In-flight security for AI agents
Security that runs in flight.
BLAZLE sits between your AI agents and the world. Every prompt, shell command and code diff is inspected before it leaves your environment: secrets redacted, injections blocked, risky actions held for a human.
40-second tour: redact, block, approve, audit.
~0.2 ms
Static detection per request
under 2 ms
50-100 ms
AI prompt-injection check
only when it is needed
3
Surfaces inspected
prompts · commands · diffs
0
Third-party AI calls for detection
your payload never leaves BLAZLE
Measured in production, October 2026. Methodology
03 / Approach
Interception, not detection.
Most tools look at what already happened. BLAZLE decides at the moment a payload is produced, before anything leaves.
After the fact
- Scans logs or commits after the payload has already left
- Exposed secrets get rotated and hoped for
- Alerts arrive minutes or hours later
- Nothing stops the request at the moment of egress
In flight, with BLAZLE
- Evaluated the instant it is produced, before it goes anywhere
- Blocked before it reaches the model, the shell or the repository
- Static rules in ~0.2 ms, ML injection check in 50-100 ms
- Per-tenant policy: block, redact or log
- Detected secrets are masked before anything is stored
AI agent
Cursor · Copilot · Devin · your pipeline
BLAZLE · BLAZIL engine
scan · score · decide · ~0.2 ms
Model · shell · repo
only what passed policy
04 / Platform
One interceptor. Four ways in.
The same detection engine, policy and audit trail, wherever your agents work.
IDE proxy
A local edge proxy for coding agents, with a VS Code extension and a git pre-commit hook.
Docs 02REST API
REST endpoints for prompts, commands and diffs. One call returns a clear verdict before anything leaves.
Docs 03MCP Copilot
Agent tool calls run through the interceptor; state-changing actions wait for a human.
Docs 04GitHub App
Pull requests are scanned before merge. Blocked findings request changes on the PR.
Docs05 / Your policies
Your rules, in plain language.
BLAZLE reads the security policies your company already wrote. No regex, no rule syntax, and your documents never leave BLAZLE.
- 01
Add your policies
Upload the security policies you already have: PDF, Word, Markdown or plain text.
- 02
Ask them anything
Ask a question in plain language, including Vietnamese, and get the section that answers it.
- 03
Turn a section into a rule
Give two or three examples. BLAZLE flags messages that mean the same, then blocks once you are ready.
When something is blocked, see which of your policies it relates to, in one click.
How the Policy Library works06 / Get started
Set up in under three minutes.
From a free account to protected agents, step by step: API key, first intercept, rules, your machine, GitHub, the MCP Copilot and audit.
07 / Dogfooding
We secure BLAZLE with BLAZLE.
Every pull request to BLAZLE, and to every repository across our parent company Kolerr Lab, is scanned by the BLAZLE GitHub App before merge. Our own AI Copilot, a full MCP server that can manage rules, incidents, API keys and policies, gets no special treatment either: everything it does runs through the same interceptor our customers rely on.
- 01
Prompt scanned
Every message to the Copilot's AI model is inspected by BLAZLE before it leaves.
- 02
Role checked
Each tool call needs the caller's own permission. No backdoor for the assistant.
- 03
Action intercepted
If BLAZLE would block it for a customer, it blocks its own Copilot too.
- 04
Human approval
Changes wait for a person. Destructive ones need a second approver.
- 05
Audited
Proposal, decision and execution land in the tamper-evident audit log.
If we wouldn't trust it with our own platform, we wouldn't ask you to.
How the MCP Copilot works08 / Built for
Developers ship. Security sleeps.
One line in front of every model call.
- REST API for prompts, shell commands and code diffs
- Local IDE proxy, VS Code extension and git pre-commit hook
- Clear verdict on every call: allowed, risk rating, matched rule
curl -X POST https://api.blazle.io/api/v1/intercept/prompt \
-H "X-API-Key: blz_live_..." \
-H "Content-Type: application/json" \
-d '{"prompt": "Deploy using this key: AKIA..."}'
{
"allowed": false,
"risk_rating": "Critical",
"findings": [{ "rule_name": "AWS Access Key" }]
}09 / Design partners
Shipping agents to production? Build it with us.
We work closely with a small group of teams running AI agents in real environments. Partners get direct access to the engineers, a say in the roadmap and hands-on help with rollout.
Apply as a design partnerQuestions, answered
Does BLAZLE add latency to my agent?
Measured in production (October 2026): static detection takes ~0.2 ms per request (under 2 ms). The AI prompt-injection check adds 50-100 ms, and only runs when it is needed.
Do you store my prompts or secrets?
Allowed requests are not stored. When a request is blocked we keep an investigation record with detected secrets masked, for your plan's retention period. The secret itself is never persisted, and detection never sends your payload to a third-party AI service.
How is this different from a secret scanner?
Scanners run after the fact, on logs or commits, once the secret has already left. BLAZLE sits in the path and decides before the payload reaches the model, the shell or the repository.
Which agents does it work with?
Anything that sends prompts, runs commands or writes code: Cursor, Copilot, Devin, custom pipelines over REST, and pull requests through the GitHub App.
Can BLAZLE follow our own security policies?
Yes. Upload the policies you already have to the Policy Library, ask them questions in plain language, and turn any section into a rule from a few example messages. New rules warn first and block once you switch them on. Your documents stay inside BLAZLE.
How does BLAZLE help with compliance?
Findings are scored on a MAS-TRM Likelihood × Impact matrix, and BLAZLE ships the evidence an auditor asks for: a tamper-evident audit chain, retention posture, access review and exportable evidence bundles for MAS-TRM and SOC 2 audits.
10 / Start
Your agents are already running. Make them run safely.
Free forever on the Hacker tier: 5,000 intercepted requests a month. No credit card required.
Watch the 3-minute setupPowered by the BLAZIL engine · 234K TPS fintech-grade core