Controls mapped to Trust Services Criteria
PacketSafari combines implemented product controls with operational security, privacy, incident, supplier, release, and continuity procedures. The mapping below makes the current delivery state explicit.
| Trust Services area | PacketSafari controls in place | Delivery status |
|---|---|---|
| Security — identity and access | MFA, administrator-enforced MFA, user and role management, capture-level authorization, session timeout, session revocation, and concurrent-session policy | Implemented |
| Security — audit and detection | Persistent security audit events, authentication and session-event visibility, operational logging, and investigation history | Implemented |
| Security — network and data path | TLS for browser and API traffic, bounded packet-evidence access, and explicit approved routes for outbound service and AI traffic | Implemented |
| Security — incident response | Documented incident intake, triage, escalation, evidence preservation, customer communication, and notification procedures | Operational |
| Security — change and release | Controlled release paths, software-component inventories, release provenance, vulnerability intake, assessment, remediation, and supported update delivery | Operational |
| Availability | Service-operated backup and recovery for SaaS; customer-operated backup, recovery, capacity, and infrastructure resilience for on-premises | Shared responsibility |
| Confidentiality | Role and capture authorization, storage boundaries, customer-controlled on-premises keys and egress, and private AI endpoint options | Shared responsibility |
| Processing integrity | Deterministic packet tooling, inspectable frame and flow evidence, explicit preliminary-versus-verified outcomes, and retained investigation history | Implemented |
| Privacy | Published data categories, rights-request channel, account deletion workflow, up-to-three-day backup rotation, and a current service-provider list | Operational |
| Supplier management | Named hosting, email, billing, and cloud-AI providers, plus deployment-specific provider and responsibility review | Operational |
Deployment responsibility
The control boundary is explicit. PacketSafari operates the application, hosting, approved egress, storage, backup, and recovery path for managed SaaS. In on-premises deployments, the customer operates infrastructure, network segmentation, storage encryption and keys, egress allowlists, backup, recovery, and administration while PacketSafari provides the application controls.
See the full SaaS and on-premises responsibility table.
Independent assurance
PacketSafari does not currently have a SOC 2 Type I or Type II report. We do not describe the service as SOC 2 certified or attested. This assurance status is separate from the controls already implemented in the product and its operation.
Enterprise customers can send a questionnaire or request current control information at contact@packetsafari.com. Security-sensitive operational records are shared through an appropriate customer review rather than exposed as unrestricted public documents.
