Compliance, Zero Trust and agentic AI glossary
Terms from financial regulation, anti-money laundering, Zero Trust identity and agentic AI as they are used on this site and in the BlueUP platform documentation. Each entry has a short definition, the primary source when the term is regulatory and, where one exists, a link to the page that covers it in depth. The same definitions appear as tooltips across the site.
Terms: AI Act · AML · Biscuit Tokens · DORA · F19 · FINOS · GDPR · gVisor · ISO 27001 · KYC · LLM · MCP · NetFoundry · NIST · OPA · OpenZiti · SEPBLAC · SPIRE · Zero Trust
European regulation
AI Act
The AI Act is Regulation (EU) 2024/1689, the European risk-based framework for AI: it bans unacceptable uses, regulates high-risk systems and requires transparency from general-purpose models. Its high-risk regime covers credit scoring and life and health insurance pricing from 2 December 2027 (Reg. 2026/1744).
Source: Regulation (EU) 2024/1689 consolidated (as amended by 2026/1744), EUR-Lex. Read more: Agentic AI and regulation: who answers when the agent acts alone.
DORA
DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.
Source: Regulation (EU) 2022/2554, EUR-Lex. Read more: DORA 2026: A practical guide for financial entities.
GDPR
The GDPR (General Data Protection Regulation) is Regulation (EU) 2016/679 on data protection, applicable since 25 May 2018. It reaches every entity established in the EU and anyone outside it offering goods or services to people in the Union or monitoring their behavior. Fines run up to 20,000,000 EUR or 4%.
Source: Regulation (EU) 2016/679, EUR-Lex. Read more: Regulatory compliance.
Anti-money laundering and supervision
AML
Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027.
Source: Law 10/2010, Spanish Official Gazette (BOE). Read more: Anatomy of agentic AI AML triage: what the machine decides.
F19
F19 (form F19-1) is the template an obliged entity uses to report to SEPBLAC any act or transaction with indications or certainty of money laundering or terrorist financing, under Article 18 of Spain's Law 10/2010 and after the special examination of Article 17. Its content and audit trail are reviewed in inspections.
Source: Suspicious transaction reporting (F19-1), sepblac.es. Read more: SEPBLAC software: automate AML reporting without losing traceability.
KYC
KYC (Know Your Customer) is the sector name for customer due diligence under Directive (EU) 2015/849: identifying and verifying the customer, identifying the beneficial owner, assessing the relationship's purpose and monitoring it over time. It is completed before the relationship opens, with exceptions (Article 14).
Source: Directive (EU) 2015/849, Articles 13 and 14, EUR-Lex. Read more: Private banking.
SEPBLAC
SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).
Source: About SEPBLAC, sepblac.es. Read more: SEPBLAC software: automate AML reporting without losing traceability.
Zero Trust and identity
Biscuit Tokens
Biscuit is an open-source authorization token from the Eclipse Foundation, verified with public keys and attenuable offline: a narrower token derives from another with no call to the issuer. In banking and insurance it bounds delegation between services. BlueUPALM issues and attenuates it; BlueUP Core has it in design.
Source: Eclipse Biscuit project, projects.eclipse.org. Read more: Technology: platform architecture.
gVisor
gVisor is an open-source container sandbox: an application kernel in user space intercepts system calls and separates the workload from the host kernel. In banking and insurance it limits the blast radius of a compromised container. BlueUP Core declares it as the runtimeClass of its Kubernetes deployment.
Source: gVisor official documentation (gvisor.dev). Read more: Technology: platform architecture.
NetFoundry
NetFoundry is the company that created and maintains OpenZiti, the open-source Zero Trust connectivity substrate, and counts Cisco Investments among its investors. A regulated entity uses it to keep services off the public internet. BlueUP is an official partner offering self-hosted deployment or managed connectivity.
Source: Cisco Investments, NetFoundry portfolio page. Read more: Technology: platform architecture.
OPA
OPA (Open Policy Agent) is an open source policy engine and a graduated CNCF project that decouples policy decisions from their enforcement and expresses them in the Rego language. In banking and insurance it allows access rules to be versioned and audited as code.
Source: Open Policy Agent, official documentation. Read more: Technology: platform architecture.
OpenZiti
OpenZiti is NetFoundry's open-source connectivity substrate: X.509 identity, end-to-end encryption and dark services with no inbound ports or public IP. VPN replacement is one of its use cases: identity is authorized before any data path exists. At BlueUP it underpins Zero Trust reachability.
Source: OpenZiti official page (NetFoundry). Read more: Technology: platform architecture.
SPIRE
SPIRE (the SPIFFE Runtime Environment) is a production-ready implementation of the SPIFFE APIs and a CNCF graduated project: it issues each workload an SVID, a verifiable identity in X.509 or JWT form. In banking and insurance it replaces static credentials with short-lived, auto-rotating workload identity.
Source: spiffe.io, official SPIRE documentation. Read more: Technology: platform architecture.
Zero Trust
Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.
Source: NIST SP 800-207 (2020), csrc.nist.gov. Read more: Zero Trust in banking: Why VPNs are no longer enough.
Agentic AI
LLM
An LLM (large language model) is an AI model that generates and predicts natural-language text after training on large corpora. The AI Act classifies as high risk the systems that assess creditworthiness or price life and health insurance (Annex III). At BlueUP, LLM gateway governance is on the roadmap.
Source: Regulation (EU) 2024/1689 (AI Act), Annex III, EUR-Lex.
MCP
MCP (Model Context Protocol) is an open standard, hosted by the Agentic AI Foundation at the Linux Foundation, that standardizes how AI applications access external tools and data. In banking and insurance it is where the host controls what an agent invokes. At BlueUP, MCP gateway governance is on the roadmap.
Source: Linux Foundation, Agentic AI Foundation (press release).
Standards and bodies
FINOS
FINOS (Fintech Open Source Foundation) is the Linux Foundation umbrella organization that unites financial services to build open technology and standards. It hosts the Common Domain Model (CDM) and the SDLC Controls working group, whose controls ComplianceView integrates alongside NIST, ISO 27001 and DORA.
Source: Fintech Open Source Foundation, finos.org. Read more: ComplianceView.
ISO 27001
ISO 27001 (ISO/IEC 27001:2022) is the international standard from ISO and IEC with the requirements for an information security management system (ISMS) and its reference controls. An accredited body audits and certifies conformity, the evidence banking and insurance use to demonstrate risk control.
Source: ISO/IEC 27001:2022, IEC Webstore. Read more: ComplianceView.
NIST
NIST (National Institute of Standards and Technology) is the US federal agency within the Department of Commerce that publishes cybersecurity standards such as the Cybersecurity Framework and the SP 800 family. Banking and insurance adopt them as a control catalog; ComplianceView maps its controls to NIST SP 800-53r5.
Source: NIST, U.S. Department of Commerce. Read more: ComplianceView.
Next step
The DORA/SEPBLAC calculator scores maturity per pillar in two minutes, and the platform is shown in a guided demo on sample data.