Compliance library

Security and resilience

Security and resilience for NIS2 reviews

The PacketSafari access, incident, supplier, continuity, and deployment controls relevant to a customer's NIS2 review.

Customer summarySecurity controls implemented
Access
MFA, roles, capture authorization, session controls, and security audit events
Response
Documented incident handling, escalation, and customer-notification procedures
Suppliers
Named service providers and deployment-specific AI, hosting, email, and payment routes
Ownership
PacketSafari operates SaaS controls; on-premises customers operate infrastructure, backups, recovery, and egress
Scope The customer determines whether NIS2 applies to its organization and deploymentLast updated July 24, 2026

Security controls in place

PacketSafari combines technical controls in the product with operational procedures for incident handling, suppliers, releases, continuity, and customer notification. The controls below map the areas most relevant to an enterprise NIS2 review.

NIS2 security areaPacketSafari controlStatus
Access controlMFA, roles, capture authorization, session timeout, revocation, and security audit eventsImplemented
Incident handlingIncident intake, triage, escalation, evidence preservation, communication, and notification proceduresOperational
Supply-chain securityNamed service providers, provider review, and deployment-specific AI and infrastructure routesOperational
Secure developmentControlled releases, component inventory, vulnerability intake, remediation, and update deliveryOperational
Business continuitySaaS backup and recovery responsibilities and on-premises customer ownership are explicitly separatedShared responsibility
Cryptography and communicationsTLS protects browser and API traffic; on-premises customers control storage encryption, keys, and network policyShared responsibility
Effectiveness and evidencePersistent audit events, investigation history, and retained packet evidence support review of security activityImplemented

Who operates each control

For managed SaaS, PacketSafari operates the application, hosting, storage, approved egress, backups, and recovery path. For on-premises deployments, PacketSafari supplies application controls and operating guidance while the customer operates infrastructure security, segmentation, storage, keys, egress, backups, and recovery.

See the detailed SaaS and on-premises responsibility table and current service-provider list.

Regulatory responsibility

PacketSafari does not designate a customer as subject to NIS2 and this page is not a regulatory attestation. Each customer determines its obligations based on its entity, sector, jurisdiction, and deployment. Availability, recovery, and notification commitments are the commitments stated in the applicable customer agreement.