The AI Runtime Control Plane
Control production AI at runtime. Prove what happened.
Deploy, enforce policy, observe traces and cost, and evaluate quality across supported production AI paths—from one runtime control plane.
- EU-hosted or self-hosted
- OpenAI- & Anthropic-compatible
- Independently verifiable evidence
Runtime path
policy · redaction · budget · enforced
Request verdict
Allowed with redaction
- Detected
- email, phone
- Action
- redacted before call
- Provider
- openai · gpt-4o
- Policy
- gdpr-pack
- Latency
- 412 ms
- DeploymentEU-hosted or self-hosted
- GatewayOpenAI- & Anthropic-compatible
- EvidenceIndependently verifiable
Provider integrations
OpenAIAnthropicGroqTogetherBedrockVoyageHow it works
One governed request. Four control-plane views.
Follow the same request from deployment to policy enforcement, traces, and evaluation—without stitching together separate tools.
- 01
Deploy
Bind a production deployment to its provider, environment, contract, and policy version.
- deployment
- support-copilot · prod-eu
- 02
Control
Evaluate input before inference, then allow, redact, block, cap spend, or require approval.
- verdict
- allowed with redaction
- 03
Observe
Inspect the request across policy decisions, provider, latency, cost, and failures.
- trace
- qlx_8f2a41c9 · 412 ms
- 04
Evaluate
Attach eval suites, compare versions, and gate promotion when quality regresses.
- eval suite
- customer-support · passed
One request identity
The same run connects deployment, enforcement, trace, and eval evidence.
Try it
Run a policy check in the sandbox
Paste a synthetic prompt, choose a policy pack, and see whether Quantlix would allow, redact, or block it—no signup, storage, or provider call.
Preview one governed request
Choose an outcome, inspect the input, and watch the request cross the runtime boundary.
Configure request
Input and enforcement
General-purpose input baseline for credential-shaped secrets, payment instruments, critical identifiers, and personal data.
Automatic abuse protection runs in the background.
Runtime inspector
Decision and request path
Watch the request cross the boundary
Run the preview to resolve the real policy action and reveal exactly what would reach the provider.
- then
Request ingress
ReadySynthetic input is ready for evaluation.
- then
Contextual policy
SelectedEnterprise baseline — general purpose
- then
Canonical decision
PendingAllowed · Warned · Redacted · Blocked
Provider boundary
GatedContinues only when the selected policy permits it.
This anonymous preview stops before persistence. Production traffic adds the enforcement event, request ID, trace, and eligible audit evidence.
No-storage contextual policy preview using production detector and enforcement-pack rules. No provider call or runtime evidence is created.
Runtime evidence
From policy documents to runtime proof
Quantlix turns model activity into defensible records — policy decisions, redaction events, provider metadata, timestamps, and trace IDs — exportable as audit bundles. It produces the evidence; your advisor renders the judgment. Quantlix does not declare anyone "compliant."
Hash-chained trace store
Every enforcement and run-seal event appends to a per-tenant SHA-256 ledger — each entry carries the digest of the prior entry, so undetected alteration breaks the chain.
Rekor anchoring → verify without trusting Quantlix
Completed segments publish Merkle roots to the public Sigstore Rekor log. Reviewers confirm anchors with a browser or the bundled verification script — no Quantlix login required.
Seven evidence artifacts
Hash-chained trace store
Full request lifecycle: policy verdicts, redacted input, provider, latency, cost.
Enforcement records
Pinned policy version, rules evaluated, verdict, and reason per request.
Redaction / PII events
Detection category and action taken — metadata only, no retained PII.
Provider & failover attribution
Per-call provider/model plus failover events when routing shifts.
Approval-gate & stop records
Human approvals, deployment stops, and access-audit events with actor identity.
Eval & adversarial detection
Eval-gated promotion results and boundary detections on live traffic.
Exportable audit bundle
Manifest-led PDF / CSV / JSON with HOW_TO_VERIFY and standalone verifier.
policy GDPR Pack
verdict Allowed with redaction
detected email, phone number
action redacted before provider call
environment production
provider openai · gpt-4o
trace_id qlx_8f2a41c9…
export audit-ready
Example record — illustrative only.
Security & deployment
Built for EU hosting, self-hosting, and security review
EU-hosted or self-hosted
Use the Quantlix EU-hosted deployment or run the runtime layer in your own environment.
Provider-independent
Works with OpenAI, Anthropic, Groq, Together, Bedrock, Voyage.
Role-based access
Separate engineering, governance, leadership, and reviewer access.
Exportable evidence
Audit bundles for buyers, auditors, and leadership review.
Security posture — stated honestly
- SOC 2 Type 1In progress
- ISO 27001On roadmap
- ISO 42001Planned
- Third-party penetration testScheduled
- Evidence integrityAppend-only · Rekor
- DeploymentEU-hosted · self-hosted
SOC 2 Type 1 in progress — report available under NDA when the examination completes. Not certified today.
For your whole team
Built for engineering, security, risk, audit, and AI leadership
One runtime evidence layer — five buying-committee lenses, not five products.
- OpenAI- & Anthropic-compatible gateway
- Provider configuration
- API keys & SDK snippets
- Policy packs
- Raw traces & request inspection
- Latency & error visibility
Who it's for
Designed for regulated AI use cases already in production
HR-tech
Candidate screening, interview copilots, employee support.
Fintech
Fraud triage, support copilots, loan-processing assistance.
Insurance
Claims triage, underwriting support, knowledge assistants.
Healthtech
Care-admin copilots, patient routing, clinical ops.
Legal-tech
Contract review, matter intake, legal research.
Govtech
Citizen-service assistants, case triage, process automation.
Engineering orgs
AI coding assistants — Claude Code, Codex, IDE extensions — governed at the gateway.
The AI Runtime Control Plane
Start with one governed AI request.
Run a policy check now, then see how the same control plane deploys, controls, observes, and evaluates production AI.