Advanced Search
Search Results
199 total results found
Is Cyber Crucible a data controller or a data processor?
Short answer: In most engagements Cyber Crucible acts as a data processor on behalf of the customer, who is the controller. The customer determines the purposes and means of processing; Cyber Crucible processes data only on the controller's documented instruct...
How are cross-border data transfers handled?
Short answer: Through the mechanism each jurisdiction recognizes — SDAIA-approved Standard Contractual Clauses for Saudi data, equivalent contractual safeguards elsewhere — backed by a completed Transfer Risk Assessment. Or avoided entirely, by deploying so th...
Does Cyber Crucible collect sensitive personal data?
Short answer: No. Cyber Crucible does not collect the categories these laws define as sensitive — biometric, health, or genetic data, or data revealing racial or ethnic origin, religious belief, or political opinion. Telemetry focuses on system behaviour and s...
What safeguards protect personal data processed by Cyber Crucible?
Short answer: Encryption in transit and at rest, pseudonymization of identifiers where feasible, role-based access control, key management with rotation, audit logging, and regular vulnerability scanning — backed by contractual terms in customer DPAs and an in...
Do I need to appoint a local representative?
Short answer: Usually your organization does, not Cyber Crucible. Several regimes require entities outside the country that process residents' personal data to appoint a local representative — and since Cyber Crucible normally acts as a processor, that obligat...
How do I request compliance documentation?
Short answer: Contact the Data Protection Officer at dpo@cybercrucible.com. Available documentation includes Standard Contractual Clauses, the Transfer Risk Assessment, Data Processing Agreements, and the data governance policy — provided subject to reasonable...
Where can I find Cyber Crucible's legal and trust documents?
Short answer: Public agreements are published on cybercrucible.com — the Mutual NDA, MSA & EULA, Service Level Agreement, Privacy Policy, and Terms of Service. Compliance documentation that is provided on request — Standard Contractual Clauses, Transfer Risk A...
What is the Cyber Crucible Mutual NDA, and who is bound by it?
Short answer: It is a binding mutual non-disclosure agreement that every Cyber Crucible employee, contractor, and vendor with potential access to customer operational data or management systems must execute before onboarding. It is published at cybercrucible.c...
What do the MSA and EULA cover?
Short answer: The Master Services Agreement governs the commercial relationship — services, obligations, liability, and term. The End User License Agreement governs use of the software itself, including the licensing scope, which applies to compiled object cod...
What does the Service Level Agreement cover?
Short answer: The SLA defines the service commitments Cyber Crucible makes to customers — availability, support responsiveness, and the associated terms. It is published at cybercrucible.com/service-level-agreement. How the SLA relates to the product's design ...
How do I complete a security questionnaire or vendor risk assessment for Cyber Crucible?
Short answer: Most questions are answered by the data governance material — what is collected, what is never collected, how it is protected in transit, where it is processed, and what deployment models are available. For anything requiring signed documentation...
Does Cyber Crucible comply with Saudi Arabia's PDPL?
Short answer: Cyber Crucible has reviewed its operations against Saudi Arabia's Personal Data Protection Law, uses SDAIA-approved Standard Contractual Clauses for any transfer of Saudi-origin personal data, and can be deployed entirely inside the Kingdom with ...
Does Cyber Crucible comply with UAE data protection law?
Short answer: Yes, under the same architecture — minimal collection, local processing, and deployment options where data never leaves the country. One UAE-specific point matters: if your entity sits in DIFC or ADGM, a different regime applies than the federal ...
Does Cyber Crucible comply with Bahrain's data protection law?
Short answer: Yes. Bahrain's law is heavily GDPR-inspired with extraterritorial reach, so the same controls that satisfy GDPR apply — minimal collection, documented processor role, strong security safeguards, and controlled transfer. What the law requires Bahr...
Does Cyber Crucible comply with Qatar's data protection law?
Short answer: Yes. Qatar's regime is more consent-centric than its neighbours, which makes minimal collection especially valuable — the less personal data processed, the smaller the consent burden. What the law requires Qatar has had a standalone data protecti...
Does Cyber Crucible comply with Oman's data protection law?
Short answer: Yes — and Oman is the most time-sensitive jurisdiction in the Gulf right now. Oman's personal data protection law reaches full effect on 5 February 2026, following a two-year grace period, so vendor stacks that were compliant-by-default are now i...
Kuwait has no comprehensive data protection law — what does that mean for vendor selection?
Short answer: Kuwait has taken a targeted sectoral approach rather than enacting a comprehensive national data protection law, with CITRA regulation governing how the telecom and IT sectors handle user content. That makes data sovereignty a commercial and secu...
Does Cyber Crucible comply with Kenya's Data Protection Act?
Short answer: Yes. Kenya's Data Protection Act 2019 restricts cross-border transfer to countries with appropriate safeguards, and applies a stricter rule to sensitive personal data. Cyber Crucible does not collect sensitive personal data at all, and can be dep...