Case study · Banking & Financial Services

A global bank proved its data never trained anyone else's model

Contractual assurance was not evidence. The Data Control Gateway verified training exclusion before every route and hashed the verification alongside the action.

Global bank · tier 1 · 38 jurisdictions · published September 2, 2026

0

routes completed without a verified boundary check

across 1.4m directives

14% → 0%

of agent traffic bypassing the gateway

38

jurisdictions covered by one enforcement point

2 hours

to answer a regulator's per-request evidence demand

previously unanswerable

Summary

A tier-1 bank had training-exclusion clauses with four model providers and no way to demonstrate they had been honoured on any specific request. Orcher moved the guarantee from the contract into the execution path: no route completes unless the boundary is verified first, and the verification is part of the permanent record.

Orcher components enforced

The situation

What was happening before Orcher.

  • Four model providers, each with a different training-exclusion posture, reached through six internal platforms with no common enforcement point.
  • Regulators in three jurisdictions had asked, in writing, for evidence that customer data had not entered third-party training corpora. The bank could produce contracts, not evidence.
  • An internal review found 14% of agent traffic bypassing the approved gateway entirely through direct SDK calls.

What Orcher enforced

The control surface, component by component.

  • Data Control Gateway became the single egress for model traffic; direct SDK routes were revoked at the network and identity layer in the same change window.
  • Every route now carries a pre-flight boundary check — provider, endpoint, contractual posture and data classification — and fails closed when any of the four disagree.
  • Classification is enforced per directive rather than per application, so a single workflow can hold different boundaries for different data classes.
  • The verification result is hashed into the Immutable Audit Ledger with the action, so evidence is produced as a by-product of execution rather than a project.

The data

Measured over the engagement window.

ControlContractual onlyEnforced by Orcher
Training exclusionClause in MSAVerified pre-route, per request
Evidence of exclusionNoneHashed with the action
Coverage of agent traffic86%100%
Data class granularityPer applicationPer directive
Failure behaviourRoute proceedsFails closed, logged

The bank's own control-comparison table, reproduced with permission.

Outcomes

What the organisation did next.

  • Two jurisdictional regulators closed open information requests on the basis of the per-request evidence.
  • The bank standardised on one enforcement point for all model traffic, retiring three partial internal proxies.
  • New provider onboarding now takes days rather than a quarter, because the boundary control is provider-agnostic.
  • Business units stopped negotiating their own model contracts — there was no longer an advantage to doing so.
A clause tells you what someone promised. We needed to show, request by request, what actually happened.
Group Head of Data Risk, tier-1 global bank (partner declined attribution by name)

Read further

The research behind this engagement.

Disclosure. Design-partner engagement, anonymised at the partner's request. Figures are measured by Orcher's own observability and ledger instrumentation over the stated period and have not been independently audited. Market figures carry their own source line.

More engagements

Other organisations that had to prove the same thing.

Run this pattern on your own workflow

Design partners deploy Orcher on one directive class, instrument it the way this study was instrumented, and keep the evidence whatever they decide afterwards.