About us
Our mission
BlueUP was founded with a clear objective: to build the trust infrastructure that enables regulated organizations to adopt agentic AI without compromising security, compliance, or data sovereignty.
We're not another cybersecurity product. We're the identity, governance, and compliance layer that makes it possible for banks, insurers, and fintech to deploy autonomous AI agents securely and in compliance.
The problem we solve
Agentic AI has changed the rules. Autonomous agents act at machine speed, but the infrastructure connecting them was designed for humans. Regulated entities face unprecedented pressure:
| Challenge | Impact |
|---|---|
| AI without governance | Agents process sensitive data, invoke tools, and make decisions without adequate controls |
| Growing regulation | DORA, AML, AI Act, GDPR demand controls that traditional infrastructure can't deliver |
| Obsolete perimeters | VPNs and firewalls grant access to the entire network: AI shortens the path from exposure to impact |
| "Connectivity tax" | Each new agent requires coordinating NAT, firewalls, VLANs, and approvals, slowing innovation |
Our approach: Identity-first
Fundamental principle
Without a valid cryptographic identity, no data path exists. Services are dark by default. Identity and policy decide whether a connection can exist.
Three design pillars:
- Identity as Perimeter — Security doesn't depend on server location, but on the verifiable cryptographic identity of every human, agent, and machine.
- Dynamic Privileges — AI proposes actions, but governance policies and human intervention act as intelligent security brakes.
- Minimum Blast Radius — Granular isolation (Cilium + gVisor is an open-source container sandbox: an application kernel in user space intercepts system calls and separates the workload from the host kernel. In banking and insurance it limits the blast radius of a compromised container. BlueUP Core declares it as the runtimeClass of its Kubernetes deployment.Read more → gVisor) ensures a compromise in one component never translates to a systemic breach.
Integrated platform
BlueUP isn't standalone products: it's a three-layer platform where each layer reinforces the others.
Layer 1: Zero Trust Reachability
Identity-first connectivity on OpenZiti is NetFoundry's open-source connectivity substrate: X.509 identity, end-to-end encryption and dark services with no inbound ports or public IP. VPN replacement is one of its use cases: identity is authorized before any data path exists. At BlueUP it underpins Zero Trust reachability.Read more → OpenZiti/NetFoundry is the company that created and maintains OpenZiti, the open-source Zero Trust connectivity substrate, and counts Cisco Investments among its investors. A regulated entity uses it to keep services off the public internet. BlueUP is an official partner offering self-hosted deployment or managed connectivity.Read more → NetFoundry. Dark services by default. BlueUP Connect desktop client. → View BlueUP Connect
Layer 2: Compliance & Governance
BlueUPALM (banking-grade Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027.Read more → AML/DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA) + ComplianceView (98 controls, continuous monitoring). → View BlueUPALM | View ComplianceView
Layer 3: Sovereign Execution
BlueUP Core (financial engine in Rust, 150,657 journals/sec (benchmark of 2026-07-02: 10,000 events with three journals each, in-memory, on a Mac mini with a 6-core Intel Core i5-8500B and 8 GB)) + MCP (Model Context Protocol) is an open standard, hosted by the Agentic AI Foundation at the Linux Foundation, that standardizes how AI applications access external tools and data. In banking and insurance it is where the host controls what an agent invokes. At BlueUP, MCP gateway governance is on the roadmap.Read more → MCP/LLM gateways, in design, for tool and AI model governance. → View Technology
Technology partner: NetFoundry
Our Zero Trust connectivity substrate is built on OpenZiti, the open-source platform developed by NetFoundry. As official partners, we offer both self-hosted deployment and managed connectivity.
NetFoundry is backed by investors including Cisco Investments and partners like Stellar Cyber and Intrusion.
Technology stack
We work with cutting-edge technologies selected for their robustness in critical environments:
| Layer | Technologies |
|---|---|
| Frontend | React, TypeScript |
| Backend | Rust (ultra-low latency), Python (AI orchestration) |
| Security | OpenZiti (Zero Trust), Keycloak (identity), Biscuit Tokens (offline authorization) |
| AI & Data | Vertex AI, vLLM, PostgreSQL, NATS JetStream |
| Infrastructure | Google Cloud, Kubernetes (Talos Linux), Terraform, Gitea Actions |
Contact
Does your organization need Zero Trust infrastructure for agentic AI, AML/DORA compliance, or VPN-free access?