# Does Cyber Crucible support South Korea's PIPA?

**Short answer:** Cyber Crucible supports an organization's obligations under South Korea's Personal Information Protection Act (PIPA) — one of the stricter regimes globally — by minimizing data and processing on the endpoint. It collects no customer content, credentials, or keys, so the consent, handling, and cross-border-transfer obligations have minimal surface in its custody.

## How it aligns

- **Processor role** under contract, on the controller's instructions.
- **Strong safeguards** — encryption, access control, and endpoint prevention support PIPA's demanding security expectations.
- **Cross-border transfer** — on-premises deployment supports keeping personal information in Korea; no customer content is transferred offshore for security processing.

## Vendor-selection notes

PIPA carries significant penalties and detailed security requirements; the minimal data footprint and on-premises option keep the vendor side low-risk. Documentation is available on request.