International Vendor-Risk Guides Country-by-country vendor-risk answers beyond the existing Gulf, Africa, and EU/UK guides — Canada, Australia, India, Singapore, Japan, Brazil, Switzerland, New Zealand, South Korea, and Turkey. States plainly what Cyber Crucible holds and how the architecture supports each regime. Does Cyber Crucible comply with Canada's PIPEDA and Quebec Law 25? Short answer: Cyber Crucible supports a Canadian organization's obligations under PIPEDA and Quebec's Law 25 primarily by processing on the endpoint and collecting no customer content, credentials, or keys — so there is little personal information in its custody to safeguard, disclose, or transfer. It acts as a service provider under the organization's control, with a data processing agreement available. How it aligns Accountability and safeguards. Strong encryption, access control, and local processing support PIPEDA's security-safeguards principle. Law 25 specifics. Quebec's phased reforms added breach reporting, privacy-by-default, and rules on transfers outside Québec; the no-collection, on-premises-capable design supports data-residency preferences and limits transfer exposure. Breach support. Prompt incident information helps the organization meet PIPEDA and Law 25 reporting duties. The honest boundary Compliance is the organization's; Cyber Crucible is a supporting control and processor. It holds no Canadian certification. A data processing agreement and documentation are available from dpo@cybercrucible.com . Does Cyber Crucible comply with Australia's Privacy Act and the APPs? Short answer: Cyber Crucible supports an Australian entity's obligations under the Privacy Act 1988 and the Australian Privacy Principles by minimizing data — it collects no customer content, credentials, or keys — and by processing locally on the endpoint. That directly supports APP 11 (security of personal information) and limits cross-border-disclosure exposure under APP 8. How it aligns APP 11 security — encryption, access control, and autonomous endpoint protection. APP 8 cross-border — on-premises deployment keeps personal information in Australia where required; no customer content is transferred offshore for security processing. Breach support — incident information to support Notifiable Data Breaches scheme obligations. Vendor-selection notes Australia's penalty regime for serious or repeated privacy breaches was substantially increased, sharpening vendor scrutiny. The minimal data footprint keeps the vendor side low-risk. Documentation is available on request. Does Cyber Crucible comply with India's Digital Personal Data Protection Act (DPDP)? Short answer: Cyber Crucible supports a data fiduciary's obligations under India's Digital Personal Data Protection Act by acting as a data processor that collects essentially no personal data and processes on the endpoint. Because customer content is never collected, the consent, purpose-limitation, and erasure obligations have minimal surface in its custody. How it aligns Processor role under contract with the data fiduciary. Data minimization — no customer content, credentials, or keys collected. Security safeguards and breach support for the fiduciary's obligations. Vendor-selection notes India notified the DPDP Rules, 2025 in November 2025, with substantive obligations phasing in over roughly the following 18 months, so the operational detail (consent management, breach reporting, cross-border mechanics) is still coming into force. On-premises deployment supports data-residency preferences in the meantime. Cyber Crucible holds no Indian certification and supports, rather than assumes, the fiduciary's duties. Documentation is available on request. Does Cyber Crucible comply with Singapore's PDPA? Short answer: Cyber Crucible supports an organization's obligations under Singapore's Personal Data Protection Act as a data intermediary that processes on the endpoint and collects no customer content, credentials, or keys. The Protection and Transfer Limitation obligations have little to attach to, because there is minimal personal data in its custody. How it aligns Data-intermediary role under a written contract. Protection obligation — encryption, access control, and endpoint prevention. Transfer limitation — on-premises deployment and no offshore transfer of customer content for security processing. Vendor-selection notes Singapore's PDPA includes a mandatory data-breach notification regime; prompt incident information supports it. A data processing agreement is available on request. Does Cyber Crucible comply with Japan's APPI? Short answer: Cyber Crucible supports a business operator's obligations under Japan's Act on the Protection of Personal Information (APPI) by minimizing data and processing locally. It collects no customer content, credentials, or keys, so the handling, third-party-provision, and cross-border-transfer rules have minimal surface in its custody. How it aligns Safe handling — encryption, access control, and endpoint protection. Cross-border transfer — on-premises deployment supports keeping personal data in Japan; no customer content is transferred offshore for security processing. Breach support — incident information to support APPI reporting expectations. Vendor-selection notes APPI amendments strengthened breach reporting and cross-border rules; the minimal data footprint keeps vendor obligations light. Documentation is available on request. Does Cyber Crucible comply with Brazil's LGPD? Short answer: Cyber Crucible supports a controller's obligations under Brazil's Lei Geral de Proteção de Dados (LGPD) as an operator (processor) that processes on the endpoint and collects no customer content, credentials, or keys. Most LGPD obligations — legal basis, data-subject rights, transfer rules — have minimal surface because there is little personal data in its custody. How it aligns Operator role under contract, processing on the controller's instructions. Security measures — encryption, access control, and autonomous endpoint prevention. Breach support for the controller's ANPD notification duties. Vendor-selection notes The ANPD has been increasingly active in enforcement and transfer guidance; on-premises deployment supports data-residency preferences. Cyber Crucible holds no Brazilian certification and supports the controller's duties. Documentation is available on request. Does Cyber Crucible comply with Switzerland's revised FADP? Short answer: Cyber Crucible supports a Swiss organization's obligations under the revised Federal Act on Data Protection (revFADP) by minimizing data and processing locally on the endpoint. Because it collects no customer content, credentials, or keys, the security, records-of-processing, and transfer obligations have minimal surface in its custody. How it aligns Processor role under a data processing agreement. Security by design — encryption, access control, and endpoint prevention support the revFADP's data-security duty. Cross-border transfer — on-premises deployment keeps personal data in Switzerland where required; Standard Contractual Clauses are available for transfers. Vendor-selection notes The revFADP aligns closely with the GDPR, so much of Cyber Crucible's GDPR support carries over. Documentation, including SCCs, is available on request. Does Cyber Crucible comply with New Zealand's Privacy Act 2020? Short answer: Cyber Crucible supports a New Zealand agency's obligations under the Privacy Act 2020 by collecting no customer content, credentials, or keys and processing on the endpoint. The Information Privacy Principles — particularly storage and security (IPP 5) and cross-border disclosure (IPP 12) — have minimal surface because there is little personal information in its custody. How it aligns IPP 5 security — encryption, access control, and autonomous endpoint protection. IPP 12 cross-border — on-premises deployment keeps personal information in New Zealand; no customer content is transferred offshore for security processing. Breach support for the agency's notifiable-privacy-breach obligations. Vendor-selection notes The Privacy Act 2020 introduced mandatory breach notification and compliance notices; prompt incident information supports both. Documentation is available on request. Does Cyber Crucible support South Korea's PIPA? Short answer: Cyber Crucible supports an organization's obligations under South Korea's Personal Information Protection Act (PIPA) — one of the stricter regimes globally — by minimizing data and processing on the endpoint. It collects no customer content, credentials, or keys, so the consent, handling, and cross-border-transfer obligations have minimal surface in its custody. How it aligns Processor role under contract, on the controller's instructions. Strong safeguards — encryption, access control, and endpoint prevention support PIPA's demanding security expectations. Cross-border transfer — on-premises deployment supports keeping personal information in Korea; no customer content is transferred offshore for security processing. Vendor-selection notes PIPA carries significant penalties and detailed security requirements; the minimal data footprint and on-premises option keep the vendor side low-risk. Documentation is available on request. Does Cyber Crucible comply with Turkey's KVKK? Short answer: Cyber Crucible supports a data controller's obligations under Turkey's Law on the Protection of Personal Data (KVKK) by collecting no customer content, credentials, or keys and processing on the endpoint. Registration, security, and transfer obligations have minimal surface because there is little personal data in its custody. How it aligns Data-processor role under contract. Security measures — encryption, access control, and endpoint prevention support the KVKK's technical-measures requirement. Cross-border transfer — on-premises deployment supports data-residency preferences under Turkey's transfer rules. Vendor-selection notes The KVKK's transfer regime and VERBIS registration obligations sit with the controller; Cyber Crucible supports, and does not assume, those duties. Documentation is available on request.