Your internal systems
No replacement, no migration. LLM Capsule reads the data where it already lives.
- ERP
- CRM
- ticketing
- document management
LLM Capsule sends approved AI a substituted version of your data, then reconstructs the real answer inside your network. This page has what a security, data, or platform team needs to judge it: the zones and data path first, then components, deployment, and integration.
Documents are not sent out to a third-party service. LLM Capsule is deployed inside your network, and your existing systems call it there.
No replacement, no migration. LLM Capsule reads the data where it already lives.
Sensitive items leave as substituted values, and the returned output is reconstructed to its original values here.
Original values and the reconstruction mapping never cross this line.
Only models your organization approved. What arrives here is the substituted document.
So the record left outside your network contains no original values.
The path runs in order. Operational systems and original values stay in your environment. Only a substituted, structure-preserving copy (the working version) crosses the boundary, and the result is reconstructed where the work happens.
Records and original values stay in the systems that already run the work. LLM Capsule connects to ERP, CRM, tickets, documents, databases and RAG. No replacement, no data migration.
Sensitive markers become a protected working version, while tables, fields and references stay usable. Only that version moves forward. Original values and the reconstruction mapping stay here.
Your policy routes the working version by workflow, data type, permissions and model approval. The work runs on an approved external or on-premise model. Original values never enter this zone.
LLM Capsule combines the model response with the local mapping and reconstructs it in its original context. The result returns straight to tickets, reports, records or workflows, with each reconstruction logged for traceability.
Technical review · implementation path
Source interfaces, the working version, the approved route, and local reconstruction, all shown as one reviewable implementation surface.
Reads directly from the operational systems that are already in place.
CONNECTED SYSTEMS
RAW INPUT FIELDS
ID identifier · CD reference code · BD unstructured body
Integration surface · REST · gRPC · JDBC · Graph API
Detection and substitution preserve the task structure.
SUBSTITUTION FLOW
Customer(capsule:person_1)ID
Ticket(capsule:champ_1)CD
Free text[context-preserving]BD
capsule:id is the substituted-value format that stands in for the original inside the capsule.
DP ENGINE
The organization selects the approved execution route.
LLM PIPELINE
The approved route can change without altering the working-version contract.
PRIVACY ISOLATION MODULE
EU GDPREU Region
The response is reconstructed in the environment where the work began.
RESPONSE TO ORIGINAL CONTEXT
RECONSTRUCTION
OUTPUT PROPERTIES
Auto restoreLocal onlyData residency
These components implement the four functions on the product page. Detection and substitution look like one step from outside. Here they split into two, so you can configure, observe and audit each on its own.
Structure-preserving substitution · one step from the outside
Finds sensitive data in structured fields or free text.
98.1%detection accuracy
Swaps sensitive values only. The shape around them stays intact.
What makes it operable at scale
Sensitivity rules keep changing. Policy keeps pace without breaking past work.
Brings the real answer back to where the work started.
Every step from detection to reconstruction leaves an auditable record.
These are technical constraints and implementation criteria, not a second set of product features. Together, they make the customer-facing capabilities reliable in production.
Each principle addresses a concrete architectural failure mode: loss of structure, system rewrites, context loss, an uncontrolled external path, manual reconstruction, or policy drift.
The same LLM Capsule instance can route different workflows through different paths, all under one governance framework.
For workflows where the rules allow a substituted, differentially-private version to reach an external model under the usual contracts (DPA, SCCs).
For workflows where no external endpoint is acceptable: classified data, operational-technology (OT) systems, or tightly regulated healthcare records.
These are the operational systems LLM Capsule reads from directly. Each connects with a single API call, and none of them change on their side.
Invocation interfaces, matched to each stack
LLM Capsule runs inside the customer environment in every mode. Path A and Path B execution choices apply across all six.
Fully internal. No external network. Path B only. Defense, classified, OT.
Internal LLM Capsule + approved external LLM. Path A for most workflows, Path B for sensitive subset.
Customer's cloud VPC. LLM Capsule and reconstruction mapping stay in the tenant; the LLM call goes to an in-region endpoint.
Listed and procurable through AWS Marketplace and Microsoft Marketplace. VPC deployment, cloud billing integration.
For ISVs and platform vendors building LLM Capsule into their own product. Library-level integration that ships inside the host application.
For teams using Slack as the operations UI. LLM Capsule runtime stays in the customer environment; the Slack App is the surface that invokes it.
A separate operator-grade topology (NFV, container, multi-region) that composes with the modes above rather than replacing them.
Once the working team is convinced, security and legal sign off. LLM Capsule records audit logs, policy history and exposure control as you run. Full documentation lives in the Trust Center.
LLM Capsule logs detection, substitution and reconstruction as events, with retention set by policy.
Every change to detection or routing policy keeps the prior version and when it changed.
Original values and the reconstruction mapping never leave the customer environment.
Bring your deployment constraints, regulatory profile, and one real workflow. We’ll show the data layer running in your environment in 30 minutes.