# Does Cyber Crucible comply with Canada's PIPEDA and Quebec Law 25?

**Short answer:** Cyber Crucible supports a Canadian organization's obligations under PIPEDA and Quebec's Law 25 primarily by processing on the endpoint and collecting no customer content, credentials, or keys — so there is little personal information in its custody to safeguard, disclose, or transfer. It acts as a service provider under the organization's control, with a data processing agreement available.

## How it aligns

- **Accountability and safeguards.** Strong encryption, access control, and local processing support PIPEDA's security-safeguards principle.
- **Law 25 specifics.** Quebec's phased reforms added breach reporting, privacy-by-default, and rules on transfers outside Québec; the no-collection, on-premises-capable design supports data-residency preferences and limits transfer exposure.
- **Breach support.** Prompt incident information helps the organization meet PIPEDA and Law 25 reporting duties.

## The honest boundary

Compliance is the organization's; Cyber Crucible is a supporting control and processor. It holds no Canadian certification. A data processing agreement and documentation are available from **dpo@cybercrucible.com**.