Skip to content
Apex
Security & trust

Built so your security team doesn't have to argue.

Aether is deployed into the kind of environment where wires are physical, doors are biometric and auditors are routine. Our security posture is engineered for that world from the model out — not bolted on as a sales sheet.

DEPLOYMENT TOPOLOGIES — four modes · same runtime · your boundary← managed | sovereign →Managed cloudSOC 2 Type IIBOUNDARYApex-operatedengineerAetherINBOUNDyour queriesOUTBOUNDApex SOC 2 regionfastest path to productionApex-managed computeregion of your choiceCustomer VPCyour cloudBOUNDARYCustomer perimeterengineerAetherINBOUNDprivate linkOUTBOUNDno public egressAWS / GCP / Azure / OCIyour VPC, our runtimeprivate networkingOn-premyour hardwareBOUNDARYCustomer DCengineerAetherINBOUNDlocalOUTBOUNDtelemetry off (opt-in)your data centreyour GPUstelemetry optionalAir-gappedsovereignBOUNDARYCryptographically isolatedengineerAetherINBOUNDlocal onlyOUTBOUND✕ zero byteszero outbound trafficITAR-clean compartmentsnational-lab consortiasame Aether runtime in every mode · same evals · same audit · the boundary moves, the model doesn't
swipe horizontally to see all four deployment modes →
Data

Customer data is not training data

Base models are never trained on customer prompts, code or experiment data. Fine-tunes are scoped, attributed and never reused across tenants. Right-to-delete is enforced by the runtime, not by a post-hoc job.

Tenancy

VPC, on-prem, air-gapped

Run in our SOC 2 Type II environment, in your VPC with private networking, or in a sovereign air-gapped configuration with no outbound traffic. Same runtime in every shape.

Identity

SSO, SCIM, role-based access

SAML / OIDC SSO. SCIM provisioning. Role-based capabilities for human users and for agents. MFA enforced on admin paths. Separation-of-duties controls for regulated environments.

Audit

Immutable trace of every action

Every model invocation, every tool call, every memory write — captured in an immutable trace your auditor reads directly. Exportable as SIEM events, OpenTelemetry spans or CSV.

Refusals

Safety at the model layer

Biosecurity, export control and IP boundaries encoded into Aether's tool-use policy — not a wrapper that someone can disable. Refusal corpus is verified per release.

Response

Disclosure and incident response

security@apexworldlabs.com — acknowledged within one business day. Coordinated disclosure programme with public hall of fame. Postmortems are written and shared for every customer-impacting incident.

Standards

The certifications and compliance regimes.

We publish where we are, not just where we'd like to be. If you need a control report or letter of attestation that isn't here, email trust@apexworldlabs.com — we can usually share something useful.

RegimeStatusNotes
SOC 2 Type IICertifiedCloud environment, audited annually by a Big-4 firm. Report under NDA.
ISO/IEC 27001In progressInformation-security management. Q3 2026 target.
ISO/IEC 42001In progressAI management system. Q4 2026 target — first cohort of certified labs.
GDPR / UK-GDPRCompliantDPA on request. EU and UK data-residency controls available.
CCPA / CPRACompliantConsumer privacy rights honoured across customer deployments.
HIPAABAA on requestBusiness Associate Agreement available for healthcare and life-science customers.
GxP / 21 CFR Part 11ReadyAutonomous-lab deploys satisfy ALCOA+ and 21 CFR Part 11 electronic-records requirements.
ITAR / EARCompatibleAir-gapped deployments supported. Export classification on request.
FedRAMPRoadmappedPartner-issued moderate authorisation in planning.
PCI-DSSOut of scopeWe do not process card-holder data. Customer integrations may bring it in scope.
Controls

The technical controls, laid out.

The defaults are strict; the optional configurations are stricter. We share the architecture diagrams under NDA on the first call.

Encryption

In transit and at rest

TLS 1.3 for transit, AES-256 for data at rest. Customer-managed keys via AWS KMS, GCP Cloud KMS or HashiCorp Vault. HSM-backed for sovereign deploys.

Network

Private by default

PrivateLink / Private Service Connect for VPC deploys. No public ingress on the control plane in any configuration. Service-mesh mTLS between every component.

Compute

Isolated tenants

Per-tenant compute pools. No shared GPUs across customers at the workload level. Confidential-compute attestation supported on H100 and H200.

Storage

Logical isolation, tenant keys

Per-tenant logical isolation with customer-held keys. Cross-tenant queries are denied by the storage layer, not by application code.

Secrets

Never on disk

Credentials, API keys and customer secrets flow through a managed secrets layer. Memory-only access; rotated automatically on suspicious activity.

Hardening

Hardened images, signed releases

Containers built from a minimal base. SBOMs published per release. Sigstore-signed images. Daily CVE scans against the runtime fleet.

Biosecurity & dual-use

Safety is engineered, not promised.

Aether for autonomous labs operates real robots, which means safety has to live somewhere other than a sales deck. Here is where it lives.

Refusal at the model

Dual-use refusals are encoded in Aether's tool-use policy. A drug-discovery agent that can call a liquid handler cannot bypass refusals by writing a Python script — the refusal lives in the model, not in a wrapper.

Capability gating

Before a robot acts in the autonomous-lab surface, the planner runs controlled-pathogen and select-agent lookups. The agent must request the capability; the gate decides.

Chain-of-custody

Every reagent, sample, plate and dilution is recorded immutably. The auditor sees what happened in the order it happened — and so does the next experiment.

Red-team

We run an internal red-team programme and accept external reports. Refusal corpus is regression-tested per release; reds team scenarios are versioned.

Vulnerability disclosure

We pay for good reports.

Email security@apexworldlabs.com with a reproducible report and we'll acknowledge within one business day. Awards scale with severity; safe-harbour applies to good-faith research that respects the scope below.

In scope

  • apexworldlabs.com and *.apexworldlabs.com
  • Aether API endpoints under the documented OpenAPI surface
  • The agent runtime image (current minor version)
  • Autonomous-lab tool-policy and capability-gating logic
  • Customer-facing console (console.apexworldlabs.com)
  • Apex-hosted documentation

Out of scope

  • Social engineering of staff or customers
  • Denial-of-service against shared infrastructure
  • Physical attacks on Apex facilities
  • Findings that depend on already-compromised endpoints
  • Self-XSS and other findings that require victim-side actions
  • Volumetric scanning that disrupts the platform
Bounty awards

What good reports actually pay.

Bands are guidance, not contract. Real awards depend on impact, originality and the quality of the report. Our hall of fame is on /security/hall-of-fame.

Critical
$15k – $50k

RCE, auth bypass, model-weight exfiltration, refusal-corpus bypass with realistic dual-use payload.

High
$5k – $15k

Privilege escalation, account takeover, sensitive-data disclosure, cross-tenant boundary breach.

Medium
$1k – $5k

Stored XSS in authenticated areas, SSRF, business-logic flaws with material impact.

Low
$250 – $1k

Reflected XSS, info disclosure, missing security headers with realistic exploit.

Bring your security team to the first call.

We answer questionnaires before they're asked. Your CISO is welcome on the first conversation, and we will share the SOC 2 report and architecture diagrams under NDA.