LLM Capsule

The context-preserving data layer that makes sensitive data usable for AI

Your originals stay inside your environment. LLM Capsule swaps only the sensitive values for stand-ins of the same shape and sends those to an approved model. Results come back reconstructed for real work. Two minutes to watch it run, on one of your own documents.

Original · your environment What goes to the model
circuit node time usable Plain masking CKT-77-AB12 █████ edge-04 ███ 09:42 ██:██ Unusable for AI Context-preserving substitution CKT-77-AB12 ⟨cap:ckt_1⟩ edge-04 ⟨cap:edge_1⟩ 09:42 09:42 Usable for AI

Drag the line to compare

Four workflow functions

Define policy, substitute in context, reconstruct locally, and keep the run visible.

LLM Capsule brings policy definition, structure-preserving substitution, local reconstruction, and operational records into one workflow inside your environment. The technical components that implement these functions are detailed in Architecture.

  1. 01

    Policy engine

    You decide what counts as sensitive

    Not a fixed vendor list. Your team names the markers: circuit and asset IDs, contract references, project code names, internal metrics. When the rules change, you edit the policy and nothing about the system changes.

    • Custom markers
    • Versioned policy
  2. 02

    Substitution layer

    Swaps values for stand-ins of the same shape

    Black out a field and the model loses the record. A substitute keeps the shape, so tables, hierarchies and cross-references still read as one document.

    • Structure preserved
    • Structure-preserving substitutes
  3. 03

    Reconstruction mapping

    Puts the real values back into the result

    The model answers in stand-ins. The mapping turns them back into real names and figures inside your environment. The output moves into the next system without anyone retyping it.

    • Reconstructed inside
    • Output ready to use
04

Admin console

Keeps policy and run records connected

Every event lands here: which policy was active, which values changed, which model ran it, what came back restored. Your audit team replays any run end to end.

  • Event log
  • Policy versions
  • Model records
  • Replay a run
Product tour

Five steps, from a ticket going out to the answer coming back

Click through the tabs to see what each step changes on screen. The example is a NOC ticket; every document goes through the same five steps.

Step 01 — Point at the source

Reads the document where it already lives

LLM Capsule runs inside your environment. It reads documents straight from the systems already there: SharePoint, Jira and ServiceNow, Salesforce, Oracle ERP, an internal NOC console, your own portal. You move nothing, build no new pipeline and leave the architecture alone.

Existing systems call LLM Capsule from inside the environment over REST, gRPC, JDBC, Graph API, on-prem API, embedded SDK, or Slack app.

In-environmentOriginals stay inExisting sources
Step 02 — Define policy

Pick the filters your business cares about

Pick from the starter pack or write your own: project codes, contract refs, network IDs, mission refs, financial terms, vulnerability labels. Add, remove or time-shift a marker whenever the rules change, and the system stays as it is. LLM Capsule logs every policy version.

11 starter markersCustom regexPolicy versionsRBAC scope
Step 03 — Substitute

Only the sensitive values change. The structure stays.

Inside your environment, sensitive values become stand-ins that keep the shape of the original. Differential-privacy-based substitution (epsilon-DP, Laplace noise, k-anonymity, NER replacement) lowers re-identification risk. Tables, cross-references, and document hierarchy come through intact.

epsilon-DPLaplace noiseNER replacementStructure preserved
NOC Ticket · INC-2025-0427
Circuit ID:ACME-CKT-4821-NYC[Circuit_A]
Device IP:10.44.72.31[Device_A]
Contract Ref:MSA-ACME-2025-0312[Contract_A]
Site Code:NYC-DC1-FLOOR3[Site_A]
Service circuit ACME-CKT-4821-NYC[Circuit_A] reported signal degradation on device 10.44.72.31[Device_A]. Per master agreement MSA-ACME-2025-0312[Contract_A], clause 4.2 mandates log retention for 36 months. On-site verification scheduled at NYC-DC1-FLOOR3[Site_A] pending change approval.
Analyze this incident for root cause and recommended actions.
✦ Run LLM Capsule
Step 04 — Process

Any model. Your policy sets the path.

Only the protected working version travels. The original values stay inside your environment. That version goes to your approved external LLM (ChatGPT, Claude, Gemini, Perplexity), or to an on-prem lightweight model on a closed network.

Path A · ExternalPath B · On-premPolicy-routed
Step 05 — Reconstruct

AI output comes back business-ready

LLM Capsule restores the AI response inside your environment: mapping lookup, original value substitution, context re-binding, output validation. Real names, figures and references come back to the ticket. The reconstruction mapping stays in that environment too.

Local restoreContext re-bindingOutput validationAudit logged
What it handles

Not everything sensitive looks like PII

LLM Capsule reads every document type below. Names and phone numbers come preset. You define the values only your company has: circuit IDs, policy numbers, lot numbers, whatever your industry runs on.

Document types it reads

  • LOG System logs BGP logs, alarm streams, NOC notes
  • PDF PDF reports incident reports, filings, contracts
  • GRAPH Topology graphs network graphs, asset relationships
  • TICKET Tickets ticket fields, history
  • MD Runbooks response steps, escalation paths
  • YAML Code & config snippets, device configs
  • XLSX Tables structured fields, cross-references
  • IMG Images & diagrams schematics, scans, annotations
  • TXT Unstructured notes clinical notes, mission briefs

Value types it swaps

Preset what a PII tool also finds

  • Name
  • Phone
  • Address
  • Account no.
  • Date
  • Amount

Custom what it cannot find

  • Circuit ID
  • Policy number
  • Chart number
  • Lot number
  • Shipment ref
  • Contract ref
  • Internal metric
  • Org structure
  • Project code
  • Mission ref

If your format is not on the list, send us one document. We run it and show you the result. Run a sample proof →

Before and after

Masking severs the structure. Substitution keeps it.

Operational documents are not tidy tables. They are logs, PDFs and tickets, and the hierarchy and cross-references inside them go missing along with the values you remove. Here is one asset hierarchy handled both ways.

prompt Which circuits fall under the 30-day retention window, and who owns them?

Plain masking Cannot be answered
PDF NOC_INC-2025-0427.pdf
Location Contract Retention Owner
90 days
inherits inherits inherits
inherits inherits inherits
30 days

The tree is gone. The identifiers that tied racks to sites were removed, so the two middle rows are indistinguishable and the circuit connects to nothing.

Context-preserving substitution Answerable
PDF NOC_INC-2025-0427.pdf
Location Contract Retention Owner
SITE-A1 MSA-A1-0312 90 days Owner 1
RACK-A1-02 inherits inherits inherits
RACK-A1-03 inherits inherits inherits
CKT-A1-03-7 SLA-A1-03-7-B 30 days Owner 2

Every row stays distinct and the nesting still resolves, so the model can trace the circuit to its rack and site and answer with the owner.

Admin console

The rules and the record live in one place

Admins decide what counts as sensitive, which models may run and who sees what. They read the record of every run in the same console.

LLM Capsule
Dashboard
Active users 74
Detections 3,842
Detections by filter
Name preset32%
Email preset18%
Customer code custom8%
Phone number preset15%
Circuit ID custom6%
Teams
Name Team Role Status
A. Miller Dev Team admin Active
M. Reyes Dev Member Password
J. Carter QA 1 Member Locked
E. Novak Design Member Inactive
S. Park QA 2 Team admin Active
D. Lawson BE Member Active
Usage
Calls this month 4,329
Tokens 348.1M
Usage by model
gpt-51,842
Opus 4.7987
Gemini Pro654
gpt-5-mini321
Opus 4.6198
Haiku 4.584
Workspaces
Shared source Type Status
incident_ticket.docx DOCX De-identified
telco_style_log.csv CSV De-identified
claims_batch_05.xlsx XLSX De-identified
msa_acme_2025.pdf PDF De-identified
noc_rca_summary.docx DOCX De-identified
meeting_notes_07.txt TXT De-identified
Policy
Filter Type Edited by
Phone number preset System
Amount preset System
Date preset System
Customer code custom A. Miller
Circuit ID custom M. Reyes
Address preset System
LLM setup
Anthropic Opus 4.7 · default Opus 4.6 Haiku 4.5
OpenAI gpt-5 gpt-5-mini
Google Gemini Pro Gemini Flash

Only registered models can be called.

Audit log
All results All periods All actions
ActionResultUserTarget
Substitution run success A. Miller incident_ticket.docx
Model call success A. Miller gpt-5
Reconstruct success A. Miller INC-24091
Source upload failed M. Reyes telco_log.csv
Policy updated success Admin NOC-team v2
  1. 01

    Set the rules

    Pick how LLM Capsule replaces values, and use the preset markers alongside the ones your team names. Register the providers and models you allow in the same place.

  2. 02

    Separate access

    Teams carry roles, and each project keeps its own sources, so one group never reads another group's documents.

  3. 03

    Read it back

    Every run leaves a row: who ran it, on what, and whether it succeeded. You also see detection counts and call volume by team.

Performance

Measured on real enterprise documents

Figures come from 2,200-character documents in finance, healthcare, legal and public-sector workflows.

Per-page processing latency 0.12s

The time from receiving a page to finishing substitution. You can put it inside real-time NOC alerting, claims intake or clinical workflows without breaking an SLA.

Reconstruction rate 100%

Share of substituted values rebuilt from the mapping held inside your environment.

Output similarity 98%

Compared against the same model reading the original document. The meaning holds on the way out and back.

Detection accuracy 98.1%

LLM Capsule catches sensitive values in structured fields and in free text, custom markers included.

Workflow accuracy 99.14%

This covers the whole path in production workflows, from the original input to the restored output.

What comes next

Start with LLM Capsule. Run every day on Syntitan.

LLM Capsule lets you run AI on work that was too sensitive before. Syntitan keeps the answers steady once that work runs every day.

LLM Capsule This page
  • Turns data that cannot leave as-is into substitutes for an approved model
  • Substitution policies and the reconstruction mapping stay in your environment
  • Results come back ready to use, and every run adds an audit row
  • Policy engine
  • Substitution layer
  • Reconstruction mapping
  • Admin console

Run a sample proof →

Syntitan In production
  • Checks the data before each run, so a broken batch does not reach the model
  • Records which version of the data each answer came from
  • Compares the versions, finds the cause, and reproduces the data from the day it worked
  • Release State
  • Run Binding
  • Diff
  • Reproduce

Explore Syntitan →

Start with one workflow AI cannot reach yet.

Bring your real workflow. We'll set up LLM Capsule on a sample document in your environment within 30 minutes.