Skip to content

Trust Center

This page gathers what BlueUP can substantiate about the security of its platform and of this website. The statements about the platform and about this website were checked on 23 September 2026 against the platform code, against the configuration of its reference deployment and against that of this website.

Certification status

As of 23 September 2026, BlueUP holds no security certification issued by a third party: neither ISO 27001 nor SOC 2. This page will only publish a certification together with its certificate number and its issuing body.

The standards BlueUP applies in its products are described under regulatory compliance; applying a standard is not the same as being certified.

Platform security architecture

The platform has a reference deployment on Kubernetes, defined in its infrastructure repository. In that deployment:

  • The BlueUPALM and ComplianceView application services run on the gVisor isolation runtime.
  • Traffic between the cluster's worker nodes travels encrypted with WireGuard.
  • The secrets of the BlueUPALM application services are stored in Google Cloud Secret Manager.
  • Disaster recovery backups of the cluster state are stored encrypted with a Cloud KMS key managed by BlueUP.

In BlueUPALM, users authenticate with OpenID Connect against Keycloak.

Processing data on behalf of client organizations

When BlueUP operates the platform on behalf of an organization, that organization is the controller of its data and BlueUP acts as processor, under Article 28 of the GDPR.

This website

This website sets no cookies and loads no analytics, advertising or tracking scripts. It does keep data in the browser's storage: the color theme (light or dark), from the first visit, and, if the search is used, the results view and the search text, the latter until the tab is closed. The only third-party content is YouTube videos: their thumbnails load with the page and the player only when play is pressed. The player runs inside a YouTube frame whose connections, cookies and storage are managed by Google, not by this website. The site's Content Security Policy (CSP) limits the external connections of its pages to these services:

  • i.ytimg.com: YouTube video thumbnails, when the page shows a video.
  • www.youtube-nocookie.com: YouTube player, only when play is pressed.
  • www.youtube.com: YouTube player redirects, only when play is pressed.
  • europe-west1-homelab-466309.cloudfunctions.net: receiver for the site's forms, only when a form is submitted.

Vulnerability disclosure

Vulnerabilities are reported to info@blueup.es, the contact published in this website's security.txt file under RFC 9116.

To review this information as part of a vendor assessment: Request a demo.

Last updated: