Available
Identity and access
MFA, admin-enforced MFA, users, roles, capture authorization, session timeout, revocation, and concurrent-session policy.
Enterprise security boundary
Control where packet evidence lives, who can access it, and which AI and egress routes are approved.
Define your deployment boundaryDeployment ownership
SaaS and on-premises use the same investigation product. Storage, identity, egress, and operational ownership change with the deployment.
| Control | Managed SaaSPacketSafari operated | On-premisesCustomer infrastructure |
|---|---|---|
| 01Core access controls | MFA, roles, capture authorization, and session revocation | MFA, roles, capture authorization, and session revocation |
| 02Enterprise identity | Standard SaaS identity controls | SAML or OIDC SSO and SCIM provisioning |
| 03Encryption in transit | TLS for browser and API traffic | TLS inside the customer deployment boundary |
| 04Storage and encryption at rest | Service-managed storage and database controls | Customer-managed disks, volumes, keys, and backup policy |
| 05Retention and residency | Defined by the hosted deployment profile | Customer-selected region, retention, and disposal workflow |
| 06Audit and SIEM | Service-operated audit controls | Security audit events and forwarding profiles |
| 07Outbound egress | Platform-managed approved routes | Customer-controlled network allowlists |
| 08Backup and recovery | Service-operated | Customer-operated with PacketSafari guidance |
At-rest encryption and recovery outcomes on-premises depend on the customer-operated storage and infrastructure profile.
Current control status
Every control is labelled by its current delivery or responsibility state.
Available
MFA, admin-enforced MFA, users, roles, capture authorization, session timeout, revocation, and concurrent-session policy.
Available
Audit-event persistence and operational visibility are part of the current platform.
On-premises
SAML or OIDC browser SSO, break-glass local login, and SCIM provisioning are available in on-premises deployments.
Customer operated
At-rest encryption, retention, disposal, network segmentation, egress allowlists, secrets, key rotation, and backups remain customer responsibilities on-premises.
Partial evidence
Provenance inventory and release evidence manifests exist; signed attestation outputs remain pending.
Enterprise evaluation