How does Cyber Crucible support California CCPA/CPRA vendor obligations?

Short answer: Cyber Crucible acts as a service provider under the CCPA/CPRA, bound by contract to process data only on the customer's instructions, and it does not sell or share personal information. Because it collects essentially no personal information in the first place, the consumer-rights and data-handling obligations have very little surface in its custody.

How it aligns

Vendor-selection notes

California's Privacy Rights Act tightened service-provider contract terms and added obligations for sensitive personal information; Cyber Crucible does not collect sensitive personal data. A CCPA-aligned data processing agreement is available on request.


Revision #2
Created 2026-07-23 15:18:37 UTC by Dennis Underwood
Updated 2026-07-23 18:20:04 UTC by Dennis Underwood