Skip to main content

How do I complete a security questionnaire or vendor risk assessment for Cyber Crucible?

Short answer: Most questions are answered by the data governance material — what is collected, what is never collected, how it is protected in transit, where it is processed, and what deployment models are available. For anything requiring signed documentation, contact dpo@cybercrucible.com.

The answers most questionnaires need

Typical question Where it's answered
What customer data does the vendor collect? What data does Cyber Crucible collect — and what does it never collect?
Is data shared with or sold to third parties? Does Cyber Crucible sell or share customer data with third parties?
How is data encrypted in transit? How is Cyber Crucible data protected in transit?
Where is data processed and stored? Where is my data processed, and can it stay inside my country?
Sub-processors and supply chain controls? How does Cyber Crucible manage supply chain and insider risk?
Third-party or foreign code components? Does Cyber Crucible embed third-party libraries or foreign code?
Controller or processor role? Is Cyber Crucible a data controller or a data processor?
Cross-border transfer mechanism? How are cross-border data transfers handled?

Two answers that commonly surprise reviewers

On certifications: Cyber Crucible's security programme is aligned with recognized industry frameworks but does not currently hold ISO 27001 or SOC 2 certification. If your process requires certified evidence, raise it early rather than late.

On data disclosure: because encryption keys, credentials, and customer files are never collected, there is nothing in those categories to disclose to any party — including under legal process. Several questionnaire items about disclosure, retention, and deletion are answered by the absence of collection rather than by a control.

Anything not covered

Contact dpo@cybercrucible.com with the specific requirement, your jurisdiction, and which deployment model you are evaluating.