BlueUP Connect
Your digital identity in the private network. No VPN, no configuration, no friction.
Access with no VPN and identity validated on every request
BlueUP Connect is a lightweight Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.Read more → Zero Trust desktop access client. Once your administrator approves your access request, the client automatically displays all the services you are authorized to use — web applications, analytics tools, dashboards — and opens them with a single click.
It is not a VPN. It does not install network drivers. It does not expose any port to the outside. Every connection is cryptographically encrypted and the user's identity is validated on every request.
Users only see what they are authorized to access
Traditional remote access solutions (VPN, SSH tunnels, bastion hosts) have three fundamental problems:
Complex configuration
Hours of IT support per user, frequent errors.
Excessive privileges
VPN grants access to the entire network, not just what is needed.
No visibility
You don't know who accesses what, or when.
BlueUP Connect inverts this paradigm: users only see exactly what they are authorized to access.
From request to first access in three steps
1. Every request leaves a ticket and a justification
BlueUP Connect is installed with assistance during a guided demo. On the workstation, the user enters their email and submits an access request with justification. The system generates a ticket (#REQ-XXXX) and notifies the administrator.
2. Approval provisions the identity automatically
The administrator reviews and approves the request in the administration panel. The system automatically provisions a unique cryptographic identity for the user and delivers it to the client.
3. Each user sees their own personalized service catalog
The client connects and displays the personalized catalog of services authorized for that user. The catalog refreshes on identity connection and on user request.
● Available · ○ Not authorized
Tailored access for employees, contractors, and auditors
Day-to-day tools, one click away
A compliance analyst accesses the AML platform, Grafana, and audit logs daily. With BlueUP Connect, they open the client and everything is available with one click — no VPN, no IP addresses to remember, no configuration.
Contractor access is revoked when the term expires
An identity is created with an expiration of N days. The contractor receives the client already installed and restricted access to exactly the services they need. When the deadline expires, access is automatically revoked.
Read-only for the auditor, under strict policy
The auditor needs read-only access to Grafana and audit records. They are provisioned with strict policies. The client shows exactly the authorized services — not one more.
Less privilege and more auditing than a VPN
| Feature | Traditional VPN | BlueUP Connect |
|---|---|---|
| Network visibility | Full subnet access | Only explicitly authorized services |
| User configuration | Manual (split tunneling, routes, DNS) | Automatic after enrollment |
| Access revocation | Change password / deactivate user | Cryptographic, no password logs; the client marks a service as revoked when the overlay stops reporting it |
| Auditing | Firewall logs, hard to correlate | Every access logged with verified identity |
| Security model | Network perimeter | Zero Trust — no perimeter |
Platforms supported today and how it is installed
| Platform | Status |
|---|---|
| 🍎 macOS (Intel + Apple Silicon) | In testing |
| 🪟 Windows (x64) | Planned |
| 🐧 Linux | On roadmap |
There is no public signed binary. The desktop distribution has been frozen since 2026-08-20 and the client is installed with assistance during a guided demo.
Declared limits
This list covers what BlueUP Connect does not yet do, or does only in part, and separates what is operational from what remains on the roadmap.
- Binary distribution: macOS and Windows builds are manual. The build and release jobs in the pipeline are disabled because no build runner is registered, so tagging a version generates no downloadable package today: automatic binary publication is roadmap.
- Desktop client merge: the target architecture is a single desktop binary with BlueUPALM and portal profiles. The merge has an enumerated trigger and proceeds only with a real consumer, for example a deployment to real workstations or an explicit customer requirement: until then the desktop distribution remains frozen as of 2026-08-20.
- Audit reporting: the access decision log chained with SHA-256 is operational and detects modification or deletion of lines, in a local file on the workstation with 0600 permissions. Forwarding to a SIEM or to a supervisory authority is not wired: it is roadmap.
- Service catalog: the catalog is a static YAML versioned in the infrastructure repository. Adding a service requires a change in that repository and reaches the workstation the next time the client refreshes the catalog. Automatic periodic refresh and managing the catalog from the client itself are roadmap.
- Per-service availability signal: the cross-check between the catalog and the services the overlay reports is modelled and covered by tests. On the live path the client emits a fixed interceptor signal today, so per-service availability is not resolved on the workstation: the dashboard on this page describes the target flow, not a production install.
- Enrollment: access depends on prior approval in the BlueUPALM panel and on a provisioning credential fixed at build time. There is no self-service sign-up: the client does not operate independently of that platform.
Talk to our team
The client is installed with assistance during a guided demo.