Non-human identity and Runtime Enforcement

Secure Agents at Runtime

Mask secrets, enforce tool policies, and stream metadata audits at the execution boundary, protecting agents before payloads hit models or external sandboxes.

Blekline Open-core

MCP and SDK ingress; Trust Vault and Lineage Firewall in your VPC.

MAde for your stack

Tokenize sensitive data inside your VPC with our Trust Vault, halt hijacked execution via the Lineage Firewall, and stream metadata-only audits to your SIEM.

NHI and Runtime Enforcement

Agent Boundary Security

01 - Non-Human IAM vs. Legacy Stack

Okta/Veza
Kong
Blekline
Okta and Veza govern people. Kong governs network traffic. Blekline enforces policy at the model and tool execution boundary — where agents actually act.

02 - Three Boundaries, one COntrol plane

Trust Vault (Ingress) Stateful tokenization replaces PII and secrets with placeholders before models reason. Hydration stays in your VPC on approved calls.
Lineage Firewall (Execution) Multi-turn context analysis blocks destructive tool calls when session lineage is contaminated by prompt injection.
Audit & SIEM (Egress) Metadata-only trails, CSV export, and SIEM webhooks (Splunk, Datadog). Evidence for security and EU AI Act workflows.
Three boundaries. One enforcement point.

03 - INfrastructure for regulated verticals

start with MCP and SDK on npm or deploy as an inline proxy sidecar in Kubernetes. Stateful tokenization, lineage blocking, and VPC isolation for banking, energy, telco, and EU sovereign workloads.

Built for Your Existing AI Architecture

Flexible Deployment

Kubernetes Sidecar
[01]
02
03

Helm install blekline-ingress

Trust Vault, Lineage, and ingress proxy in your cluster. Image: ghcr.io/blekline/sidecar. Auto-inject via mutating webhook (opt-in annotation).
HELM
Docker
Network Policy
Auto-inject
SDK & CLI
01
[02]
03

Add @blekline/mcp-server to project MCP config

npx @blekline/mcp-server or @blekline/client. Tool calls evaluated before execution. Prompts masked before they leave your environment.
Cursor
VSCode
Claude Code
npx @blekline/mcp-server
MCP / API
01
02
[03]

Govern agent calls from your application

Swap the model base URL or route MCP through @blekline/mcp-proxy. One hop between your agent and OpenAI, Anthropic, or downstream tools.
MCP proxy
OPENAI-COMPATIBLE
Ingress gateway
Kubernetes Sidecar
[01]
02
03

Made for coders and developers

Wire Blekline via npx or the TypeScript/Python SDK. Tool calls are evaluated before execution; prompts are masked before they leave your environment.
HELM
Docker
Network Policy
Auto-inject
SDK & CLI
01
[02]
03

Add @blekline/mcp-server to project MCP config

npx @blekline/mcp-server or @blekline/client. Tool calls evaluated before execution. Prompts masked before they leave your environment.
Cursor
VSCode
Claude Code
npx @blekline/mcp-server
MCP / API
01
02
[03]

Govern agent calls from your application

Swap the model base URL or route MCP through @blekline/mcp-proxy. One hop between your agent and OpenAI, Anthropic, or downstream tools.
MCP proxy
OPENAI-COMPATIBLE
Ingress gateway

Move Faster, Stay Secure, Remain Compliant

Engineered for Regulated Verticals

01 - Runtime Agent Governance

Enforces Non-Human Identity (NHIM) lineage, runtime intent validation, and human-in-the-loop kill switches required for AIUC-1 compliance.

02 - Threat Mitigation

Defense against LLM01 (Prompt Injection), LLM02 (Insecure Output Handling), and LLM06 (Sensitive Information Disclosure).

03 - Data Sovereignty and Auditing

Stateful PII tokenization at the pod boundary (Art. 32) and immutable execution logs to meet EU AI Act transparency rules.

04 - AI Management System Controls

Satisfies technical infrastructure safeguards, audit logging, and data masking requirements for ISO 42001 certification audits.

05 - Risk Management Framework

Technical enforcement layer mapping directly to NIST AI RMF Govern, Map, Measure, and Protect functions.

Optimized, for Production Agents

AI-first Infrastructure

01 - MCP Proxy

Every downstream tool call passes through policy first.

02 - Ingress PRoxy

Swap the model base URL. Deploy sidecar in your cluster.

03 - Trust Vault

Tokenize secrets before they hit the model. Hydrate in-cluster.

04 - Lineage Firewall

After prompt injection, block destructive tools for that session.

05 - Self-hosted

Docker + Helm. Enforcement stays in your network.

06 - Fleet policy

Push policy updates without redeploying every agent.

01 - MCP Proxy

Every downstream tool call passes through policy first.

02 - Ingress PRoxy

Swap the model base URL. Deploy sidecar in your cluster.

03 - Trust Vault

Tokenize secrets before they hit the model. Hydrate in-cluster.

04 - Lineage Firewall

After prompt injection, block destructive tools for that session.

05 - Self-hosted

Docker + Helm. Enforcement stays in your network.

06 - Fleet policy

Push policy updates without redeploying every agent.

Comparison

Why Blekline

IAM (Okta, Veza)
API gateway (Kong)
Blekline (NHIM)
Governance
People and app access
HTTP routes and APIs
Agent prompts, models, and MCP tools
Enforcement
At login and provisioning
When a request hits your API
On every prompt and tools/call
Agent-Specific
No session lineage
No MCP tool semantics
Allow · mask · block + metadata audit
Secrets & prompt injection
Vaulting ≠ masking at execution
TLS termination
Mask/block secrets in prompts and tool args; lineage block on hijacked sessions
Audit & Wiring
Access review reports
API access logs
Metadata allow/mask/block per interaction · CSV + SIEM · npm, Helm sidecar, or mask API

Built for Developers. Scaled for Enterprise.

Authoritative mask API + fleet ingress
Trust Vault
Lineage
policy dashboard
SIEM export
EEA-first by default
dedicated SLA
US addendum on request
Deploy to production with confidence — governed agent execution with audit evidence your security team can export.

Get Started → Book Call

Frequently Asked Questions

FAQ's

CISO's, CTO's and DAta protection officers

01

Who sees our data when Blekline enforces policy?

Masking runs over HTTPS to apply detection. Audit defaults to metadata only — decisions, tool names, and counts, not raw prompts. For stricter control, run the ingress sidecar in your VPC so enforcement stays inside your network. Default SaaS is EEA-first (Frankfurt compute, Ireland database).

02

What happens if a model or tool tries to exfiltrate PII mid-workflow?

Blekline can mask or block at ingress (prompts and tool args) and redact on the return path before your agent consumes the response. Lineage Firewall can block destructive tools when a session is contaminated by prompt injection. You get an allow/mask/block record per interaction — not just a post-hoc alert.

03

Will this slow down how we ship agents?

No rip-and-replace. Wire one path — MCP proxy, SDK, or ingress gateway — and expand from there. Open-core packages let security review the code while engineering keeps shipping.
Compliance and Legal Officers

04

What contractual assurances do we get on processing and subprocessors?

Standard DPA, published subprocessors at blekline.com/subprocessors, and privacy documentation for diligence. Default SaaS is EEA-first. US-primary hosting is available on the enterprise program with a signed US Processing Addendum — flag that in your transfer assessment if you choose US-primary.

05

Does masking satisfy data minimization, or do we still own classification?

Masking operationalizes minimization at execution time. You still own what counts as personal data, retention, and high-risk AI obligations under the EU AI Act. Blekline is the control layer; legal judgment stays with you.

06

Do we need this if we already have Okta or Veza?

Okta and Veza govern human and app access, who may use which system. Blekline governs what software agents do at runtime — tool calls, prompts, and session lineage. Most regulated teams need both layers.
Finance Executives

07

Is this a productivity tool or a risk-control line item?

Risk control. You are buying governed agent execution — enforceable policy and audit evidence — not another seat on ChatGPT. Price it like security infrastructure, not like an AI subscription.

08

What does a pilot actually buy us versus a full rollout?

One production workflow with measurable outcomes: entities masked, tools blocked, violations logged. Enough to justify platform spend or kill the bet before a multi-year commitment.

09

How do we compare this to building it ourselves?

In-house means MCP enforcement, policy streaming, audit schema, lineage state, and multi-vendor ingress — quarters of engineering on non-differentiating work. Blekline compresses that to weeks with evidence your board can read.

Push Secured Agents to Production