# How do I get Cyber Crucible's security due-diligence package?

**Short answer:** Request it from **dpo@cybercrucible.com**. Under a mutual NDA, Cyber Crucible provides a prepared vendor security package that answers the domains of the standard questionnaires (SIG, CAIQ) and stands in for a SOC 2 report where a reviewer would ordinarily look for one.

## What the package and its companions include

- A prepared vendor security and trust package: architecture, data handling, encryption, access management, secure development, incident response, business continuity, regulatory alignment, and a control-framework mapping.
- One-page program summaries for compliance, audit, and AI/SDLC governance.
- A certificate of insurance, W-9, and financial information, available on request.
- Standard Contractual Clauses, a Transfer Risk Assessment, and a Data Processing Agreement, available on request.

## Public documents you can read now

| Document | Location |
|---|---|
| Service Level Agreement | [cybercrucible.com/service-level-agreement](https://www.cybercrucible.com/service-level-agreement) |
| Mutual NDA | [cybercrucible.com/mutualNDA](https://www.cybercrucible.com/mutualNDA) |
| MSA & EULA | cybercrucible.com/msa-and-eula |
| Privacy Policy | cybercrucible.com/privacy-policy |

Everything beyond the public agreements is provided to reviewers under NDA, subject to reasonable confidentiality measures.