Advanced Search
Search Results
90 total results found
Does Cyber Crucible have a SOC 2 report?
Short answer: No. Cyber Crucible does not currently hold a SOC 2 attestation, and it says so plainly rather than implying otherwise. The reason is architectural: Cyber Crucible is a locally-executing software product, not a cloud custodian of customer data, so...
Is Cyber Crucible ISO 27001, PCI-DSS, CMMC, or FedRAMP certified?
Short answer: No. Cyber Crucible has not obtained, and does not claim, ISO/IEC 27001, PCI-DSS, HIPAA, CMMC, or FedRAMP certification or authorization. It states this directly, because claiming a certification a vendor does not hold is exactly the kind of incon...
What independent security validation does Cyber Crucible have?
Short answer: Cyber Crucible's Windows kernel drivers are objectively tested and cryptographically signed under Microsoft's Windows Hardware Compatibility Program (WHCP). That is an external, independent attestation of the quality and tamper-resistance of the ...
How does Cyber Crucible support GLBA and financial-institution vendor requirements?
Short answer: As a software service provider to a financial institution, Cyber Crucible supports the institution's obligations under the GLBA Safeguards expectations and the interagency information-security guidelines — primarily by never collecting the non-pu...
Does Cyber Crucible meet FFIEC and third-party risk management expectations?
Short answer: Cyber Crucible is built to be examinable against the security, operations, and business-continuity expectations that examiners apply to bank technology, and its prepared vendor package is organized to serve as the due-diligence evidence a financi...
What security and compliance frameworks does Cyber Crucible align to?
Short answer: Cyber Crucible maps its controls to the NIST Cybersecurity Framework, relevant NIST SP 800-53 control families, and the CIS Critical Security Controls, and it maps to the SOC 2 Trust-Service Criteria for reviewer convenience. These are self-asses...
Does Cyber Crucible use AI, and is it a large language model?
Short answer: Cyber Crucible uses proprietary AI — but only during development, not on your endpoint, and it is not a large language model. Its Genetic AI is a design-time discovery tool that identifies the deterministic set of behavioral variables indicating ...
How is AI governed in Cyber Crucible's development lifecycle?
Short answer: Because Cyber Crucible's Genetic AI is used only at design time, it is governed under the secure development lifecycle (SDLC) rather than as a live production system. The discovery work happens in a controlled internal environment, its output is ...
Where is Cyber Crucible's data processed — is it stored in the cloud?
Short answer: Threat analysis and response happen locally on the endpoint, not in the cloud. Cyber Crucible does not collect customer files, credentials, or keys, and it does not store customer content with a third-party public-cloud provider. The management a...
What is Cyber Crucible's service availability and support SLA?
Short answer: Cyber Crucible's published Service Level Agreement commits to 99.9% monthly service availability (excluding scheduled maintenance and causes beyond its reasonable control), with a defined downtime-credit remedy. Support response times are tiered ...
How does Cyber Crucible handle data retention and deletion?
Short answer: Cyber Crucible minimizes what it holds and retains data only as long as necessary to provide the service. It never collects customer content, credentials, or keys in the first place, so the highest-risk categories have nothing to retain. Behavior...
Does Cyber Crucible have a Data Privacy Officer?
Short answer: Yes. Cyber Crucible has engaged a contracted Data Privacy Officer with cross-jurisdictional expertise spanning the EU/UK GDPR, California CCPA/CPRA, HIPAA, PCI-DSS, and global data-protection regimes including the Saudi Arabian PDPL. The DPO is r...
Is Cyber Crucible subject to US export controls?
Short answer: Yes — Cyber Crucible's software is subject to the U.S. Department of Commerce Export Administration Regulations (EAR). It is not ITAR-controlled and is not administered by the Department of State. No special license is required to provide the sof...
How does Cyber Crucible reduce third-party and vendor risk for regulated buyers?
Short answer: By removing the risk rather than only managing it. The three facts that answer the hardest vendor-risk questions are: Cyber Crucible collects no customer content, credentials, or keys; protection runs locally and survives any backend outage; and ...
How do I get Cyber Crucible's security due-diligence package?
Short answer: Request it from dpo@cybercrucible.com. Under a mutual NDA, Cyber Crucible provides a prepared vendor security package that answers the domains of the standard questionnaires (SIG, CAIQ) and stands in for a SOC 2 report where a reviewer would ordi...
¿Cuenta Cyber Crucible con un informe SOC 2?
Respuesta breve: No. Cyber Crucible no cuenta actualmente con una certificación SOC 2, y lo indica con claridad en lugar de dar a entender lo contrario. El motivo es arquitectónico: Cyber Crucible es un producto de software que se ejecuta localmente, no un cus...
¿Cuenta Cyber Crucible con certificación ISO 27001, PCI-DSS, CMMC o FedRAMP?
Respuesta breve: No. Cyber Crucible no ha obtenido, ni afirma tener, certificación o autorización ISO/IEC 27001, PCI-DSS, HIPAA, CMMC o FedRAMP. Esto se indica de manera directa, ya que afirmar poseer una certificación que un proveedor no tiene es precisamente...
¿Qué validación de seguridad independiente tiene Cyber Crucible?
Respuesta breve: Los controladores del kernel de Windows de Cyber Crucible se someten a pruebas objetivas y se firman criptográficamente bajo el Windows Hardware Compatibility Program (WHCP) de Microsoft. Se trata de una certificación externa e independiente d...