Built so your security team can do its job.
Everything your CISO, your auditor, and your procurement team need — consolidated in one place. Security architecture, certifications, legal terms, live status, biosecurity policy, vulnerability disclosure. We engineer the controls and we document them; you verify.
The engineering controls, laid out.
Refusals at the model layer, capability gating between intent and action, immutable audit traces, and an active vulnerability-disclosure programme.
Compliance evidence, downloadable.
The evidence pack your security and procurement teams will ask for. Some documents are NDA-gated and arrive after a short request; the rest download directly.
- SOC 2 Type II reportAvailable · NDA-gatedLatest audit covering security, availability and confidentiality. Email trust@apexworldlabs.com for the NDA and download link.
- Sub-processor listPublic · currentEvery third-party processor in our infrastructure, by data category and region. Updated quarterly with 30-day advance notice on changes.
- Data Processing Addendum (DPA)PublicGDPR / UK-GDPR / CCPA / LGPD compliant DPA, ready for counter-signature. Includes SCC module two.
- Business Associate Agreement (BAA)Available on requestHIPAA-compliant BAA for covered-entity and business-associate customers. Issued for the Enterprise tier.
- Penetration-test summaryAnnual · NDA-gatedExecutive summary of our annual external penetration test. Findings remediated and re-tested. Full report under NDA.
- Insurance certificatePublicCyber-liability, E&O and general liability certificates. Coverage details and limits on the certificate.
- Vendor security questionnairePre-completedCAIQ v4 and SIG Lite questionnaires, pre-completed. Saves your security team a week.
- Responsible-disclosure policyPublicScope, awards up to $50k, six-week embargo, safe-harbour. The contract for security researchers working with us.
What we are on the hook for.
Concrete commitments, written so a procurement team can quote them. Each is enforced by an engineering control documented elsewhere on the trust center.
Customer data is not training data
Base models are never trained on customer prompts, code or experiment data. Fine-tunes are scoped to the customer that requested them and never re-used.
Data residency under your control
Run in our SOC 2 Type II environment, in your VPC with private networking, or in a sovereign air-gapped configuration. Same runtime; you choose the boundary.
Audit trails are immutable
Every model invocation, every tool call, every memory write — captured in a hash-linked trace that your auditor can read directly.
Refusals are engineered, not promised
Biosecurity, export-control and dual-use refusals are encoded in the model's tool-use policy. We red-team them quarterly and publish the methodology.
Incidents get postmortems
Customer-impacting incidents are disclosed on /status within hours of detection and a postmortem follows within ten business days.
No retaliation against researchers
Good-faith security research is protected under our safe-harbour policy. Findings are paid through the bounty programme and acknowledged publicly.
The documents your legal team will ask for.
Each document is structured, dated, and contact-attributed. DPAs, BAAs and order-form addenda are available under MSA.
How the system behaves in production.
Live status, biosecurity architecture, refusal methodology, and the audit substrate. Reading these gives a CISO the operational picture in under an hour.
Who to email.
The right inbox routes faster than the general one. A real human reads each.
| For | What it's for | |
|---|---|---|
| Trust & compliance | trust@apexworldlabs.com | SOC 2 reports under NDA, security questionnaires, sub-processor lists. |
| Security | security@apexworldlabs.com | Vulnerability disclosure, bounty programme, coordinated disclosure. |
| Trust & safety | safety@apexworldlabs.com | Misuse reports, refusal-corpus extensions, researcher access. |
| Privacy | privacy@apexworldlabs.com | Data-subject requests under GDPR, UK-GDPR, CCPA, and equivalent regimes. |
Bring your CISO to the first call.
We answer questionnaires before they're asked. Apex's trust posture is designed to make the procurement conversation short.