Infrastructure for fintech & agentic AI
Fintech companies and organizations deploying autonomous AI agents face a dilemma: agents need access to data, tools, and services to be useful, but every access point is a potential attack surface.
Risks the traditional network cannot contain
| Challenge | Risk |
|---|---|
| Agents with broad access | Each agent needs access to APIs, databases, and tools. Without granular control, the attack surface grows exponentially. |
| Machine speed | A compromised agent can exfiltrate data, escalate privileges, and move laterally before a human can react. |
| Compliance without slowing innovation | DORA, AI Act, GDPR demand controls that traditional infrastructure (firewalls, VPNs) cannot deliver without creating bottlenecks. |
| "Connectivity tax" | Each new agent or service requires coordinating routing, NAT, firewalls, VLANs, and approvals. This slows deployment. |
AI agents with Zero Trust, without rebuilding the network
BlueUP provides the infrastructure layer that enables deploying AI agents with native Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.Read more → Zero Trust security, without rebuilding the existing network.
1. No identity, no route to the service (BlueUP Connect)
Services published over OpenZiti are dark by default. No public IP, no response to scans, non-existent for anyone without a valid cryptographic identity.
- No VPN: Agents connect through identity-first encrypted tunnels
- No open ports: Those services are "dark" until policy creates the path
- Multi-environment: Works over existing networks, clouds, Kubernetes, edge, and third-party
→ BlueUP Connect (Zero Trust desktop client)
2. Only the authorized tools (layer in design)
Agents will only be able to discover and invoke tools for which they have explicit authorization. This layer is in design, not implemented today:
- MCP (Model Context Protocol) is an open standard, hosted by the Agentic AI Foundation at the Linux Foundation, that standardizes how AI applications access external tools and data. In banking and insurance it is where the host controls what an agent invokes. At BlueUP, MCP gateway governance is on the roadmap.Read more → MCP Gateway (in design): Will control which tools are reachable by identity and policy
- LLM Gateway (in design): Will govern access to language models with human approval
- Auditability: Every tool invocation will be logged with identity, action, and result
3. A compromised agent does not take the rest with it
If an agent is compromised, impact is contained:
- gVisor is an open-source container sandbox: an application kernel in user space intercepts system calls and separates the workload from the host kernel. In banking and insurance it limits the blast radius of a compromised container. BlueUP Core declares it as the runtimeClass in its Kubernetes manifest.Read more → gVisor sandbox: Kernel-level isolation of the platform application services (runtimeClass gvisor), the triage agent included
- Deny-by-default: Agent can only communicate with approved destinations
- Kill switch: Automated containment on anomalous behavior
- Identity-bound telemetry: Every action produces auditable evidence
4. What it contributes to DORA, AI Act, and GDPR
| Regulation | What BlueUP contributes |
|---|---|
| DORA | Incident classification, deadline calculation and a draft initial report; submission to the supervisor is roadmap |
| AI Act | A person sets the triage priority; auditing the model's reasoning is roadmap |
| GDPR | mTLS encryption, European infrastructure (AI triage uses an external model provider); minimization of the client identifier in design |
| AML/CFT | Operational sanctions screening and F19 download as PDF; generating and submitting the DMO file are roadmap |
Compliance remains the entity's responsibility: the platform contributes capabilities, it does not replace it. The detail per requirement is in regulatory compliance.
Why BlueUP vs. a point solution?
| Feature | Point solution | BlueUP |
|---|---|---|
| Security model | Filter on existing network | Identity is the network |
| Deployment | Requires infrastructure changes | Over existing infrastructure |
| Scope | Network only, model only, or API only | Integrated platform: network + compliance + governance |
| Compliance | Bolted on | On the same platform as the network and governance, with its declared limits |
Connectivity on open source: OpenZiti and NetFoundry
Our Zero Trust connectivity substrate is built on OpenZiti, the open-source platform developed by NetFoundry. NetFoundry is the company that created and maintains OpenZiti, the open-source Zero Trust connectivity substrate, and counts Cisco Investments among its investors. A regulated entity uses it to keep services off the public internet. BlueUP is an official partner offering self-hosted deployment or managed connectivity.Read more → NetFoundry is our strategic partner for customers who need managed connectivity, backed by investors including Cisco.
Technical whitepaper
Download our complete analysis on identity-first architecture for agentic AI, with detailed attack scenarios and the 5 technical controls.
Talk to our team
A demo shows the Zero Trust infrastructure for AI agents running over the existing network.