Choose your world. The capsule opens with every capability.
One capsule, identity, rules and proof, sealed for your domain. Open it and see the full regulatory arsenal, not one headline. What we cover, and what we don't yet, in full disclosure.
Why now
AI agents reach your dataModels read organizational data, not just people.
IAMGoverns users, not models.
DLPDetects data, but doesn't prevent real access.
EncryptionFalls the moment the provider holds the key.
Regulators now ask a new question: who can really see the data?
A new control layer · not a competitor
A new control layer · No Data · No Keys · Proof
Not DLP, not more encryption, a new layer above them all: the provider cannot see the data, holds no key, yet everything is cryptographically proven. The combination of the three sides is what no existing tool does. Items marked ▲ stand on it.
The AI era · three moves
The AI era, in three moves
Not another checklist, one model: decide what is exposed, control how AI computes on it, and bind proof to every touch.
AAccess Minimization
Local scan maps the sensitive fields, then only the necessary slice is decrypted, need-to-know. Aligns with GDPR Art 5(1)(c) and EDPB 28/2024.
CControlled Computation
When AI must act, it sees only the problematic slice inside a sandbox you control, never the whole asset, never the key.
BBound Proof
Every access, human or AI agent, binds a tamper-evident receipt. Helps keep and prove the operation logs the AI Act requires (Art 12, Art 26(6)).
The AI Act's high-risk duties were deferred to 2027–2028 (Digital Omnibus). We prepare you for what's coming, see the access layer in the Capsule Access API.
One capsule · two modes of ownership
One capsule · two modes of ownership
Same capsule, same codes, the only difference is where the key lives.
🛠️ Connected
online · control
The key lives on the server, revoke · rotate · converse · prove. Activated by your plan.
🔐 Sovereign
offline · forever
The key is in the code, opens offline, forever, surviving even NoData. Free.
🌉 The bridge is signed: every Sovereign capsule is ECDSA-signed and the file verifies itself before it opens, forgery or tampering is refused, so nothing malicious can be injected into the Capsule.
You don't implement dozens of controls. You inherit them from the capsule.
🩺🔒
Health Capsule
HIPAAHITECH42 CFR Part 2GDPR Health
Sealed and ready. Inside, 11 delivered requirements (3 on the new layer ▲), including breach-notification Safe Harbor. Open it.
🩺
Health Capsule
HIPAA · HITECH · 42 CFR Part 2 · GDPR Health
Deep coverage
11 delivered · 3 partial · 1 no
11delivered
3partial
1not incl. · full disclosure
✓Delivered · 11
✓
§164.402 / .404
Breach notification, Safe Harbor▲ trinity
Sovereign encryption → a breach triggers no notice: the key is never with us.
✓
§164.312(a)(2)(iv)
ePHI encryption
The key is out of the equation, no scenario where the provider exposes PHI.
✓
§164.312(b)
Audit controls▲ trinity
A signed log, verifiable to OCR even without us.
✓
GDPR Art. 34(3)(a)
Notification waiver via encryption
A health-data breach with no wave of individual notices.
✓
42 CFR §2.16
Substance-use records (SUD)
Criminal-exposure records, mathematically blocked, every touch proven.
✓
GDPR Art. 32(1)(a)
Security of processing
A no-key architecture at the depth a regulator likes to see.
✓
§164.312(c)(1)
Record integrity
Every change is cryptographically detectable, holds up in court.
✓
§164.312(a)(1)
Access control
Revocable even after sharing: key rotation cuts off access to the sealed object.
✓
§164.502(b)
Minimum necessary▲ trinity
The AI has no key to the identifying fields, math, not filtering.
✓
§164.308(b) / .502(e)
Business Associate Agreement (BAA)
The safest BAA: the provider holds no key and no stored value.
✓
§164.528
Accounting of disclosures
Who saw what and when, ready to verify in one click.
◐Partial · 3
◐
§164.312(d)
Person/entity authentication
Dual-channel (link+code), but no enterprise SSO/SCIM.
◐
GDPR Art. 9
Special-category health data
Heightened safeguards, not the lawful basis (consent).
◐
42 CFR §2.31
Consent to disclose
We prove access under approved policy, we don't manage the forms.
✕Not included · full disclosure · 1
✕
§164.514(b)(2)
de-identification (Safe Harbor)
We block AI from PHI mathematically, but don't strip the 18 identifiers from the record.
5 capsules · one product, sealed for every world. Based on code-verified capabilities (2026-07-07). General information, not legal advice, verify with your regulatory counsel.