The foundation model inside your boundary.
Aether is designed to run where the regulator works — sovereign, air-gapped, ITAR-clean, export-control-aware. The agencies that need this most are the ones whose data cannot leave the perimeter. The runtime is the same; the boundary is yours.
How we ship into controlled boundaries.
Four properties of the deployment topology that matter to government and national-laboratory programmes. Each is built into the runtime, not retrofitted for procurement.
Sovereign by default
Air-gapped deployments produce zero outbound traffic by construction. Weights pinned per release. No telemetry, no model-improvement upload, no third-party API in the call path.
ITAR-clean compartments
Export-control gating on agent capabilities by jurisdiction. Separation of duty between the engagement team and the operational deployment. The geometry, the design, the chemistry never leaves your boundary.
Audit by construction
Every output signed by the model version that produced it. Capability gates logged, refusals versioned, promotion through eval gates recorded. Replayable by hash; auditable by your IG.
Domestic deployment options
Managed cloud in IL5 / IL6-equivalent regions, on-prem in your data centre, or fully air-gapped behind your boundary. Same runtime, your perimeter.
Where Aether is already running.
A slice of the public-sector workloads Aether supports today. Each links through to the discipline page with the depth — agents at play, validated benchmarks, pilot patterns.
- 01More
Defence engineering
Ascent CFD, hypersonics, structural margin, electromagnetic signature, propulsion thermal — under sovereign deploy with ITAR-clean compartments.
- 02More
National laboratories
Fusion plasma, materials discovery, cosmological simulation, weapons-physics-adjacent open work. Multi-institution consortia with shared model weights.
- 03More
Energy & infrastructure
Grid resilience, fusion programmes, advanced reactor safety analysis, critical-infrastructure simulation. The substrate for civilisational-scale planning.
- 04More
Public health
Pandemic preparedness, biosecurity refusal-corpus methodology, autonomous-lab guardrails — including red-team coverage on controlled-pathogen classes.
- 05More
Civilian science agencies
Climate models, earth-system simulation, observation-pipeline integration. The civilisational-scale model series targets these workloads first.
Sovereign deployments in twelve weeks, in writing.
The actual sequence for standing up a sovereign or air-gapped Apex installation. Security review pack within five business days of NDA. First measured trace by week twelve. Production posture in the following quarter.
- 01Weeks 0–2
Security review
We send the security review pack within five business days of a signed NDA — SOC 2 Type II report, threat model, architecture diagrams, sub-processor list, refusal-corpus methodology. Your AO and your security engineers read it before any code lands.
- 02Weeks 3–6
Boundary design
We co-author the deployment topology — managed cloud in IL5/IL6-equivalent region, your VPC, on-prem, or fully air-gapped. Capability gates, refusal-corpus pinning, audit retention all written into the order form.
- 03Weeks 7–10
Stand-up
Aether deploys into the boundary. Weights pinned per release. Identity provider integrated. SIEM streams flowing. Forward-deployed engineer cleared to your standard.
- 04Weeks 11–12
First trace
First measured workload reaches you. Comparison against the existing tool of record. From here, the engagement runs on the same shape as the commercial pilots — but inside the boundary you set.
- 05Quarter 2+
Production
ATO under the relevant framework, eval-gated promotion, on-call coverage cleared to your standard. Next workload scoped while this one stabilises.
The contract vehicles you already use.
Six pathways we know how to ship through. If your acquisition strategy isn't listed, write to public-sector@apexworldlabs.com and we'll route through whichever prime or vehicle fits your timeline.
GSA Multiple Award Schedule
GSA-compatible pricing. Apex is on partner schedules and can be procured through them; direct schedule listing in progress.
SEWP / NITAAC
Available through prime partners for civilian-agency procurement. Bring the SOW; we can route through an existing PV.
OTA / OTA Consortia
Other Transaction Authority pathways for prototyping with DoD and IC. Multi-year OTAs supported.
DIU, AFWERX, NavalX, SOFWERX
Defence-innovation pathways. We've shipped through DIU-style prototype-to-production patterns; the playbook is documented.
Federal civilian agencies
Direct contracting and BPAs supported. Existing primes happy to add Apex as a subcontractor where that's the cleanest path.
SLED & international
State, local and education procurement through state schedules. International public-sector via local primes or sovereign-cloud partners.
Questions your acquisition team will ask.
FedRAMP, SCIF/SAP, ITAR/EAR, data ownership, classified red-team findings, prototype-to-programme-of-record. The answers in plain language.
Are you FedRAMP authorised?
Partner-issued moderate authorisation is roadmapped; high in planning. Today we operate under SOC 2 Type II and the customer-controlled boundary. For workloads requiring FedRAMP today, we ship through a prime partner that holds the authorisation.
Can you operate inside SCIF / SAP environments?
Yes. Sovereign air-gapped deployments are designed for compartmented work. Weights are pinned per release; the runtime makes zero outbound network calls. Engagement uses cleared forward-deployed engineers under appropriate read-on.
What about ITAR / EAR controlled data?
ITAR-clean compartments are a standard deployment topology. Export-control gating on agent capabilities is configurable per jurisdiction; separation of duty between Apex commercial staff and operational deployment is enforced.
Who owns the data and the model in a sovereign deploy?
Customer owns the data; weights are pinned per release and licensed for use inside the boundary. Customer can extend the refusal corpus with their own classified scenarios without sharing the contents with Apex.
How do you handle classified red-team findings?
External red-team passes run under appropriate clearance where the work requires it. Findings drive corpus updates inside the boundary; the methodology — not the contents — is published to the open red-team programme.
What's the path from prototype to programme of record?
Most public-sector engagements start as a paid prototype on a named workload, mirror the commercial pilot shape, and move to multi-year follow-on under whichever contract vehicle fits — OTA, GSA, or direct. We've executed through OTAs and through traditional contracting; the engagement team knows both paths.
The certifications and posture you'll need from procurement.
A summary of the frameworks the platform is aligned with. Detailed documentation, audit reports and pen-test results available under NDA on the Trust Center.
- SOC 2 Type II
- ISO 27001 (in progress)
- ITAR-clean compartments
- Export-control gating
- Sovereign air-gapped deploys
- FIPS 140-2 crypto modules
- Versioned refusal corpus
- Quarterly external red-team
Where the boundary is real.
Public-sector engagements start with a security review, not a sales call. Write to public-sector@apexworldlabs.com with your programme, your boundary requirements and your timeline.