For IT Architects, Platform & Security Engineering

Low-latency, event-driven. Deploy where your data lives.

Bucephalus is an event-driven fraud and AML platform that plugs into your existing payments, card and core-banking systems via streaming and REST, not batch ETL. Deployment is your choice — on-prem, private cloud, or managed — with a consistent API surface, observability stack and security posture across environments.

Event-driven core Stream-native scoring under your latency budget Kafka / Pulsar / MQ ingestion, stateless scoring services, deterministic rule fallback.
Integration surface REST, OpenAPI, webhooks, SDKs ISO 20022, SWIFT, card-scheme and custom core-banking adapters. Signed requests, idempotent endpoints.
Security & sovereignty Data stays in your jurisdiction EU/EEA residency, KMS-backed encryption, fine-grained RBAC, SBOM, audit log export.

Performance targets, integration patterns and deployment topologies are finalised during the technical discovery phase of the pilot. Reference implementations and sandbox credentials are provided under NDA.

Architecture · Federated Design

The Federated Defence Network: Peer-to-Peer Nodes, AI-Orchestrated, Cryptographically Verifiable

Bucephalus is built as a federated defence network: the Silbad Hub and every bank's Autonomous Station Agent sit on the same peer-to-peer ring and communicate continuously, context-aware, under AI orchestration — not through brittle request-response APIs. Data stays sovereign; intelligence flows.

Federation Core AI-Driven Mesh continuous · context-aware // Silbad Hub // Bank A // Bank B // Bank C // Bank D // Bank N
Underlying Trust Layer Hash-Chained Audit Signed Model Artefacts Cryptographic Attestation
Peer-to-peer ring · no central data lake · AI-orchestrated continuous flow

How the Network Works

Bucephalus is not a hub-and-spoke platform. The Silbad Hub and every bank's Autonomous Station Agent sit on the same ring and communicate as peers. Messaging is not request-response; it is continuous, context-aware and governed by AI — peer-to-peer decentralisation, orchestrated by federated AI.

Each Station scores transactions locally at the edge, shares only anonymised patterns across the ring, and benefits from models, typologies and threat intelligence that evolve in real time. The Hub participates as a peer — aggregating, curating, redistributing — not as a gatekeeper or single point of failure.

Federation Capabilities
  • AI-based fraud detection — real-time
  • Autonomous rule generation
  • Dynamic risk scoring
  • Edge-based decision logic
  • Self-adaptive compliance engine
  • All nodes — Silbad Hub and Station agents — are peers on the same AI-driven ring; no request-response bottleneck, no single point of failure
  • Raw data never leaves the bank — full GDPR and banking secrecy compliance
  • Station agents score and decide locally at the edge; operations continue under network partition
  • Hub participates as a peer — aggregates anonymised patterns, curates threat feeds, orchestrates federated learning
  • Cryptographic audit layer makes every message, decision and model update verifiable and tamper-evident
  • Scales from regional banks to Tier 1 multi-national institutions
Definition

The Silbad Federated Defence Network is AI-driven, continuously operating, context-aware infrastructure purpose-built for financial-crime defence. It combines peer-to-peer decentralisation — no central data lake, no gatekeeper — with intelligent orchestration: AI decides what flows across the ring, when, and in what context. Raw transaction data stays inside every bank; only anonymised intelligence moves.

Why a Federated Architecture — and Not a Central Cloud Hub

Most AML and fraud platforms centralise transaction data in the vendor's cloud — a direct tension with GDPR, banking secrecy and operational resilience under DORA. A federated architecture keeps the data inside every bank, lets local station agents decide at the edge, and uses AI orchestration to share only anonymised patterns across the ring. The result: full sovereignty, verifiable decisions, and a single platform compliance teams can prove is theirs. This direction aligns with public-policy work by FATF (federated analytics for public-private AML information sharing) and the BIS Innovation Hub (Project Aurora / Aurum on privacy-preserving analytics).

Central Cloud Hub · common pattern
  • Transaction data centralised in vendor's cloud
  • Hub-and-spoke integration, vendor-side decisions
  • Single point of failure and compliance concentration
vs
Federated Defence Network · Silbad
  • Transaction data stays inside every bank
  • Edge decisions, AI-orchestrated continuous flow
  • Cryptographic verifiability of every message and model update

Continuous, Not Request-Response

Peers exchange context, scores and model updates as an ongoing stream — not one-shot API calls. The ring is always on, always reasoning.

AI-Orchestrated Messaging

What each peer shares, when, and with whom is governed by AI — not by hard-wired schedules. Relevance, risk and latency shape the flow.

Peer-to-Peer by Design

Hub and Station agents are equals on the ring. No central data lake, no gatekeeper, no single point of failure — peer-to-peer decentralisation, applied to banking.

Autonomous Edge Agents

Every Station scores, decides and queues alerts locally. Self-adaptive rule generation and dynamic risk scoring run at the edge, close to the transaction.

Verifiable Trust

Hash-chained audit logs, signed model artefacts and cryptographic attestation make every peer-to-peer message and model update independently verifiable.

Human-in-the-Loop

Every high-impact decision is explainable and subject to analyst or four-eyes oversight. Continuous AI, deliberate humans — aligned with EU AI Act requirements.

Inside the Station

Eight tightly integrated services, sharing a single audit-grade event log.

AML Engine

Scenario-based and statistical AML monitoring with case generation.

Fraud Engine

Real-time scoring with ML, device intelligence and behavioural signals.

Sanctions Engine

Live screening with fuzzy matching against EU, OFAC, UN and national lists.

Case Management

Workflow, evidence, decisions and SLA control for analyst teams.

Reporting Module

STR / SAR, PSD2 fraud reporting and supervisory exports.

IAM

Role- and attribute-based access, MFA, step-up and session control.

API Gateway

OAuth2 / mTLS-protected inbound, outbound, internal and admin APIs.

Audit Log

Immutable, hash-chained event store covering every decision and change.

Deployment Models

Deploy where your data lives.

Bucephalus is designed to fit your operating model — not dictate it. Run it on-premises as a turnkey appliance, in your own private cloud, or as a managed service on Silbad's EU/EEA-resident infrastructure. The platform, APIs and security posture are identical across all three modes.

Option 1 Fastest to go-live

On-Premises (Turnkey)

A factory-provisioned Silbad Station appliance — hardware, OS and the full Bucephalus stack pre-installed — delivered to your data centre. After the basic API integration, the system is operational.

  • Pre-installed appliance shipped ready to rack
  • Hardened OS, Bucephalus services, monitoring stack — all pre-configured
  • API connectors to core banking / card / AML systems activated on site
  • Data never leaves your data centre — maximum sovereignty
Ideal for Banks with strict data-residency or banking-secrecy constraints and existing data-centre operations.
Option 2 You own the infrastructure

Private Cloud (Bank-Managed)

Deploy the Silbad Station into your own private cloud — AWS, Azure, GCP, OCI, OpenStack or VMware. You keep full control of networking, IAM and observability; we deliver the platform as infrastructure-as-code.

  • Helm charts, Terraform and Ansible references provided
  • Runs inside your VPC, your subnets, your IAM boundary
  • Integrates with your existing SIEM, secrets manager and KMS
  • Your SRE/DevOps team owns operations; Silbad provides platform support
Ideal for Banks with a cloud-first strategy and a mature platform / SRE organisation.
Option 3 We run it for you

Silbad Cloud (Managed)

Hosted in Silbad's EU/EEA-resident infrastructure with per-tenant isolation. Silbad SRE operates the platform end-to-end under a clear shared-responsibility model — you focus on investigations, not operations.

  • EU/EEA data residency, isolated tenant per institution
  • 24/7 Silbad SRE — patching, upgrades, incident response, backups
  • SOC 2 / ISO 27001-aligned operating controls
  • Predictable subscription pricing, fastest time-to-value
Ideal for Mid-size banks and institutions without a large platform team that need a regulated managed service.

At a Glance

Dimension On-Premises Private Cloud Silbad Cloud
Infrastructure owner Bank Bank Silbad (EU/EEA)
Data residency Bank DC Bank cloud region EU/EEA, Silbad region
Operations (run / patch / upgrade) Bank IT + Silbad support Bank SRE + Silbad support Silbad SRE (24/7)
Typical time to go-live Fastest (appliance pre-built) Depends on cloud readiness Fast (pre-provisioned tenant)
Scaling model Appliance capacity + add-on nodes Elastic in your cloud account Elastic, Silbad-managed
Commercial model Licence + appliance Licence + your cloud bill Subscription (bundled)

All three modes share the same codebase, API contract and security controls. Banks may also adopt a hybrid model — for example, production on-premises with disaster-recovery in Silbad Cloud, or staging in your private cloud and production on-premises.

APIs & Integration

Built to plug into your bank — not replace it.

Bucephalus exposes a clear API surface and ships with proven adapters for the systems your bank already runs. Most institutions move from contract to first scored transaction in weeks, not quarters.

Inbound APIs

Called by core banking, channels and payment systems to submit transactions and receive scoring decisions in real time.

Outbound APIs

Used by Bucephalus to push STR / SAR submissions, sanctions feedback and supervisory exports to authorities and partner systems.

Internal APIs

Service-to-service traffic between detection engines, case management and the audit log — fully meshed with mTLS and SPIFFE identity.

Admin APIs

Configuration, rule management, model lifecycle and tenant operations — segregated, audited and protected by step-up authentication.

Where Bucephalus Connects

Core Banking

Temenos, Finastra, Mambu, FIS, Oracle Flexcube, plus custom and legacy host systems via ISO 20022 / proprietary adapters.

Card & Payments

Card switch, 3DS server, instant payments (SCT Inst, FedNow), wallets and processor integrations.

SWIFT & Cross-Border

SWIFT MT/MX, SEPA, Target2, ISO 20022 — both screening at message ingress and post-event monitoring.

KYC & Identity

eIDAS, video-KYC vendors, document verification, sanctions and adverse-media data providers.

Data & Risk

Streaming via Kafka / Pulsar, batch via S3 / Parquet, BI via standard JDBC, with native Snowflake and Databricks connectors.

Security & Observability

SIEM (Splunk, Sentinel, QRadar), IAM (Okta, Entra ID, Keycloak), HSM and KMS, OpenTelemetry-native logging.

API Security Baseline

OAuth 2.1 + OIDC mTLS (mutual TLS) Per-tenant rate limiting Schema-validated payloads Signed webhooks Idempotency keys OWASP ASVS L3 baseline
Security & Governance

Controls that survive a supervisory inspection.

Bucephalus treats financial-crime tooling as critical ICT infrastructure under DORA[2]: explicit access models, segregation of duties, four-eyes approvals on every irreversible action and a complete trail to back it all up.

Identity & Access Management

Combined RBAC and ABAC: roles define what a user can do, attributes (region, product, risk tier) refine when they can do it. Least-privilege is the default, not the exception.

Strong Authentication

MFA enforced for every privileged action, with step-up authentication for high-risk operations (rule changes, model deployments, STR submission).

Session Control

Idle and absolute session timeouts, concurrent-session limits, device binding for administrators and full session telemetry to the audit log.

Encryption Everywhere

TLS 1.3 in transit, AES-256 at rest, customer-managed keys (BYOK) optional, and per-tenant cryptographic isolation.

Segregation of Duties

The platform enforces SoD at the role and workflow level — incompatible permissions can't be granted to the same identity, and incompatible actions can't be taken in the same session.

AML Officer System Administrator
Decision maker Approver
Rule author Rule deployer
Model trainer Model approver

Four-Eyes Principle

The following actions cannot be taken by a single user. A second authorised reviewer must approve before the change takes effect — and both identities are written to the audit log.

  • STR / SAR submission
  • Rule and scenario changes
  • Model deployment and rollback
  • High-risk case decisions
  • Customer risk-rating overrides
  • Sanctions match resolution
Turnkey Solution · End-to-End IFF Defence

A Complete Defence Against Illicit Financial Flows

Bucephalus is not a point tool. It is a turnkey, end-to-end platform that detects, disrupts and documents the full spectrum of Illicit Financial Flows (IFF) — every criminal and commercial channel through which illicit value crosses a regulated institution.

A

Crime-Related IFF

Flows arising from or connected to predicate criminal offences.

Fraud

Card fraud, account takeover, authorised push-payment (APP) fraud, social engineering and identity fraud.

Money Laundering

Placement, layering and integration of criminal proceeds — structuring, smurfing, round-tripping, mule networks.

Terrorist Financing

Detection of low-value, dispersed funding patterns aligned with FATF R.5 and EU CFT obligations.

Corruption & Bribery

PEP screening, kickback patterns, unexplained wealth flows and politically sensitive counterparties.

Tax-Crime Flows

Proceeds-of-crime flows from tax evasion, VAT carousel fraud (MTIC) and criminal tax offences.

Human Trafficking & Smuggling

Typology-driven detection of exploitation-linked payments, recruiter-victim patterns, migrant smuggling channels.

Drug Trafficking

Narco-economy cash-proxy flows, trade-based laundering, bulk cash placement and corridor anomalies.

Cybercrime Proceeds

Ransomware pay-outs, business email compromise (BEC), pig-butchering, crypto off-ramp laundering.

Sanctions Evasion & Proliferation

Screening against EU/UN/OFAC, dual-use goods, front companies and proliferation-finance typologies.

B

Tax- & Commercial-Related IFF

Flows arising from tax abuse and commercial manipulation.

Trade Mispricing / Invoice Manipulation

Under- and over-invoicing of goods and services to shift value across borders — a primary IFF channel identified by UNCTAD and GFI.

Transfer Pricing Abuse

Non-arm's-length intra-group pricing used to erode the tax base. Cross-references OECD BEPS and DAC6 hallmarks.

Shell Companies & BO Concealment

Layered ownership, nominee directors, opaque trusts — mapped against the EU Central BO Registers and FATF R.24/R.25.

Offshore Profit Shifting

Conduit entities in low- or zero-tax jurisdictions, treaty-shopping and hybrid mismatch patterns.

Commodity Trading Corruption

Oil, metals and agri-commodity trading as vehicles for corruption, kickbacks and value-extraction models.