# Does Cyber Crucible comply with Australia's Privacy Act and the APPs?

**Short answer:** Cyber Crucible supports an Australian entity's obligations under the Privacy Act 1988 and the Australian Privacy Principles by minimizing data — it collects no customer content, credentials, or keys — and by processing locally on the endpoint. That directly supports APP 11 (security of personal information) and limits cross-border-disclosure exposure under APP 8.

## How it aligns

- **APP 11 security** — encryption, access control, and autonomous endpoint protection.
- **APP 8 cross-border** — on-premises deployment keeps personal information in Australia where required; no customer content is transferred offshore for security processing.
- **Breach support** — incident information to support Notifiable Data Breaches scheme obligations.

## Vendor-selection notes

Australia's penalty regime for serious or repeated privacy breaches was substantially increased, sharpening vendor scrutiny. The minimal data footprint keeps the vendor side low-risk. Documentation is available on request.