Skip to content

BlueUP Connect

Preview

Your digital identity in the private network. No VPN, no configuration, no friction.

Access with no VPN and identity validated on every request

BlueUP Connect is a lightweight Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.Read more → Zero Trust desktop access client. Once your administrator approves your access request, the client automatically displays all the services you are authorized to use — web applications, analytics tools, dashboards — and opens them with a single click.

It is not a VPN. It does not install network drivers. It does not expose any port to the outside. Every connection is cryptographically encrypted and the user's identity is validated on every request.


Users only see what they are authorized to access

Traditional remote access solutions (VPN, SSH tunnels, bastion hosts) have three fundamental problems:

Complex configuration

Hours of IT support per user, frequent errors.

Excessive privileges

VPN grants access to the entire network, not just what is needed.

No visibility

You don't know who accesses what, or when.

BlueUP Connect inverts this paradigm: users only see exactly what they are authorized to access.


From request to first access in three steps

1. Every request leaves a ticket and a justification

BlueUP Connect is installed with assistance during a guided demo. On the workstation, the user enters their email and submits an access request with justification. The system generates a ticket (#REQ-XXXX) and notifies the administrator.

Assisted BlueUP Connect install
"Request access"
email + name + justification
Ticket submitted — awaiting approval

2. Approval provisions the identity automatically

The administrator reviews and approves the request in the administration panel. The system automatically provisions a unique cryptographic identity for the user and delivers it to the client.

Admin approves in BlueUPALM panel
System generates Ziti identity + certificate
Client receives credential automatically
Silent enrollment — no user intervention required

3. Each user sees their own personalized service catalog

The client connects and displays the personalized catalog of services authorized for that user. The catalog refreshes on identity connection and on user request.

BlueUP Connect● Online
BlueUPALM — Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027.Read more → AML PlatformOpen ↗
Grafana — ObservabilityOpen ↗
Kibana — Audit LogsOpen ↗
Administration PanelNo access

● Available · ○ Not authorized


Tailored access for employees, contractors, and auditors

Day-to-day tools, one click away

A compliance analyst accesses the AML platform, Grafana, and audit logs daily. With BlueUP Connect, they open the client and everything is available with one click — no VPN, no IP addresses to remember, no configuration.

Contractor access is revoked when the term expires

An identity is created with an expiration of N days. The contractor receives the client already installed and restricted access to exactly the services they need. When the deadline expires, access is automatically revoked.

Read-only for the auditor, under strict policy

The auditor needs read-only access to Grafana and audit records. They are provisioned with strict policies. The client shows exactly the authorized services — not one more.


Less privilege and more auditing than a VPN

FeatureTraditional VPNBlueUP Connect
Network visibilityFull subnet accessOnly explicitly authorized services
User configurationManual (split tunneling, routes, DNS)Automatic after enrollment
Access revocationChange password / deactivate userCryptographic, no password logs; the client marks a service as revoked when the overlay stops reporting it
AuditingFirewall logs, hard to correlateEvery access logged with verified identity
Security modelNetwork perimeterZero Trust — no perimeter

Platforms supported today and how it is installed

PlatformStatus
🍎 macOS (Intel + Apple Silicon)In testing
🪟 Windows (x64)Planned
🐧 LinuxOn roadmap

There is no public signed binary. The desktop distribution has been frozen since 2026-08-20 and the client is installed with assistance during a guided demo.


Declared limits

This list covers what BlueUP Connect does not yet do, or does only in part, and separates what is operational from what remains on the roadmap.

  • Binary distribution: macOS and Windows builds are manual. The build and release jobs in the pipeline are disabled because no build runner is registered, so tagging a version generates no downloadable package today: automatic binary publication is roadmap.
  • Desktop client merge: the target architecture is a single desktop binary with BlueUPALM and portal profiles. The merge has an enumerated trigger and proceeds only with a real consumer, for example a deployment to real workstations or an explicit customer requirement: until then the desktop distribution remains frozen as of 2026-08-20.
  • Audit reporting: the access decision log chained with SHA-256 is operational and detects modification or deletion of lines, in a local file on the workstation with 0600 permissions. Forwarding to a SIEM or to a supervisory authority is not wired: it is roadmap.
  • Service catalog: the catalog is a static YAML versioned in the infrastructure repository. Adding a service requires a change in that repository and reaches the workstation the next time the client refreshes the catalog. Automatic periodic refresh and managing the catalog from the client itself are roadmap.
  • Per-service availability signal: the cross-check between the catalog and the services the overlay reports is modelled and covered by tests. On the live path the client emits a fixed interceptor signal today, so per-service availability is not resolved on the workstation: the dashboard on this page describes the target flow, not a production install.
  • Enrollment: access depends on prior approval in the BlueUPALM panel and on a provisioning credential fixed at build time. There is no self-service sign-up: the client does not operate independently of that platform.

Talk to our team

The client is installed with assistance during a guided demo.

Request a personalized demo

Last updated: