Skip to content

BlueUPALM: banking-grade AML/DORA platform

Available

Application for the analysis and detection of information potentially derived from money laundering. It implements a Hybrid Asynchronous Authorization architecture that combines centralized governance with decentralized execution at the edge.

The platform in action, in four minutes

BlueUPALM: AML/DORA Commercial Presentation

View full presentation with scene index

One system for compliance, IT and audit

Compliance Officers

Analysts investigating suspicious activity and managing Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027.Read more → AML alerts.

System Administrators

IT staff managing access policies, hybrid auth and edge deployments.

External Auditors

Regulators reviewing compliance logs and immutable audit trails.

Detect at the edge without losing the audit trail

Real-time threat detection

Identify and block suspicious transactions with ultra-low latency.

Immutable auditing

Maintain cryptographic logs of all actions and decisions for compliance.

Secure edge operations

Enable autonomous agent operations in decentralized environments securely.

See the risk, read the policy, control who has access

  • Risk Dashboards — Visual analytics of flagged transactions and risk scores
  • Policy Management UI — Read-only view of the centralized Cerbos policies (application layer), versioned through GitOps
  • Identity & Access Control — Granular control over Ziti identities (device provisioning and approval), Keycloak users and network access

Low latency, outage tolerance and data sovereignty

Ultra-Low Latency

Edge verification with minimal delay in transaction processing.

High Resilience

System must remain operational during network fluctuations (offline capability).

Data Sovereignty

Sensitive PII and financial data never leaves authorized perimeters.

Declared limits

What BlueUPALM does not do yet, or does only in part, with the status its source repository gives it: operational, modelled or roadmap.

  • AI triage governance: validation of every agent decision against the Cerbos policy engine (PDP) is operational when CERBOS_URL points to a deployed Cerbos, as in the reference stack. Without that variable, the agent resolves with embedded local rules, a development fallback that is neither the PDP nor the versioned policy; with the variable set, a connection failure to the PDP degrades to the same fallback request by request.
  • Model reasoning audit: roadmap. Reasoning-trace capture for the LLM (Langfuse) is in the design and has no deployment.
  • Agent service identity: modelled. SPIFFE/SPIRE is present in the triage agent configuration, but the identity it presents to the PDP is the literal ai-triage-agent, not an SVID issued by SPIRE.
  • Policy management from the interface: modelled. The Cerbos policy editor and policy list exist as read-only components and are mounted today only in the screenshot application, not in the main application routing.
  • Sanctions screening: operational with a local three-level matching engine (exact, alias and fuzzy) and EU, OFAC and UN list updates from OpenSanctions. Integration with commercial list providers (Dow Jones, Refinitiv) is roadmap.
  • DMO reporting to SEPBLAC: the API exposes DMO file queries and F19 PDF downloads; the frontend DMO management screens read demonstration data, and generating the file and submitting it to the Servicio Ejecutivo are roadmap: what exists today is the typed data model of the DMO file and its operations, and the special examination flow that leaves the case marked as generated.
  • DORA incident reporting to the supervisor: the platform classifies the incident, generates the initial report draft (ITS 2025/302, Annex I) in PDF and XML and computes the 4-hour, 72-hour and 30-day deadlines; submission to the competent supervisor is roadmap.

Next steps to evaluate BlueUPALM

Commercial Demo

4-minute video presentation covering all features. → View demo

Regulatory Compliance

DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA, SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC, The GDPR (General Data Protection Regulation) is Regulation (EU) 2016/679 on data protection, applicable since 25 May 2018. It reaches every entity established in the EU and anyone outside it offering goods or services to people in the Union or monitoring their behavior. Fines run up to 20,000,000 EUR or 4%.Read more → GDPR and The AI Act is Regulation (EU) 2024/1689, the European risk-based framework for AI: it bans unacceptable uses, regulates high-risk systems and requires transparency from general-purpose models. Its high-risk regime covers credit scoring and life and health insurance pricing from 2 December 2027 (Reg. 2026/1744).Read more → AI Act — full coverage.

View compliance

Screenshots

Full BlueUPALM frontend gallery with Dark Glassmorphism design. → View screenshots

Request Demo

Personalized 30-45 minute session adapted to your sector and use case. → Request demo

See the real interface before the demo

Dashboard

Login


Talk to our team

The demo walks through BlueUPALM in a 30-45 minute session adapted to the institution's sector and use case.

Request a personalized demo

Last updated: