# Compliance evidence Blekline is **runtime evidence infrastructure** for agent security assessments — not a certifying body. ## What we provide - **OWASP ASI Top 10** — strongest coverage on **ASI02** (tool misuse): enforce tool calls, scan secrets in tool arguments, MCP proxy boundary - **AIUC-1 alignment** — security and accountability domains map to Activity audit exports, sidecar auth, and mask/enforce controls - **Honest gaps** — MCP registry, per-agent RBAC, and SPIRE JWT verify are roadmap items ## What we do not provide - AIUC-1 or OWASP certification for your organization - EU AI Act conformity assessment or legal classification of your use case - SOC 2 / ISO 27001 attestation (roadmap for Blekline infra) ## Public vs enterprise pack | Surface | Contents | |---------|----------| | **This doc + EU AI Act overview** | High-level positioning, no full control matrix | | **Enterprise sandbox** (NDA) | Full OWASP ASI + AIUC-1 mapping, SoA template, red team playbook, K8s/Docker/MCP tracks | Request sandbox access: [Contact sales](https://blekline.com) or your Blekline operator. ## Related - [EU AI Act overview](/docs/introduction/eu-ai-act) - [Trust boundaries](/docs/security/trust-boundaries) - [Kubernetes deployment](/docs/enterprise/k8s-deployment) **Disclaimer:** Integrating Blekline helps you **export evidence** for your auditor. Certification requires customer scoping, auditor sign-off, and organizational controls outside Blekline's product scope.