Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

90 total results found

Does Cyber Crucible have a SOC 2 report?

Vendor Due Diligence & Security Trust

Short answer: No. Cyber Crucible does not currently hold a SOC 2 attestation, and it says so plainly rather than implying otherwise. The reason is architectural: Cyber Crucible is a locally-executing software product, not a cloud custodian of customer data, so...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Is Cyber Crucible ISO 27001, PCI-DSS, CMMC, or FedRAMP certified?

Vendor Due Diligence & Security Trust

Short answer: No. Cyber Crucible has not obtained, and does not claim, ISO/IEC 27001, PCI-DSS, HIPAA, CMMC, or FedRAMP certification or authorization. It states this directly, because claiming a certification a vendor does not hold is exactly the kind of incon...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

What independent security validation does Cyber Crucible have?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible's Windows kernel drivers are objectively tested and cryptographically signed under Microsoft's Windows Hardware Compatibility Program (WHCP). That is an external, independent attestation of the quality and tamper-resistance of the ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How does Cyber Crucible support GLBA and financial-institution vendor requirements?

Vendor Due Diligence & Security Trust

Short answer: As a software service provider to a financial institution, Cyber Crucible supports the institution's obligations under the GLBA Safeguards expectations and the interagency information-security guidelines — primarily by never collecting the non-pu...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Does Cyber Crucible meet FFIEC and third-party risk management expectations?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible is built to be examinable against the security, operations, and business-continuity expectations that examiners apply to bank technology, and its prepared vendor package is organized to serve as the due-diligence evidence a financi...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

What security and compliance frameworks does Cyber Crucible align to?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible maps its controls to the NIST Cybersecurity Framework, relevant NIST SP 800-53 control families, and the CIS Critical Security Controls, and it maps to the SOC 2 Trust-Service Criteria for reviewer convenience. These are self-asses...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Does Cyber Crucible use AI, and is it a large language model?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible uses proprietary AI — but only during development, not on your endpoint, and it is not a large language model. Its Genetic AI is a design-time discovery tool that identifies the deterministic set of behavioral variables indicating ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How is AI governed in Cyber Crucible's development lifecycle?

Vendor Due Diligence & Security Trust

Short answer: Because Cyber Crucible's Genetic AI is used only at design time, it is governed under the secure development lifecycle (SDLC) rather than as a live production system. The discovery work happens in a controlled internal environment, its output is ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Where is Cyber Crucible's data processed — is it stored in the cloud?

Vendor Due Diligence & Security Trust

Short answer: Threat analysis and response happen locally on the endpoint, not in the cloud. Cyber Crucible does not collect customer files, credentials, or keys, and it does not store customer content with a third-party public-cloud provider. The management a...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

What is Cyber Crucible's service availability and support SLA?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible's published Service Level Agreement commits to 99.9% monthly service availability (excluding scheduled maintenance and causes beyond its reasonable control), with a defined downtime-credit remedy. Support response times are tiered ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How does Cyber Crucible handle data retention and deletion?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible minimizes what it holds and retains data only as long as necessary to provide the service. It never collects customer content, credentials, or keys in the first place, so the highest-risk categories have nothing to retain. Behavior...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Does Cyber Crucible have a Data Privacy Officer?

Vendor Due Diligence & Security Trust

Short answer: Yes. Cyber Crucible has engaged a contracted Data Privacy Officer with cross-jurisdictional expertise spanning the EU/UK GDPR, California CCPA/CPRA, HIPAA, PCI-DSS, and global data-protection regimes including the Saudi Arabian PDPL. The DPO is r...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Is Cyber Crucible subject to US export controls?

Vendor Due Diligence & Security Trust

Short answer: Yes — Cyber Crucible's software is subject to the U.S. Department of Commerce Export Administration Regulations (EAR). It is not ITAR-controlled and is not administered by the Department of State. No special license is required to provide the sof...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How does Cyber Crucible reduce third-party and vendor risk for regulated buyers?

Vendor Due Diligence & Security Trust

Short answer: By removing the risk rather than only managing it. The three facts that answer the hardest vendor-risk questions are: Cyber Crucible collects no customer content, credentials, or keys; protection runs locally and survives any backend outage; and ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How do I get Cyber Crucible's security due-diligence package?

Vendor Due Diligence & Security Trust

Short answer: Request it from dpo@cybercrucible.com. Under a mutual NDA, Cyber Crucible provides a prepared vendor security package that answers the domains of the standard questionnaires (SIG, CAIQ) and stands in for a SOC 2 report where a reviewer would ordi...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

¿Cuenta Cyber Crucible con un informe SOC 2?

Diligencia Debida del Proveedor y Confi...

Respuesta breve: No. Cyber Crucible no cuenta actualmente con una certificación SOC 2, y lo indica con claridad en lugar de dar a entender lo contrario. El motivo es arquitectónico: Cyber Crucible es un producto de software que se ejecuta localmente, no un cus...

Language
es
TranslatedFrom
414
Source
Vendor Due Diligence & Security Trust

¿Cuenta Cyber Crucible con certificación ISO 27001, PCI-DSS, CMMC o FedRAMP?

Diligencia Debida del Proveedor y Confi...

Respuesta breve: No. Cyber Crucible no ha obtenido, ni afirma tener, certificación o autorización ISO/IEC 27001, PCI-DSS, HIPAA, CMMC o FedRAMP. Esto se indica de manera directa, ya que afirmar poseer una certificación que un proveedor no tiene es precisamente...

Language
es
TranslatedFrom
415
Source
Vendor Due Diligence & Security Trust

¿Qué validación de seguridad independiente tiene Cyber Crucible?

Diligencia Debida del Proveedor y Confi...

Respuesta breve: Los controladores del kernel de Windows de Cyber Crucible se someten a pruebas objetivas y se firman criptográficamente bajo el Windows Hardware Compatibility Program (WHCP) de Microsoft. Se trata de una certificación externa e independiente d...

Language
es
TranslatedFrom
416
Source
Vendor Due Diligence & Security Trust