The AI Runtime Control Plane
Control production AI at runtime. Prove what happened.
Deploy, enforce policy, observe traces and cost, and evaluate quality across supported production AI paths—from one runtime control plane.
Watch the 48-second overview- EU-hosted or self-hosted
- OpenAI- & Anthropic-compatible
- Independently verifiable evidence
Runtime path
Request verdict
Allowed with redaction
- Detected
- email, phone
- Action
- redacted before call
- Policy
- gdpr-pack
- Latency
- 412 ms
Provider integrations
OpenAIAnthropicGroqTogetherBedrockVoyageNorcaster in 48 seconds
Keep your AI tools. Add the control your business needs.
See how Norcaster adds protection, spending control and a clear activity history to the AI applications your business already uses.
Read the video transcript
AI can help your business move faster.
But once it becomes part of everyday work, you also need to know what it’s doing—and keep sensitive information safe.
Norcaster connects to the AI tools you already use. There’s no need to replace the way your team works.
Choose your AI service. Set clear protection rules. And see every request in one place.
Everyday requests continue as normal.
But when a request contains sensitive information, Norcaster can stop it before it reaches the AI service.
Every decision is recorded, so your team can understand what happened, why it happened, and when.
Keep the AI tools you already use. Add the control your business needs.
Norcaster. The AI Runtime Control Plane.
How it works
One governed request. Four control-plane views.
Follow the same request from deployment to policy enforcement, traces, and evaluation—without stitching together separate tools.
- 01
Deploy
Bind a production deployment to its provider, environment, contract, and policy version.
- Live deployment
- support-copilot · prod-eu
A customer-support bot live in EU production, bound to one policy version.
- 02
Control
Evaluate input before inference, then allow, redact, block, cap spend, or require approval.
- Policy decision
- Allowed — personal data removed
Checked before the model ran — names and emails never reached the provider.
- 03
Observe
Inspect the request across policy decisions, provider, latency, cost, and failures.
- Request trace
- qlx_8f2a41c9 · 412 ms
One ID holds the decision, provider, cost, and speed of this request.
- 04
Evaluate
Attach eval suites, compare versions, and gate promotion when quality regresses.
- Quality check
- Passed vs. the previous version
Quality is scored before promotion — a regression blocks the rollout.
One request identity
The same run connects deployment, enforcement, trace, and eval evidence.
Try it
Run a policy check in the sandbox
Paste a synthetic prompt, choose a policy pack, and see whether Norcaster would allow, redact, or block it—no signup, storage, or provider call.
Configure request
Input and enforcement
General-purpose input baseline for credential-shaped secrets, payment instruments, critical identifiers, and personal data.
Automatic abuse protection runs in the background.
Runtime inspector
Decision and request path
Watch the request cross the boundary
Run the preview to resolve the real policy action and reveal exactly what would reach the provider.
- then
Request ingress
ReadySynthetic input is ready for evaluation.
- then
Contextual policy
SelectedEnterprise baseline — general purpose
- then
Canonical decision
PendingAllowed · Warned · Redacted · Blocked
Provider boundary
GatedContinues only when the selected policy permits it.
This anonymous preview stops before persistence. Production traffic adds the enforcement event, request ID, trace, and eligible audit evidence.
No-storage contextual policy preview using production detector and enforcement-pack rules. No provider call or runtime evidence is created.
Runtime evidence
From policy documents to runtime proof
Governed requests leave a defensible record — policy decision, redactions, provider, timestamp, trace ID — exportable as an audit bundle. Norcaster produces the evidence; your advisor renders the judgment. Norcaster does not declare anyone "compliant."
Tamper-evident by design. On Enterprise plans, enforcement decisions at the model boundary append to a per-tenant SHA-256 hash chain — any alteration breaks the chain.
Verify without trusting Norcaster. Completed chain segments anchor to a public transparency log (Sigstore Rekor) — reviewers check them in a browser, no Norcaster login.
Framework-scoped exports. Audit bundles export as EU AI Act obligations or SOC 2 Trust Services Criteria from one evidence store. For SOC 2, only a licensed CPA firm attests.
policy GDPR Pack
verdict Allowed with redaction
detected email, phone number
action redacted before provider call
environment production
provider openai · gpt-4o
trace_id qlx_8f2a41c9…
export bundle exported · verifiable
Example record — illustrative only.
Security & deployment
Built for EU hosting, self-hosting, and security review
EU-hosted or self-hosted
Use the Norcaster EU-hosted deployment or run the runtime layer in your own environment.
Provider-independent
Works with OpenAI, Anthropic, Groq, Together, Bedrock, Voyage.
Role-based access
Separate engineering, governance, leadership, and reviewer access.
Exportable evidence
Audit bundles for buyers, auditors, and leadership review.
Security posture — stated honestly
- SOC 2 Type IIWindow opens Nov 2026
- ISO 27001On roadmap
- ISO 42001Planned
- Third-party penetration testPlanned · in Type II window
- Evidence integrityAppend-only · Rekor
- DeploymentEU-hosted · self-hosted
SOC 2 Type II preparation underway — observation window opens Nov 2026; report available under NDA after the examination. Not certified today.
For your whole team
Built for engineering, security, risk, audit, and AI leadership
One runtime evidence layer — five buying-committee lenses, not five products.
- OpenAI- & Anthropic-compatible gateway
- Policy packs
- Raw traces & request inspection
Who it's for
Designed for regulated AI use cases already in production
Fintech
Fraud triage, support copilots, loan-processing assistance.
Insurance
Claims triage, underwriting support, knowledge assistants.
Healthtech
Care-admin copilots, patient routing, clinical ops.
Engineering orgs
AI coding assistants — Claude Code, Codex, IDE extensions — governed at the gateway.
Plus HR-tech, legal-tech, and govtech.
The AI Runtime Control Plane
Start with one governed AI request.
Run a policy check now, then see how the same control plane deploys, controls, observes, and evaluates production AI.