Security controls in place
PacketSafari combines technical controls in the product with operational procedures for incident handling, suppliers, releases, continuity, and customer notification. The controls below map the areas most relevant to an enterprise NIS2 review.
| NIS2 security area | PacketSafari control | Status |
|---|---|---|
| Access control | MFA, roles, capture authorization, session timeout, revocation, and security audit events | Implemented |
| Incident handling | Incident intake, triage, escalation, evidence preservation, communication, and notification procedures | Operational |
| Supply-chain security | Named service providers, provider review, and deployment-specific AI and infrastructure routes | Operational |
| Secure development | Controlled releases, component inventory, vulnerability intake, remediation, and update delivery | Operational |
| Business continuity | SaaS backup and recovery responsibilities and on-premises customer ownership are explicitly separated | Shared responsibility |
| Cryptography and communications | TLS protects browser and API traffic; on-premises customers control storage encryption, keys, and network policy | Shared responsibility |
| Effectiveness and evidence | Persistent audit events, investigation history, and retained packet evidence support review of security activity | Implemented |
Who operates each control
For managed SaaS, PacketSafari operates the application, hosting, storage, approved egress, backups, and recovery path. For on-premises deployments, PacketSafari supplies application controls and operating guidance while the customer operates infrastructure security, segmentation, storage, keys, egress, backups, and recovery.
See the detailed SaaS and on-premises responsibility table and current service-provider list.
Regulatory responsibility
PacketSafari does not designate a customer as subject to NIS2 and this page is not a regulatory attestation. Each customer determines its obligations based on its entity, sector, jurisdiction, and deployment. Availability, recovery, and notification commitments are the commitments stated in the applicable customer agreement.
