PacketSafari Trust Center
Security facts.Plainly stated.
A concise view of where capture data lives, which controls protect it, when providers are involved, and who operates each boundary.
- Managed data region
- eu-north-1 AWS Stockholm
- Encryption boundary
- TLS + EBS Transit, volumes, snapshots
- Backup rotation
- 3 days After live-system deletion
- AI request context
- Bounded Not a whole large capture
01 / Security
Controls you can verify.
MFA, authorization, encryption, release checks, and egress are shown with the operating boundary attached.
01Identity and access
02Encryption in transit
03Encryption at rest
04Software security
05Network egress
02 / Data flow
Follow the capture boundary.
The public frontend, managed capture path, optional AI path, and on-premises path stay visibly separate.
- 01CloudFrontPublic frontend only
No uploaded PCAP storage - 02AWS StockholmApplication, captures
and backups - 03PacketSafariBounded processing
and evidence retrieval - 04Approved AIOptional selected context
or customer endpoint
01Public frontend
02Application and capture data
03AI-assisted analysis
04Anoncap
03 / Service providers
Purpose before provider.
Each provider is tied to a specific service and data scope. Optional sign-in providers do not receive uploaded captures.
Amazon Web Services
Application hosting, encrypted storage and snapshots, and outbound product email through AWS SES.
Account data, PCAPs, analysis data, operational data, and email addresses as applicable.OpenAI
Hosted AI processing when the managed cloud AI feature is enabled.
Selected bounded packet context, analysis results, prompts, and model outputs.Paddle
Checkout, subscriptions, payment processing, and billing activation.
Billing and subscription data; not uploaded PCAPs.hosting.de
PacketSafari mailbox infrastructure.
Support, operational, and contact email data.GitHub and Google
Optional sign-in integrations only when enabled.
Identity data needed for sign-in; not uploaded PCAPs.Contract and transfer details are maintained in the subprocessor and transfer summary.
04 / Retention and incident contact
Deletion has a defined clock.
Organization policy sets capture deadlines. Legal holds pause retention actions; on-premises customers set their own schedule.
Enterprise Shared SaaS
Archive eligible after 7 days; deletion scheduled at 14 days.
Configured by planEnterprise Dedicated SaaS
Archive eligible after 14 days; deletion scheduled at 30 days.
Configured by planOn-premises
Retention, disposal, backups, and recovery are set by the customer.
Customer-operatedScheduled retention processing records warning and purge audit events, honors legal holds, and applies configured grace periods. Live-system deletion can leave backup copies for up to three days while backup rotation completes.
Current posture
Framework information, without certification theatre.
PacketSafari publishes current posture pages for enterprise review. It does not currently have a SOC 2 Type I or Type II report, certification, or audit attestation.
