Skip to main content

Does Cyber Crucible comply with Brazil's LGPD?

Short answer: Cyber Crucible supports a controller's obligations under Brazil's Lei Geral de Proteção de Dados (LGPD) as an operator (processor) that processes on the endpoint and collects no customer content, credentials, or keys. Most LGPD obligations — legal basis, data-subject rights, transfer rules — have minimal surface because there is little personal data in its custody.

How it aligns

  • Operator role under contract, processing on the controller's instructions.
  • Security measures — encryption, access control, and autonomous endpoint prevention.
  • Breach support for the controller's ANPD notification duties.

Vendor-selection notes

The ANPD has been increasingly active in enforcement and transfer guidance; on-premises deployment supports data-residency preferences. Cyber Crucible holds no Brazilian certification and supports the controller's duties. Documentation is available on request.