Skip to main content

Does Cyber Crucible comply with Turkey's KVKK?

Short answer: Cyber Crucible supports a data controller's obligations under Turkey's Law on the Protection of Personal Data (KVKK) by collecting no customer content, credentials, or keys and processing on the endpoint. Registration, security, and transfer obligations have minimal surface because there is little personal data in its custody.

How it aligns

  • Data-processor role under contract.
  • Security measures — encryption, access control, and endpoint prevention support the KVKK's technical-measures requirement.
  • Cross-border transfer — on-premises deployment supports data-residency preferences under Turkey's transfer rules.

Vendor-selection notes

The KVKK's transfer regime and VERBIS registration obligations sit with the controller; Cyber Crucible supports, and does not assume, those duties. Documentation is available on request.