Skip to main content

How do I get Cyber Crucible's security due-diligence package?

Short answer: Request it from dpo@cybercrucible.com. Under a mutual NDA, Cyber Crucible provides a prepared vendor security package that answers the domains of the standard questionnaires (SIG, CAIQ) and stands in for a SOC 2 report where a reviewer would ordinarily look for one.

What the package and its companions include

  • A prepared vendor security and trust package: architecture, data handling, encryption, access management, secure development, incident response, business continuity, regulatory alignment, and a control-framework mapping.
  • One-page program summaries for compliance, audit, and AI/SDLC governance.
  • A certificate of insurance, W-9, and financial information, available on request.
  • Standard Contractual Clauses, a Transfer Risk Assessment, and a Data Processing Agreement, available on request.

Public documents you can read now

Document Location
Service Level Agreement cybercrucible.com/service-level-agreement
Mutual NDA cybercrucible.com/mutualNDA
MSA & EULA cybercrucible.com/msa-and-eula
Privacy Policy cybercrucible.com/privacy-policy

Everything beyond the public agreements is provided to reviewers under NDA, subject to reasonable confidentiality measures.