BlueUPALM: Commercial demo
Video presentation of BlueUPALM, the banking-grade platform for automating the complete regulatory compliance lifecycle (SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC/DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA).

Subtitles available
This video includes subtitles in Spanish and English. Enable them using the CC button on the YouTube player.
Video contents
| Scene | Time | Topic |
|---|---|---|
| 1 | 0:00 — 0:32 | The Problem — SEPBLAC/DORA regulatory pressure |
| 2 | 0:32 — 0:59 | The Solution — BlueUPALM centralized dashboard |
| 3 | 0:59 — 1:35 | Clients & Risk — 360° profiles, due diligence |
| 4 | 1:35 — 2:13 | AML Alert Engine — 7 indicators, four-eyes |
| 5 | 2:13 — 2:43 | Communications — DMO, F19, audit trail |
| 6 | 2:43 — 3:19 | DORA — Operational resilience, 4h/72h/1month timers |
| 7 | 3:19 — 3:57 | Architecture — Zero Trust microservices, NATS, Biscuit |
| 8 | 3:57 — 4:12 | Closing — CTA and operational sovereignty |
Key features
Zero Trust security
- OpenZiti is NetFoundry's open-source connectivity substrate: X.509 identity, end-to-end encryption and dark services with no inbound ports or public IP. VPN replacement is one of its use cases: identity is authorized before any data path exists. At BlueUP it underpins Zero Trust reachability.Read more → OpenZiti Dark Services — services invisible to the public network
- Biscuit is an open-source authorization token from the Eclipse Foundation, verified with public keys and attenuable offline: a narrower token derives from another with no call to the issuer. In banking and insurance it bounds delegation between services. BlueUPALM issues and attenuates it; BlueUP Core has it in design.Read more → Biscuit Tokens — offline cryptographic attenuation
- SPIRE (the SPIFFE Runtime Environment) is a production-ready implementation of the SPIFFE APIs and a CNCF graduated project: it issues each workload an SVID, a verifiable identity in X.509 or JWT form. In banking and insurance it replaces static credentials with short-lived, auto-rotating workload identity.Read more → SPIRE SVIDs — verifiable identity per workload
- End-to-end mTLS encryption
AML/CFT engine
- Screening against EU, OFAC and UN sanctions lists
- Fuzzy matching with Dice coefficient
- 360° KYC (Know Your Customer) is the sector name for customer due diligence under Directive (EU) 2015/849: identifying and verifying the customer, identifying the beneficial owner, assessing the relationship's purpose and monitoring it over time. It is completed before the relationship opens, with exceptions (Article 14).Read more → KYC profile with 8-factor risk analysis
- Four-Eyes principle for function segregation
DORA compliance
- Automatic incident classification (Minor/Significant/Major)
- Regulatory timers: 4h → 72h → 1 month
- ITS templates compatible with BdE, DGSFP and CNMV
- MTTD: 4 min | MTTR: 1 hour
SEPBLAC legal workflow
- 10-state Special Examination (Art. 17, Law 10/2010)
- Automatic F19 (form F19-1) is the template an obliged entity uses to report to SEPBLAC any act or transaction with indications or certainty of money laundering or terrorist financing, under Article 18 of Spain's Law 10/2010 and after the special examination of Article 17. Its content and audit trail are reviewed in inspections.Read more → F19 form generation
- Immutable cryptographic audit trail
Technical data
| Metric | Value |
|---|---|
| Functional modules | 9 |
| Security controls | 13 |
| Unit tests | 65/65 ✅ |
| Frontend stack | React 19 + Vite |
| Backend stack | FastAPI + NATS JetStream |
| Edge security | Rust + Biscuit |
| Infrastructure | Cloud-Native Kubernetes |
Screenshots
Full gallery of the BlueUPALM frontend with Dark Glassmorphism design. → View screenshots
Regulatory Compliance
DORA, SEPBLAC, The GDPR (General Data Protection Regulation) is Regulation (EU) 2016/679 on data protection, applicable since 25 May 2018. It reaches every entity established in the EU and anyone outside it offering goods or services to people in the Union or monitoring their behavior. Fines run up to 20,000,000 EUR or 4%.Read more → GDPR and The AI Act is Regulation (EU) 2024/1689, the European risk-based framework for AI: it bans unacceptable uses, regulates high-risk systems and requires transparency from general-purpose models. Its high-risk regime covers credit scoring and life and health insurance pricing from 2 December 2027 (Reg. 2026/1744).Read more → AI Act — full coverage. → View compliance
Interested?
Request a personalized demo for your organization. → Request demo