Skip to main content

Where is Cyber Crucible's data processed — is it stored in the cloud?

Short answer: Threat analysis and response happen locally on the endpoint, not in the cloud. Cyber Crucible does not collect customer files, credentials, or keys, and it does not store customer content with a third-party public-cloud provider. The management and reporting backend runs on Cyber Crucible-operated infrastructure in the United States, and a fully on-premises or air-gapped deployment is available for organizations that require zero external data flow.

Why local processing matters

  • The protective decision never leaves the device. Detect–Decide–Respond runs in the kernel on the endpoint, typically in under 200 milliseconds, with no cloud round trip in the critical path.
  • Backend-independent protection. A management-backend outage does not reduce endpoint protection.
  • Deployment choice. Organizations with strict data-residency or sovereignty mandates can run Cyber Crucible entirely within their own secured infrastructure.

What a reviewer can rely on

Because customer content is never collected, the question "where does our data go?" has a simple answer for the highest-risk categories: it does not go anywhere. Detailed infrastructure and sub-processor information is provided to reviewers under NDA.