Request a personalized demo

Tell us about your organization and we'll contact you to schedule the demo.

Skip to content

Zero Trust infrastructure for agentic AIAI agents in production without opening a port or rebuilding the network

Identity decides every data path: banks, insurers and fintechs deploy agents with AML and DORA compliance built in.

AI GovernanceLayer 3 · MCP/LLM gateways
Compliance & GovernanceLayer 2 · DORA, AML, AI Act
Zero Trust AccessibilityLayer 1 · OpenZiti / NetFoundry
  • 150,657journals/sec · BlueUP Core, benchmark 2026-07-02
  • 98compliance controls · ComplianceView
  • 9integrated AML modules · BlueUPALM
  • Zeropublic IPs · services invisible by default
Connectivity substrate
NetFoundryOpenZiti

Official partner of NetFoundry, which is backed by Cisco Investments

The problem

Agentic AI has changed the rules. Autonomous agents don't just answer questions: they act at machine speed, invoke tools, move data, and make decisions. But the infrastructure connecting them was designed for humans.

  • AI multiplies attack velocity

    A compromised agent exfiltrates data before a human can react

  • Network perimeters no longer contain

    VPNs and firewalls grant access to the entire network, not just what's needed

  • Regulation demands more controls

    DORA, AI Act, AML require governance that traditional infra can't deliver

  • The "connectivity tax" slows innovation

    Each new agent requires coordinating NAT, firewalls, VLANs, and approvals

Market context

3,383
major ICT incidents reported by EU financial entities in 2025 (ESAs, first DORA report, 2026)
€4.2 billion
of payment fraud reported across the EEA in 2024 (EBA and ECB, joint report, 2025)
6.5%
of the DORA registers of information analysed passed all quality checks (ESAs, 2024 dry run)
+76%
more suspicious activity reports reached Sepblac in 2024 than in 2023 (Sepblac, 2024 activity report)

The solution: identity before connectivity

In BlueUP's architecture, without a valid cryptographic identity, no data path exists. Services are dark by default. Identity and policy decide whether a connection can exist.


Three-layer platform

BlueUP isn't standalone products: it's an integrated platform where each layer reinforces the others.

Zero Trust reachability

Connectivity starts with identity, not the network.

Services have no public IP, don't respond to port scans and don't appear on Shodan: they only exist for authenticated identities whose policy matches. Every agent, service and person carries a verifiable cryptographic identity, and a data path is granted only when policy agrees; without that identity, there is no path. The substrate is OpenZiti, the open-source platform with encrypted tunnels and dark services, on which BlueUP, an official NetFoundry partner, offers self-hosted deployment or managed connectivity. Users work through BlueUP Connect, the desktop client that surfaces only their authorized services. See the technical architecture.

BlueUP Connect

Compliance and governance

Regulatory compliance is built into the architecture by design, not bolted on afterwards.

BlueUPALM delivers banking-grade AML/DORA compliance across nine integrated modules: a screening engine with fuzzy matching against EU, OFAC and UN lists, a ten-state SEPBLAC legal workflow with automatic F19 generation, and DORA incident management with regulatory timers. ComplianceView adds continuous monitoring with 96 controls aligned to NIST, ISO 27001, DORA and FINOS, gathered by automated collectors. For a platform like this, DORA, AML, the AI Act and GDPR are architectural requirements, not add-ons.

BlueUPALM · ComplianceView

Sovereign execution

Business logic runs on controlled infrastructure, with institutional-grade performance.

The BlueUP Core engine, written in Rust, runs multi-GAAP accounting (Sectoral, IFRS and Tax) at 150,657 journals/sec (benchmark of 2026-07-02: 10,000 events with three journals each, in-memory, on a Mac mini with a 6-core Intel Core i5-8500B and 8 GB), on a base of 11 crates and 1,320 tests. The platform services are deployed under the gVisor sandbox (runtimeClass), with kernel-level isolation. Governance for AI agents is in design on that same infrastructure: an MCP Gateway that decides which tools each agent may invoke, by identity and policy, and an LLM Gateway that controls access to language models with human approval points for high-risk actions. More in the technical architecture.

Agentic AI for fintech · BlueUP Core

Skip to resources

Solutions by industry

The platform applies with different building blocks and priorities depending on the regulated industry:

  • Private Banking — Enhanced KYC (Know Your Customer) is the sector name for customer due diligence under Directive (EU) 2015/849: identifying and verifying the customer, identifying the beneficial owner, assessing the relationship's purpose and monitoring it over time. It is completed before the relationship opens, with exceptions (Article 14).Read more → KYC onboarding, continuous screening and regulatory traceability for high-net-worth clients.
  • Insurance — Industry-specific AML compliance (life, pensions, non-life) with integrated SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC workflow.
  • Fintech & Agentic AI — Zero Trust governance for fintechs operating with autonomous agents and MCP.

Resources


BlueUPALM in action

BlueUPALM automates the complete regulatory compliance lifecycle, from transactional data ingestion to official supervisor communication.

  • 9 integrated modules: Dashboard, Clients, Alerts, Communications, DORA...
  • AML engine with fuzzy screening against EU, OFAC and UN lists
  • 10-state SEPBLAC legal workflow with automatic F19 (form F19-1) is the template an obliged entity uses to report to SEPBLAC any act or transaction with indications or certainty of money laundering or terrorist financing, under Article 18 of Spain's Law 10/2010 and after the special examination of Article 17. Its content and audit trail are reviewed in inspections.Read more → F19 generation
  • DORA incident management with regulatory timers
  • View full presentation | View documentation

ComplianceView in action

ComplianceView continuously monitors your organization's regulatory compliance posture.

  • 98 unified controls with cross-mapping to 4 regulatory frameworks
  • 11 automated collectors: Gitea, GitHub, Trivy, GCP, Docker, Kubernetes, NATS, GitHub Actions, AWS, Azure and GitLab CI
  • Weighted scoring by security zone with 30-day trending
  • View product | View compliance

Technology partner

Our Zero Trust connectivity substrate is built on OpenZiti, the open-source platform developed by NetFoundry. As official partners, we offer both self-hosted deployment and managed connectivity.

View full architecture


Tech stack

LayerTechnologies
FrontendReact, TypeScript, CSS Modules
BackendRust (Axum), Python (FastAPI), NATS JetStream
SecurityOpenZiti, Keycloak, SPIRE, OPA, Biscuit Tokens
AI & DataVertex AI, MCP SDK, vLLM / Ollama (sovereign)
InfrastructureGoogle Cloud, Kubernetes, Terraform, Gitea Actions, Cilium, gVisor

Contact

Does your organization need Zero Trust infrastructure for agentic AI, AML/DORA compliance, or VPN-free access?

Measure your DORA maturity