Agent Runtime Governance

Blekline is open-core NHIM and runtime enforcement. Mask, enforce, lineage, and metadata-only audit when a prompt is sent or a tool is invoked, before anything reaches a model or downstream system.

01 - Our Mission

Blekline started from a simple observation: the teams we talked to weren’t worried about AI being too powerful. They were worried about losing control of it quietly, a customer detail pasted for context, credentials in a debugging session, destructive SQL after prompt injection.

Nobody making a mistake on purpose; just people moving fast in a world where the model is always listening.Audit logs catch it too late. Static IAM does not observe what agents actually do. Neither scales.So we built what was missing: open-core NHIM and runtime enforcement at the MCP, SDK, and ingress boundary. Mask, enforce, lineage, and metadata-only audit before execution. Not a dashboard you check on Fridays. Something that runs every time an agent acts.Open core: server, proxy, SDK, and cursor-hooks on GitHub and npm.

Cloud: fleet policy, authoritative PII mask, Trust Vault, Lineage, SIEM, and enterprise residency options.

Today: Digital proxy and protocol layer. EEA-first by default. Enterprises should not have to choose between moving fast with AI and keeping non-human identities under control.

FOunder of Blekline

Tine Maher

AI Ingress Control Plane

Build Production Agent Interaction Governance

Agent RUntimes
CLaude COde
Cursor
VSCode
Codex
SDK / REST
Prompt
Tool call
Interaction Governance

Blekline Control Plane

Blekline masks and enforces prompts and tool calls before models and APIs, redacts responses on the return path, with metadata-only audit for security review.
Open core
MCP + API gateway
Metadata-only audit
Ingress
Mask / ENforce / Block
Egress
REsponse / MAsk
Audit
Metadata EXport / SIEM
Masked
Enforced
Audited
Model API'S
Claude
OPenai
Gemini
POlicy
Enoforced
Tools
MCP servers / internal APIs / Webhooks
Developer
VSCode
Terminal
Claude
Cursor
Codex
Prompt
Context
Tool Call
Ingress

Blekline Ingress

Policy enforcement, PII masking, approval queues and audit trails, with mask/block/send options.
Zero retention
Role-Aware
SOC2 Ready
MCP, agent-first
Sanitized
Approved
Auditable
Models
Claude
OPenai
Gemini
Execution
sandboxes
Redacted data
ENvironment
Daytona / Modal / Cloudflare / Vercel

We're building the infrastructure that enables the modern enterprise to move fast with AI, without risk.