Does Cyber Crucible comply with GDPR?

Short answer: Yes, by design rather than by policy. Content, credentials, encryption keys, and session tokens are never collected; analysis happens on the endpoint; Cyber Crucible acts as processor under a written DPA; and deployment options keep personal data inside the EU — or inside your own building.

Mapping to GDPR principles

Pseudonymization

Where behavioural telemetry could indirectly identify an individual, identifiers are pseudonymized or masked — a safeguard GDPR explicitly recognizes.

What this does not do

It does not make your organization GDPR compliant. Your obligations depend on your own processing purposes, lawful bases, notices, and records. What it removes is a common difficulty: a security vendor continuously exporting personal data to a third country.


Revision #2
Created 2026-07-21 19:00:16 UTC by Dennis Underwood
Updated 2026-07-21 19:33:22 UTC by Dennis Underwood