Approach
Safety at Apex is engineered, not promised. We treat safety as a continuous engineering discipline with measurable surfaces, not as a one-time certification or a sales talking-point. The controls below are properties of the runtime and the model; they do not depend on customer engineers reading carefully.
Model-layer refusals
Our foundation model encodes refusal behaviour for known dual-use risks — particularly in chemistry, biology, weapons design and cybersecurity-offence. The corpus is versioned alongside the model and regression-tested per release. Customer-extended scenarios are supported under NDA for sovereign and regulated deployments.
Capability gating
Between the model's intent and a tool call sits a capability gate. Every tool the model wants to call must declare the capability it requires. In autonomous-lab deployments, capability gates perform controlled-pathogen and select-agent lookups before a robot is allowed to act.
Audit traces
Every model invocation, every tool call, every memory write is captured in an immutable, hash-linked trace. Traces are exportable as OpenTelemetry spans, SIEM events or JSONL. Customers can pin retention and access controls independently from us.
Export control
Our deployment templates support sovereign and air-gapped configurations. We can ship into environments where data and weights never leave a defined boundary. ITAR and EAR compatibility is supported under appropriate licensing.
Vulnerability disclosure
Email security@apexworldlabs.com. We acknowledge within one business day and aim to remediate in-scope reports within 90 days. Scope, awards and safe-harbour are documented at /security. Severe findings are paid up to $50,000.
Independent evaluation
We commission external red-team passes quarterly and welcome additional review from accredited security researchers. We do not retaliate against good-faith research that respects our scope; researchers are publicly acknowledged on /security/hall-of-fame.
Researcher access
We offer free, tracked access for academic safety research. Email safety@apexworldlabs.com with a short description of the work. We prioritise applications from groups working on alignment, biosecurity evaluation, and AI evaluation methodology.
Incident disclosure
Customer-impacting incidents are disclosed on /status within hours of detection, with a postmortem published within ten business days. Customers with executed MSAs are notified directly through their account contacts.
Open commitments
- We will not deploy a model to production that has not passed the refusal-corpus regression for that release.
- We will not retaliate against good-faith vulnerability researchers.
- We will publish a postmortem for every customer-impacting incident.
- We will support sovereign deployments where the customer's regulatory environment requires it.