# How does Cyber Crucible support California CCPA/CPRA vendor obligations?

**Short answer:** Cyber Crucible acts as a service provider under the CCPA/CPRA, bound by contract to process data only on the customer's instructions, and it does not sell or share personal information. Because it collects essentially no personal information in the first place, the consumer-rights and data-handling obligations have very little surface in its custody.

## How it aligns

- **Service-provider role** under a written contract that prohibits secondary use.
- **No sale or sharing** of personal information.
- **Supports consumer rights** (access, deletion) by not holding the personal information that would otherwise have to be searched or deleted.

## Vendor-selection notes

California's Privacy Rights Act tightened service-provider contract terms and added obligations for sensitive personal information; Cyber Crucible does not collect sensitive personal data. A CCPA-aligned data processing agreement is available on request.