Skip to main content

What safeguards protect personal data processed by Cyber Crucible?

Short answer: Encryption in transit and at rest, pseudonymization of identifiers where feasible, role-based access control, key management with rotation, audit logging, and regular vulnerability scanning — backed by contractual terms in customer DPAs and an internal information security programme.

Technical

  • Personal data encrypted in transit (TLS 1.3) and at rest.
  • Per-agent JSON Web Encryption of operational payloads, using unique key pairs.
  • Sensitive identifiers pseudonymized or anonymized wherever feasible.
  • Access controlled through authentication and role-based permissions.
  • Cryptographic key management policies ensuring keys are securely stored and rotated.
  • Logging and auditing of access and administrative actions to detect unauthorized activity.
  • Regular vulnerability scanning and security testing.

Contractual

Customer contracts and DPAs include terms on data security, confidentiality, and breach notification. Sub-processors are engaged only under written agreements mandating equivalent protections. Employees and contractors are bound by mutual non-disclosure agreements.

Organizational

An information security management programme governs ongoing compliance, with security awareness training for relevant staff, documented incident response, data retention and deletion procedures, and periodic internal audits.

On certifications — stated plainly

Cyber Crucible's security programme is aligned with recognized industry frameworks. Cyber Crucible does not currently hold ISO 27001 or SOC 2 certification, and certification is not currently planned.

Alignment means the controls follow the practices those frameworks describe. It does not mean an external auditor has assessed and certified them, and it should not be represented that way in your own compliance documentation. If your procurement process requires certified evidence, that requirement is not met today — contact dpo@cybercrucible.com to discuss what documentation is available.