Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

199 total results found

Does Cyber Crucible meet Nigeria's data localization requirement?

Country Compliance Guides

Short answer: Yes — and this is the jurisdiction where the architecture matters most. Nigeria's Data Protection Act 2023 imposes a data localization requirement: personal data of Nigerian citizens must be stored within Nigeria. Cyber Crucible's on-premises dep...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible comply with South Africa's POPIA?

Country Compliance Guides

Short answer: Yes. POPIA restricts cross-border transfer unless the destination offers substantively similar protection or the data subject consents. Cyber Crucible minimizes what is processed to begin with, and can be deployed so no transfer occurs. What the ...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible comply with Egypt's data protection law?

Country Compliance Guides

Short answer: Yes. Egypt requires prior approval for cross-border transfers of personal data — a materially higher bar than contractual safeguards. Cyber Crucible can be deployed so that no transfer occurs, removing the approval requirement rather than navigat...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible comply with Ghana's Data Protection Act?

Country Compliance Guides

Short answer: Yes, and Ghana is comparatively straightforward. Ghana is notable among African jurisdictions for not imposing additional requirements on cross-border transfer beyond its general data protection obligations — so the standard controls apply withou...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible meet Zambia's data localization requirement?

Country Compliance Guides

Short answer: Yes. Zambia's Data Protection Act requires controllers to process and store personal and sensitive personal data on a data centre or server within Zambia. Cyber Crucible's on-premises deployment satisfies this directly — the backend runs inside y...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible comply with Rwanda's data protection law?

Country Compliance Guides

Short answer: Yes. Rwanda's data protection law is supervised by the National Cyber Security Authority, and sector-specific rules add localization obligations — notably for licensed banks, which must maintain primary data within Rwanda. The on-premises deploym...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible comply with Morocco's data protection law?

Country Compliance Guides

Short answer: Yes. Morocco's Law No. 09-08 and its implementing decree govern personal data processing, supervised by the CNDP. The same controls apply — minimal collection, documented processor role, strong safeguards, and in-country or air-gapped deployment ...

Type
FAQ
Source
Country Compliance Guides

What are the data protection requirements in Libya?

Country Compliance Guides

Short answer: Libya has not yet developed comprehensive data protection regulations. That makes data sovereignty a commercial, security, and counterparty decision rather than a local compliance obligation — but for organizations handling sensitive operations, ...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible comply with GDPR?

Country Compliance Guides

Short answer: Yes, by design rather than by policy. Content, credentials, encryption keys, and session tokens are never collected; analysis happens on the endpoint; Cyber Crucible acts as processor under a written DPA; and deployment options keep personal data...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible comply with UK GDPR?

Country Compliance Guides

Short answer: Yes. UK GDPR and the Data Protection Act 2018 track EU GDPR closely, so the same mapping applies — minimal collection, processor role under a written DPA, strong technical safeguards, and deployment options that keep data in the UK or entirely on...

Type
FAQ
Source
Country Compliance Guides

Does Cyber Crucible have a SOC 2 report?

Vendor Due Diligence & Security Trust

Short answer: No. Cyber Crucible does not currently hold a SOC 2 attestation, and it says so plainly rather than implying otherwise. The reason is architectural: Cyber Crucible is a locally-executing software product, not a cloud custodian of customer data, so...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Is Cyber Crucible ISO 27001, PCI-DSS, CMMC, or FedRAMP certified?

Vendor Due Diligence & Security Trust

Short answer: No. Cyber Crucible has not obtained, and does not claim, ISO/IEC 27001, PCI-DSS, HIPAA, CMMC, or FedRAMP certification or authorization. It states this directly, because claiming a certification a vendor does not hold is exactly the kind of incon...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

What independent security validation does Cyber Crucible have?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible's Windows kernel drivers are objectively tested and cryptographically signed under Microsoft's Windows Hardware Compatibility Program (WHCP). That is an external, independent attestation of the quality and tamper-resistance of the ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How does Cyber Crucible support GLBA and financial-institution vendor requirements?

Vendor Due Diligence & Security Trust

Short answer: As a software service provider to a financial institution, Cyber Crucible supports the institution's obligations under the GLBA Safeguards expectations and the interagency information-security guidelines — primarily by never collecting the non-pu...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Does Cyber Crucible meet FFIEC and third-party risk management expectations?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible is built to be examinable against the security, operations, and business-continuity expectations that examiners apply to bank technology, and its prepared vendor package is organized to serve as the due-diligence evidence a financi...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

What security and compliance frameworks does Cyber Crucible align to?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible maps its controls to the NIST Cybersecurity Framework, relevant NIST SP 800-53 control families, and the CIS Critical Security Controls, and it maps to the SOC 2 Trust-Service Criteria for reviewer convenience. These are self-asses...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Does Cyber Crucible use AI, and is it a large language model?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible uses proprietary AI — but only during development, not on your endpoint, and it is not a large language model. Its Genetic AI is a design-time discovery tool that identifies the deterministic set of behavioral variables indicating ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How is AI governed in Cyber Crucible's development lifecycle?

Vendor Due Diligence & Security Trust

Short answer: Because Cyber Crucible's Genetic AI is used only at design time, it is governed under the secure development lifecycle (SDLC) rather than as a live production system. The discovery work happens in a controlled internal environment, its output is ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust