Skip to content
Apex
Legal · Updated April 2026

Trust and safety

How Apex engineers safety — not promises, controls. Refusals, capability gating, audit traces, vulnerability disclosure and researcher access.

Approach

Safety at Apex is engineered, not promised. We treat safety as a continuous engineering discipline with measurable surfaces, not as a one-time certification or a sales talking-point. The controls below are properties of the runtime and the model; they do not depend on customer engineers reading carefully.

Model-layer refusals

Our foundation model encodes refusal behaviour for known dual-use risks — particularly in chemistry, biology, weapons design and cybersecurity-offence. The corpus is versioned alongside the model and regression-tested per release. Customer-extended scenarios are supported under NDA for sovereign and regulated deployments.

Capability gating

Between the model's intent and a tool call sits a capability gate. Every tool the model wants to call must declare the capability it requires. In autonomous-lab deployments, capability gates perform controlled-pathogen and select-agent lookups before a robot is allowed to act.

Audit traces

Every model invocation, every tool call, every memory write is captured in an immutable, hash-linked trace. Traces are exportable as OpenTelemetry spans, SIEM events or JSONL. Customers can pin retention and access controls independently from us.

Export control

Our deployment templates support sovereign and air-gapped configurations. We can ship into environments where data and weights never leave a defined boundary. ITAR and EAR compatibility is supported under appropriate licensing.

Vulnerability disclosure

Email security@apexworldlabs.com. We acknowledge within one business day and aim to remediate in-scope reports within 90 days. Scope, awards and safe-harbour are documented at /security. Severe findings are paid up to $50,000.

Independent evaluation

We commission external red-team passes quarterly and welcome additional review from accredited security researchers. We do not retaliate against good-faith research that respects our scope; researchers are publicly acknowledged on /security/hall-of-fame.

Researcher access

We offer free, tracked access for academic safety research. Email safety@apexworldlabs.com with a short description of the work. We prioritise applications from groups working on alignment, biosecurity evaluation, and AI evaluation methodology.

Incident disclosure

Customer-impacting incidents are disclosed on /status within hours of detection, with a postmortem published within ten business days. Customers with executed MSAs are notified directly through their account contacts.

Open commitments

  • We will not deploy a model to production that has not passed the refusal-corpus regression for that release.
  • We will not retaliate against good-faith vulnerability researchers.
  • We will publish a postmortem for every customer-impacting incident.
  • We will support sovereign deployments where the customer's regulatory environment requires it.