Sys.Init // Governed_AI_Platform

Governed AI.
Sensitive Data.

KARECTL is an AI-conformant, Kubernetes-native platform for organisations that work with sensitive data under strict regulation. Operational AI and research analytics run side by side on one architecture, each in its own governed environment.

> System.Context

Uncompromising security. Full capability.

KARECTL brings infrastructure, identity, data tooling, AI inference and self-service provisioning together on a single Kubernetes-native architecture. The same platform supports operational AI, such as follow-up triage and waiting-list prioritisation, and research analytics. Each runs in its own governed environment, with its own approvals and access rules.

Safe data principles are built in: sensitive data stays within the governed environment, compute is brought to the data, and platform activity is centrally logged. A tamper-evident audit trail is in development.

KARECTL is in production at Lancashire Teaching Hospitals NHS Foundation Trust, on-premises and on Microsoft Azure. It is built on K8TRE, the open-source Trusted Research Environment we co-develop.

> Module.AI

AI-conformant by design.

On KARECTL, artificial intelligence (AI) models and agents work under the same controls as people: identity, access, isolation, audit and approval. The platform is working towards CNCF Kubernetes AI Conformance, the Cloud Native Computing Foundation's programme for Kubernetes platforms that run AI workloads.

[SYS_01]

Self-Hosted AI Inference

Large language models (LLMs) run on the platform's own infrastructure using vLLM, inside the governed environment. No sensitive data is sent to third-party AI services.

[SYS_02]

Operational AI

AI applications support live services, such as follow-up triage and waiting-list prioritisation. Each is approved through the organisation's information governance and clinical safety processes before it is used.

[SYS_03]

Research and Federated Analysis

Approved researchers work in isolated project workspaces and can take part in multi-site studies through federated analysis, so raw data stays with the organisation that holds it. Agentic research tools and AI orchestration of federated analysis are in development.

[SYS_04]

Agentic Platform Operations

AI agents interpret platform alerts and telemetry, then propose fixes or apply pre-approved routine ones, reducing repetitive work for engineers. Their actions are logged like any other user's.

One architecture for operational AI and research.

> Protocol.Execution

One architecture. Separate governed environments.

PHASE_01

Unified Infrastructure

A single Kubernetes-native platform brings together compute, identity, networking, data tooling and AI services for operational and research use. One governed foundation.

PHASE_02

Scoped Access

Approved people, and approved AI tools, get access scoped to their project or service, dataset and role. Multi-factor authentication (MFA) is enforced through Keycloak.

PHASE_03

Governed Compute

Compute is brought to the data. Analytics, AI inference and agents run inside the governed environment.

PHASE_04

Controlled Release

Research outputs are reviewed before anything leaves the environment.

> System.Specs

Built for those who understand the stakes.

KARECTL is both a safe place to store and query sensitive data and an active platform for putting AI to work on it.

>_

Kubernetes-Native by Design

Not a legacy product retrofitted for the cloud. KARECTL is built on Kubernetes from the ground up, delivering elastic, auditable and reproducible environments that scale with demand.

>_

Infrastructure-Agnostic

Designed to run where an organisation needs it. KARECTL is in production on-premises and on Microsoft Azure, from a shared configuration with small environment-specific additions.

>_

Scale to Zero

Idle workspaces scale to zero, so compute spend follows activity rather than provisioned capacity. Baseline infrastructure costs remain.

> Target.Profiles

Built for organisations where the stakes are real.

01

OPERATIONAL_TEAMS

Put AI to work on live services, under governance.

  • →Run AI applications on sensitive data inside the governed environment
  • →Self-hosted models: no data sent to third-party AI services
  • →Each application approved through governance and clinical safety processes
  • →Platform activity logged for audit
02

RESEARCHERS

Analyse sensitive data in an approved environment.

  • →Automated project provisioning, reducing the wait between approval and analysis
  • →Familiar tools: R, Python, JupyterHub and RStudio
  • →Collaborate across institutions without transferring raw data between them
  • →Research outputs reviewed before release
03

PLATFORM_TEAMS

Run one platform for every use.

  • →In production on-premises and on Microsoft Azure
  • →Security and compliance rules enforced as code
  • →AI-assisted remediation of routine platform issues
  • →Idle workspaces scale to zero
KARECTL_

An AI-conformant platform for governed AI and analytics on sensitive data.

© 2026 Lancashire Teaching Hospitals NHS Foundation Trust. All rights reserved.