Governed AI.
Sensitive Data.
KARECTL is an AI-conformant, Kubernetes-native platform for organisations that work with sensitive data under strict regulation. Operational AI and research analytics run side by side on one architecture, each in its own governed environment.
> System.Context
Uncompromising security. Full capability.
KARECTL brings infrastructure, identity, data tooling, AI inference and self-service provisioning together on a single Kubernetes-native architecture. The same platform supports operational AI, such as follow-up triage and waiting-list prioritisation, and research analytics. Each runs in its own governed environment, with its own approvals and access rules.
Safe data principles are built in: sensitive data stays within the governed environment, compute is brought to the data, and platform activity is centrally logged. A tamper-evident audit trail is in development.
KARECTL is in production at Lancashire Teaching Hospitals NHS Foundation Trust, on-premises and on Microsoft Azure. It is built on K8TRE, the open-source Trusted Research Environment we co-develop.
> Module.AI
AI-conformant by design.
On KARECTL, artificial intelligence (AI) models and agents work under the same controls as people: identity, access, isolation, audit and approval. The platform is working towards CNCF Kubernetes AI Conformance, the Cloud Native Computing Foundation's programme for Kubernetes platforms that run AI workloads.
Self-Hosted AI Inference
Large language models (LLMs) run on the platform's own infrastructure using vLLM, inside the governed environment. No sensitive data is sent to third-party AI services.
Operational AI
AI applications support live services, such as follow-up triage and waiting-list prioritisation. Each is approved through the organisation's information governance and clinical safety processes before it is used.
Research and Federated Analysis
Approved researchers work in isolated project workspaces and can take part in multi-site studies through federated analysis, so raw data stays with the organisation that holds it. Agentic research tools and AI orchestration of federated analysis are in development.
Agentic Platform Operations
AI agents interpret platform alerts and telemetry, then propose fixes or apply pre-approved routine ones, reducing repetitive work for engineers. Their actions are logged like any other user's.
One architecture for operational AI and research.
> Protocol.Execution
One architecture. Separate governed environments.
Unified Infrastructure
A single Kubernetes-native platform brings together compute, identity, networking, data tooling and AI services for operational and research use. One governed foundation.
Scoped Access
Approved people, and approved AI tools, get access scoped to their project or service, dataset and role. Multi-factor authentication (MFA) is enforced through Keycloak.
Governed Compute
Compute is brought to the data. Analytics, AI inference and agents run inside the governed environment.
Controlled Release
Research outputs are reviewed before anything leaves the environment.
> System.Specs
Built for those who understand the stakes.
KARECTL is both a safe place to store and query sensitive data and an active platform for putting AI to work on it.
Kubernetes-Native by Design
Not a legacy product retrofitted for the cloud. KARECTL is built on Kubernetes from the ground up, delivering elastic, auditable and reproducible environments that scale with demand.
Infrastructure-Agnostic
Designed to run where an organisation needs it. KARECTL is in production on-premises and on Microsoft Azure, from a shared configuration with small environment-specific additions.
Scale to Zero
Idle workspaces scale to zero, so compute spend follows activity rather than provisioned capacity. Baseline infrastructure costs remain.
> Target.Profiles
Built for organisations where the stakes are real.
- →Run AI applications on sensitive data inside the governed environment
- →Self-hosted models: no data sent to third-party AI services
- →Each application approved through governance and clinical safety processes
- →Platform activity logged for audit
- →Automated project provisioning, reducing the wait between approval and analysis
- →Familiar tools: R, Python, JupyterHub and RStudio
- →Collaborate across institutions without transferring raw data between them
- →Research outputs reviewed before release
- →In production on-premises and on Microsoft Azure
- →Security and compliance rules enforced as code
- →AI-assisted remediation of routine platform issues
- →Idle workspaces scale to zero