The AI Runtime Control Plane
Your AI. Under control. In production.
One runtime layer in front of your models: policy enforced before inference, every decision recorded—so engineering ships and security can prove what ran.
Watch the 48-second overview- EU-hosted or self-hosted
- OpenAI- & Anthropic-compatible
- Independently verifiable evidence
01 / Connect
OpenAI- & Anthropic-compatible APIs
02 / Control
AI Runtime Control Plane
Enforce before inference
03 / Execute
Models & providers
Observe & evaluateConnected by request identity
Controls apply on supported production paths, as configured.
Provider integrations
OpenAIAnthropicGroqTogetherBedrockVoyageNorcaster in 48 seconds
Keep your AI tools. Add the control your business needs.
See how Norcaster adds protection, spending control and a clear activity history to the AI applications your business already uses.
Read the video transcript
AI can help your business move faster.
But once it becomes part of everyday work, you also need to know what it’s doing—and keep sensitive information safe.
Norcaster connects to the AI tools you already use. There’s no need to replace the way your team works.
Choose your AI service. Set clear protection rules. And see every request in one place.
Everyday requests continue as normal.
But when a request contains sensitive information, Norcaster can stop it before it reaches the AI service.
Every decision is recorded, so your team can understand what happened, why it happened, and when.
Keep the AI tools you already use. Add the control your business needs.
Norcaster. The AI Runtime Control Plane.
How it works
One governed request. Four control-plane views.
Follow the same request from deployment to policy enforcement, traces, and evaluation—without stitching together separate tools.
- 01
Deploy
Bind a production deployment to its provider, environment, contract, and policy version.
- Live deployment
- support-copilot · prod-eu
A customer-support bot live in EU production, bound to one policy version.
- 02
Control
Evaluate input before inference, then allow, redact, block, cap spend, or require approval.
- Policy decision
- Allowed — personal data removed
Checked before the model ran — names and emails never reached the provider.
- 03
Observe
Inspect the request across policy decisions, provider, latency, cost, and failures.
- Request trace
- qlx_8f2a41c9 · 412 ms
One ID holds the decision, provider, cost, and speed of this request.
- 04
Evaluate
Attach eval suites, compare versions, and gate promotion when quality regresses.
- Quality check
- Passed vs. the previous version
Quality is scored before promotion — a regression blocks the rollout.
One request identity
The same run connects deployment, enforcement, trace, and eval evidence.
Try it
Run a policy check in the sandbox
Paste a synthetic prompt, choose a policy pack, and see whether Norcaster would allow, redact, or block it—no signup, storage, or provider call.
Configure request
Input and enforcement
General-purpose input baseline for credential-shaped secrets, payment instruments, critical identifiers, and personal data.
Verification
Cloudflare Turnstile helps prevent automated abuse so this sandbox stays fast for real visitors.
Complete the verification checkbox above, then preview the policy decision.
Runtime inspector
Decision and request path
Watch the request cross the boundary
Run the preview to resolve the real policy action and reveal exactly what would reach the provider.
- then
Request ingress
ReadySynthetic input is ready for evaluation.
- then
Contextual policy
SelectedEnterprise baseline — general purpose
- then
Canonical decision
PendingAllowed · Warned · Redacted · Blocked
Provider boundary
GatedContinues only when the selected policy permits it.
This anonymous preview stops before persistence. Production traffic adds the enforcement event, request ID, trace, and eligible audit evidence.
No-storage contextual policy preview using production detector and enforcement-pack rules. No provider call or runtime evidence is created.
Runtime evidence
Prove what happened.
Governed requests leave a defensible record — policy decision, redactions, provider, timestamp, trace ID — exportable as an audit bundle. Norcaster produces the evidence; your advisor renders the judgment. Norcaster does not declare anyone "compliant."
Tamper-evident by design. On Enterprise plans, enforcement decisions at the model boundary append to a per-tenant SHA-256 hash chain — any alteration breaks the chain.
Verify without trusting Norcaster. Completed chain segments anchor to a public transparency log (Sigstore Rekor) — reviewers check them in a browser, no Norcaster login.
Framework-scoped exports. Audit bundles export against nine framework views — EU AI Act, SOC 2, DORA, NIST AI RMF, ISO/IEC 27001, ISO/IEC 42001, GDPR, HIPAA and PCI DSS — from one evidence store. Each bundle stamps the mapping's validation status — Norcaster's own reading until an external reviewer has walked the rows; auditors, certification bodies and regulators judge.
policy GDPR Pack
verdict Allowed with redaction
detected email, phone number
action redacted before provider call
environment production
provider openai · gpt-4o
trace_id qlx_8f2a41c9…
export bundle exported · verifiable
Example record — illustrative only.
Security & deployment
Built for EU hosting, self-hosting, and security review
EU-hosted or self-hosted
Choose a hosting mode. The policy engine and the evidence record stay the same.
See deployment options →Provider-independent
Works with OpenAI, Anthropic, Groq, Together, Bedrock, Voyage.
Role-based access
Separate engineering, governance, leadership, and reviewer access.
Exportable evidence
Audit bundles for buyers, auditors, and leadership review.
Security posture — stated honestly
- SOC 2 Type IIWindow opens Nov 2026
- ISO 27001On roadmap
- ISO 42001Planned
- Third-party penetration testPlanned · in Type II window
- Evidence integrityAppend-only · Rekor
- DeploymentEU-hosted · self-hosted
SOC 2 Type II preparation underway — observation window opens Nov 2026; report available under NDA after the examination. Not certified today.
Deployment
Run the control plane where your models run.
Managed EU-hosted, self-hosted in your environment, or a hybrid data plane that keeps prompts and evidence inside your boundary. Same policy engine, same evidence record, whichever you choose.
EU-hosted
Norcaster runs on EU infrastructure (Frankfurt). Change one base URL and start recording.
Self-hosted
A first-class deployment mode. The licence is verified locally against a public key; the deployment makes no calls to Norcaster unless the optional signed update check is switched on.
Hybrid data plane
Enforcement runs inside your network via the Sync Agent; prompts, personal data and evidence stay inside the boundary and only allow-listed metadata reaches Norcaster. Available to design partners; enterprise hardening is ongoing.
Govern a model you host yourself. Norcaster wraps any OpenAI-compatible endpoint — including vLLM and NVIDIA NIM — with input policy, output policy and one per-request trace. Your model stays where it is; only the governance runs through us.
- Environment check
- Install & boot QA
- Register AI systems and policies
- Evidence walk with your control owners
- Handover & hypercare
Self-hosted and hybrid installs are delivered as a scoped onboarding with written acceptance criteria.
For your whole team
Built for engineering, security, risk, audit, and AI leadership
One runtime evidence layer — five buying-committee lenses, not five products.
- OpenAI- & Anthropic-compatible gateway
- Policy packs
- Raw traces & request inspection
Who it's for
Designed for regulated AI use cases already in production
Fintech
Fraud triage, support copilots, loan-processing assistance.
Insurance
Claims triage, underwriting support, knowledge assistants.
Healthtech
Care-admin copilots, patient routing, clinical ops.
Engineering orgs
AI coding assistants — Claude Code, Codex, IDE extensions — governed at the gateway.
Plus HR-tech, legal-tech, and govtech.
The AI Runtime Control Plane
Start with one governed AI request.
Run a policy check now, then see how the same control plane deploys, controls, observes, and evaluates production AI.