The AI Runtime Control Plane

Control production AI at runtime. Prove what happened.

Deploy, enforce policy, observe traces and cost, and evaluate quality across supported production AI paths—from one runtime control plane.

  • EU-hosted or self-hosted
  • OpenAI- & Anthropic-compatible
  • Independently verifiable evidence
Example governed requestIllustrative

Runtime path

Your app · agent · copilot
Quantlix Runtime Control Layer

policy · redaction · budget · enforced

Policy check
PII redaction
Budget control
Enforced
Evidence recordhash-chained
OpenAI · Anthropic · Groq · Together · Bedrock

Request verdict

Allowed with redaction

Detected
email, phone
Action
redacted before call
Provider
openai · gpt-4o
Policy
gdpr-pack
Latency
412 ms
Tamper-evident evidence record · hash-chained · export ready
  • DeploymentEU-hosted or self-hosted
  • GatewayOpenAI- & Anthropic-compatible
  • EvidenceIndependently verifiable

Provider integrations

OpenAIAnthropicGroqTogetherBedrockVoyage
View integrations →

How it works

One governed request. Four control-plane views.

Follow the same request from deployment to policy enforcement, traces, and evaluation—without stitching together separate tools.

  1. 01

    Deploy

    Bind a production deployment to its provider, environment, contract, and policy version.

    deployment
    support-copilot · prod-eu
  2. 02

    Control

    Evaluate input before inference, then allow, redact, block, cap spend, or require approval.

    verdict
    allowed with redaction
  3. 03

    Observe

    Inspect the request across policy decisions, provider, latency, cost, and failures.

    trace
    qlx_8f2a41c9 · 412 ms
  4. 04

    Evaluate

    Attach eval suites, compare versions, and gate promotion when quality regresses.

    eval suite
    customer-support · passed

One request identity

The same run connects deployment, enforcement, trace, and eval evidence.

request_id: qlx_8f2a41c9

Try it

Run a policy check in the sandbox

Paste a synthetic prompt, choose a policy pack, and see whether Quantlix would allow, redact, or block it—no signup, storage, or provider call.

Interactive policy lab

Preview one governed request

Choose an outcome, inspect the input, and watch the request cross the runtime boundary.

Production policy modules
Boundary runtime preview
stage: inputmode: no-store

Configure request

Input and enforcement

Before provider
enterprise-baseline

General-purpose input baseline for credential-shaped secrets, payment instruments, critical identifiers, and personal data.

POST /run
Synthetic only · not stored522 chars left

Automatic abuse protection runs in the background.

Runtime inspector

Decision and request path

Awaiting run
Preflight ready

Watch the request cross the boundary

Run the preview to resolve the real policy action and reveal exactly what would reach the provider.

  1. Request ingress

    Ready

    Synthetic input is ready for evaluation.

    then
  2. Contextual policy

    Selected

    Enterprise baseline — general purpose

    then
  3. Canonical decision

    Pending

    Allowed · Warned · Redacted · Blocked

    then
  4. Provider boundary

    Gated

    Continues only when the selected policy permits it.

This anonymous preview stops before persistence. Production traffic adds the enforcement event, request ID, trace, and eligible audit evidence.

No-storage contextual policy preview using production detector and enforcement-pack rules. No provider call or runtime evidence is created.

Runtime evidence

From policy documents to runtime proof

Quantlix turns model activity into defensible records — policy decisions, redaction events, provider metadata, timestamps, and trace IDs — exportable as audit bundles. It produces the evidence; your advisor renders the judgment. Quantlix does not declare anyone "compliant."

Hash-chained trace store

Every enforcement and run-seal event appends to a per-tenant SHA-256 ledger — each entry carries the digest of the prior entry, so undetected alteration breaks the chain.

Rekor anchoring → verify without trusting Quantlix

Completed segments publish Merkle roots to the public Sigstore Rekor log. Reviewers confirm anchors with a browser or the bundled verification script — no Quantlix login required.

Seven evidence artifacts

  • Hash-chained trace store

    Full request lifecycle: policy verdicts, redacted input, provider, latency, cost.

  • Enforcement records

    Pinned policy version, rules evaluated, verdict, and reason per request.

  • Redaction / PII events

    Detection category and action taken — metadata only, no retained PII.

  • Provider & failover attribution

    Per-call provider/model plus failover events when routing shifts.

  • Approval-gate & stop records

    Human approvals, deployment stops, and access-audit events with actor identity.

  • Eval & adversarial detection

    Eval-gated promotion results and boundary detections on live traffic.

  • Exportable audit bundle

    Manifest-led PDF / CSV / JSON with HOW_TO_VERIFY and standalone verifier.

policy GDPR Pack

verdict Allowed with redaction

detected email, phone number

action redacted before provider call

environment production

provider openai · gpt-4o

trace_id qlx_8f2a41c9…

export audit-ready

Example record — illustrative only.

Security & deployment

Built for EU hosting, self-hosting, and security review

  • EU-hosted or self-hosted

    Use the Quantlix EU-hosted deployment or run the runtime layer in your own environment.

  • Provider-independent

    Works with OpenAI, Anthropic, Groq, Together, Bedrock, Voyage.

  • Role-based access

    Separate engineering, governance, leadership, and reviewer access.

  • Exportable evidence

    Audit bundles for buyers, auditors, and leadership review.

Security posture — stated honestly

  • SOC 2 Type 1In progress
  • ISO 27001On roadmap
  • ISO 42001Planned
  • Third-party penetration testScheduled
  • Evidence integrityAppend-only · Rekor
  • DeploymentEU-hosted · self-hosted

SOC 2 Type 1 in progress — report available under NDA when the examination completes. Not certified today.

For your whole team

Built for engineering, security, risk, audit, and AI leadership

One runtime evidence layer — five buying-committee lenses, not five products.

Platform & AI Engineers

Integrate fast. Keep control. Debug request by request.

View developer flow
  • OpenAI- & Anthropic-compatible gateway
  • Provider configuration
  • API keys & SDK snippets
  • Policy packs
  • Raw traces & request inspection
  • Latency & error visibility

Who it's for

Designed for regulated AI use cases already in production

  • HR-tech

    Candidate screening, interview copilots, employee support.

  • Fintech

    Fraud triage, support copilots, loan-processing assistance.

  • Insurance

    Claims triage, underwriting support, knowledge assistants.

  • Healthtech

    Care-admin copilots, patient routing, clinical ops.

  • Legal-tech

    Contract review, matter intake, legal research.

  • Govtech

    Citizen-service assistants, case triage, process automation.

  • Engineering orgs

    AI coding assistants — Claude Code, Codex, IDE extensions — governed at the gateway.

The AI Runtime Control Plane

Start with one governed AI request.

Run a policy check now, then see how the same control plane deploys, controls, observes, and evaluates production AI.

Quantlix — The AI Runtime Control Plane