Non-Human Identity Management and Runtime Enforcement

Prevent exfiltration at the agent boundary. Trust Vault and Lineage in your VPC. Metadata-only audit evidence. EEA-first by default.

01 - Stack positioning

How Blekline fits your security stack

IAM (Okta, Veza)
Kong / API gateway
Blekline (NHIM)
Primary job
Identity and access reviews
Route and secure HTTP APIs
Allow · mask · block on agent actions
Policy timing
Login and provisioning
Request hits API route
Prompt or tools/call
MCP & agent tools
No MCP lineage
No tool semantics
mcp-proxy, MCP server, SDK
Prompt injection prevention
-
-
Lineage Firewall
Secrets in prompts / tool args
Vault ≠ runtime mask
TLS only
Trust Vault in VPC
Audit for CISO
Access review reports
API access logs
Metadata allow/mask/block + SIEM
Typical deploy
IdP + IGA
Cluster ingress
npm · Helm sidecar · SaaS mask API

Built for Developers. Scaled for Enterprise.

02 - Seamless Integration

AI-safe execution in minutes

Launch quickly, reduce prompt exposure risk, and give your team a safer path to AI productivity.

AI Ingress Control Plane

Build Production Agent Interaction Governance

Agent RUntimes
CLaude COde
Cursor
VSCode
Codex
SDK / REST
Prompt
Tool call
Interaction Governance

Blekline Control Plane

Blekline masks and enforces prompts and tool calls before models and APIs, redacts responses on the return path, with metadata-only audit for security review.
Open core
MCP + API gateway
Metadata-only audit
Ingress
Mask / ENforce / Block
Egress
REsponse / MAsk
Audit
Metadata EXport / SIEM
Masked
Enforced
Audited
Model API'S
Claude
OPenai
Gemini
POlicy
Enoforced
Tools
MCP servers / internal APIs / Webhooks
Developer
VSCode
Terminal
Claude
Cursor
Codex
Prompt
Context
Tool Call
Ingress

Blekline Ingress

Policy enforcement, PII masking, approval queues and audit trails, with mask/block/send options.
Zero retention
Role-Aware
SOC2 Ready
MCP, agent-first
Sanitized
Approved
Auditable
Models
Claude
OPenai
Gemini
Execution
sandboxes
Redacted data
ENvironment
Daytona / Modal / Cloudflare / Vercel

03 - FAQ's

Frequently asked questions

CISO's, CTO's and DAta protection officers

Who sees our data when Blekline enforces policy?

Masking runs over HTTPS to apply detection. Audit defaults to metadata only — decisions, tool names, and counts, not raw prompts. For stricter control, run the ingress sidecar in your VPC so enforcement stays inside your network. Default SaaS is EEA-first (Frankfurt compute, Ireland database).

What happens if a model or tool tries to exfiltrate PII mid-workflow?

Blekline can mask or block at ingress (prompts and tool args) and redact on the return path before your agent consumes the response. Lineage Firewall can block destructive tools when a session is contaminated by prompt injection. You get an allow/mask/block record per interaction — not just a post-hoc alert.

Will this slow down how we ship agents?

No rip-and-replace. Wire one path — MCP proxy, SDK, or ingress gateway — and expand from there. Open-core packages let security review the code while engineering keeps shipping.
Compliance and Legal Officers

What contractual assurances do we get on processing and subprocessors?

Standard DPA, published subprocessors at blekline.com/subprocessors, and privacy documentation for diligence. Default SaaS is EEA-first. US-primary hosting is available on the enterprise program with a signed US Processing Addendum — flag that in your transfer assessment if you choose US-primary.

Does masking satisfy data minimization, or do we still own classification?

Masking operationalizes minimization at execution time. You still own what counts as personal data, retention, and high-risk AI obligations under the EU AI Act. Blekline is the control layer; legal judgment stays with you.

Do we need this if we already have Okta or Veza?

Okta and Veza govern human and app access, who may use which system. Blekline governs what software agents do at runtime — tool calls, prompts, and session lineage. Most regulated teams need both layers.
Finance Executives

Is this a productivity tool or a risk-control line item?

Risk control. You are buying governed agent execution — enforceable policy and audit evidence — not another seat on ChatGPT. Price it like security infrastructure, not like an AI subscription.

What does a pilot actually buy us versus a full rollout?

One production workflow with measurable outcomes: entities masked, tools blocked, violations logged. Enough to justify platform spend or kill the bet before a multi-year commitment.

How do we compare this to building it ourselves?

In-house means MCP enforcement, policy streaming, audit schema, lineage state, and multi-vendor ingress — quarters of engineering on non-differentiating work. Blekline compresses that to weeks with evidence your board can read.