Fathom-1.0 已发布阅读公告 →
Wyrmlabs
WYRMLABS智 能 实 验 室

安全与合规

企业级安全,适用于每一次部署。

安全架构

Wyrmlabs employs a defense-in-depth security architecture across all layers of our infrastructure. Our systems are designed to protect data at rest and in transit, enforce strict access controls, and maintain comprehensive audit trails.

  • Encryption: All data is encrypted at rest using AES-256 and in transit using TLS 1.3. API communications are secured with mutual TLS where supported.
  • Access Control: Role-based access control (RBAC) with principle of least privilege. All access is authenticated via OAuth 2.0 / OIDC with support for SAML and SCIM for enterprise customers.
  • Network Security: Multi-layered network segmentation with private VPCs, WAF, DDoS protection, and intrusion detection systems. All infrastructure is deployed in SOC 2-compliant data centers.
  • Audit Logging: Comprehensive logging of all system access, API calls, and administrative actions. Logs are immutable and retained for a minimum of 12 months.
  • Vulnerability Management: Continuous vulnerability scanning, regular penetration testing by independent third parties, and a responsible disclosure program for external researchers.

合规认证

Wyrmlabs maintains compliance with the following standards and frameworks:

  • SOC 2 Type II: Our information security controls are audited annually by an independent CPA firm. Reports are available under NDA to enterprise customers.
  • PIPL Compliance: Full compliance with the Personal Information Protection Law of the People's Republic of China. Our Data Protection Officer oversees all data handling practices.
  • GDPR: We meet the requirements of the EU General Data Protection Regulation for users in the European Economic Area, including data processing agreements and Standard Contractual Clauses.
  • ISO 27001: Certified for information security management. Certification available upon request.

模型安全

Our commitment to security extends to the Fathom model itself. We conduct ongoing red-teaming, adversarial robustness testing, and bias evaluations. We maintain a coordinated vulnerability disclosure program and work with external researchers to identify and address model-level security concerns.

数据处理

Wyrmlabs offers data residency options for enterprise customers, including deployment within mainland China, Singapore, the European Union, or the United States. Customer data is never used for model training without explicit opt-in, and all data processing agreements include strict confidentiality provisions.

For Fathom Edge deployments (on-device inference), no data leaves the local device unless explicitly configured to do so. This makes Edge deployments suitable for air-gapped environments and classified workloads.

联系我们的安全团队

For security-related inquiries, vulnerability disclosures, or to request compliance documentation: contact@wyrmlabs.be