Cloud and security controls
PacketSafari uses BSI guidance and C5 control expectations as reference points for German enterprise security and cloud-assurance reviews.
The controls below cover identity, logging, communications security, incidents, changes, suppliers, continuity, and data protection across both delivery models.
| BSI/C5 control area | PacketSafari control | Status |
|---|---|---|
| Identity and authorization | MFA, roles, capture authorization, session timeout, revocation, and concurrent-session controls | Implemented |
| Logging and monitoring | Persistent security audit events and operational visibility | Implemented |
| Communications security | TLS for browser and API traffic plus explicit approved egress routes | Implemented |
| Incident management | Documented intake, triage, escalation, evidence preservation, communication, and notification procedures | Operational |
| Change and vulnerability management | Controlled releases, component inventory, vulnerability handling, remediation, and supported updates | Operational |
| Supplier management | Current hosting, mail, billing, and AI providers are identified and reviewed by deployment | Operational |
| Continuity | SaaS backup and recovery are service-operated; on-premises continuity is customer-operated with PacketSafari guidance | Shared responsibility |
| Data protection | Published retention, deletion, privacy-request, and provider information | Operational |
SaaS and on-premises responsibilities
Managed SaaS reviews focus on PacketSafari-operated controls and suppliers. On-premises reviews also require customer infrastructure evidence for storage, keys, network controls, backups, recovery, and administration.
Independent assurance
PacketSafari does not hold a BSI certification and does not have an external C5 attestation report. Customers can use the published deployment responsibility table, privacy information, service-provider list, and current control answers in their own review.
