Analysis

Capsule's Nemotron circuit breaker is the runtime half of the agent security stack.

Fine-tuned NVIDIA Nemotron SLMs judge each agent action before execution. Company: 96.9% vs 86% third-party; decisions as low as 71ms. Seed was $7M (Lama). Valuation Undisclosed.

Sep 4, 2026 · 4 min read

This week's agent-security noise is mostly pre-runtime: skill firewalls, install-time scanners, policy that never sees the tool call. Capsule is shipping the other half — a circuit breaker that judges the action before it runs.

SiliconANGLE reported on September 2 that Capsule Security fine-tuned two NVIDIA Nemotron models into what it calls an "AI circuit breaker." The models evaluate an agent's intended action immediately before execution. Customers can allow, flag, or block in real time. SecurityWeek's same-day write-up frames the same product: specialized models in the execution path, not a post-incident monitor. Founded in 2025 by Naor Paz (CEO) and Lidan Hazout (CTO). Public launch in April with $7 million seed led by Lama Partners, per SiliconANGLE. Valuation: Undisclosed.

Company metrics need hard labels. Capsule says its most accurate detector scored 96.9% on an internal benchmark against 86% for the strongest third-party model evaluated. SiliconANGLE and SecurityWeek both carry those figures; neither names the third-party. Treat 96.9% vs 86% as company claim until an independent bake-off prints. Decisions as low as 71 milliseconds — again company-stated, tied to the smaller fine-tuned Nemotron path in Capsule's own technical blog. Memory cut by close to half; larger model runnable on a single NVIDIA L40S, per SiliconANGLE. StepShield, an academic step-level rogue-agent benchmark, is cited by Capsule at 98% in coverage — company-reported results on a public benchmark, not CyberMerge's audit.

Training stack, as SiliconANGLE and Capsule's NVIDIA-collaborative blog describe it: Nemotron 3 Ultra supporting the run; real agent traces; adversarial examples; human review on the decision boundary. Classification, not full generation — which is how they argue for inline latency. That architecture thesis is coherent. It is still a vendor thesis until third parties reproduce it.

Put Capsule next to the rest of this week's stack. AIR raised to firewall the skills agents install. HiddenLayer and Lasso priced runtime and guardrail capital. CrowdStrike and others keep shipping discovery-plus-control SKUs. Capsule's bet is narrower and sharper: if the agent already has credentials, the only useful question is whether this next action fits the task — before the tool runs. Permissions constrain reach. They do not judge intent. Post-facto monitoring finds the incident after the database is gone. The circuit breaker sits in between.

Ecosystem signals, not valuation signals: Capsule has published a Claude Platform security integration via Anthropic's Compliance API, and SecurityBrief coverage notes membership in Anthropic's Claude Security Program. Google Cloud's July Gemini Startup Forum: Cybersecurity cohort listed Capsule among 33 startups. Those are partnership and program facts. They are not ARR.

The sourced facts: fine-tuned Nemotron circuit breaker; allow/flag/block before execution; company 96.9% vs 86% third-party (unnamed); as low as 71 ms; ~half memory; single L40S; $7 million Lama-led seed; founders Paz and Hazout; valuation Undisclosed. Question the benches. Ask whether buyers will stack pre-runtime skill controls with inline runtime breakers — or pick one budget line and call it done. The industry is evolving toward stacked controls. Capsule is pricing the runtime half. Prove the numbers outside the press release.

Sources