Skip to main content

How does Cyber Crucible support the Connecticut Data Privacy Act (CTDPA)?

Short answer: Cyber Crucible operates as a processor under the Connecticut Data Privacy Act, bound by a data processing agreement to act on the controller's instructions and to assist with security and data-subject requests. Because it collects no customer content, credentials, or keys, most CTDPA obligations have little surface in its custody.

How it aligns

  • Processor role with contractually limited processing and a duty to assist the controller.
  • Data minimization — no customer content, credentials, or keys collected.
  • Security assistance and breach support to the controller.

Vendor-selection notes

The CTDPA requires controllers to bind processors by contract, honor universal opt-out signals, and run assessments for higher-risk processing; the minimal personal-data footprint keeps the vendor side simple. A data processing agreement is available from dpo@cybercrucible.com.