If sensitive internal data is holding AI work back
Blocked work runs in the systems you already use.
Same path whether a person asks or a system calls.
LLM Capsule substitutes the sensitive values but keeps the structure and relationships the model needs. Your approved model runs on that protected version, and LLM Capsule restores the real values through a mapping kept inside your environment.
Inside your company or inside your product, LLM Capsule works the same way.
AI work that stalled on sensitive data now runs where your teams already work.
Blocked work runs in the systems you already use.
Same path whether a person asks or a system calls.
The feature you could not ship goes into your product through the SDK or API.
Substitute, run on the approved model path, reconstruct inside your environment. All three happen within one request.
Plays on its own. Click the last step to reconstruct it yourself.
The original values stay in a reconstruction mapping in your environment.
Stand-in values appear here.
Only the protected version travels the approved model path.
external · VPC · on-prem
LLM Capsule looks the values up inside your environment. No original values are sent back to the model.
Only the ⟨capsule:…⟩ form leaves your environment. Your original values and the reconstruction mapping stay inside.
Masking removes the value, so the answer comes back incomplete. A privacy vault stores protected values, but how much task context survives varies by tool.
LLM Capsule substitutes while preserving context and restores an answer ready for real work.
circuit_id = ██████on node ███history ████
values + mapping→ context varies by tool
circuit_id = ⟨capsule:circuit_1⟩on node ⟨capsule:node_1⟩history kept
When substitution alone cannot keep the originals inside and still give the task what it needs, DTS rebuilds data with the required patterns, distributions, and relationships.
Relationships that consistent substitution already preserves stay as they are. Only the data that needs rebuilding is rebuilt.
Customer inquiries or contract review: names, accounts and codes are swapped and the content stays intact. The same person keeps the same stand-in, and the answer comes back with real values.
Transaction pattern analysis or clinical and claims analytics: the relationships between amounts, timing and results are the answer. Swapping values one by one erases the pattern, so DTS rebuilds the data with the relationships the task needs. Rebuilt data serves analysis, training, and evaluation. Decisions on an individual customer case still run through the substitution and reconstruction path.
Not every dataset needs rebuilding.
Rebuilt data is not restored back to the originals.
Self-tested figures. Processing time is per 2,200-character page and excludes answer generation.

Works onBGP logs · circuit IDs
Returns asReconstructed incident ticket

Works onAsset IDs · ICS alerts
Returns asUpdated field work order

Works onClinical notes · medical record IDs
Returns asReconstructed EHR record

Works onCitizen requests · admin documents
Returns asDraft replies · audit trail
Operational data changes weekly. When quality drifts, answers move between runs and last month’s approved result has nothing behind it. Syntitan, CUBIG’s AI-ready data platform, records the data version and run conditions behind each result and revalidates after changes.
Data you could not send to a model runs on your approved path, and the real values come back in the answer. What changes is the integration point, and its scope depends on your workflow.
Each data version is recorded with its run conditions and revalidated after changes, so you can reproduce the result at audit and show the basis.
Each can be adopted on its own. The operating scope grows with repeated work, changes, and revalidation.
We collected the questions workflow owners and approvers ask first.
Yes. The approved model path can be an external API, a VPC endpoint or a local model. Only the protected version travels that path.
LLM Capsule can run on-prem, in a VPC or in a controlled network. You set the deployment boundary and the approved model path during architecture review.
Start with one representative workflow: logs, tickets, tables, PDFs, scans, or any other operational record you already work with.
No. LLM Capsule substitutes the values before the model call and restores the result afterward, so prompts and the model itself stay as they are. What changes is the integration point, and that depends on your workflow and model endpoint.
Your team does, per workflow. That includes the business identifiers and references a standard PII detector would miss.
The deployment boundary, the approved model path, the substitution policy, where the original values and the reconstruction mapping live, and how the result is reconstructed.
One representative data sample, the model path you want to use, and the output your workflow needs. We run the full round trip on it.
They are separate CUBIG products that solve different problems. LLM Capsule runs AI work that sensitive operational data had blocked, inside your environment. Syntitan records the data version and run conditions behind each result and revalidates after changes. Each can be adopted on its own, and the operating scope grows with repeated work, changes, and revalidation needs.
Start with the free Slack bot. More integrations are on the way.

Ask AI in Slack, without leaving your workspace. Free to use.

Ask Claude from Microsoft Teams, in active development and not yet available.

Bring LLM Capsule into Jira and Confluence, in active development and not yet available.
New integrations are in the works. Browse the full directory.
Explore all integrations →AI responses can be wrong or incomplete. Review anything you plan to act on.
See what stays in your environment and how the real values come back in the answer.