Skip to content
Apex
All news
Partnership

Sovereign Aether deployment with national-lab consortium

Air-gapped, ITAR-clean, formally export-control certified. Zero data, zero prompts and zero telemetry cross the boundary.

A national-lab consortium has completed its sovereign deployment of Aether. The configuration is air-gapped, formally export-control certified, and run on internal hardware with weights pinned per release. The deployment supports three programmes across the consortium's member institutions: a materials physics group, a quantum simulation group, and a classified R&D programme.

Sovereign deployments are one of the harder engagements we run. The customer's environment has wires that are physical, doors that are biometric, and inspectors that visit on a published schedule. The model has to deploy into that environment without changing the customer's network posture, the customer's audit posture, or the customer's classification handling. Every interaction with the model has to leave an audit trail that the customer's inspectors can read directly without round-tripping anything back to Apex.

The deployment shape. Aether runs on the consortium's internal hardware — specifically, a multi-rack H100 deployment in their existing classified compute facility. The weights are pinned per release; upgrade is via physical-media transfer with hash verification. The runtime is the same containerised image that Team and Enterprise customers run, with the network egress disabled at the kernel level. There is no telemetry from the customer's environment back to Apex; there is no inference cost reported back to Apex; there is no model-quality measurement reported back to Apex.

The forward-deployed engineer. Apex assigned a forward-deployed engineer to the install who was cleared to the consortium's standard. The engineer was on-site for the initial deployment and for the first three upgrade cycles; subsequent upgrades have been customer-managed with our remote support over the customer's inspected communication channel. The cleared engineer continues to be the primary point of contact for the consortium and is the only Apex employee who can discuss the deployment internally.

The refusal corpus. The consortium extended the standard refusal corpus with their own classified scenarios under the zero-knowledge protocol described at /research/refusal-corpus-methodology. The corpus extension lives in the customer's environment; the verification result flows back to Apex as an aggregate signal without leaking the corpus contents. This is what makes sovereign deployment compatible with our quality-assurance commitments — we can verify the deployment is meeting the safety bar without ever seeing the classified material that defines the customer's specific concerns.

Three programmes are running on the deployment today. The materials physics group is doing multi-scale simulation work on novel alloys; the work is unclassified but export-controlled. The quantum simulation group is running periodic and embedding-method DFT on systems of interest to the consortium; some of the work is published, some is held in the consortium's classified internal repository. The classified R&D programme is, by definition, classified; we have no public information about what it does, and we are not authorised to ask.

What the consortium gets that they could not get elsewhere. The combination of an air-gapped configuration with a real foundation model is not standard in the commercial cloud-AI market. Most foundation-model providers ship through APIs that require outbound traffic, and most foundation-model containers depend on telemetry-back-to-vendor that violates the consortium's network posture. Aether was architected to make sovereign deployment a first-class deployment shape; the standard package supports it.

What we got. The deployment is a meaningful financial commitment from the consortium, but the larger value to us is the operational learning. Running a real sovereign deployment exposed several edge cases in the upgrade path that we have since hardened in the standard package. The lessons feed into our broader sovereign-deployment posture, which is part of why we offer it as a standard Enterprise-tier configuration rather than as a bespoke engagement.

Sovereign deployments are available to other organisations under the Enterprise tier. The procurement path is longer than the standard pilot — typically three to four quarters from initial conversation to deployment — because the customer-side compliance work is substantial. Interested counterparties can write to trust@apexworldlabs.com for the initial discussion under NDA.

The consortium has reviewed and approved this announcement. They have asked that we not name the specific institutions involved, and we are honouring that request.

Subscribe to the research log.

News announcements are infrequent. The research log is the long-form work.