In-flight security for AI agents

Security that runs in flight.

BLAZLE sits between your AI agents and the world. Every prompt, shell command and code diff is inspected before it leaves your environment: secrets redacted, injections blocked, risky actions held for a human.

40-second tour: redact, block, approve, audit.

~0.2 ms

Static detection per request

under 2 ms

50-100 ms

AI prompt-injection check

only when it is needed

3

Surfaces inspected

prompts · commands · diffs

0

Third-party AI calls for detection

your payload never leaves BLAZLE

Measured in production, October 2026. Methodology

03 / Approach

Interception, not detection.

Most tools look at what already happened. BLAZLE decides at the moment a payload is produced, before anything leaves.

After the fact

  • Scans logs or commits after the payload has already left
  • Exposed secrets get rotated and hoped for
  • Alerts arrive minutes or hours later
  • Nothing stops the request at the moment of egress

In flight, with BLAZLE

  • Evaluated the instant it is produced, before it goes anywhere
  • Blocked before it reaches the model, the shell or the repository
  • Static rules in ~0.2 ms, ML injection check in 50-100 ms
  • Per-tenant policy: block, redact or log
  • Detected secrets are masked before anything is stored

AI agent

Cursor · Copilot · Devin · your pipeline

BLAZLE · BLAZIL engine

scan · score · decide · ~0.2 ms

Model · shell · repo

only what passed policy

05 / Your policies

Your rules, in plain language.

BLAZLE reads the security policies your company already wrote. No regex, no rule syntax, and your documents never leave BLAZLE.

  1. 01

    Add your policies

    Upload the security policies you already have: PDF, Word, Markdown or plain text.

  2. 02

    Ask them anything

    Ask a question in plain language, including Vietnamese, and get the section that answers it.

  3. 03

    Turn a section into a rule

    Give two or three examples. BLAZLE flags messages that mean the same, then blocks once you are ready.

When something is blocked, see which of your policies it relates to, in one click.

How the Policy Library works

06 / Get started

Set up in under three minutes.

From a free account to protected agents, step by step: API key, first intercept, rules, your machine, GitHub, the MCP Copilot and audit.

07 / Dogfooding

We secure BLAZLE with BLAZLE.

Every pull request to BLAZLE, and to every repository across our parent company Kolerr Lab, is scanned by the BLAZLE GitHub App before merge. Our own AI Copilot, a full MCP server that can manage rules, incidents, API keys and policies, gets no special treatment either: everything it does runs through the same interceptor our customers rely on.

  1. 01

    Prompt scanned

    Every message to the Copilot's AI model is inspected by BLAZLE before it leaves.

  2. 02

    Role checked

    Each tool call needs the caller's own permission. No backdoor for the assistant.

  3. 03

    Action intercepted

    If BLAZLE would block it for a customer, it blocks its own Copilot too.

  4. 04

    Human approval

    Changes wait for a person. Destructive ones need a second approver.

  5. 05

    Audited

    Proposal, decision and execution land in the tamper-evident audit log.

If we wouldn't trust it with our own platform, we wouldn't ask you to.

How the MCP Copilot works

08 / Built for

Developers ship. Security sleeps.

One line in front of every model call.

  • REST API for prompts, shell commands and code diffs
  • Local IDE proxy, VS Code extension and git pre-commit hook
  • Clear verdict on every call: allowed, risk rating, matched rule
Read the quickstart
interceptDevelopers
curl -X POST https://api.blazle.io/api/v1/intercept/prompt \
  -H "X-API-Key: blz_live_..." \
  -H "Content-Type: application/json" \
  -d '{"prompt": "Deploy using this key: AKIA..."}'

{
  "allowed": false,
  "risk_rating": "Critical",
  "findings": [{ "rule_name": "AWS Access Key" }]
}

09 / Design partners

Shipping agents to production? Build it with us.

We work closely with a small group of teams running AI agents in real environments. Partners get direct access to the engineers, a say in the roadmap and hands-on help with rollout.

Apply as a design partner

Questions, answered

Does BLAZLE add latency to my agent?

Measured in production (October 2026): static detection takes ~0.2 ms per request (under 2 ms). The AI prompt-injection check adds 50-100 ms, and only runs when it is needed.

Do you store my prompts or secrets?

Allowed requests are not stored. When a request is blocked we keep an investigation record with detected secrets masked, for your plan's retention period. The secret itself is never persisted, and detection never sends your payload to a third-party AI service.

How is this different from a secret scanner?

Scanners run after the fact, on logs or commits, once the secret has already left. BLAZLE sits in the path and decides before the payload reaches the model, the shell or the repository.

Which agents does it work with?

Anything that sends prompts, runs commands or writes code: Cursor, Copilot, Devin, custom pipelines over REST, and pull requests through the GitHub App.

Can BLAZLE follow our own security policies?

Yes. Upload the policies you already have to the Policy Library, ask them questions in plain language, and turn any section into a rule from a few example messages. New rules warn first and block once you switch them on. Your documents stay inside BLAZLE.

How does BLAZLE help with compliance?

Findings are scored on a MAS-TRM Likelihood × Impact matrix, and BLAZLE ships the evidence an auditor asks for: a tamper-evident audit chain, retention posture, access review and exportable evidence bundles for MAS-TRM and SOC 2 audits.

10 / Start

Your agents are already running. Make them run safely.

Free forever on the Hacker tier: 5,000 intercepted requests a month. No credit card required.

Watch the 3-minute setup

Powered by the BLAZIL engine · 234K TPS fintech-grade core