Skip to main content

Vendor Due Diligence & Security Trust

How Cyber Crucible answers enterprise and financial-institution vendor-risk questionnaires — what it holds and does not hold, how it supports regulatory obligations, how AI is governed, service levels, and how its architecture reduces third-party risk. Stated plainly and honestly.

Does Cyber Crucible have a SOC 2 report?

Short answer: No. Cyber Crucible does not currently hold a SOC 2 attestation, and it says so plai...

Is Cyber Crucible ISO 27001, PCI-DSS, CMMC, or FedRAMP certified?

Short answer: No. Cyber Crucible has not obtained, and does not claim, ISO/IEC 27001, PCI-DSS, HI...

What independent security validation does Cyber Crucible have?

Short answer: Cyber Crucible's Windows kernel drivers are objectively tested and cryptographicall...

How does Cyber Crucible support GLBA and financial-institution vendor requirements?

Short answer: As a software service provider to a financial institution, Cyber Crucible supports ...

Does Cyber Crucible meet FFIEC and third-party risk management expectations?

Short answer: Cyber Crucible is built to be examinable against the security, operations, and busi...

What security and compliance frameworks does Cyber Crucible align to?

Short answer: Cyber Crucible maps its controls to the NIST Cybersecurity Framework, relevant NIST...

Does Cyber Crucible use AI, and is it a large language model?

Short answer: Cyber Crucible uses proprietary AI — but only during development, not on your endpo...

How is AI governed in Cyber Crucible's development lifecycle?

Short answer: Because Cyber Crucible's Genetic AI is used only at design time, it is governed und...

Where is Cyber Crucible's data processed — is it stored in the cloud?

Short answer: Threat analysis and response happen locally on the endpoint, not in the cloud. Cybe...

What is Cyber Crucible's service availability and support SLA?

Short answer: Cyber Crucible's published Service Level Agreement commits to 99.9% monthly service...

How does Cyber Crucible handle data retention and deletion?

Short answer: Cyber Crucible minimizes what it holds and retains data only as long as necessary t...

Does Cyber Crucible have a Data Privacy Officer?

Short answer: Yes. Cyber Crucible has engaged a contracted Data Privacy Officer with cross-jurisd...

Is Cyber Crucible subject to US export controls?

Short answer: Yes — Cyber Crucible's software is subject to the U.S. Department of Commerce Expor...

How does Cyber Crucible reduce third-party and vendor risk for regulated buyers?

Short answer: By removing the risk rather than only managing it. The three facts that answer the ...

How do I get Cyber Crucible's security due-diligence package?

Short answer: Request it from dpo@cybercrucible.com. Under a mutual NDA, Cyber Crucible provides ...