v0.4.0GitHub

Core concepts

Runtime enforcement

Non-Human Identity & Runtime Enforcement — ingress, egress, and audit at the agent boundary.

View as Markdown

Blekline is Non-Human Identity & Runtime Enforcement infrastructure: a control plane for what autonomous agents send, execute, and expose at the execution boundary.

See the [NHIM overview](/docs/introduction/nhim) for the full hub — simulator, definitions, threat model, and Shipped/Roadmap table.

Three boundaries

BoundaryWhat it governsPrimary surfaces
IngressPrompts and tool arguments before models/toolsMCP proxy, SDK /api/mask, /api/mcp/enforce-tool-call
EgressModel outputs and outbound API payloadsIngress proxy response mask, SDK hooks
AuditEvidence for security reviewActivity log, /api/audit, SIEM forward

Where to start

What this is not

Not a browser extension product, not full CASB/DLP, not a model routing marketplace. See Architecture.


Next steps: Quick start · NHIM overview · EU AI Act