How does Cyber Crucible support the Connecticut Data Privacy Act (CTDPA)?
Short answer: Cyber Crucible operates as a processor under the Connecticut Data Privacy Act, bound by a data processing agreement to act on the controller's instructions and to assist with security and data-subject requests. Because it collects no customer content, credentials, or keys, most CTDPA obligations have little surface in its custody.
How it aligns
- Processor role with contractually limited processing and a duty to assist the controller.
- Data minimization — no customer content, credentials, or keys collected.
- Security assistance and breach support to the controller.
Vendor-selection notes
The CTDPA requires controllers to bind processors by contract, honor universal opt-out signals, and run assessments for higher-risk processing; the minimal personal-data footprint keeps the vendor side simple. A data processing agreement is available from dpo@cybercrucible.com.