Blekline is Non-Human Identity & Runtime Enforcement infrastructure: a control plane for what autonomous agents send, execute, and expose at the execution boundary.
See the [NHIM overview](/docs/introduction/nhim) for the full hub — simulator, definitions, threat model, and Shipped/Roadmap table.
Three boundaries
| Boundary | What it governs | Primary surfaces |
|---|---|---|
| Ingress | Prompts and tool arguments before models/tools | MCP proxy, SDK /api/mask, /api/mcp/enforce-tool-call |
| Egress | Model outputs and outbound API payloads | Ingress proxy response mask, SDK hooks |
| Audit | Evidence for security review | Activity log, /api/audit, SIEM forward |
Where to start
- Developers: MCP proxy · Python SDK · Runtime Simulator
- Security: Trust boundaries · Why ingress
- Egress detail: Egress governance
- Glossary: Definitions
What this is not
Not a browser extension product, not full CASB/DLP, not a model routing marketplace. See Architecture.
Next steps: Quick start · NHIM overview · EU AI Act