Get started

From nothing to a protected inbox

Five steps. Create the organization, link one browser, tell Blade who you are allowed to email, then watch a message be scanned before it leaves.

Dashboard and API

The dashboard runs at https://dashboard-production-1df6.up.railway.app and talks to the API on port 8000.

Chrome

Chrome 120 or newer, with developer mode available for loading an unpacked extension.

Open signup

The API has to allow open signup for you to create the first organization yourself.

The path

What you actually do

01

Create your organization

The signup form takes an organization name, your work email, and a password of at least 12 characters. One call creates the organization and its owner, signs you in, and lands you on the onboarding page.

Common passwords are rejected. If the email or the organization already exists, sign in instead.

02

Find your organization code

The onboarding page shows the code as soon as the account exists. Afterwards it lives in the dashboard under Settings, in the Organization code card, with a copy button next to it.

It reads BLD- followed by the code, and it is visible to owners and admins only. Treat it as a credential: anything holding it can submit and read scan traffic for your organization. Regenerating it unlinks every install you have already set up.

03

Install the Chrome extension and link it

Build the extension, open chrome://extensions, turn on Developer mode, choose Load unpacked, and select frontend/packages/extension/dist. Then click the Blade toolbar icon, paste the organization code under Organization code, and press Link.

Chrome 120 or newer. The manifest is generated at build time, so build before loading: VITE_BACKEND_URL=http://localhost:8000 pnpm --filter @bladedlp/extension build. The popup status card changes from Not linked yet to protection on for your organization, which is how you know the link took.

04

Classify your domains

Open Approved domains and add a row for each domain that matters, with a direction of sender, recipient, or both, and a classification of internal, partner, or blocked. Recipient classification is what the policy rules react to.

The field accepts a full email address as well as a bare domain. Add the address you send from as a sender row classified internal, or every message carrying a detection is blocked by the unapproved sender rule before the rest of the policy is reached.

05

Send a test message and read the verdict

Send a message with patient identifiers from the linked account. The same body gets three different answers: allowed to a recipient on your internal or partner list, held for review when it is high risk to a personal mailbox, and refused outright to a domain you classified as blocked.

Held messages wait in Quarantine until someone approves or rejects them, and the sending tab picks the decision up within a few seconds. Every scan shows up on the dashboard overview under Recent events, with its action and where it happened, and in the audit log.

Start with one inbox

The account and the code take a minute. Everything after that happens in the browser, so nothing you send has to leave the machine to be checked.