstatement.

Products

Three products. One register.

Each is sold on its own and each writes to the same canonical register. They are deliberately sequenced: Tessera governs the connective data, Argus proves the chain across the estate that will never be consolidated, and Portus removes the intermediaries where consolidation is possible.

Entry point — mapping, reference and static data

Every institution runs on translation nobody owns.

These mappings decide the numbers, and they are created without approval, changed without control and left to decay without review. Tessera finds them, then governs them — and the first three levels of control require no change to any existing process.

Discovery
Control
Passive
Crawl

Find what nobody declared

Read-only sweep of databases, file shares, ETL, BI layers and code repositories. Detects mapping logic hardcoded in SQL and stored procedures, not only the tables that look like mappings.

Detective

Control without ownership

Baseline and drift alerting, named owners and certification cycles, and an approved version held and continuously reconciled against what is actually running. Tessera becomes the record of what should run without executing anything.

Active
Declare

Reach where crawling cannot

Teams register mappings directly, confirm or reject machine-found candidates, and import the registers they already keep. This is how vendor configuration screens and undocumented knowledge enter the estate — and every confirmation sharpens detection.

Preventive

System of record

Four-eyes change control, bitemporal versioning, impact modelled across every dependent process before commit, and consumers subscribing to a published version rather than holding private copies.

What you can say when you are asked Levels 01–03 change nothing about how you work today
00
Unknown

Nobody knows it exists.

01
Known

We are told within minutes if it changes.

02
Accountable

A named person confirms it is correct, on a cycle.

03
Approved

What is running is checked against a signed-off version.

04
Controlled

It cannot change without review and approval.

05
Single source

One version. Every system takes it from the same place.

Each level is a sentence you can defend in a committee or to a supervisor, and it is a property of each individual mapping rather than of the deployment. The first three are applied to data that stays exactly where it is, in the systems that already hold it. The target is not everything at level five — it is everything on a critical reporting path at level four or above, and nothing at all left at level zero.

Lineage and traceability

Prove the chain across the estate you will never rebuild.

Most of the architecture will not be consolidated — the cost is too high, the systems too entrenched, the disruption too great. Argus governs that reality rather than wishing it away: it maps the hops, records what each does to the data, and holds the evidenced path from obligation to reported field.

Hop discovery

Every intermediary on a reporting path — what it consumes, what it introduces, and which consumer depends on it.

Obligation register

Obligations decomposed once, with the source paragraph held against every object.

Evidence on retrieval

The path from obligation to reported field is read rather than rebuilt, so it is consistent between requests. Inconsistency across submissions is itself a finding.

Exception management

Every break surfaced with severity, owner, blast radius and a proposed amendment.

Collection and modelling platform

Collect once. Model for each use.

The web exists because every consuming function needs a different shape of the same data, and each has built its own chain of intermediaries to get it. Portus is the first hop from every source and the only hop before the consumer. It is the end state rather than the entry, and it is sold only to institutions already running the first two.

Single collection point

Sources land once. Nothing between a source and a consumer introduces data that did not come from a source or a governed mapping.

Purpose-built models

One collection, many models. Finance, interest rate risk, liquidity, MREL and front office each get the shape they need, not a canonical compromise that serves none of them.

Hop retirement

Intermediaries whose only distinctive content was enrichment lose their reason to exist, and can be retired individually rather than in a programme.

Lineage by construction

Because the enrichment happens here, lineage is written as the data moves. It is produced, not inferred.

Argus Lineage across every hop, consolidated or not SourceCollectEnrichModelConsume Tessera Mapping, reference & static data Portus

Portus collects once and builds the model each consumer needs. Tessera governs the data every model is enriched with. Argus holds the evidenced path across the whole of it, including the parts that will never be consolidated.

Outcomes

Control usually costs money. Here it does not.

The reason matters, and it is worth stating plainly: most of what is spent on this today buys no control at all. Rebuilding lineage for each supervisory request, hunting mappings during a migration, reconciling because nobody trusts the chain — that is reconstruction, and reconstruction re-establishes facts that should already have been recorded.

01 — Risk

Detected in minutes, not at audit

Coverage of the estate moves from unknown to measured. Time to detect an uncontrolled change falls from the audit cycle to minutes, and every attestation is supported by evidence rather than assumption.

02 — Cost

Waste removed, not control thinned

Migration programmes stop funding months of consultants documenting mappings. Supervisory requests stop being archaeology. The same team does the same controls with the reconstruction taken out.

03 — Efficiency

Answers without a queue

Impact analysis before a change moves from weeks of tracing to minutes of graph traversal, and second line answers its own questions instead of raising a ticket to the data team.

Architecture

The web exists because every hop adds data.

Data reaches the system that reports it through a dozen intermediaries, and almost every one exists to join something in — a mapping, a classification, a piece of static data. Multiply that by every consuming function needing a different shape of the same data and the web is the inevitable result. Govern the connective data first, and the hops lose the reason they were built.

Today

Three consumers, three separate chains, seven intermediaries. Each one joins in its own mapping, so the same underlying data is enriched several times in several places — and the results have to be reconciled afterwards.

Finance & accountingInterest rate riskLiquidity Source + each intermediary joins in its own mapping

Collect once, model many

Every source lands once, unchanged. Enrichment is applied a single time from the governed register. Each consumer's model is then built from that one collection — the models differ, the data underneath them does not.

CollectEnrichFinance & accountingInterest rate riskLiquidityPortusOne landingApplied once Source

Centralise the logic before the pipes. Every hop's enrichment is registered and served long before a single pipe is retired — so lineage is owned from the first day rather than the last, and most institutions will stop well short of the right-hand diagram and still be far better off.

Intelligence

The model runs inside your perimeter, and never decides a control.

Discovery at this scale is not tractable by rules alone — establishing that an artefact is a mapping, pulling logic out of a stored procedure, or recognising that three systems name the same domain differently are all judgement problems. But a control product cannot rest on a judgement it can neither reproduce nor explain, so the boundary is drawn explicitly.

Advisory

What the model does

  • Classifying whether an artefact is a mapping
  • Extracting obligations from rulebook prose
  • Parsing mapping logic out of SQL, SAS and stored procedures
  • Matching equivalent domains across systems
  • Explaining why an exception occurred
  • Drafting remediations, rationale and impact summaries
Deterministic

What code does

  • Reconciliation of published against running
  • Threshold and limit evaluation
  • Version comparison and diffing
  • Drift and change detection
  • Coverage and completeness calculation
  • Anything presented to a supervisor as evidence
No AI component makes a control decision, and no AI output reaches a regulator without human attestation.

Local inference

The model runs on your infrastructure or inside your own cloud tenancy. No customer data is sent to an external model provider, so there is no new concentration exposure to identify, document and monitor.

Shipped intelligence

Detection improves centrally and arrives as versioned releases — the engine runs inside your perimeter while the intelligence is developed outside it. Nothing leaves in order for it to get better.

Reproducible by design

Every classification is stamped with the model version and prompt revision that produced it, at temperature zero against a pinned release. A judgement made eighteen months ago can be re-run to the same answer during an audit.

The name

Veritas. Trax. Truth, and the path that proves it.

The two halves of the name are the two halves of the problem. Neither is worth much on its own.

Veritas

Truth

One canonical statement of what is required.

Not three teams' readings held in three tools with no authoritative version. A single register the firm can stand behind, with the source attached to every object in it.

Trax

The trace

The evidenced path from that statement to the data.

Source domain, mapping, enrichment, model, reported field — held end to end and retrieved on demand, rather than rebuilt by hand each time a supervisor asks.

A register without a trace is an assertion. A trace without a register is an audit trail to nowhere. We hold both, as one object.

About Veritrax
The method was built by hand first, on a live programme, under a real deadline — before any of it was software.

Veritrax is built by practitioners who have run multi-jurisdiction regulatory transformation inside a globally systemic bank: obligation decomposition, control framework design and end-to-end data lineage across UK, European, US, Middle Eastern and Asian supervisory regimes.

We build for institutions that need this ready rather than built. The largest banks will attempt these capabilities in house; mid-tier, regional and specialist institutions face the same rulebook without the scale to fund and maintain bespoke infrastructure for it. That is who we are for.

Design partner programme

We are taking on a small number of design partners.

If you own data governance, regulatory reporting or second-line assurance and you cannot currently say who owns your mappings or when each was last reviewed, we would like to speak with you. Early partners shape the register model and keep preferential terms.

Start a conversation