top of page

 Business Data Privacy

  • We are committed to ensuring that enterprises retain full control over their data while using our services. By default, we do not use any business data input or processed by customers to train our models. Models are built solely using public data, licensed sources, and content from our research teams, ensuring your information remains entirely private.

  • We provide transparent and controllable data retention policies to help enterprises meet ISO/IEC 27001, SOC 2 Type I, and various regulatory requirements. Customers can set their own retention periods and request immediate deletion when necessary, making compliance and governance more flexible.

  • In product design and system architecture, security is at our core. We implement multi-layered security architecture principles to ensure comprehensive protection at every stage from development to operations. We maintain 24/7 automated security monitoring and incident response mechanisms (24/7 Automated Monitoring) and undergo regular independent third-party penetration testing, red team exercises, and SOC 2 Type I audits to ensure that control measures remain continuously effective.

  • We believe data security is the prerequisite for enterprise AI adoption. Through rigorous processes and international-level verification, we build a trustworthy environment for enterprises, allowing you to leverage artificial intelligence to create value with peace of mind.

Abstract Background

Security and Privacy

We are dedicated to protecting customer data, systems, and products to build long-term trust in our enterprise platform.

Security Compliance and Certifications

We assist enterprise customers in complying with major privacy and information security regulations, including GDPR and CCPA, and provide a Data Processing Addendum (DPA) to support their compliance requirements. We have obtained ISO/IEC 27001 and SOC 2 Type I certifications, with our information security management practices and internal control processes independently audited and verified to meet international standards. These security and compliance frameworks are also widely adopted by leading global cloud and AI service providers such as OpenAI, Google, and Microsoft.

ISO/IEC 27001:2022 logo, ISO/IEC 27701:2019 logo, and AICPA SOC logo

External Testing

Our systems and cloud services undergo regular third-party security testing, such as penetration testing, to identify and remediate vulnerabilities before potential attackers can exploit them.

AI Model Evaluation and Third-Party Verification

ACE has officially passed the trustworthiness evaluation and obtained the recognition report from the AI Evaluation Center (AIEC), among the first Traditional Chinese models in Taiwan to pass this assessment.

The AIEC is guided by Taiwan's Ministry of Digital Affairs and was established in accordance with international standards (NIST, ISO, EU regulations, etc.). It aims to promote the establishment of a locally regulatable and verifiable testing system in Taiwan through a comprehensive framework covering safety, fairness, explainability, privacy, and cybersecurity. APMIC's self-developed Traditional Chinese language model, ACE-1-24B, has become one of the first Traditional Chinese models to pass AIEC testing — not only meeting international-grade verification standards, but also demonstrating its practical capabilities in privacy, security, and governance. This marks a key step toward standardizing AI models for Taiwan's industry.

AIEC logo and APMIC logo

Customer Compliance Support

We are dedicated to helping enterprise customers navigate the regulatory and contractual requirements of their respective industries, including finance, manufacturing, and government sectors.

Product Compliance Features

ISO/IEC 27001

Our Information Security Management System (ISMS) is ISO/IEC 27001 certified, covering organizational information asset protection, risk management, and continuous improvement processes.

ISO/IEC 27701

Our Privacy Information Management System (PIMS) is certified under ISO/IEC 27701, covering organizational personal data protection, privacy risk management, and continuous improvement processes.

SOC 2 Type I

Our products and cloud services have undergone SOC 2 Type I audits, complying with Security, Availability, and Confidentiality. Third parties continuously monitor and verify the effectiveness of our control measures.

20251125_zhiting_首頁畫面.png

 Reporting Security Issues

We encourage security researchers and partners to assist in our dedicated vulnerability reporting process. If you discover any security weaknesses, please notify us and we will evaluate and respond according to a strict protocol.

bottom of page