Compliance library

Security and assurance

Security controls for SOC 2 reviews

Implemented PacketSafari controls mapped to SOC 2 security, availability, confidentiality, processing integrity, and privacy areas.

Customer summaryTechnical and operational controls implemented
Identity
MFA, roles, capture authorization, session timeout, revocation, and concurrent-session controls
Audit
Security audit events, operational visibility, incident procedures, and investigation history
Data
TLS, access boundaries, retention and deletion rules, backup rotation, and AI egress controls
Assurance
Controls are available for customer review; an independent SOC 2 Type I or Type II report is not currently available
Scope PacketSafari does not claim a Type I or Type II attestationLast updated July 24, 2026

Controls mapped to Trust Services Criteria

PacketSafari combines implemented product controls with operational security, privacy, incident, supplier, release, and continuity procedures. The mapping below makes the current delivery state explicit.

Trust Services areaPacketSafari controls in placeDelivery status
Security — identity and accessMFA, administrator-enforced MFA, user and role management, capture-level authorization, session timeout, session revocation, and concurrent-session policyImplemented
Security — audit and detectionPersistent security audit events, authentication and session-event visibility, operational logging, and investigation historyImplemented
Security — network and data pathTLS for browser and API traffic, bounded packet-evidence access, and explicit approved routes for outbound service and AI trafficImplemented
Security — incident responseDocumented incident intake, triage, escalation, evidence preservation, customer communication, and notification proceduresOperational
Security — change and releaseControlled release paths, software-component inventories, release provenance, vulnerability intake, assessment, remediation, and supported update deliveryOperational
AvailabilityService-operated backup and recovery for SaaS; customer-operated backup, recovery, capacity, and infrastructure resilience for on-premisesShared responsibility
ConfidentialityRole and capture authorization, storage boundaries, customer-controlled on-premises keys and egress, and private AI endpoint optionsShared responsibility
Processing integrityDeterministic packet tooling, inspectable frame and flow evidence, explicit preliminary-versus-verified outcomes, and retained investigation historyImplemented
PrivacyPublished data categories, rights-request channel, account deletion workflow, up-to-three-day backup rotation, and a current service-provider listOperational
Supplier managementNamed hosting, email, billing, and cloud-AI providers, plus deployment-specific provider and responsibility reviewOperational

Deployment responsibility

The control boundary is explicit. PacketSafari operates the application, hosting, approved egress, storage, backup, and recovery path for managed SaaS. In on-premises deployments, the customer operates infrastructure, network segmentation, storage encryption and keys, egress allowlists, backup, recovery, and administration while PacketSafari provides the application controls.

See the full SaaS and on-premises responsibility table.

Independent assurance

PacketSafari does not currently have a SOC 2 Type I or Type II report. We do not describe the service as SOC 2 certified or attested. This assurance status is separate from the controls already implemented in the product and its operation.

Enterprise customers can send a questionnaire or request current control information at contact@packetsafari.com. Security-sensitive operational records are shared through an appropriate customer review rather than exposed as unrestricted public documents.