Goldman was the first place to do a system like that, and when it was copied at other investment banks like JP Morgan and Bank of America, they opted to use Python instead of an in-house language and so "bank python" was born. Actually, the banks all poached engineers from one another, so many of the people that built the system at one place ended up building it again at another, hence why there are so many similarities between the equivalent systems at all these US investment banks. Some of those people eventually went on to build it again as a SaaS offering: https://www.beacon.io/
You are correct. (Full disclosure: I work at Beacon.)
Financial institutions are extremely sensitive about where their data is held, processed, stored and/or sent to. Some of it is just basic corporate governance ("we do not like the additional risk"). Some you could lump in with secrecy and competitive edge ("this is our secret sauce, no way are we going to let anyone else get it"). Some is driven by regulations ("we hold/process highly sensitive financial and personal data on individuals, sending it to a third party is a huge no-no"). And some is just garden variety contract obligations.
[Note that I intentionally chose to omit any consideration for "plain" security. In this industry that can get political.]
Where data governance/sovereignity is concerned, the term "SaaS" is commonly understood as: "send data to a third party, get results back". You can imagine how well that plays with any data an institution considers precious.