COMPANY PROFILE
Ocrolus Inc.: Security Built for the Infrastructure of AI-Native Fintech
Ocrolus is an AI-native fintech infrastructure company based in New York that powers lending decisions for banks, fintechs, and mortgage companies across the US. Their platform automates underwriting workflows across small-business, mortgage, and consumer lending - classifying financial documents, extracting key data, detecting fraud, and delivering comprehensive cash-flow and income analysis with exceptional precision and reliability. By processing sensitive borrower data at scale across bank statements, pay stubs, and financial documents, Ocrolus enables lenders to make faster, more accurate credit decisions. For a company handling sensitive financial data, maintaining rigorous compliance standards and borrower data protection are not optional; they are table stakes.
THE OPPORTUNITY
Elevating Security for a Modern, AI-Native Team
1. Evolving from log visibility to actionable security outcomes
As Ocrolus grew, strong log visibility and dashboards were no longer sufficient on their own. The team needed a step change: agentic workflows, automated investigations, and security outcomes that went beyond what happened to what to do about it.
2. Scaling security outcomes without scaling headcount
With rapid infrastructure growth across cloud, identity, endpoints, and SaaS, Ocrolus sought a smarter way to keep pace. The goal was clear: empower a lean, high-performing security team to consistently meet SLAs at scale, with automation and intelligence doing the heavy lifting.
3. Traditional Managed Detection and Response MDR providers could not deliver an agentic SecOps transformation
Evaluating the MDR market made one thing clear: traditional providers and AI-bolted delivery models were built for a different era. They could manage alerts. They could not reason about intent, adapt to new attack surfaces, or automate the full detection-to-response loop. The operating model itself was the bottleneck.
4. Monitoring AI adoption and emerging behavioural anomalies
As Ocrolus rapidly expanded its AI-powered infrastructure, including frontier model workloads, the team recognized that AI-native operations demand AI-native security. Standard detection approaches were not designed with this environment in mind. Ocrolus needed a security layer that could understand context, learn what normal looks like across AI workloads, and surface genuine anomalies in real time. Trench was purpose-built for exactly this challenge.
TRANSFORMATION
From Static Rules to an Agentic Detection and Automation Engine
BEFORE TRENCH
- Centralized log visibility and dashboards established a solid data foundation
- Rapidly expanding AI-native infrastructure requiring deeper behavioral context and continuous workload monitoring
- Security workflows managed manually, with alerts across multiple tools requiring analyst coordination
- Incident investigations managed through multi-step analyst workflows across remediation, reporting, and stakeholder communication
- Threat hunting driven by skilled analysts, with opportunities to extend coverage and integrate real-time intelligence at scale
AFTER TRENCH
- 2X ROI on security operations, delivering real security outcomes
- AI workload baselines and behavioral anomaly detection through Intent Graph, continuously monitoring frontier model activity
- Complete headless SecOps experience - all workflows automated end-to-end inside Slack, no console switching, no manual handoffs
- Full remediation, reporting, and stakeholder communication completed in under an hour, consistently
- Real-time threat intel feeding dynamic detections - hypothesis-driven autonomous hunting running continuously across the full attack surface
To me, having a SIEM and a SOC as separate entities or vendors does not make sense anymore. Modern security monitoring should integrate them into one solution and that is exactly where Trench is leading the industry.
AGENTIC TRANSFORMATION STORY
The transition from a legacy SIEM to an AI-powered Agentic SIEM was not simply a technology upgrade for Ocrolus; it was a fundamental rethinking of what security operations could and should look like. As an AI-native fintech handling sensitive financial data at scale, Ocrolus required a security posture that matched the speed, complexity, and intelligence of its own platform. The journey unfolded across four distinct phases, each building on the last to deliver a fully agentic, always-on SecOps engine.
01 PHASE Establishing the Unified Data Foundation
Every agentic security capability begins with data quality. Trench replaced fragmented, siloed log pipelines with a security-first data lake at the core of the Ocrolus environment. Signals from cloud infrastructure, identity providers, endpoints, SaaS applications, and AI workloads were ingested and normalized in real time - with zero pipeline maintenance.
The outcome: A single, authoritative source of truth that gave every downstream agent complete, high-fidelity context - the prerequisite for accurate detection, fast investigation, and confident response.
02 PHASE Replacing Static Rules with Intent Graph Detection
Legacy SIEMs operate on fixed rules; they flag what has been seen before. As Ocrolus scaled its AI-native infrastructure, the attack surface evolved faster than any ruleset could keep up with. Trench's Intent Graph changed the detection paradigm entirely.
Rather than matching events to known signatures, Intent Graph continuously baselines behavioral patterns across both traditional and AI workloads. It learns what normal looks like - and surfaces anomalies that no pre-written rule would ever catch, including emerging threats specific to frontier model activity.
The outcome: 100% detection coverage across the full attack surface, including AI workloads, without the noise and false positives that burdened rule-based systems.
03 PHASE Deploying Purpose-Built Agents Across Every SecOps Workflow
With the data foundation and detection engine in place, Trench Agentic Studio enabled Ocrolus to deploy specialized agents across every critical security workflow, operating continuously, without human initiation.
- Detection Agents evaluate signals through Intent Graph reasoning and live threat intelligence, prioritizing what genuinely demands attention.
- Investigation Agents auto-triage every alert 24x7, running end-to-end case closure from initial triage through full remediation and stakeholder reporting - in under an hour.
- Hunting Agents run continuous, hypothesis-driven threat hunts across the full attack surface, augmenting analyst-led investigations with real-time intelligence.
- Response Agents execute automated playbooks from containment through communication, eliminating manual handoffs and shift-gap risk entirely.
The outcome: A fully autonomous SecOps capability that scales with the organization, not with headcount.
04 PHASE Going Headless - Security That Comes to the Team
The final and defining shift was operational: eliminating the console entirely. For a lean, high-performing security team managing an AI-native organization, the traditional model of logging into a SIEM to check on security is a friction point that slows response and fragments attention.
With Trench's headless model, every finding, investigation outcome, and response action surfaces directly inside Slack - enriched with full context, supporting evidence, and a clear recommended action. Security stopped being something the team went to check. It became something that came to them.
The outcome:A security function that integrates seamlessly into the team's existing workflow, making proactive, intelligent security a natural part of every working day.