Skip to content

About us

BlueUP: Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.Read more → Zero Trust infrastructure for regulated industries

Our mission

BlueUP was founded with a clear objective: to build the trust infrastructure that enables regulated organizations to adopt agentic AI without compromising security, compliance, or data sovereignty.

We're not another cybersecurity product. We're the identity, governance, and compliance layer that makes it possible for banks, insurers, and fintech to deploy autonomous AI agents securely and in compliance.

The problem we solve

Agentic AI has changed the rules. Autonomous agents act at machine speed, but the infrastructure connecting them was designed for humans. Regulated entities face unprecedented pressure:

ChallengeImpact
AI without governanceAgents process sensitive data, invoke tools, and make decisions without adequate controls
Growing regulationDORA, AML, AI Act, GDPR demand controls that traditional infrastructure can't deliver
Obsolete perimetersVPNs and firewalls grant access to the entire network: AI shortens the path from exposure to impact
"Connectivity tax"Each new agent requires coordinating NAT, firewalls, VLANs, and approvals, slowing innovation

Our approach: Identity-first

Fundamental principle

Without a valid cryptographic identity, no data path exists. Services are dark by default. Identity and policy decide whether a connection can exist.

Three design pillars:

  1. Identity as Perimeter — Security doesn't depend on server location, but on the verifiable cryptographic identity of every human, agent, and machine.
  2. Dynamic Privileges — AI proposes actions, but governance policies and human intervention act as intelligent security brakes.
  3. Minimum Blast Radius — Granular isolation (Cilium + gVisor is an open-source container sandbox: an application kernel in user space intercepts system calls and separates the workload from the host kernel. In banking and insurance it limits the blast radius of a compromised container. BlueUP Core declares it as the runtimeClass of its Kubernetes deployment.Read more → gVisor) ensures a compromise in one component never translates to a systemic breach.

Integrated platform

BlueUP isn't standalone products: it's a three-layer platform where each layer reinforces the others.

Layer 1: Zero Trust Reachability

Identity-first connectivity on OpenZiti is NetFoundry's open-source connectivity substrate: X.509 identity, end-to-end encryption and dark services with no inbound ports or public IP. VPN replacement is one of its use cases: identity is authorized before any data path exists. At BlueUP it underpins Zero Trust reachability.Read more → OpenZiti/NetFoundry is the company that created and maintains OpenZiti, the open-source Zero Trust connectivity substrate, and counts Cisco Investments among its investors. A regulated entity uses it to keep services off the public internet. BlueUP is an official partner offering self-hosted deployment or managed connectivity.Read more → NetFoundry. Dark services by default. BlueUP Connect desktop client. → View BlueUP Connect

Layer 2: Compliance & Governance

BlueUPALM (banking-grade Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027.Read more → AML/DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA) + ComplianceView (98 controls, continuous monitoring). → View BlueUPALM | View ComplianceView

Layer 3: Sovereign Execution

BlueUP Core (financial engine in Rust, 150,657 journals/sec (benchmark of 2026-07-02: 10,000 events with three journals each, in-memory, on a Mac mini with a 6-core Intel Core i5-8500B and 8 GB)) + MCP (Model Context Protocol) is an open standard, hosted by the Agentic AI Foundation at the Linux Foundation, that standardizes how AI applications access external tools and data. In banking and insurance it is where the host controls what an agent invokes. At BlueUP, MCP gateway governance is on the roadmap.Read more → MCP/LLM gateways, in design, for tool and AI model governance. → View Technology

Technology partner: NetFoundry

Our Zero Trust connectivity substrate is built on OpenZiti, the open-source platform developed by NetFoundry. As official partners, we offer both self-hosted deployment and managed connectivity.

NetFoundry is backed by investors including Cisco Investments and partners like Stellar Cyber and Intrusion.

Technology stack

We work with cutting-edge technologies selected for their robustness in critical environments:

LayerTechnologies
FrontendReact, TypeScript
BackendRust (ultra-low latency), Python (AI orchestration)
SecurityOpenZiti (Zero Trust), Keycloak (identity), Biscuit Tokens (offline authorization)
AI & DataVertex AI, vLLM, PostgreSQL, NATS JetStream
InfrastructureGoogle Cloud, Kubernetes (Talos Linux), Terraform, Gitea Actions

Contact

Does your organization need Zero Trust infrastructure for agentic AI, AML/DORA compliance, or VPN-free access?

Request a personalized demo

Last updated: