Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

199 total results found

How does Cyber Crucible support New York DFS Part 500 cybersecurity requirements?

US State & Sector Vendor-Risk Guides

Short answer: For a financial institution covered by New York DFS Part 500 (23 NYCRR 500), Cyber Crucible supports several required controls — multi-factor authentication, encryption, access controls, and incident response — while reducing third-party risk bec...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support California CCPA/CPRA vendor obligations?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible acts as a service provider under the CCPA/CPRA, bound by contract to process data only on the customer's instructions, and it does not sell or share personal information. Because it collects essentially no personal information in t...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support the Texas Data Privacy and Security Act (TDPSA)?

US State & Sector Vendor-Risk Guides

Short answer: Under the Texas Data Privacy and Security Act, Cyber Crucible acts as a processor bound by a data processing agreement, assisting the controller with security and data-subject requests. Its data-minimization design — collecting no customer conten...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Virginia's Consumer Data Protection Act (VCDPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible supports a controller's VCDPA obligations as a processor operating under a data processing agreement, helping with data-security duties and consumer-rights requests. Its no-collection design means it holds little to no personal dat...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support the Colorado Privacy Act (CPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible operates as a processor under the Colorado Privacy Act, bound by a data processing agreement to follow the controller's instructions, assist with security, and support consumer rights. Because it collects essentially no personal da...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Massachusetts 201 CMR 17.00 (WISP)?

US State & Sector Vendor-Risk Guides

Short answer: Massachusetts 201 CMR 17.00 requires any organization holding personal information about a Massachusetts resident to maintain a Written Information Security Program with specific safeguards. Cyber Crucible supports a customer's WISP with encrypti...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible address Illinois BIPA and biometric-data concerns?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible does not collect, store, or process biometric identifiers or biometric information, so it does not create the exposure Illinois's Biometric Information Privacy Act (BIPA) is written to address. There is no biometric data in its cus...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Pennsylvania's breach-notification law?

US State & Sector Vendor-Risk Guides

Short answer: Pennsylvania's Breach of Personal Information Notification Act (73 P.S. §2301, as amended by Act 151 of 2022) requires notifying affected residents — and, for larger breaches, the Attorney General — after a breach of covered personal information....

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support the Connecticut Data Privacy Act (CTDPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible operates as a processor under the Connecticut Data Privacy Act, bound by a data processing agreement to act on the controller's instructions and to assist with security and data-subject requests. Because it collects no customer con...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Utah's Consumer Privacy Act (UCPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible acts as a processor under the Utah Consumer Privacy Act, following the controller's documented instructions under a data processing agreement. Its no-collection design means there is little personal data in its custody for the UCPA...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Oregon's Consumer Privacy Act (OCPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible operates as a processor under the Oregon Consumer Privacy Act, bound by contract to process only on the controller's instructions and to assist with security and consumer-rights requests. Because it collects essentially no personal...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Washington's My Health My Data Act?

US State & Sector Vendor-Risk Guides

Short answer: Washington's My Health My Data Act regulates "consumer health data" broadly and carries a private right of action, so vendors that touch such data face real exposure. Cyber Crucible does not collect consumer health data — it analyzes process and ...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support the newer 2025–2026 state privacy laws?

US State & Sector Vendor-Risk Guides

Short answer: A wave of comprehensive state privacy laws took effect across 2025 and 2026 — including New Jersey, Delaware, Iowa, Nebraska, New Hampshire, Tennessee, Minnesota, Maryland, and, in 2026, Indiana, Kentucky, and Rhode Island. They share a common st...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

Does Cyber Crucible comply with Canada's PIPEDA and Quebec Law 25?

International Vendor-Risk Guides

Short answer: Cyber Crucible supports a Canadian organization's obligations under PIPEDA and Quebec's Law 25 primarily by processing on the endpoint and collecting no customer content, credentials, or keys — so there is little personal information in its custo...

Type
FAQ
Source
International Vendor-Risk Guides

Does Cyber Crucible comply with Australia's Privacy Act and the APPs?

International Vendor-Risk Guides

Short answer: Cyber Crucible supports an Australian entity's obligations under the Privacy Act 1988 and the Australian Privacy Principles by minimizing data — it collects no customer content, credentials, or keys — and by processing locally on the endpoint. Th...

Type
FAQ
Source
International Vendor-Risk Guides

Does Cyber Crucible comply with India's Digital Personal Data Protection Act (DPDP)?

International Vendor-Risk Guides

Short answer: Cyber Crucible supports a data fiduciary's obligations under India's Digital Personal Data Protection Act by acting as a data processor that collects essentially no personal data and processes on the endpoint. Because customer content is never co...

Type
FAQ
Source
International Vendor-Risk Guides

Does Cyber Crucible comply with Singapore's PDPA?

International Vendor-Risk Guides

Short answer: Cyber Crucible supports an organization's obligations under Singapore's Personal Data Protection Act as a data intermediary that processes on the endpoint and collects no customer content, credentials, or keys. The Protection and Transfer Limitat...

Type
FAQ
Source
International Vendor-Risk Guides

Does Cyber Crucible comply with Japan's APPI?

International Vendor-Risk Guides

Short answer: Cyber Crucible supports a business operator's obligations under Japan's Act on the Protection of Personal Information (APPI) by minimizing data and processing locally. It collects no customer content, credentials, or keys, so the handling, third-...

Type
FAQ
Source
International Vendor-Risk Guides