# BlueUP > BlueUP Technology construye infraestructura Zero Trust identity-first y compliance AML/DORA para banca, seguros y fintech en España y la UE. La cartera está en prelanzamiento: cada producto declara abajo su estado real y se enseña en demo guiada, no en descarga pública. ## Productos - BlueUPALM (AML/DORA), estado: Disponible. Plataforma AML/DORA de grado bancario: screening contra listas EU/OFAC/ONU, workflow SEPBLAC con F19 y gestión de incidentes DORA. https://www.blueup.es/es/bc/ - ComplianceView (Monitorización de compliance), estado: Disponible. Monitorización continua de 98 controles alineados a NIST, ISO 27001, DORA y FINOS, con recolectores automáticos y tendencia a 30 días. https://www.blueup.es/es/complianceview/ - BlueUP Connect (Cliente Zero Trust de puesto), estado: Vista previa. Cliente de escritorio que muestra solo los servicios autorizados para la identidad, sobre OpenZiti (partner NetFoundry). https://www.blueup.es/es/ztaclient/ - BlueUP Core (Motor financiero), estado: En desarrollo. Motor contable multi-GAAP en Rust (150.657 asientos/seg, benchmark 2026-07-02) con modelos regulatorios tipados. https://www.blueup.es/es/core/ ## Métricas propias - 150.657 asientos/seg (BlueUP Core, benchmark 2026-07-02) - 98 controles de compliance (ComplianceView) - 9 módulos AML integrados (BlueUPALM) - Cero IP pública: servicios invisibles por defecto ## Partner tecnológico - Partner oficial de NetFoundry, que cuenta con el respaldo de Cisco Investments. El sustrato de conectividad es OpenZiti. ## Páginas importantes - Tecnología: https://www.blueup.es/es/tecnologia - Cumplimiento regulatorio: https://www.blueup.es/es/compliance - Banca privada: https://www.blueup.es/es/soluciones/banca-privada - Aseguradoras: https://www.blueup.es/es/soluciones/aseguradoras - Fintech e IA agéntica: https://www.blueup.es/es/soluciones/fintech-ia-agentica - Calculadora DORA/SEPBLAC: https://www.blueup.es/es/herramientas/calculadora-dora - Glosario de compliance, Zero Trust e IA agéntica: https://www.blueup.es/es/glosario - Blog: https://www.blueup.es/es/blog/ - Sobre nosotros: https://www.blueup.es/es/about - Contacto: https://www.blueup.es/es/contact - Solicitar demo: https://www.blueup.es/es/request-demo - Política de privacidad: https://www.blueup.es/es/privacidad ## Artículos - 2026-08-03: DORA para fintech e insurtech: guía práctica y checklist de 90 días: https://www.blueup.es/es/blog/dora-fintech-insurtech-90-dias - 2026-08-03: Registro de Información DORA: por qué casi nadie lo pasa a la primera: https://www.blueup.es/es/blog/registro-informacion-dora - 2026-06-08: IA agéntica y regulación: quién responde cuando el agente actúa solo: https://www.blueup.es/es/blog/ia-agentica-regulacion - 2026-06-08: Anatomía de un triaje AML con agente de IA: qué decide la máquina: https://www.blueup.es/es/blog/triaje-aml-agente-ia - 2026-06-02: Anatomía de un incidente DORA: del indicio a la notificación: https://www.blueup.es/es/blog/incidente-dora-caso-practico - 2026-06-02: Software SEPBLAC: automatizar el reporting sin perder trazabilidad: https://www.blueup.es/es/blog/software-sepblac - 2026-05-16: IA Agéntica y Zero Trust: Por qué la identidad debe preceder a la conectividad: https://www.blueup.es/es/blog/ia-agentica-zero-trust - 2026-05-01: Automatización AML con IA: Del screening manual al triaje inteligente: https://www.blueup.es/es/blog/aml-automatizacion-ia - 2026-05-01: DORA 2026: Guía práctica para entidades financieras: https://www.blueup.es/es/blog/dora-guia-entidades-2026 - 2026-05-01: Zero Trust en banca: Por qué las VPN ya no son suficientes: https://www.blueup.es/es/blog/zero-trust-banca ## Glosario - AI Act: AI Act es el Reglamento (UE) 2024/1689, el marco europeo de la IA basado en riesgo: prohíbe usos inaceptables, regula los sistemas de alto riesgo y exige transparencia a los modelos de uso general. Alcanza al credit scoring y al seguro de vida y salud como alto riesgo desde el 2 de diciembre de 2027 (Reg. 2026/1744). https://www.blueup.es/es/glosario#ai-act - AML: AML (anti-money laundering) es la prevención del blanqueo de capitales y la financiación del terrorismo. En España, la Ley 10/2010 obliga a entidades de crédito y financieras a aplicar diligencia debida y a comunicar al SEPBLAC las operaciones sospechosas; el Reglamento (UE) 2024/1624 la armoniza desde julio de 2027. https://www.blueup.es/es/glosario#aml - Biscuit Tokens: Biscuit es un token de autorización open-source de la Eclipse Foundation, verificado con clave pública y con atenuación offline: de un token se deriva otro con menos permisos sin contactar con el emisor. En banca y seguros acota la delegación entre servicios. BlueUPALM lo emite y atenúa; en BlueUP Core sigue en diseño. https://www.blueup.es/es/glosario#biscuit-tokens - DORA: DORA (Digital Operational Resilience Act) es el Reglamento (UE) 2022/2554 sobre la resiliencia operativa digital del sector financiero. Obliga a bancos, aseguradoras y empresas de inversión de la UE a resistir las perturbaciones y amenazas TIC, responder a ellas y recuperarse. Se aplica desde el 17 de enero de 2025. https://www.blueup.es/es/glosario#dora - F19: F19 (formulario F19-1) es el modelo con el que un sujeto obligado comunica al SEPBLAC un hecho u operación con indicio de blanqueo de capitales o de financiación del terrorismo, conforme al artículo 18 de la Ley 10/2010 y tras el examen especial del artículo 17. Su contenido y trazabilidad se examinan en inspección. https://www.blueup.es/es/glosario#f19 - FINOS: FINOS (Fintech Open Source Foundation) es la organización paraguas de la Linux Foundation que reúne al sector financiero para construir tecnología y estándares abiertos. Aloja el Common Domain Model (CDM) y el grupo de trabajo SDLC Controls, cuyos controles integra ComplianceView junto a NIST, ISO 27001 y DORA. https://www.blueup.es/es/glosario#finos - GDPR: GDPR (General Data Protection Regulation) es el Reglamento (UE) 2016/679 de protección de datos, aplicable desde el 25 de mayo de 2018. Alcanza a toda entidad establecida en la UE y a quien, desde fuera, ofrezca bienes o servicios a personas en la Unión o controle su conducta. Multas de hasta 20.000.000 EUR o el 4 %. https://www.blueup.es/es/glosario#gdpr - gVisor: gVisor es un sandbox de contenedores open-source: un kernel de aplicación en espacio de usuario intercepta las llamadas al sistema y separa la carga de trabajo del kernel anfitrión. En banca y seguros acota el impacto de un contenedor comprometido. BlueUP Core lo declara como runtimeClass en Kubernetes. https://www.blueup.es/es/glosario#gvisor - ISO 27001: ISO 27001 (ISO/IEC 27001:2022) es la norma internacional de ISO e IEC con los requisitos de un sistema de gestión de seguridad de la información (SGSI) y sus controles de referencia. Un organismo acreditado audita y certifica la conformidad, prueba con la que banca y seguros demuestran su control del riesgo. https://www.blueup.es/es/glosario#iso-27001 - KYC: KYC (Know Your Customer) es el nombre sectorial de la diligencia debida con el cliente de la Directiva (UE) 2015/849: identificar y verificar al cliente, identificar al titular real, evaluar el propósito de la relación y seguirla en el tiempo. Se completa antes de abrir la relación, salvo excepciones (art. 14). https://www.blueup.es/es/glosario#kyc - LLM: LLM (large language model) es un modelo de IA que genera y predice texto en lenguaje natural tras entrenarse con grandes corpus. El AI Act clasifica de alto riesgo los sistemas que evalúan la solvencia o fijan precios de seguros de vida y salud (anexo III). En BlueUP, la gobernanza de gateways LLM está en roadmap. https://www.blueup.es/es/glosario#llm - MCP: MCP (Model Context Protocol) es un estándar abierto, alojado en la Agentic AI Foundation de la Linux Foundation, que normaliza el acceso de las aplicaciones de IA a herramientas y datos externos. En banca y seguros es donde el host controla qué invoca un agente. En BlueUP, la gobernanza de gateways MCP está en roadmap. https://www.blueup.es/es/glosario#mcp - NetFoundry: NetFoundry es la empresa que creó y mantiene OpenZiti, el sustrato de conectividad Zero Trust open-source, y cuenta con Cisco Investments entre sus inversores. Una entidad regulada lo usa para dejar sus servicios sin IP pública. BlueUP es partner oficial y ofrece despliegue self-hosted o conectividad managed. https://www.blueup.es/es/glosario#netfoundry - NIST: NIST (National Institute of Standards and Technology) es la agencia federal estadounidense del Departamento de Comercio que publica estándares de ciberseguridad como el Cybersecurity Framework y la familia SP 800. Banca y seguros los usan como catálogo de controles; ComplianceView alinea los suyos con NIST SP 800-53r5. https://www.blueup.es/es/glosario#nist - OPA: OPA (Open Policy Agent) es un motor de políticas open-source, proyecto graduado de la CNCF, que separa la decisión de política del punto donde se aplica y la expresa en el lenguaje Rego. En banca y seguros permite versionar y auditar como código las reglas de acceso. https://www.blueup.es/es/glosario#opa - OpenZiti: OpenZiti es el sustrato de conectividad open-source de NetFoundry: identidad X.509, cifrado extremo a extremo y servicios dark sin puertos de entrada ni IP pública. Sustituir la VPN es uno de sus casos de uso: la identidad se autoriza antes de que exista ruta de datos. En BlueUP sostiene la accesibilidad Zero Trust. https://www.blueup.es/es/glosario#openziti - SEPBLAC: SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) es la Unidad de Inteligencia Financiera de España y autoridad supervisora de prevención del blanqueo y financiación del terrorismo. Los sujetos obligados le comunican toda operación con indicio (Ley 10/2010). https://www.blueup.es/es/glosario#sepblac - SPIRE: SPIRE (SPIFFE Runtime Environment) es una implementación lista para producción de las APIs de SPIFFE, proyecto graduado de la CNCF: emite a cada workload un SVID, identidad verificable en X.509 o JWT. En banca y seguros sustituye las credenciales estáticas por identidad de corta duración y rotación automática. https://www.blueup.es/es/glosario#spire - Zero Trust: Zero Trust es el modelo de seguridad que NIST formaliza en SP 800-207: la ubicación de red no otorga confianza implícita y cada acceso se autentica y autoriza por separado. En banca y seguros acota el movimiento lateral tras el robo de una credencial; BlueUP lo aplica con identidad criptográfica por servicio. https://www.blueup.es/es/glosario#zero-trust ## Contacto - info@blueup.es # BlueUP (English) > BlueUP Technology builds identity-first Zero Trust infrastructure and AML/DORA compliance software for banking, insurance and fintech in Spain and the EU. The portfolio is pre-launch: each product states its real status below and is shown in a guided demo, not as a public download. ## Products - BlueUPALM (AML/DORA), status: Available. Bank-grade AML/DORA platform: EU/OFAC/UN list screening, SEPBLAC workflow with F19 and DORA incident management. https://www.blueup.es/en/bc/ - ComplianceView (Compliance monitoring), status: Available. Continuous monitoring of 98 controls mapped to NIST, ISO 27001, DORA and FINOS, with automated collectors and 30-day trending. https://www.blueup.es/en/complianceview/ - BlueUP Connect (Zero Trust desktop client), status: Preview. Desktop client that exposes only the services authorised for the identity, built on OpenZiti (NetFoundry partner). https://www.blueup.es/en/ztaclient/ - BlueUP Core (Financial engine), status: In development. Multi-GAAP accounting engine in Rust (150,657 journals/sec, benchmark 2026-07-02) with typed regulatory models. https://www.blueup.es/en/core/ ## Own metrics - 150,657 journals/sec (BlueUP Core, benchmark 2026-07-02) - 98 compliance controls (ComplianceView) - 9 integrated AML modules (BlueUPALM) - Zero public IPs: services invisible by default ## Technology partner - Official partner of NetFoundry, which is backed by Cisco Investments. The connectivity substrate is OpenZiti. ## Key pages - Technology: https://www.blueup.es/en/technology - Regulatory compliance: https://www.blueup.es/en/compliance - Private banking: https://www.blueup.es/en/solutions/private-banking - Insurance: https://www.blueup.es/en/solutions/insurance - Fintech and agentic AI: https://www.blueup.es/en/solutions/fintech-agentic-ai - DORA/SEPBLAC calculator: https://www.blueup.es/en/tools/calculadora-dora - Compliance, Zero Trust and agentic AI glossary: https://www.blueup.es/en/glossary - Blog: https://www.blueup.es/en/blog/ - About us: https://www.blueup.es/en/about - Contact: https://www.blueup.es/en/contact - Request a demo: https://www.blueup.es/en/request-demo - Privacy policy: https://www.blueup.es/en/privacy ## Articles - 2026-08-03: DORA for fintech and insurtech: a practical guide and 90-day checklist: https://www.blueup.es/en/blog/dora-fintech-insurtech-90-days - 2026-08-03: DORA Register of Information: why almost no one passes first time: https://www.blueup.es/en/blog/dora-register-of-information - 2026-06-08: Anatomy of agentic AI AML triage: what the machine decides: https://www.blueup.es/en/blog/agentic-ai-aml-triage - 2026-06-08: Agentic AI and regulation: who answers when the agent acts alone: https://www.blueup.es/en/blog/agentic-ai-regulation - 2026-06-02: Anatomy of a DORA incident: from first signal to notification: https://www.blueup.es/en/blog/dora-incident-case-study - 2026-06-02: SEPBLAC software: automate AML reporting without losing traceability: https://www.blueup.es/en/blog/sepblac-software - 2026-05-16: Agentic AI and Zero Trust: Why identity must precede connectivity: https://www.blueup.es/en/blog/agentic-ai-zero-trust - 2026-05-01: AML Automation with AI: From manual screening to intelligent triage: https://www.blueup.es/en/blog/aml-automation-ai - 2026-05-01: DORA 2026: A practical guide for financial entities: https://www.blueup.es/en/blog/dora-guide-entities-2026 - 2026-05-01: Zero Trust in banking: Why VPNs are no longer enough: https://www.blueup.es/en/blog/zero-trust-banking ## Glossary - AI Act: The AI Act is Regulation (EU) 2024/1689, the European risk-based framework for AI: it bans unacceptable uses, regulates high-risk systems and requires transparency from general-purpose models. Its high-risk regime covers credit scoring and life and health insurance pricing from 2 December 2027 (Reg. 2026/1744). https://www.blueup.es/en/glossary#ai-act - AML: Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027. https://www.blueup.es/en/glossary#aml - Biscuit Tokens: Biscuit is an open-source authorization token from the Eclipse Foundation, verified with public keys and attenuable offline: a narrower token derives from another with no call to the issuer. In banking and insurance it bounds delegation between services. BlueUPALM issues and attenuates it; BlueUP Core has it in design. https://www.blueup.es/en/glossary#biscuit-tokens - DORA: DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025. https://www.blueup.es/en/glossary#dora - F19: F19 (form F19-1) is the template an obliged entity uses to report to SEPBLAC any act or transaction with indications or certainty of money laundering or terrorist financing, under Article 18 of Spain's Law 10/2010 and after the special examination of Article 17. Its content and audit trail are reviewed in inspections. https://www.blueup.es/en/glossary#f19 - FINOS: FINOS (Fintech Open Source Foundation) is the Linux Foundation umbrella organization that unites financial services to build open technology and standards. It hosts the Common Domain Model (CDM) and the SDLC Controls working group, whose controls ComplianceView integrates alongside NIST, ISO 27001 and DORA. https://www.blueup.es/en/glossary#finos - GDPR: The GDPR (General Data Protection Regulation) is Regulation (EU) 2016/679 on data protection, applicable since 25 May 2018. It reaches every entity established in the EU and anyone outside it offering goods or services to people in the Union or monitoring their behavior. Fines run up to 20,000,000 EUR or 4%. https://www.blueup.es/en/glossary#gdpr - gVisor: gVisor is an open-source container sandbox: an application kernel in user space intercepts system calls and separates the workload from the host kernel. In banking and insurance it limits the blast radius of a compromised container. BlueUP Core declares it as the runtimeClass of its Kubernetes deployment. https://www.blueup.es/en/glossary#gvisor - ISO 27001: ISO 27001 (ISO/IEC 27001:2022) is the international standard from ISO and IEC with the requirements for an information security management system (ISMS) and its reference controls. An accredited body audits and certifies conformity, the evidence banking and insurance use to demonstrate risk control. https://www.blueup.es/en/glossary#iso-27001 - KYC: KYC (Know Your Customer) is the sector name for customer due diligence under Directive (EU) 2015/849: identifying and verifying the customer, identifying the beneficial owner, assessing the relationship's purpose and monitoring it over time. It is completed before the relationship opens, with exceptions (Article 14). https://www.blueup.es/en/glossary#kyc - LLM: An LLM (large language model) is an AI model that generates and predicts natural-language text after training on large corpora. The AI Act classifies as high risk the systems that assess creditworthiness or price life and health insurance (Annex III). At BlueUP, LLM gateway governance is on the roadmap. https://www.blueup.es/en/glossary#llm - MCP: MCP (Model Context Protocol) is an open standard, hosted by the Agentic AI Foundation at the Linux Foundation, that standardizes how AI applications access external tools and data. In banking and insurance it is where the host controls what an agent invokes. At BlueUP, MCP gateway governance is on the roadmap. https://www.blueup.es/en/glossary#mcp - NetFoundry: NetFoundry is the company that created and maintains OpenZiti, the open-source Zero Trust connectivity substrate, and counts Cisco Investments among its investors. A regulated entity uses it to keep services off the public internet. BlueUP is an official partner offering self-hosted deployment or managed connectivity. https://www.blueup.es/en/glossary#netfoundry - NIST: NIST (National Institute of Standards and Technology) is the US federal agency within the Department of Commerce that publishes cybersecurity standards such as the Cybersecurity Framework and the SP 800 family. Banking and insurance adopt them as a control catalog; ComplianceView maps its controls to NIST SP 800-53r5. https://www.blueup.es/en/glossary#nist - OPA: OPA (Open Policy Agent) is an open source policy engine and a graduated CNCF project that decouples policy decisions from their enforcement and expresses them in the Rego language. In banking and insurance it allows access rules to be versioned and audited as code. https://www.blueup.es/en/glossary#opa - OpenZiti: OpenZiti is NetFoundry's open-source connectivity substrate: X.509 identity, end-to-end encryption and dark services with no inbound ports or public IP. VPN replacement is one of its use cases: identity is authorized before any data path exists. At BlueUP it underpins Zero Trust reachability. https://www.blueup.es/en/glossary#openziti - SEPBLAC: SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010). https://www.blueup.es/en/glossary#sepblac - SPIRE: SPIRE (the SPIFFE Runtime Environment) is a production-ready implementation of the SPIFFE APIs and a CNCF graduated project: it issues each workload an SVID, a verifiable identity in X.509 or JWT form. In banking and insurance it replaces static credentials with short-lived, auto-rotating workload identity. https://www.blueup.es/en/glossary#spire - Zero Trust: Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity. https://www.blueup.es/en/glossary#zero-trust ## Contact - info@blueup.es