Skip to content
Apex
Trust Center

Built so your security team can do its job.

Everything your CISO, your auditor, and your procurement team need — consolidated in one place. Security architecture, certifications, legal terms, live status, biosecurity policy, vulnerability disclosure. We engineer the controls and we document them; you verify.

SOC 2
Type II · cloud environment
99.95%
API availability target
≤1 day
security-report acknowledgement
Quarterly
external red-team pass
Commitments

What we are on the hook for.

Concrete commitments, written so a procurement team can quote them. Each is enforced by an engineering control documented elsewhere on the trust center.

Customer data is not training data

Base models are never trained on customer prompts, code or experiment data. Fine-tunes are scoped to the customer that requested them and never re-used.

Data residency under your control

Run in our SOC 2 Type II environment, in your VPC with private networking, or in a sovereign air-gapped configuration. Same runtime; you choose the boundary.

Audit trails are immutable

Every model invocation, every tool call, every memory write — captured in a hash-linked trace that your auditor can read directly.

Refusals are engineered, not promised

Biosecurity, export-control and dual-use refusals are encoded in the model's tool-use policy. We red-team them quarterly and publish the methodology.

Incidents get postmortems

Customer-impacting incidents are disclosed on /status within hours of detection and a postmortem follows within ten business days.

No retaliation against researchers

Good-faith security research is protected under our safe-harbour policy. Findings are paid through the bounty programme and acknowledged publicly.

Contacts

Who to email.

The right inbox routes faster than the general one. A real human reads each.

ForEmailWhat it's for
Trust & compliancetrust@apexworldlabs.comSOC 2 reports under NDA, security questionnaires, sub-processor lists.
Securitysecurity@apexworldlabs.comVulnerability disclosure, bounty programme, coordinated disclosure.
Trust & safetysafety@apexworldlabs.comMisuse reports, refusal-corpus extensions, researcher access.
Privacyprivacy@apexworldlabs.comData-subject requests under GDPR, UK-GDPR, CCPA, and equivalent regimes.

Bring your CISO to the first call.

We answer questionnaires before they're asked. Apex's trust posture is designed to make the procurement conversation short.