Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

199 total results found

Where is Cyber Crucible's data processed — is it stored in the cloud?

Vendor Due Diligence & Security Trust

Short answer: Threat analysis and response happen locally on the endpoint, not in the cloud. Cyber Crucible does not collect customer files, credentials, or keys, and it does not store customer content with a third-party public-cloud provider. The management a...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

What is Cyber Crucible's service availability and support SLA?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible's published Service Level Agreement commits to 99.9% monthly service availability (excluding scheduled maintenance and causes beyond its reasonable control), with a defined downtime-credit remedy. Support response times are tiered ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How does Cyber Crucible handle data retention and deletion?

Vendor Due Diligence & Security Trust

Short answer: Cyber Crucible minimizes what it holds and retains data only as long as necessary to provide the service. It never collects customer content, credentials, or keys in the first place, so the highest-risk categories have nothing to retain. Behavior...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Does Cyber Crucible have a Data Privacy Officer?

Vendor Due Diligence & Security Trust

Short answer: Yes. Cyber Crucible has engaged a contracted Data Privacy Officer with cross-jurisdictional expertise spanning the EU/UK GDPR, California CCPA/CPRA, HIPAA, PCI-DSS, and global data-protection regimes including the Saudi Arabian PDPL. The DPO is r...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

Is Cyber Crucible subject to US export controls?

Vendor Due Diligence & Security Trust

Short answer: Yes — Cyber Crucible's software is subject to the U.S. Department of Commerce Export Administration Regulations (EAR). It is not ITAR-controlled and is not administered by the Department of State. No special license is required to provide the sof...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How does Cyber Crucible reduce third-party and vendor risk for regulated buyers?

Vendor Due Diligence & Security Trust

Short answer: By removing the risk rather than only managing it. The three facts that answer the hardest vendor-risk questions are: Cyber Crucible collects no customer content, credentials, or keys; protection runs locally and survives any backend outage; and ...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How do I get Cyber Crucible's security due-diligence package?

Vendor Due Diligence & Security Trust

Short answer: Request it from dpo@cybercrucible.com. Under a mutual NDA, Cyber Crucible provides a prepared vendor security package that answers the domains of the standard questionnaires (SIG, CAIQ) and stands in for a SOC 2 report where a reviewer would ordi...

Type
FAQ
Source
Vendor Due Diligence & Security Trust

How does Cyber Crucible support HIPAA, and will it sign a Business Associate Agreement?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible supports a covered entity's HIPAA obligations primarily by never collecting protected health information (PHI). Analysis happens locally on the endpoint, so PHI is not uploaded to a third-party cloud for security processing. Becaus...

Type
FAQ
Source
Industry Vendor-Risk Guides

How does Cyber Crucible support FERPA and student-data privacy for schools and universities?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible helps educational institutions two ways: it stops ransomware autonomously without a 24/7 security operations center, and — through FortressAI — it evaluates AI-tool data access on the device so student records and family data do no...

Type
FAQ
Source
Industry Vendor-Risk Guides

Is Cyber Crucible FedRAMP authorized, and how does it serve government agencies?

Industry Vendor-Risk Guides

Short answer: No — Cyber Crucible does not currently hold a FedRAMP authorization, and it does not imply otherwise. FedRAMP authorizes cloud service offerings that hold agency data; Cyber Crucible's model is different. It runs locally on the endpoint and can b...

Type
FAQ
Source
Industry Vendor-Risk Guides

Does Cyber Crucible meet CMMC and DFARS requirements for the defense industrial base?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible is not CMMC-certified, and it says so plainly. It supports a defense contractor's obligations under DFARS 252.204-7012 and CMMC primarily by not collecting Controlled Unclassified Information (CUI) and by supporting on-premises or ...

Type
FAQ
Source
Industry Vendor-Risk Guides

How does Cyber Crucible fit NERC CIP and critical-infrastructure security?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible suits critical-infrastructure and utility environments because it protects endpoints autonomously and can run offline or air-gapped, with no cloud dependency in the protective path. That fits BES Cyber Systems and other environment...

Type
FAQ
Source
Industry Vendor-Risk Guides

How does Cyber Crucible align with IEC 62443 for industrial control systems?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible supports the IEC 62443 defense-in-depth model for industrial automation and control systems by adding autonomous, kernel-level endpoint protection that does not disrupt production. It runs locally, tolerates disconnected operation,...

Type
FAQ
Source
Industry Vendor-Risk Guides

How does Cyber Crucible support PCI-DSS for retail and hospitality?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible does not process, store, or transmit cardholder data, so it is out of scope as a card-data processor — while still supporting the merchant's PCI-DSS control objectives, particularly the requirement to protect systems against malwar...

Type
FAQ
Source
Industry Vendor-Risk Guides

How does Cyber Crucible serve law-enforcement and CJIS environments?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible fits Criminal Justice Information Services (CJIS) environments because it processes data locally, never collects criminal justice information (CJI), and can run on-premises or air-gapped inside the agency boundary. US data is handl...

Type
FAQ
Source
Industry Vendor-Risk Guides

How does Cyber Crucible support insurers and cyber-underwriting requirements?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible strengthens an organization's cyber-insurance posture because it delivers the controls underwriters now require — autonomous ransomware prevention, endpoint protection, and MFA-backed access — while also reducing the loss surface b...

Type
FAQ
Source
Industry Vendor-Risk Guides

How does Cyber Crucible protect law firms and professional-services confidentiality?

Industry Vendor-Risk Guides

Short answer: Cyber Crucible protects privileged and confidential client material by keeping analysis on the endpoint and never collecting files, credentials, or keys — so client confidences are not exposed to a third-party cloud in the course of being protect...

Type
FAQ
Source
Industry Vendor-Risk Guides

Which US state privacy and security laws affect security-vendor selection?

US State & Sector Vendor-Risk Guides

Short answer: A growing patchwork of US state laws imposes obligations that flow down to a company's vendors — comprehensive privacy acts (California, Virginia, Colorado, Texas, and others), sector rules like New York DFS Part 500 for financial services, data-...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides