# Blekline Docs (llms.txt) # https://app.blekline.com/docs/introduction/nhim > NHIM and runtime enforcement for production AI agents — mask secrets, enforce tool policy, block contaminated lineage, metadata-only audit at the MCP, SDK, and ingress sidecar boundary. Default SaaS: EEA-first. Marketing: https://blekline.com/llms.txt OSS: https://github.com/Blekline/blekline-oss Sitemap: https://app.blekline.com/sitemap.xml Last-Updated: 2026-08-06 --- ## Intent router | Intent | URL | |--------|-----| | NHIM overview | /docs/introduction/nhim | | NHIM audit (no account) | /docs/get-started/nhim-audit-quickstart | | NHIM Audit CLI reference | /docs/tools/nhim-audit | | Eval journey Track 0→3 | /docs/get-started/eval-journey | | K8s fleet + auto-inject | /docs/deploy/k8s-fleet · /docs/enterprise/k8s-deployment | | Docker sidecar | /docs/deploy/docker-sidecar | | MCP self-serve eval | /docs/get-started/mcp-eval | | Runtime simulator | /docs/playground/runtime-enforcement | | Trust / claims table | /docs/security/trust-boundaries | | CI merge gate | /docs/deploy/ci-nhim-gate | | Sign up | /auth/signup | | Platform eval signup | /auth/signup?intent=platform | Full index: /llms-full.txt --- ## Start here - /docs/introduction/nhim — architecture, shipped features, roadmap - /docs/get-started/nhim-audit-quickstart — `npx @blekline/nhim-audit@0.2.1 audit --profile generic` - /docs/get-started/eval-journey — Track 0→3 sequence - /docs/tools/nhim-audit — NHIM-001..019 rules, JSON schema 2.0, limitations - /docs/security/trust-boundaries — diligence claims (source of truth) - /docs/playground/runtime-enforcement — interactive simulator --- ## Deploy & runtime (0.2.1-nhim) - /docs/deploy/k8s-fleet — Helm fleet, mandatory-hop NetworkPolicy - /docs/enterprise/k8s-deployment — standalone sidecar + mutating webhook auto-inject - /docs/deploy/docker-sidecar — Docker NHIM sidecar on :8787 - /docs/deploy/ci-nhim-gate — GitHub Actions audit gate - /docs/enterprise/trust-vault-sidecar — ingress tokenize/hydrate - /docs/enterprise/lineage-enforcement — execution boundary - /docs/enterprise/nhim-verification — post-deploy verification - /docs/api/ingress-proxy — sidecar OpenAPI Images: `ghcr.io/blekline/sidecar:0.2.1-nhim` · `ghcr.io/blekline/admission:0.2.1-nhim` --- ## Open-core packages (npm) - @blekline/nhim-audit@0.2.1 — static K8s audit, SARIF/JSON, no account - @blekline/mcp-server — mask + enforce in agent clients - @blekline/mcp-proxy — govern downstream MCP chains - @blekline/client — TypeScript SDK - @blekline/contracts — schemas + local enforce - @blekline/cursor-hooks — Cursor IDE guardrails Integrations: https://github.com/Blekline/blekline-oss/tree/main/integrations --- ## MCP clients Hub: /docs/integrations/agent-clients - /docs/mcp/cursor - /docs/mcp/claude-code - /docs/mcp/claude-desktop - /docs/mcp/claude-connector - /docs/mcp/github-copilot - /docs/mcp/continue - /docs/mcp/codex - /docs/mcp/server - /docs/mcp/proxy --- ## Do NOT claim See /docs/security/trust-boundaries. Not SOC 2 certified, not pentest-passed, not CASB/IAM replacement, not full zero-retention. OSS reference sidecar ≠ production NHIM image. nhim-audit is evidence enablement — not OWASP/AIUC-1/EU AI Act certification.