Does Cyber Crucible collect sensitive personal data?

Short answer: No. Cyber Crucible does not collect the categories these laws define as sensitive — biometric, health, or genetic data, or data revealing racial or ethnic origin, religious belief, or political opinion. Telemetry focuses on system behaviour and security events, not personal attributes.

Why the category doesn't arise

The software's job is to determine whether a program is behaving maliciously. Nothing about that requires knowing anything about a person. Sensitive personal data has no role in the detection logic, so it is not collected.

Why this matters disproportionately

Sensitive data usually attracts the strictest treatment in every regime — explicit consent, additional safeguards, mandatory risk assessment before transfer, and in some jurisdictions registration obligations that would not otherwise apply.

Kenya, for example, permits transfer of sensitive personal data only where the data subject has consented and appropriate safeguards exist. A vendor that never collects sensitive data keeps you out of that path entirely.

Data minimization

Only the personal data strictly necessary for the security purpose is collected. Customers can further tailor which telemetry sources are gathered, and fields not essential to threat detection are excluded or discarded promptly.


Revision #2
Created 2026-07-21 18:59:50 UTC by Dennis Underwood
Updated 2026-07-21 19:32:59 UTC by Dennis Underwood