Governance · evidence

Norcaster with Vanta, Drata, or Secureframe

Compliance readiness platforms such as Vanta, Drata, and Secureframe collect evidence about the organization — people, devices, policies, vendors, and cloud configuration — and track it against frameworks like SOC 2 and ISO 27001. Norcaster does not replace them. It produces the runtime evidence for the AI slice of the same audit: what each governed AI request sent, which policy version was enforced, what was blocked or redacted, and who approved what — the traffic a readiness platform cannot see.

What each surface evidences

AreaReadiness platformNorcaster
People, HR, and security trainingCollects and tracksOut of scope
Endpoints and device postureCollects and tracksOut of scope
Cloud and infrastructure configurationCollects and tracksOut of scope for your estate; Norcaster’s own posture is published in the Trust Center
Vendor and risk management programsSystem of recordSupplies inputs: provider attribution and failover events per request
Policies and change managementTracks documents, approvals, and org-wide change processesPins the policy version to every runtime decision; platform audit trail for lifecycle changes
The AI request boundaryCannot see inside AI trafficEnforcement records, blocked events, and redaction events on every governed request
Human oversight of AITracks that a process existsApproval and deployment-stop records with actor identity and timestamp
Monitoring and anomaly detection for AITracks the monitoring programOne policy verdict per request; adversarial-input detections stored with violation codes

The readiness column describes the category in general terms; each vendor’s scope differs. Vanta, Drata, and Secureframe are trademarks of their respective owners; Norcaster is not affiliated with them.

One audit, two evidence surfaces

An auditor samples evidence across the whole control environment. The readiness platform remains the system of record for organizational controls. Norcaster supplies the part most AI-heavy companies cannot otherwise produce: per-request proof that the approved controls operated on live AI traffic during the observation window. Runtime evidence accrues in real time and cannot be backfilled, so the window you can cover starts when the gateway does.

Norcaster states this boundary in the product and in every SOC 2 bundle: HR, endpoints, physical security, business continuity, and org-wide vendor management stay readiness-platform territory.

The honesty boundary

Neither a readiness platform nor Norcaster can declare a company compliant. A SOC 2 report is performed and issued only by a licensed CPA firm under AICPA standards. Norcaster’s status vocabulary is deliberate — evidence captured / controls active — never “compliant”. Where a criterion depends on a human judgment, the obligations map tags it requires attestation and records who attested and when, rather than showing evidence a stored field cannot back.

A practical workflow

  1. Route production AI traffic through Norcaster — the run API or the OpenAI- and Anthropic-compatible gateway — so every request carries a policy decision.
  2. Open the obligations map and see which SOC 2 criteria are runtime-evidenced, which mix runtime records with an attested process, and which remain organizational.
  3. Record attestations for the organizational judgments — the periodic access review, for example — with owner and review date.
  4. Export the SOC 2 audit bundle. It carries a criterion-mapping section citing which bundle sections back which Trust Services Criteria.
  5. Hand it to your auditor alongside the readiness platform’s evidence. Either party can verify the bundle with the standalone script; no Norcaster account is required.

Details: SOC 2 runtime evidence, how proof works, and EU AI Act readiness for the same evidence store projected onto a different framework.

Common questions

Does Norcaster replace Vanta, Drata, or Secureframe?

No — it complements them. A readiness platform covers the organization: laptops, people, policies, org-wide controls. It cannot see inside AI runtime traffic. Norcaster evidences that slice — the requests, redactions, policy decisions, and approvals on gatewayed AI traffic. Two different evidence surfaces, one audit; HR, endpoints, physical security, BCP, and org-wide vendor management remain readiness-platform territory, and Norcaster states that boundary in the product and in every SOC 2 bundle.

Working alongside readiness platforms

Can software perform or issue a SOC 2 report?

No. A SOC 2 report can only be performed and issued by a licensed CPA firm under AICPA standards — no software platform can attest, including Norcaster. What software can do is produce the evidence the auditor samples. Norcaster produces the runtime evidence for the AI slice of a SOC 2 examination: boundary enforcement, monitoring, change management, processing integrity, and confidentiality records captured per request on gatewayed AI traffic.

SOC 2 runtime evidence

What SOC 2 evidence can Norcaster produce for AI systems?

Nine Trust Services Criteria groups map to the AI runtime, honesty-tagged: runtime-evidenced where a stored field backs the criterion (system boundaries CC6.6–6.7, monitoring CC7.1–7.2, change management CC8.1, processing integrity PI1, confidentiality C1), mixed where runtime records meet an attested process (incident management, availability), and requires-attestation where the judgment is organizational (the access review, risk and vendor programs). A SOC 2 audit bundle adds a criterion-mapping section a CPA firm's workpapers can cite.

The full criterion mapping

Is Norcaster itself SOC 2 certified?

Not yet, and we say so plainly: SOC 2 Type II preparation is underway, the observation window opens November 2026, and the report follows the examination, available under NDA. We deliberately skipped Type I. Meanwhile, EU-hosted and self-hosted deployment options shrink the vendor-risk surface a security review must assess.

Trust center

Capabilities described as of September 2026. Norcaster is not a CPA firm; this page is not an attestation, an audit deliverable, or legal advice. SOC 2 examinations and reports are performed and issued exclusively by licensed CPA firms under AICPA standards.