The AI Runtime Control Plane

Your AI. Under control. In production.

One runtime layer in front of your models: policy enforced before inference, every decision recorded—so engineering ships and security can prove what ran.

Watch the 48-second overview
  • EU-hosted or self-hosted
  • OpenAI- & Anthropic-compatible
  • Independently verifiable evidence
Your AI. One control plane.Architecture overview

01 / Connect

AI applicationsYour product
Agents & copilotsYour assistants
WorkflowsYour AI processes

OpenAI- & Anthropic-compatible APIs

02 / Control

Norcaster

AI Runtime Control Plane

Deployment & policy version
Policy enforcement
PII redaction
Budget controls

Enforce before inference

03 / Execute

Models & providers

OpenAI
Anthropic
Groq
Together
Bedrock
VoyageEmbeddings
Your own models

Observe & evaluateConnected by request identity

Traces & costQuality evalsVerifiable evidence

Controls apply on supported production paths, as configured.

Provider integrations

OpenAIAnthropicGroqTogetherBedrockVoyage
View integrations →

Norcaster in 48 seconds

Keep your AI tools. Add the control your business needs.

See how Norcaster adds protection, spending control and a clear activity history to the AI applications your business already uses.

Read the video transcript

AI can help your business move faster.

But once it becomes part of everyday work, you also need to know what it’s doing—and keep sensitive information safe.

Norcaster connects to the AI tools you already use. There’s no need to replace the way your team works.

Choose your AI service. Set clear protection rules. And see every request in one place.

Everyday requests continue as normal.

But when a request contains sensitive information, Norcaster can stop it before it reaches the AI service.

Every decision is recorded, so your team can understand what happened, why it happened, and when.

Keep the AI tools you already use. Add the control your business needs.

Norcaster. The AI Runtime Control Plane.

How it works

One governed request. Four control-plane views.

Follow the same request from deployment to policy enforcement, traces, and evaluation—without stitching together separate tools.

  1. 01

    Deploy

    Bind a production deployment to its provider, environment, contract, and policy version.

    Live deployment
    support-copilot · prod-eu

    A customer-support bot live in EU production, bound to one policy version.

  2. 02

    Control

    Evaluate input before inference, then allow, redact, block, cap spend, or require approval.

    Policy decision
    Allowed — personal data removed

    Checked before the model ran — names and emails never reached the provider.

  3. 03

    Observe

    Inspect the request across policy decisions, provider, latency, cost, and failures.

    Request trace
    qlx_8f2a41c9 · 412 ms

    One ID holds the decision, provider, cost, and speed of this request.

  4. 04

    Evaluate

    Attach eval suites, compare versions, and gate promotion when quality regresses.

    Quality check
    Passed vs. the previous version

    Quality is scored before promotion — a regression blocks the rollout.

One request identity

The same run connects deployment, enforcement, trace, and eval evidence.

request_id: qlx_8f2a41c9

Try it

Run a policy check in the sandbox

Paste a synthetic prompt, choose a policy pack, and see whether Norcaster would allow, redact, or block it—no signup, storage, or provider call.

Boundary runtime preview
stage: inputmode: no-store

Configure request

Input and enforcement

Before provider
enterprise-baseline

General-purpose input baseline for credential-shaped secrets, payment instruments, critical identifiers, and personal data.

POST /run
Synthetic only · not stored522 chars left

Verification

Cloudflare Turnstile helps prevent automated abuse so this sandbox stays fast for real visitors.

Complete the verification checkbox above, then preview the policy decision.

Runtime inspector

Decision and request path

Awaiting run
Preflight ready

Watch the request cross the boundary

Run the preview to resolve the real policy action and reveal exactly what would reach the provider.

  1. Request ingress

    Ready

    Synthetic input is ready for evaluation.

    then
  2. Contextual policy

    Selected

    Enterprise baseline — general purpose

    then
  3. Canonical decision

    Pending

    Allowed · Warned · Redacted · Blocked

    then
  4. Provider boundary

    Gated

    Continues only when the selected policy permits it.

This anonymous preview stops before persistence. Production traffic adds the enforcement event, request ID, trace, and eligible audit evidence.

No-storage contextual policy preview using production detector and enforcement-pack rules. No provider call or runtime evidence is created.

Runtime evidence

Prove what happened.

Governed requests leave a defensible record — policy decision, redactions, provider, timestamp, trace ID — exportable as an audit bundle. Norcaster produces the evidence; your advisor renders the judgment. Norcaster does not declare anyone "compliant."

  • Tamper-evident by design. On Enterprise plans, enforcement decisions at the model boundary append to a per-tenant SHA-256 hash chain — any alteration breaks the chain.

  • Verify without trusting Norcaster. Completed chain segments anchor to a public transparency log (Sigstore Rekor) — reviewers check them in a browser, no Norcaster login.

  • Framework-scoped exports. Audit bundles export against nine framework views — EU AI Act, SOC 2, DORA, NIST AI RMF, ISO/IEC 27001, ISO/IEC 42001, GDPR, HIPAA and PCI DSS — from one evidence store. Each bundle stamps the mapping's validation status — Norcaster's own reading until an external reviewer has walked the rows; auditors, certification bodies and regulators judge.

policy GDPR Pack

verdict Allowed with redaction

detected email, phone number

action redacted before provider call

environment production

provider openai · gpt-4o

trace_id qlx_8f2a41c9…

export bundle exported · verifiable

Example record — illustrative only.

Security & deployment

Built for EU hosting, self-hosting, and security review

  • EU-hosted or self-hosted

    Choose a hosting mode. The policy engine and the evidence record stay the same.

    See deployment options →
  • Provider-independent

    Works with OpenAI, Anthropic, Groq, Together, Bedrock, Voyage.

  • Role-based access

    Separate engineering, governance, leadership, and reviewer access.

  • Exportable evidence

    Audit bundles for buyers, auditors, and leadership review.

Security posture — stated honestly

  • SOC 2 Type IIWindow opens Nov 2026
  • ISO 27001On roadmap
  • ISO 42001Planned
  • Third-party penetration testPlanned · in Type II window
  • Evidence integrityAppend-only · Rekor
  • DeploymentEU-hosted · self-hosted

SOC 2 Type II preparation underway — observation window opens Nov 2026; report available under NDA after the examination. Not certified today.

Deployment

Run the control plane where your models run.

Managed EU-hosted, self-hosted in your environment, or a hybrid data plane that keeps prompts and evidence inside your boundary. Same policy engine, same evidence record, whichever you choose.

  • EU-hosted

    Norcaster runs on EU infrastructure (Frankfurt). Change one base URL and start recording.

  • Self-hosted

    A first-class deployment mode. The licence is verified locally against a public key; the deployment makes no calls to Norcaster unless the optional signed update check is switched on.

  • Hybrid data plane

    Enforcement runs inside your network via the Sync Agent; prompts, personal data and evidence stay inside the boundary and only allow-listed metadata reaches Norcaster. Available to design partners; enterprise hardening is ongoing.

Govern a model you host yourself. Norcaster wraps any OpenAI-compatible endpoint — including vLLM and NVIDIA NIM — with input policy, output policy and one per-request trace. Your model stays where it is; only the governance runs through us.

  1. Environment check
  2. Install & boot QA
  3. Register AI systems and policies
  4. Evidence walk with your control owners
  5. Handover & hypercare

Self-hosted and hybrid installs are delivered as a scoped onboarding with written acceptance criteria.

For your whole team

Built for engineering, security, risk, audit, and AI leadership

One runtime evidence layer — five buying-committee lenses, not five products.

Platform & AI Engineers

Integrate fast. Keep control. Debug request by request.

View developer flow
  • OpenAI- & Anthropic-compatible gateway
  • Policy packs
  • Raw traces & request inspection

Who it's for

Designed for regulated AI use cases already in production

  • Fintech

    Fraud triage, support copilots, loan-processing assistance.

  • Insurance

    Claims triage, underwriting support, knowledge assistants.

  • Healthtech

    Care-admin copilots, patient routing, clinical ops.

  • Engineering orgs

    AI coding assistants — Claude Code, Codex, IDE extensions — governed at the gateway.

Plus HR-tech, legal-tech, and govtech.

The AI Runtime Control Plane

Start with one governed AI request.

Run a policy check now, then see how the same control plane deploys, controls, observes, and evaluates production AI.