Technology
BlueUP is not a standalone product: it's an integrated platform in three layers designed so regulated organizations can adopt agentic AI without compromising security, compliance, or sovereignty.
Platform architecture
Tool and model
governance
Banking-grade regulatory
compliance
Identity-first connectivity
Dark services by default
Layer 1: Zero Trust reachability
The fundamental principle: without a valid cryptographic identity, no data path exists.
Services published over OpenZiti have no public IP, don't respond to port scans, don't appear on Shodan. They only "exist" for authenticated identities with matching policy.
OpenZiti
Open-source connectivity substrate: encrypted tunnels, dark services, service policy.
BlueUP Connect
Desktop client showing users only their authorized services.
Cryptographic identity
Every agent, service and human has a verifiable cryptographic identity.
Dark services
No inbound ports, no public IP, invisible to the internet.
Technology Partner: NetFoundry
Our connectivity substrate is built on OpenZiti, the open-source platform developed by NetFoundry. As an official NetFoundry partner, we offer both self-hosted deployment and managed connectivity for customers who require it.
NetFoundry is backed by investors including Cisco Investments and partners like Stellar Cyber and Intrusion for high-security environments.
Layer 2: Compliance and governance
Continuous monitoring and compliance capabilities on the same platform, not bolted on.
BlueUPALM
Banking-grade AML/DORA compliance: screening, incident management.
ComplianceView
98 controls aligned with NIST (National Institute of Standards and Technology) is the US federal agency within the Department of Commerce that publishes cybersecurity standards such as the Cybersecurity Framework and the SP 800 family. Banking and insurance adopt them as a control catalog; ComplianceView maps its controls to NIST SP 800-53r5.Read more → NIST, ISO 27001 (ISO/IEC 27001:2022) is the international standard from ISO and IEC with the requirements for an information security management system (ISMS) and its reference controls. An accredited body audits and certifies conformity, the evidence banking and insurance use to demonstrate risk control.Read more → ISO 27001, DORA, and FINOS (Fintech Open Source Foundation) is the Linux Foundation umbrella organization that unites financial services to build open technology and standards. It hosts the Common Domain Model (CDM) and the SDLC Controls working group, whose controls ComplianceView integrates alongside NIST, ISO 27001 and DORA.Read more → FINOS. Automated collectors.
OPA
Centralized access and infrastructure policy evaluation.
Cerbos PDP
Contextual ABAC/RBAC authorization for business logic.
Layer 3: Sovereign execution
Business logic runs on controlled infrastructure with institutional-grade performance.
BlueUP Core (financial engine in Rust)
11 crates, 1,320 tests, multi-GAAP accounting (Sectoral/IFRS/Tax), 150,657 journals/sec (benchmark of 2026-07-02: 10,000 events with three journals each, in-memory, on a Mac mini with a 6-core Intel Core i5-8500B and 8 GB).
MCP gateway (in design)
Layer in design, not implemented today: it will govern which tools agents can invoke, by identity and policy.
LLM gateway (in design)
Layer in design, not implemented today: it will control access to language models with human approval points.
gVisor is an open-source container sandbox: an application kernel in user space intercepts system calls and separates the workload from the host kernel. In banking and insurance it limits the blast radius of a compromised container. BlueUP Core declares it as the runtimeClass in its Kubernetes manifest.Read more → gVisor sandbox
Kernel-level isolation of the application services: runtimeClass gvisor on BlueUPALM (the triage agent included), on ComplianceView and on OPA.
Identity substrate
The entire system shares a unified identity model:
| Layer | Technology | Function |
|---|---|---|
| Humans | Keycloak OIDC/PKCE | Federated authentication without static passwords |
| Workloads | SPIRE SVIDs (X.509 or JWT) | Rotating cryptographic identity per service |
| Authorization | Biscuit Tokens | Authorization tokens with offline attenuation |
| Encryption | mTLS on the OpenZiti overlay; WireGuard between cluster nodes | Mutual verification on every overlay connection |
Complete technology stack
| Layer | Technologies |
|---|---|
| Frontend | React, TypeScript, CSS Modules |
| Backend | Rust (Axum), Python (FastAPI), NATS JetStream |
| Security | OpenZiti, Keycloak, SPIRE, OPA, Biscuit Tokens, Cerbos |
| AI & Data | External model provider (triage), MCP SDK; local or regional provider (vLLM / Ollama) in design |
| Infrastructure | Google Cloud, Kubernetes (Talos Linux), Terraform, Gitea Actions |
| Isolation | Cilium (network), gVisor (kernel), eBPF (observability) |
Design principles
Identity as perimeter
Security doesn't depend on server location, but on verifiable cryptographic identity.
Dynamic privileges
AI proposes, but OPA policies and human intervention act as security brakes.
Minimum blast radius
A compromise in one agent never translates to a systemic breach.
Compliance as an architectural requirement
DORA, AML, The AI Act is Regulation (EU) 2024/1689, the European risk-based framework for AI: it bans unacceptable uses, regulates high-risk systems and requires transparency from general-purpose models. Its high-risk regime covers credit scoring and life and health insurance pricing from 2 December 2027 (Reg. 2026/1744).Read more → AI Act and The GDPR (General Data Protection Regulation) is Regulation (EU) 2016/679 on data protection, applicable since 25 May 2018. It reaches every entity established in the EU and anyone outside it offering goods or services to people in the Union or monitoring their behavior. Fines run up to 20,000,000 EUR or 4%.Read more → GDPR are architectural requirements, not add-ons.
AI provider
Triage uses an external model provider; a local or regional provider is in design.
Application by industry
This architecture is applied differently depending on the regulated industry it serves. See operational details in:
- Private Banking — Enhanced KYC (Know Your Customer) is the sector name for customer due diligence under Directive (EU) 2015/849: identifying and verifying the customer, identifying the beneficial owner, assessing the relationship's purpose and monitoring it over time. It is completed before the relationship opens, with exceptions (Article 14).Read more → KYC, continuous screening and traceability for HNWI.
- Insurance — Insurance-specific AML with integrated SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC workflow.
- Fintech & Agentic AI — Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.Read more → Zero Trust governance for autonomous agents.
Reference material: DORA 2026 guide and DORA calculator.
Want to dive deeper into the architecture?
Download our technical whitepaper on identity-first architecture for agentic AI.