BlueUPALM — AML/DORA
Banking-grade regulatory compliance platform. Money laundering detection, DORA incident management and automated SEPBLAC communications. Native Zero Trust architecture.
View product
We design and build cybersecurity platforms, regulatory compliance and intelligent agent orchestration. Native Zero Trust. Data sovereignty. AI Governance.
Technology Stack & Partners
A model that decouples the governance plane from the execution plane, combining centralized control with ultra-low latency at the edge.
| Phase | Component | Description |
|---|---|---|
| Decision | Hybrid Identity | Keycloak (humans) + SPIRE SVIDs (workloads). No static API keys. |
| Decision | OPA Policy Engine | Real-time centralized evaluation at every critical control point. |
| Decision | Sovereign LLM | vLLM / Ollama — processing never leaves the controlled infrastructure. |
| Execution | Biscuit Tokens | Capability tokens with cryptographic proof of master authorization. |
| Execution | Async Attenuation | Agents restrict privileges locally but never escalate them. |
| Execution | Edge Verification | Local public key — zero latency and full offline operability. |
BlueUPALM automates the complete regulatory compliance lifecycle — from transactional data ingestion to official supervisor communication — with Zero Trust architecture, AML engine and DORA incident management.
IDColab enables automotive workshops to share repair information, inventory and billing with external collaborators (assessors, insurers, suppliers) securely and without exposing their internal systems to the internet.
| Layer | Technologies |
|---|---|
| Frontend | React, Angular, TypeScript, CSS Modules |
| Backend | Rust (Axum), Python (FastAPI), Quarkus + Camel, NATS |
| Security | OpenZiti, Keycloak, SPIRE, OPA, Biscuit Tokens |
| Data & AI | Vertex AI, MCP SDK, Trino, Qdrant, PostgreSQL |
| Infrastructure | Google Cloud, Cloud Run, Docker, Terraform, GitHub Actions, Cilium, gVisor |
| Pillar | Description |
|---|---|
| Identity as Perimeter | Security doesn't depend on server location, but on the cryptographic identity of humans and machines. |
| Dynamic Privileges | AI proposes, but OPA policies and human intervention act as intelligent security brakes. |
| Minimum Blast Radius | Isolation with Cilium and gVisor sandboxes: a compromise in one agent never translates into a systemic breach. |
Does your organization need Zero Trust infrastructure, AML compliance or want to explore multi-agent orchestration with AI?