Non-human identity and Runtime Enforcement
Ready to Secure Runtime

Deploy Blekline in your Kubernetes cluster or Docker VPC — sidecar enforcement, Trust Vault, and Lineage Firewall. Upload NHIM posture and prove runtime governance in hours. Metadata-only audit for security review.
Platform & security leaders
01
What do we need before starting a platform eval?
A Blekline workspace, cluster or Docker access, and optionally an NHIM audit JSON from staging (npx @blekline/nhim-audit). Track 01 (Kubernetes) takes ~2 hours; Track 02 (Docker sidecar) ~1 hour. Sandbox packs include Helm values, mandatory-hop templates, and a deployment checklist.
02
Does prompt or tool payload content leave our network during eval?
Sidecar and fleet deployments keep enforcement in your VPC. Masking can run locally; cloud mask path uses transient PII detection only when configured. Activity defaults to metadata-only audit — not full prompt retention. See trust boundaries.
03
Is billing required during the platform eval?
No. Platform eval runs without Stripe until you convert to a paid Platform subscription or sign an enterprise SOW. Self-serve MCP billing is a separate path — choose it only if you also want cloud masking in the IDE without a sidecar.
One MCP hop between your IDE and every downstream tool. Mask secrets and enforce allow · mask · block before model or tool execution. Live in Cursor, Claude Code, or VS Code in under 30 minutes — no cluster required.
Engineering & security teams
01
Which clients does self-serve MCP support?
Cursor, Claude Code, Claude Desktop, GitHub Copilot / VS Code, Continue, and Codex — any MCP-compatible client. One server sits between your agent and downstream tools; optional @blekline/mcp-proxy governs existing MCP servers with the same policy.
02
What leaves my machine when I mask a prompt?
On the default cloud mask path, text is sent transiently to Blekline’s mask API (EEA-first) for PII detection and tokenization — not stored in Activity by default. For local-only processing, use sidecar local_only mode or the platform eval path in your VPC. Policy evaluation and audit metadata go to your Blekline workspace.
03
How does pricing work for self-serve MCP?
Start with a card-free tryout (50 cloud masks), then subscribe for team seats when you are ready. Platform eval (K8s/Docker) is a separate track with no billing during eval. You pick your path at signup; switch anytime from the workspace chooser.
Frequently Asked Questions
FAQs
CISO's, CTO's and DAta protection officers
01
Who sees our data when Blekline enforces policy?
Masking runs over HTTPS to apply detection. Audit defaults to metadata only — decisions, tool names, and counts, not raw prompts. For stricter control, run the ingress sidecar in your VPC so enforcement stays inside your network. Default SaaS is EEA-first (Frankfurt compute, Ireland database).
02
What happens if a model or tool tries to exfiltrate PII mid-workflow?
Blekline can mask or block at ingress (prompts and tool args) and redact on the return path before your agent consumes the response. Lineage Firewall can block destructive tools when a session is contaminated by prompt injection. You get an allow/mask/block record per interaction — not just a post-hoc alert.
03
Will this slow down how we ship agents?
No rip-and-replace. Wire one path — MCP proxy, SDK, or ingress gateway — and expand from there. Open-core packages let security review the code while engineering keeps shipping.
Compliance and Legal Officers
04
What contractual assurances do we get on processing and subprocessors?
Standard DPA, published subprocessors at blekline.com/subprocessors, and privacy documentation for diligence. Default SaaS is EEA-first. US-primary hosting is available on the enterprise program with a signed US Processing Addendum — flag that in your transfer assessment if you choose US-primary.
05
Does masking satisfy data minimization, or do we still own classification?
Masking operationalizes minimization at execution time. You still own what counts as personal data, retention, and high-risk AI obligations under the EU AI Act. Blekline is the control layer; legal judgment stays with you.
06
Do we need this if we already have Okta or Veza?
Okta and Veza govern human and app access, who may use which system. Blekline governs what software agents do at runtime — tool calls, prompts, and session lineage. Most regulated teams need both layers.
Finance Executives
07
Is this a productivity tool or a risk-control line item?
Risk control. You are buying governed agent execution — enforceable policy and audit evidence — not another seat on ChatGPT. Price it like security infrastructure, not like an AI subscription.
08
What does a pilot actually buy us versus a full rollout?
One production workflow with measurable outcomes: entities masked, tools blocked, violations logged. Enough to justify platform spend or kill the bet before a multi-year commitment.
09
How do we compare this to building it ourselves?
In-house means MCP enforcement, policy streaming, audit schema, lineage state, and multi-vendor ingress — quarters of engineering on non-differentiating work. Blekline compresses that to weeks with evidence your board can read.
