Blekline masks secrets and PII, enforces tool policy, and writes metadata-only audit events before prompts and tool calls reach models. Start on Free. You do not need to clone the open-source repo.
1. Who you are
| Path | Best for | Start here |
|---|---|---|
| Free | Local hooks and stdio MCP — secrets never leave your machine | Local (Free) |
| Standard | Hosted proxy, shared team policy, active PII vault ($199 / €199) | Standard (hosted) |
| Fleet | Single-tenant sidecar in your cluster ($499 / €499) | Fleet K8s |
| Enterprise | In-VPC admission, optional eBPF, customer KMS | Enterprise in-VPC |
Create a workspace — Free is local mask only; Standard adds hosted proxy and vault.
Full catalog comparison: Plans & pricing.
2. Connect a client
Wedge order (do one, then expand):
| Client | What you get | Guide |
|---|---|---|
| Claude Code | Project .claude/ MCP — mask and evaluate tool calls in the CLI | Claude Code |
| Claude Desktop | Workspace OAuth connector or local stdio MCP | Claude connector · Desktop |
| Cursor | MCP + chat hooks (block + clipboard on native chat) | Cursor |
Other surfaces: VS Code (extension first) · MCP self-serve eval · browser extension.
3. Prove it
- Send a test prompt that includes an email address or a fake API key.
- Confirm the model sees the masked text.
- Open Operations → Activity — events are metadata only (no raw prompt storage). See Data handling.
Platform and cluster eval
Need in-VPC Trust Vault or a merge-blocking cluster gate? After the Free path:
- [NHIM audit quickstart](/docs/get-started/nhim-audit-quickstart) (no account required)
- Kubernetes fleet · Docker sidecar
- [Eval journey](/docs/get-started/eval-journey) — Track 01 / 02 / 03
Next: Quick Start · Claude Code · Claude connector · Cursor · Open workspace