Trust & Compliance

Enterprise-grade architecture

LLM Capsule is built for regulated enterprise environments. Certified, auditable, and designed for data sovereignty. This page is for security, compliance, and procurement teams evaluating how the architecture maps to your review framework.

Certifications & recognition

12 certifications, awards, and global recognitions

From international standards (ISO/IEC) to national certifications (KISA, GS) and category recognition (Gartner, Deutsche Telekom, AWS).

ISO
ISO/IEC 27001
Information Security Management
ISO
ISO/IEC 42001
AI Management System
KISA
KISA Fast Track
Korea Information Security
GS
GS Certification
Good Software (Korea)
AWARD
Security Innovation Award
MSIT (Korea)
RECOGNITION
T Challenge 2026 — Top 12
Deutsche Telekom · Data Security & Governance
AWARD
AI Medical Innovation
Healthcare AI category
RECOGNITION
Startup World Cup
Global recognition
RECOGNITION
Next Rise Global Innovator
Korea-Global innovation showcase
VENDOR
Gartner Vendor
AI / data category recognition
RECOGNITION
Emerging AI+X Top 100
Korea AI excellence
MARKETPLACE
AWS Marketplace
Listed and procurable
Compliance frameworks

How LLM Capsule capabilities map to GDPR / HIPAA / SOX / EU AI Act review workflows

LLM Capsule provides architectural controls that support GDPR, HIPAA, SOX, and EU AI Act review workflows. The matrix below maps each capability to the relevant article or section so compliance, security, and procurement teams have a starting reference. This is not a compliance certification — final compliance determination is the customer's, in their own deployment context.

LLM Capsule capability GDPR HIPAA SOX EU AI Act
Local encapsulation (data never leaves) Art. 5 (lawfulness), Art. 32 (security of processing) Pseudonymization before transmission 164.502(d), 164.514(b) De-identification methodology Section 404 Internal control over data flow Art. 10 (data governance), Art. 15 (cybersecurity) Data quality and protection requirements
Local restoration (token vault) Art. 32 Pseudonymization is reversible only inside controlled environment 164.514(c) Re-identification key separation Section 404 Authorized re-identification only Art. 10 Reversibility for legitimate use only
Audit logs (every event) Art. 30 Records of processing activities 164.312(b) Audit controls Section 404, 802 Internal control + record retention Art. 12, 13, 19 Logging, transparency, conformity
Policy versioning + time-shifting Art. 5(2), 24 Accountability principle 164.316 Policies and procedures Section 302, 404 Internal control over policy changes Art. 17, 18 Quality and risk management system
RBAC + scope Art. 32 Access control 164.308(a)(4), 164.312(a) Workforce security + access control Section 404 Segregation of duties Art. 14 Human oversight
On-prem / Path B execution Art. 44, Chapter V International transfer restriction (avoidance) 164.308(a)(8) Contingency plan, environment control Section 404 Environment control Art. 25 Conformity assessment when high-risk
DPA, SCCs, Vendor Security Art. 28 Processor obligations BAA equivalent Business associate framework Auditor reliance Vendor management Art. 28 Provider obligations
Audit framework

What the audit log captures

Every event in the LLM Capsule lifecycle is logged with structured metadata — ready for review by privacy, security, and compliance teams.

Detection events

Every detection: which marker, which document, which version, confidence, timestamp. Reproducible across policy versions.

Policy versions

Yesterday's policy archived, today's enforced. Diff visible. Time-shifting markers — query historical decisions under historical policy.

Token mappings

Local token vault never leaves. Token issuance + retrieval logged with workflow ID and user identity. Vault encrypted at rest.

Detection accuracy

98.1% baseline detection rate measured on industry benchmarks. Per-deployment evaluation against your own document corpus.

Model + path routing

Which workflow routed to which model on which path (A external / B on-prem). Full per-event traceability for regulator review.

Admin console

The control surface for security and compliance teams

One console for policies, audit, detection accuracy, and deployment health.

LLM Capsule · Admin Console ● Active
Time Event Status
09:14:02 PII token resolved success
09:13:47 Policy rule triggered warning
09:13:21 Model inference logged success
09:12:58 Unauthorized marker attempt error
09:12:33 Token scope validated success
Compliance downloads

Documentation for procurement and compliance

The documents your legal, security, and procurement teams need to move forward. Form-gated to coordinate with Sales / Customer Success on questions.

FORM-GATED · 1 BUSINESS DAY

Data Processing Agreement (DPA) Template

CUBIG's standard DPA template aligned with GDPR Article 28 obligations. Includes Standard Contractual Clauses (SCCs) for international transfers. Customizable for sector-specific requirements.

Request DPA →
FORM-GATED · 1 BUSINESS DAY

Vendor Security Questionnaire

Pre-filled CUBIG responses to standard SIG, CAIQ, and SOC2 vendor security questionnaires. For procurement and security review teams. Includes architectural diagrams and audit framework details.

Request Questionnaire →

From blocked AI workflows to operational AI.

See how LLM Capsule plugs into your existing enterprise environment in 30 minutes. Bring your documents, deployment constraints, and evaluation questions.