Skip to main content

Recently Updated Pages

How does Cyber Crucible fit NERC CIP and critical-infrastructure security?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible suits critical-infrastructure and utility environments because it pr...

Updated 1 month ago by Dennis Underwood

Does Cyber Crucible meet CMMC and DFARS requirements for the defense industrial base?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible is not CMMC-certified, and it says so plainly. It supports a defense...

Updated 1 month ago by Dennis Underwood

Is Cyber Crucible FedRAMP authorized, and how does it serve government agencies?

Industry Vendor-Risk Guides

Short answer: No — Cyber Crucible does not currently hold a FedRAMP authorization, and it does no...

Updated 1 month ago by Dennis Underwood

How does Cyber Crucible support FERPA and student-data privacy for schools and universities?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible helps educational institutions two ways: it stops ransomware autonom...

Updated 1 month ago by Dennis Underwood

How does Cyber Crucible support HIPAA, and will it sign a Business Associate Agreement?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible supports a covered entity's HIPAA obligations primarily by never col...

Updated 1 month ago by Dennis Underwood

How do I get Cyber Crucible's security due-diligence package?

Vendor Due Diligence & Security Trust

Short answer: Request it from dpo@cybercrucible.com. Under a mutual NDA, Cyber Crucible provides ...

Updated 1 month ago by Dennis Underwood

How does Cyber Crucible reduce third-party and vendor risk for regulated buyers?

Vendor Due Diligence & Security Trust

Short answer: By removing the risk rather than only managing it. The three facts that answer the ...

Updated 1 month ago by Dennis Underwood

Is Cyber Crucible subject to US export controls?

Vendor Due Diligence & Security Trust

Short answer: Yes — Cyber Crucible's software is subject to the U.S. Department of Commerce Expor...

Updated 1 month ago by Dennis Underwood

How does Cyber Crucible handle data retention and deletion?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible minimizes what it holds and retains data only as long as necessary t...

Updated 1 month ago by Dennis Underwood

Does Cyber Crucible have a Data Privacy Officer?

Vendor Due Diligence & Security Trust

Short answer: Yes. Cyber Crucible has engaged a contracted Data Privacy Officer with cross-jurisd...

Updated 1 month ago by Dennis Underwood

What is Cyber Crucible's service availability and support SLA?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible's published Service Level Agreement commits to 99.9% monthly service...

Updated 1 month ago by Dennis Underwood

Where is Cyber Crucible's data processed — is it stored in the cloud?

Vendor Due Diligence & Security Trust

Short answer: Threat analysis and response happen locally on the endpoint, not in the cloud. Cybe...

Updated 1 month ago by Dennis Underwood

How is AI governed in Cyber Crucible's development lifecycle?

Vendor Due Diligence & Security Trust

Short answer: Because Cyber Crucible's Genetic AI is used only at design time, it is governed und...

Updated 1 month ago by Dennis Underwood

Does Cyber Crucible use AI, and is it a large language model?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible uses proprietary AI — but only during development, not on your endpo...

Updated 1 month ago by Dennis Underwood

What security and compliance frameworks does Cyber Crucible align to?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible maps its controls to the NIST Cybersecurity Framework, relevant NIST...

Updated 1 month ago by Dennis Underwood

Does Cyber Crucible meet FFIEC and third-party risk management expectations?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible is built to be examinable against the security, operations, and busi...

Updated 1 month ago by Dennis Underwood

How does Cyber Crucible support GLBA and financial-institution vendor requirements?

Vendor Due Diligence & Security Trust

Short answer: As a software service provider to a financial institution, Cyber Crucible supports ...

Updated 1 month ago by Dennis Underwood

What independent security validation does Cyber Crucible have?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible's Windows kernel drivers are objectively tested and cryptographicall...

Updated 1 month ago by Dennis Underwood

Is Cyber Crucible ISO 27001, PCI-DSS, CMMC, or FedRAMP certified?

Vendor Due Diligence & Security Trust

Short answer: No. Cyber Crucible has not obtained, and does not claim, ISO/IEC 27001, PCI-DSS, HI...

Updated 1 month ago by Dennis Underwood

Does Cyber Crucible have a SOC 2 report?

Vendor Due Diligence & Security Trust

Short answer: No. Cyber Crucible does not currently hold a SOC 2 attestation, and it says so plai...

Updated 1 month ago by Dennis Underwood