Enterprise security boundary

Set the boundary before the capture arrives.

Control where packet evidence lives, who can access it, and which AI and egress routes are approved.

Define your deployment boundary
Customer-approved investigation pathPolicy enforced
  1. 01
    IdentityUsers, roles, MFA, and capture authorization
  2. 02
    PacketSafari Core EngineBounded packet processing and evidence access
  3. 03
    Packet evidenceStorage, retention, backup, and deletion policy
  4. 04
    Approved AIExplicit model routing and egress policy

Deployment ownership

Know who controls each boundary.

SaaS and on-premises use the same investigation product. Storage, identity, egress, and operational ownership change with the deployment.

Security control ownership for PacketSafari SaaS and on-premises deployments
ControlManaged SaaSPacketSafari operatedOn-premisesCustomer infrastructure
01Core access controlsMFA, roles, capture authorization, and session revocationMFA, roles, capture authorization, and session revocation
02Enterprise identityStandard SaaS identity controlsSAML or OIDC SSO and SCIM provisioning
03Encryption in transitTLS for browser and API trafficTLS inside the customer deployment boundary
04Storage and encryption at restService-managed storage and database controlsCustomer-managed disks, volumes, keys, and backup policy
05Retention and residencyDefined by the hosted deployment profileCustomer-selected region, retention, and disposal workflow
06Audit and SIEMService-operated audit controlsSecurity audit events and forwarding profiles
07Outbound egressPlatform-managed approved routesCustomer-controlled network allowlists
08Backup and recoveryService-operatedCustomer-operated with PacketSafari guidance

At-rest encryption and recovery outcomes on-premises depend on the customer-operated storage and infrastructure profile.

Current control status

Available, owned, or pending.

Every control is labelled by its current delivery or responsibility state.

01

Available

Identity and access

MFA, admin-enforced MFA, users, roles, capture authorization, session timeout, revocation, and concurrent-session policy.

02

Available

Security audit events

Audit-event persistence and operational visibility are part of the current platform.

03

On-premises

Enterprise identity

SAML or OIDC browser SSO, break-glass local login, and SCIM provisioning are available in on-premises deployments.

04

Customer operated

Infrastructure controls

At-rest encryption, retention, disposal, network segmentation, egress allowlists, secrets, key rotation, and backups remain customer responsibilities on-premises.

05

Partial evidence

Release attestation

Provenance inventory and release evidence manifests exist; signed attestation outputs remain pending.

Enterprise evaluation

Agree the boundary. Then test it.

Evaluate with your capture