Product-security practices
PacketSafari maintains security checks and release records across development, delivery, vulnerability handling, and supported operation.
The controls below cover secure development, component visibility, vulnerability handling, supported updates, and the customer responsibilities that change between SaaS and on-premises delivery.
| CRA area | PacketSafari control | Status |
|---|---|---|
| Secure development | Security review is part of development, release, and supported operation | Operational |
| Component visibility | Software-component inventories and release provenance are maintained for release paths | Implemented |
| Vulnerability handling | Issues can be received, assessed, prioritized, remediated, and tracked into a release | Operational |
| Security updates | PacketSafari deploys managed SaaS releases and supplies supported on-premises updates | Operational |
| Access protection | MFA, roles, capture authorization, session controls, and audit events protect product access | Implemented |
| Customer instructions | Deployment responsibilities for storage, identity, egress, backup, recovery, and updates are published | Published |
SaaS and on-premises updates
PacketSafari operates the managed SaaS release path. On-premises customers operate the deployed infrastructure and apply updates within their environment under the agreed support and lifecycle model.
Conformity status
PacketSafari has not published a formal Cyber Resilience Act conformity assessment. Product classification and contractual obligations depend on the software, delivery model, and regulatory context being evaluated. Signed release attestations are not represented as available unless they are included in the applicable release and customer agreement.
