Enterprise

Procurement Pack

Security, privacy, and OSS boundary summary for enterprise procurement.

View as Markdown

Summary for security, legal, and procurement reviewers evaluating Blekline.

Product summary

Blekline provides Non-Human Identity & Runtime Enforcement at the agent boundary — mask, enforce, and audit prompts and tool calls before they reach LLMs and downstream systems.

Workspace routes (post-signup)

After account creation, workspaces land on the path chooser at /auth/choose-plan?gate=signup:

RouteAudienceBillingOutcome
Platform evalK8s/Docker pilots, security architectureNo Stripe during eval (SOW for production)nhim-audit upload → deployment checklist → compliance export
Self-serve MCPCursor / Claude Code integratorsCard-free tryout (50 masks) or Stripe subscriptionAPI key + MCP wiring → MCP hub
EnterpriseProcurement, fleet rollout, regulated buyersCustom SOWTrust Vault, Lineage Firewall, private VNet, dedicated SLA

Platform eval does not substitute for a production contract — eval workspaces are fixed-scope pilots with relaxed billing gates for posture and deploy tooling only.

OSS vs enterprise boundary

CapabilityOSSCloud SaaSEnterprise program
MCP server, proxy, SDKYesYesYes
Ingress sidecar (contracts)YesYesYes
Cloud mask API + MCP ingressPrivacy+Yes
Fleet MCP + tool-call governanceCompliance+Yes
SIEM export + advanced governanceGovernance+Yes
Enterprise vault controlsGovernance+Yes
Trust Vault (sidecar tokenization)Yes
Lineage Firewall (destructive block)Yes
Azure authoritative PIIYesYes
Private VNet / dedicated SLAYes

Self-serve tiers (reference)

Public self-serve plans on Stripe: Privacy (basic), Compliance (builder), Governance (pro). Enterprise is custom SOW only. See in-app billing matrix for seat caps and feature dots.

Security artifacts

Pilot engagement

Design partner and pilot programs available — GitHub design partner issue, enterprise@blekline.com, or the enterprise lead form on the path chooser.

Definitions