Get started

Eval journey

Choose your deployment track — Kubernetes fleet, Docker sidecar, or MCP — and prove runtime enforcement on your stack in hours, not quarters.

View as Markdown

Blekline governs non-human identity at the agent boundary: mask secrets and PII, enforce tool policy, block contaminated lineage, and export metadata-only audit evidence — before models, sandboxes, and MCP tools act.

This guide is the fastest path from curiosity to proof. Pick one track, run one workflow, and leave with evidence your security team can reproduce.

Start here

  1. Create a workspace — every signup opens the path chooser so you pick platform eval or self-serve MCP in one step.
  2. Platform evalTrack 01 (Kubernetes) or Track 02 (Docker): sidecar enforcement, Trust Vault, Lineage Firewall, posture upload. No billing during eval.
  3. Self-serve MCP — Track 03: wire @blekline/mcp-server in Cursor, Claude Code, or VS Code; mask and enforce tool calls with cloud policy in minutes.
  4. Enterprise pilot — procurement pack, dedicated SLA, and sandbox grant from the same chooser or book a pilot.

Optional: append ?intent=platform or ?intent=self_serve to pre-highlight your path on signup.

Choose your track

TrackBest forTime to first enforceWhat you prove
01 — Kubernetes fleetRegulated production, platform & security teams~2 hoursMandatory-hop sidecar, NetworkPolicy, optional admission webhook
02 — Docker sidecarVPC eval, platform engineering~1 hourTrust Vault + Lineage on :8787, health and enforce events
03 — MCP integratorIDE and agent client teams~30 minutesMask prompts, evaluate tool calls, live policy in your editor

Recommended enterprise sequence: [NHIM audit](/docs/get-started/nhim-audit-quickstart) on staging → Kubernetes fleet or Docker sidecar → procurement with posture JSON attached.

Choose your path

PathGuide
Scan your cluster[NHIM audit quickstart](/docs/get-started/nhim-audit-quickstart)
K8s platform evalKubernetes fleet
Docker platform evalDocker sidecar
MCP self-serveMCP self-serve eval

Track 01 — Kubernetes fleet

Production-grade eval: mandatory-hop enforcement, fleet policy SSE, and compliance export.

  1. Run npx @blekline/nhim-audit audit --profile generic --plain --json and upload JSON to Operations → Posture.
  2. Provision eval namespace, sidecar secrets, and image pull for ghcr.io/blekline/sidecar.
  3. Helm install blekline-ingress and apply mandatory-hop NetworkPolicy.
  4. Optional: mutating admission webhook for opt-in pod injection.
  5. Request probe token if CRITICAL gaps remain; confirm runtime enforce in Activity.

Kubernetes fleet guide · NHIM verification

Track 02 — Docker sidecar

Validate Trust Vault, Lineage Firewall, and ingress proxy without a full cluster rollout.

  1. Optional: NHIM audit quickstart against staging.
  2. Pull ghcr.io/blekline/sidecar and configure workspace token + secrets.
  3. Start the compose stack; verify /health (401 without auth, 200 with token).
  4. Trigger first allow/mask/block event in Operations → Activity.

Docker sidecar guide

Track 03 — MCP client eval

Fastest path for developers: one MCP hop between your agent and every downstream tool.

  1. Create a workspace API key with mask:write and events:write scopes.
  2. Follow MCP self-serve eval — connect Cursor, Claude Code, or VS Code in minutes.
  3. Run the live MCP test in Operations → MCP; confirm mask and enforce tools respond.

MCP server · Agent clients hub

CI and posture gates

Keep agent infrastructure aligned with NHIM posture on every merge:

RoleStart here
Security / CISO[Runtime enforcement](/docs/introduction/interaction-governance) · Threat model · Benchmarks
Platform / SREArchitecture · Trust Vault sidecar
ComplianceEU AI Act mapping · Compliance evidence
ProcurementProcurement pack

Enterprise sandbox

Track 01/02 sandbox packs (Helm values, checklists, probe tokens) ship on grant approval. Email enterprise@blekline.com with your nhim-audit.json, or request a pilot.


Try it now: Runtime simulator · Glossary · Open workspace