Built so your security team doesn't have to argue.
Aether is deployed into the kind of environment where wires are physical, doors are biometric and auditors are routine. Our security posture is engineered for that world from the model out — not bolted on as a sales sheet.
Customer data is not training data
Base models are never trained on customer prompts, code or experiment data. Fine-tunes are scoped, attributed and never reused across tenants. Right-to-delete is enforced by the runtime, not by a post-hoc job.
VPC, on-prem, air-gapped
Run in our SOC 2 Type II environment, in your VPC with private networking, or in a sovereign air-gapped configuration with no outbound traffic. Same runtime in every shape.
SSO, SCIM, role-based access
SAML / OIDC SSO. SCIM provisioning. Role-based capabilities for human users and for agents. MFA enforced on admin paths. Separation-of-duties controls for regulated environments.
Immutable trace of every action
Every model invocation, every tool call, every memory write — captured in an immutable trace your auditor reads directly. Exportable as SIEM events, OpenTelemetry spans or CSV.
Safety at the model layer
Biosecurity, export control and IP boundaries encoded into Aether's tool-use policy — not a wrapper that someone can disable. Refusal corpus is verified per release.
Disclosure and incident response
security@apexworldlabs.com — acknowledged within one business day. Coordinated disclosure programme with public hall of fame. Postmortems are written and shared for every customer-impacting incident.
The certifications and compliance regimes.
We publish where we are, not just where we'd like to be. If you need a control report or letter of attestation that isn't here, email trust@apexworldlabs.com — we can usually share something useful.
| Regime | Status | Notes |
|---|---|---|
| SOC 2 Type II | Certified | Cloud environment, audited annually by a Big-4 firm. Report under NDA. |
| ISO/IEC 27001 | In progress | Information-security management. Q3 2026 target. |
| ISO/IEC 42001 | In progress | AI management system. Q4 2026 target — first cohort of certified labs. |
| GDPR / UK-GDPR | Compliant | DPA on request. EU and UK data-residency controls available. |
| CCPA / CPRA | Compliant | Consumer privacy rights honoured across customer deployments. |
| HIPAA | BAA on request | Business Associate Agreement available for healthcare and life-science customers. |
| GxP / 21 CFR Part 11 | Ready | Autonomous-lab deploys satisfy ALCOA+ and 21 CFR Part 11 electronic-records requirements. |
| ITAR / EAR | Compatible | Air-gapped deployments supported. Export classification on request. |
| FedRAMP | Roadmapped | Partner-issued moderate authorisation in planning. |
| PCI-DSS | Out of scope | We do not process card-holder data. Customer integrations may bring it in scope. |
The technical controls, laid out.
The defaults are strict; the optional configurations are stricter. We share the architecture diagrams under NDA on the first call.
In transit and at rest
TLS 1.3 for transit, AES-256 for data at rest. Customer-managed keys via AWS KMS, GCP Cloud KMS or HashiCorp Vault. HSM-backed for sovereign deploys.
Private by default
PrivateLink / Private Service Connect for VPC deploys. No public ingress on the control plane in any configuration. Service-mesh mTLS between every component.
Isolated tenants
Per-tenant compute pools. No shared GPUs across customers at the workload level. Confidential-compute attestation supported on H100 and H200.
Logical isolation, tenant keys
Per-tenant logical isolation with customer-held keys. Cross-tenant queries are denied by the storage layer, not by application code.
Never on disk
Credentials, API keys and customer secrets flow through a managed secrets layer. Memory-only access; rotated automatically on suspicious activity.
Hardened images, signed releases
Containers built from a minimal base. SBOMs published per release. Sigstore-signed images. Daily CVE scans against the runtime fleet.
Safety is engineered, not promised.
Aether for autonomous labs operates real robots, which means safety has to live somewhere other than a sales deck. Here is where it lives.
Dual-use refusals are encoded in Aether's tool-use policy. A drug-discovery agent that can call a liquid handler cannot bypass refusals by writing a Python script — the refusal lives in the model, not in a wrapper.
Before a robot acts in the autonomous-lab surface, the planner runs controlled-pathogen and select-agent lookups. The agent must request the capability; the gate decides.
Every reagent, sample, plate and dilution is recorded immutably. The auditor sees what happened in the order it happened — and so does the next experiment.
We run an internal red-team programme and accept external reports. Refusal corpus is regression-tested per release; reds team scenarios are versioned.
We pay for good reports.
Email security@apexworldlabs.com with a reproducible report and we'll acknowledge within one business day. Awards scale with severity; safe-harbour applies to good-faith research that respects the scope below.
In scope
- apexworldlabs.com and *.apexworldlabs.com
- Aether API endpoints under the documented OpenAPI surface
- The agent runtime image (current minor version)
- Autonomous-lab tool-policy and capability-gating logic
- Customer-facing console (console.apexworldlabs.com)
- Apex-hosted documentation
Out of scope
- Social engineering of staff or customers
- Denial-of-service against shared infrastructure
- Physical attacks on Apex facilities
- Findings that depend on already-compromised endpoints
- Self-XSS and other findings that require victim-side actions
- Volumetric scanning that disrupts the platform
What good reports actually pay.
Bands are guidance, not contract. Real awards depend on impact, originality and the quality of the report. Our hall of fame is on /security/hall-of-fame.
RCE, auth bypass, model-weight exfiltration, refusal-corpus bypass with realistic dual-use payload.
Privilege escalation, account takeover, sensitive-data disclosure, cross-tenant boundary breach.
Stored XSS in authenticated areas, SSRF, business-logic flaws with material impact.
Reflected XSS, info disclosure, missing security headers with realistic exploit.
Bring your security team to the first call.
We answer questionnaires before they're asked. Your CISO is welcome on the first conversation, and we will share the SOC 2 report and architecture diagrams under NDA.