Trust Center

Enterprise-grade architecture, built for regulated industries.

LLM Capsule is a context-preserving data layer for AI: certified, auditable, and designed for data sovereignty. Security, compliance, and procurement teams can evaluate how the architecture maps to their review framework, right on this page.

12 Certifications & recognitions issuing body and year on every entry
4 Framework mappings GDPR · HIPAA · SOX · EU AI Act
Every event Audit-logged detection, policy, mapping, routing
Certifications · Awards · Programs

12 entries, verifiable at the source

Every entry lists the issuing body and year.
Your team can verify each one at the source.

International Standard
ISO/IEC 27001
Information Security Management · KFQ · 2026

Systematic management of sensitive information, audited by an independent certifier.

International Standard
ISO/IEC 42001
AI Management System · KFQ · 2026

Responsible AI governance and risk management, audited by an independent certifier.

Korean SW Quality · Grade 1
GS Certification (Grade 1)
LLM Capsule · TTA · 2024 · Innovation Procurement Marketplace

Top-grade Korean government software-quality certification, supporting public-sector procurement.

Government Track
KISA Fast Track
Korea Internet & Security Agency · 2024

Selected for the KISA information-security industry Fast Track program.

Government Award
Information Security Product Innovation Award
Minister of Science and ICT Prize · 2024

Grand Prize, Information & Physical Security category.

Industry Award
Deutsche Telekom T-Challenge 2026 · 2nd Place
T-Mobile / Deutsche Telekom · 2026

Placed 2nd in the global open-innovation program with substitution and local restoration technology.

Analyst Recognition
Gartner Hyper-Synthetic Data Report
Named among 26 global key vendors · 2025

The only Asia-based company named in the June 2025 report.

Industry Recognition
2026 Emerging AI+X Top 100
Korea AI Industry Association · 2026

Selected for AI-ready data and privacy technology.

Government Program
2026 AI Voucher Selected Supplier
Ministry of Science and ICT · NIPA · 2026

Institutions can adopt CUBIG solutions, including LLM Capsule, via government vouchers.

Startup Program
NVIDIA Inception · SKT × Hana Bank Accelerator
2024–2025

NVIDIA Inception member and joint AI startup accelerator selection.

Global Recognition
Startup World Cup Finalist · NextRise Global Innovator
2024

Global startup competition finalist and innovator selection.

Marketplace
AWS Marketplace
Listed · procurement-ready

Available for direct purchase and private-offer deployment through AWS.

Compliance Frameworks

Mapped to your review framework

Each architectural control below is mapped to the relevant article or section of GDPR, HIPAA, SOX, and the EU AI Act.
A starting reference for your review.

Capability GDPR HIPAA SOX EU AI Act
Local substitution (originals stay inside)
Art. 5, Art. 32 Substitution before transmission (may qualify as pseudonymisation, Art. 4(5))
164.502(d), 164.514 Supports review against de-identification provisions
Section 404 Internal control over data flow
Art. 10, Art. 15 Data governance and cybersecurity requirements
Local reconstruction (restore mapping)
Art. 32 Reversal happens only inside the controlled environment
164.514(c) Restore-mapping keys kept separate
Section 404 Authorized users only
Art. 10 Reversal for legitimate use only
Audit logs (every event)
Art. 30 Records of processing activities
164.312(b) Audit controls
Section 404, 802 Internal control and record retention
Art. 12, 13, 19 Logging, transparency, conformity
Policy versioning + time-shifting
Art. 5(2), 24 Accountability principle
164.316 Policies and procedures
Section 302, 404 Control over policy changes
Art. 17, 18 Quality and risk management system
RBAC + scope
Art. 32 Access control
164.308(a)(4), 164.312(a) Workforce security and access control
Section 404 Segregation of duties
Art. 14 Human oversight
On-prem / air-gapped execution
Art. 44, Chapter V In on-prem / air-gapped deployments, no cross-border transfer occurs
164.308(a)(8) Contingency plan, environment control
Section 404 Environment control
Art. 43 Supports conformity assessment for high-risk AI
DPA, SCCs, vendor security
Art. 28 Processor obligations
BAA equivalent Business associate framework
Auditor reliance Vendor management
Art. 16 Provider obligations

A reference, not a compliance certification. Final determination rests with the customer.

Audit Framework

What the audit log captures

Every event in the LLM Capsule lifecycle is logged with structured metadata, ready for review by privacy, security, and compliance teams.

Detection events

Every detection: which marker, which document, which version, confidence, timestamp. Reproducible across policy versions.

Policy versions

Yesterday's policy archived, today's enforced, the diff visible. Time-shifting lets you query past decisions under the policy of that time.

Restore-mapping records

The restore mapping stays inside your environment. Every issuance and lookup is logged with workflow ID and user identity, and the store is encrypted at rest.

PII detection F1
Detection accuracy

PII detection F1 of 0.94 with automated substitution. Evaluated per deployment against your own document corpus.

Model + path routing

Which workflow routed to which model on which path (external or on-prem). Full per-event traceability for regulator review.

Admin Console

The screen your review will look at

Policies, access scopes, and the audit trail live in one console. Click through the menus below the way your review team would.

LLM Capsule
Dashboard
Active users 74
Detections 3,842
Detections by filter
Name preset32%
Email preset18%
Customer code custom8%
Phone number preset15%
Circuit ID custom6%
Teams
Name Team Role Status
A. Miller Dev Team admin Active
M. Reyes Dev Member Password
J. Carter QA 1 Member Locked
E. Novak Design Member Inactive
S. Park QA 2 Team admin Active
D. Lawson BE Member Active
Usage
Calls this month 4,329
Tokens 348.1M
Usage by model
gpt-51,842
Opus 4.7987
Gemini Pro654
gpt-5-mini321
Opus 4.6198
Haiku 4.584
Workspaces
Shared source Type Status
incident_ticket.docx DOCX De-identified
telco_style_log.csv CSV De-identified
claims_batch_05.xlsx XLSX De-identified
msa_acme_2025.pdf PDF De-identified
noc_rca_summary.docx DOCX De-identified
meeting_notes_07.txt TXT De-identified
Policy
Filter Type Edited by
Phone number preset System
Amount preset System
Date preset System
Customer code custom A. Miller
Circuit ID custom M. Reyes
Address preset System
LLM setup
Anthropic Opus 4.7 · default Opus 4.6 Haiku 4.5
OpenAI gpt-5 gpt-5-mini
Google Gemini Pro Gemini Flash

Only registered models can be called.

Audit log
All results All periods All actions
ActionResultUserTarget
Substitution run success A. Miller incident_ticket.docx
Model call success A. Miller gpt-5
Reconstruct success A. Miller INC-24091
Source upload failed M. Reyes telco_log.csv
Policy updated success Admin NOC-team v2
  1. 01

    Check the rules

    What counts as sensitive, which models are allowed, and who set each rule. Presets and custom markers are both visible.

  2. 02

    Check the scopes

    Teams, roles, and workspace boundaries. Who can see what, and which sources each team works from.

  3. 03

    Check the record

    Every run leaves an entry: who did what, on which target, with which outcome. Detection counts and call volumes sit alongside.

Documentation

Documents for procurement and legal

The documents your legal, security, and procurement teams need to move forward.
Request them through a short form and we will tailor them to your review.

Form-gated · 1 business day
Data Processing Agreement (DPA) template

CUBIG's standard DPA template aligned with GDPR Article 28 obligations. Includes Standard Contractual Clauses (SCCs) for international transfers. Customizable for sector-specific requirements.

Request the DPA
Form-gated · 1 business day
Vendor security questionnaire

Pre-filled CUBIG responses to standard SIG, CAIQ, and SOC2 vendor security questionnaires, with architecture diagrams and audit framework details for procurement and security review.

Request the questionnaire

When the checklist is closed, try it on your data.

Bring your documents, deployment constraints, and evaluation questions.
We will walk your review team through the architecture on your own workflow.