Zero Trust infrastructure for agentic AIAI agents in production without opening a port or rebuilding the network
Identity decides every data path: banks, insurers and fintechs deploy agents with AML and DORA compliance built in.
Identity decides every data path: banks, insurers and fintechs deploy agents with AML and DORA compliance built in.
Official partner of NetFoundry, which is backed by Cisco Investments
Agentic AI has changed the rules. Autonomous agents don't just answer questions: they act at machine speed, invoke tools, move data, and make decisions. But the infrastructure connecting them was designed for humans.
AI multiplies attack velocity
A compromised agent exfiltrates data before a human can react
Network perimeters no longer contain
VPNs and firewalls grant access to the entire network, not just what's needed
Regulation demands more controls
DORA, AI Act, AML require governance that traditional infra can't deliver
The "connectivity tax" slows innovation
Each new agent requires coordinating NAT, firewalls, VLANs, and approvals
In BlueUP's architecture, without a valid cryptographic identity, no data path exists. Services are dark by default. Identity and policy decide whether a connection can exist.
BlueUP isn't standalone products: it's an integrated platform where each layer reinforces the others.
Connectivity starts with identity, not the network.
Services have no public IP, don't respond to port scans and don't appear on Shodan: they only exist for authenticated identities whose policy matches. Every agent, service and person carries a verifiable cryptographic identity, and a data path is granted only when policy agrees; without that identity, there is no path. The substrate is OpenZiti, the open-source platform with encrypted tunnels and dark services, on which BlueUP, an official NetFoundry partner, offers self-hosted deployment or managed connectivity. Users work through BlueUP Connect, the desktop client that surfaces only their authorized services. See the technical architecture.
Regulatory compliance is built into the architecture by design, not bolted on afterwards.
BlueUPALM delivers banking-grade AML/DORA compliance across nine integrated modules: a screening engine with fuzzy matching against EU, OFAC and UN lists, a ten-state SEPBLAC legal workflow with automatic F19 generation, and DORA incident management with regulatory timers. ComplianceView adds continuous monitoring with 96 controls aligned to NIST, ISO 27001, DORA and FINOS, gathered by automated collectors. For a platform like this, DORA, AML, the AI Act and GDPR are architectural requirements, not add-ons.
Business logic runs on controlled infrastructure, with institutional-grade performance.
The BlueUP Core engine, written in Rust, runs multi-GAAP accounting (Sectoral, IFRS and Tax) at 150,657 journals/sec (benchmark of 2026-07-02: 10,000 events with three journals each, in-memory, on a Mac mini with a 6-core Intel Core i5-8500B and 8 GB), on a base of 11 crates and 1,320 tests. The platform services are deployed under the gVisor sandbox (runtimeClass), with kernel-level isolation. Governance for AI agents is in design on that same infrastructure: an MCP Gateway that decides which tools each agent may invoke, by identity and policy, and an LLM Gateway that controls access to language models with human approval points for high-risk actions. More in the technical architecture.
The platform applies with different building blocks and priorities depending on the regulated industry:
BlueUPALM automates the complete regulatory compliance lifecycle, from transactional data ingestion to official supervisor communication.
ComplianceView continuously monitors your organization's regulatory compliance posture.
Our Zero Trust connectivity substrate is built on OpenZiti, the open-source platform developed by NetFoundry. As official partners, we offer both self-hosted deployment and managed connectivity.
| Layer | Technologies |
|---|---|
| Frontend | React, TypeScript, CSS Modules |
| Backend | Rust (Axum), Python (FastAPI), NATS JetStream |
| Security | OpenZiti, Keycloak, SPIRE, OPA, Biscuit Tokens |
| AI & Data | Vertex AI, MCP SDK, vLLM / Ollama (sovereign) |
| Infrastructure | Google Cloud, Kubernetes, Terraform, Gitea Actions, Cilium, gVisor |
Does your organization need Zero Trust infrastructure for agentic AI, AML/DORA compliance, or VPN-free access?