# How does Cyber Crucible support the Connecticut Data Privacy Act (CTDPA)?

**Short answer:** Cyber Crucible operates as a processor under the Connecticut Data Privacy Act, bound by a data processing agreement to act on the controller's instructions and to assist with security and data-subject requests. Because it collects no customer content, credentials, or keys, most CTDPA obligations have little surface in its custody.

## How it aligns

- **Processor role** with contractually limited processing and a duty to assist the controller.
- **Data minimization** — no customer content, credentials, or keys collected.
- **Security assistance and breach support** to the controller.

## Vendor-selection notes

The CTDPA requires controllers to bind processors by contract, honor universal opt-out signals, and run assessments for higher-risk processing; the minimal personal-data footprint keeps the vendor side simple. A data processing agreement is available from **dpo@cybercrucible.com**.