How do I get Cyber Crucible's security due-diligence package?
Short answer: Request it from dpo@cybercrucible.com. Under a mutual NDA, Cyber Crucible provides a prepared vendor security package that answers the domains of the standard questionnaires (SIG, CAIQ) and stands in for a SOC 2 report where a reviewer would ordinarily look for one.
What the package and its companions include
- A prepared vendor security and trust package: architecture, data handling, encryption, access management, secure development, incident response, business continuity, regulatory alignment, and a control-framework mapping.
- One-page program summaries for compliance, audit, and AI/SDLC governance.
- A certificate of insurance, W-9, and financial information, available on request.
- Standard Contractual Clauses, a Transfer Risk Assessment, and a Data Processing Agreement, available on request.
Public documents you can read now
| Document | Location |
|---|---|
| Service Level Agreement | cybercrucible.com/service-level-agreement |
| Mutual NDA | cybercrucible.com/mutualNDA |
| MSA & EULA | cybercrucible.com/msa-and-eula |
| Privacy Policy | cybercrucible.com/privacy-policy |
Everything beyond the public agreements is provided to reviewers under NDA, subject to reasonable confidentiality measures.