Contracts enforce, YAML policy, egress rules — same code paths as MCP / CI, running in your browser.
Lineage contamination uses a simplified graph — mirrors Lineage Firewall semantics; production runs in the sidecar with session TTL.
SPIFFE / IAM attestation is narrative only — no SPIRE or STS call from the docs page. Verify workload identity on fleet eval or K8s deployment.
Identity & policy
spiffe://blekline.internal/ns/prod/sa/data-agent-v2
Threat / payload
Run enforcement
Policy and payload are evaluated locally with Blekline contracts.
Runtime interceptor
Awaiting execution — enforce a scenario to stream traces.
Trace output appears here after execution.