---
title: "Norcaster with Vanta, Drata, or Secureframe"
description: "How Norcaster complements compliance readiness platforms: they evidence the organization, Norcaster evidences the AI runtime slice they cannot see. Two evidence surfaces, one audit — and only a licensed CPA firm attests."
canonical: https://www.norcaster.com/docs/norcaster-and-readiness-platforms
---
<!-- Generated at build time from the rendered page by portal/scripts/generate-llms.mjs. The page is the source of truth; edit it, not this file. -->

Governance · evidence

# Norcaster with Vanta, Drata, or Secureframe

Compliance readiness platforms such as Vanta, Drata, and Secureframe collect evidence about the organization — people, devices, policies, vendors, and cloud configuration — and track it against frameworks like SOC 2 and ISO 27001. Norcaster does not replace them. It produces the runtime evidence for the AI slice of the same audit: what each governed AI request sent, which policy version was enforced, what was blocked or redacted, and who approved what — the traffic a readiness platform cannot see.

## What each surface evidences

| Area | Readiness platform | Norcaster |
| --- | --- | --- |
| People, HR, and security training | Collects and tracks | Out of scope |
| Endpoints and device posture | Collects and tracks | Out of scope |
| Cloud and infrastructure configuration | Collects and tracks | Out of scope for your estate; Norcaster’s own posture is published in the Trust Center |
| Vendor and risk management programs | System of record | Supplies inputs: provider attribution and failover events per request |
| Policies and change management | Tracks documents, approvals, and org-wide change processes | Pins the policy version to every runtime decision; platform audit trail for lifecycle changes |
| The AI request boundary | Cannot see inside AI traffic | Enforcement records, blocked events, and redaction events on every governed request |
| Human oversight of AI | Tracks that a process exists | Approval and deployment-stop records with actor identity and timestamp |
| Monitoring and anomaly detection for AI | Tracks the monitoring program | One policy verdict per request; adversarial-input detections stored with violation codes |

The readiness column describes the category in general terms; each vendor’s scope differs. Vanta, Drata, and Secureframe are trademarks of their respective owners; Norcaster is not affiliated with them.

## One audit, two evidence surfaces

An auditor samples evidence across the whole control environment. The readiness platform remains the system of record for organizational controls. Norcaster supplies the part most AI-heavy companies cannot otherwise produce: per-request proof that the approved controls operated on live AI traffic during the observation window. Runtime evidence accrues in real time and cannot be backfilled, so the window you can cover starts when the gateway does.

Norcaster states this boundary in the product and in every SOC 2 bundle: HR, endpoints, physical security, business continuity, and org-wide vendor management stay readiness-platform territory.

## The honesty boundary

Neither a readiness platform nor Norcaster can declare a company compliant. A SOC 2 report is performed and issued only by a licensed CPA firm under AICPA standards. Norcaster’s status vocabulary is deliberate — **evidence captured / controls active** — never “compliant”. Where a criterion depends on a human judgment, the obligations map tags it *requires attestation* and records who attested and when, rather than showing evidence a stored field cannot back.

## A practical workflow

1. Route production AI traffic through Norcaster — the run API or the OpenAI- and Anthropic-compatible gateway — so every request carries a policy decision.
2. Open the obligations map and see which SOC 2 criteria are runtime-evidenced, which mix runtime records with an attested process, and which remain organizational.
3. Record attestations for the organizational judgments — the periodic access review, for example — with owner and review date.
4. Export the SOC 2 audit bundle. It carries a criterion-mapping section citing which bundle sections back which Trust Services Criteria.
5. Hand it to your auditor alongside the readiness platform’s evidence. Either party can verify the bundle with the standalone script; no Norcaster account is required.

Details: [SOC 2 runtime evidence](https://www.norcaster.com/docs/soc2-evidence), [how proof works](https://www.norcaster.com/evidence), and [EU AI Act readiness](https://www.norcaster.com/docs/eu-ai-act-readiness) for the same evidence store projected onto a different framework.

## Common questions

### Does Norcaster replace Vanta, Drata, or Secureframe?

No — it complements them. A readiness platform covers the organization: laptops, people, policies, org-wide controls. It cannot see inside AI runtime traffic. Norcaster evidences that slice — the requests, redactions, policy decisions, and approvals on gatewayed AI traffic. Two different evidence surfaces, one audit; HR, endpoints, physical security, BCP, and org-wide vendor management remain readiness-platform territory, and Norcaster states that boundary in the product and in every SOC 2 bundle.

[Working alongside readiness platforms →](https://www.norcaster.com/docs/norcaster-and-readiness-platforms)

### Can software perform or issue a SOC 2 report?

No. A SOC 2 report can only be performed and issued by a licensed CPA firm under AICPA standards — no software platform can attest, including Norcaster. What software can do is produce the evidence the auditor samples. Norcaster produces the runtime evidence for the AI slice of a SOC 2 examination: boundary enforcement, monitoring, change management, processing integrity, and confidentiality records captured per request on gatewayed AI traffic.

[SOC 2 runtime evidence →](https://www.norcaster.com/docs/soc2-evidence)

### What SOC 2 evidence can Norcaster produce for AI systems?

Nine Trust Services Criteria groups map to the AI runtime, honesty-tagged: runtime-evidenced where a stored field backs the criterion (system boundaries CC6.6–6.7, monitoring CC7.1–7.2, change management CC8.1, processing integrity PI1, confidentiality C1), mixed where runtime records meet an attested process (incident management, availability), and requires-attestation where the judgment is organizational (the access review, risk and vendor programs). A SOC 2 audit bundle adds a criterion-mapping section a CPA firm's workpapers can cite.

[The full criterion mapping →](https://www.norcaster.com/docs/soc2-evidence)

### Is Norcaster itself SOC 2 certified?

Not yet, and we say so plainly: SOC 2 Type II preparation is underway, the observation window opens November 2026, and the report follows the examination, available under NDA. We deliberately skipped Type I. Meanwhile, EU-hosted and self-hosted deployment options shrink the vendor-risk surface a security review must assess.

[Trust center →](https://www.norcaster.com/trust)

Capabilities described as of September 2026. Norcaster is not a CPA firm; this page is not an attestation, an audit deliverable, or legal advice. SOC 2 examinations and reports are performed and issued exclusively by licensed CPA firms under AICPA standards.
