Real

Contracts enforce, YAML policy, egress rules — same code paths as MCP / CI, running in your browser.

Demo

Lineage contamination uses a simplified graph — mirrors Lineage Firewall semantics; production runs in the sidecar with session TTL.

Simulated

SPIFFE / IAM attestation is narrative only — no SPIRE or STS call from the docs page. Verify workload identity on fleet eval or K8s deployment.

01

Identity & policy

NHI selector + Trust Vault policy YAML

spiffe://blekline.internal/ns/prod/sa/data-agent-v2

Policy definitionYAML
02

Threat / payload

Edit the tool-call JSON or pick a scenario above.
Tool call payloadJSON

Run enforcement

Policy and payload are evaluated locally with Blekline contracts.

03

Runtime interceptor

Idle
ATTESTATION
EVALUATION
POLICY
LINEAGE
ENFORCEMENT

Awaiting execution — enforce a scenario to stream traces.

Trace output appears here after execution.