PacketSafari

PacketSafari Trust Center

Security facts.Plainly stated.

A concise view of where capture data lives, which controls protect it, when providers are involved, and who operates each boundary.

01
Managed data region
EU or US
Customer selected
02
Encryption boundary
TLS + EBS
Transit, volumes, snapshots
03
Backup rotation
3 days
After live-system deletion
04
AI request context
Bounded
Not a whole large capture

01 / Security

Controls you can verify.

MFA, authorization, encryption, release checks, and egress are shown with the operating boundary attached.

01Identity and access

MFA is available and can be required by an organization. Roles, capture authorization, session controls, and audit events are implemented.
The same application controls are available; customer identity integration and operations remain customer-managed.
Implemented

02Encryption in transit

TLS protects browser and API traffic.
TLS is configured within the customer deployment boundary.
Implemented

03Encryption at rest

Capture storage uses encrypted EBS volumes and encrypted backup snapshots.
Customer-managed disks, volumes, keys, and backup encryption.
Customer-operated

04Software security

Automated SBOM and dependency-vulnerability scans support controlled release checks.
Customers apply their own infrastructure and operating-system security controls.
Implemented

05Network egress

Platform-managed routes control approved service and AI destinations.
Customer-controlled network allowlists and egress policy.
Customer-operated

02 / Data flow

Follow the capture boundary.

The public frontend, managed capture path, optional AI path, and on-premises path stay visibly separate.

  1. 01Cloudflare PagesMarketing website only
    No uploaded PCAP storage
  2. 02EU or US regionApplication, captures
    and backups
  3. 03PacketSafariBounded processing
    and evidence retrieval
  4. 04Approved AIOptional selected context
    or customer endpoint

01Public marketing website

Cloudflare Pages delivers www.packetsafari.com globally and does not store uploaded PCAPs.
The marketing website remains separate; customer deployments control their own application frontend delivery path.
Implemented

02Application and capture data

Managed application, captures, and backups operate in a customer-selected EU or US region.
Customer chooses the infrastructure location and data residency.
Configured by plan

03AI-assisted analysis

When enabled, selected bounded packet context, analysis results, and prompts are sent through the approved OpenAI route or a selected OpenRouter-backed model route. A large capture is not sent as one model prompt.
Customer chooses an OpenAI-compatible or private AI endpoint and controls that provider relationship.
Optional

04Anoncap

Optional field-aware anonymization creates an anonymized sibling capture; the original remains subject to its normal access and retention controls.
The same anonymization workflow can run inside the customer deployment boundary.
Optional

03 / Service providers

Purpose before provider.

Each provider is tied to a specific service and data scope. Optional sign-in providers do not receive uploaded captures.

01

Amazon Web Services

Application hosting, encrypted storage and snapshots, and outbound product email through AWS SES.

Account data, PCAPs, analysis data, operational data, and email addresses as applicable.
02

OpenAI

Primary hosted AI processing when managed cloud AI or an OpenAI-specific feature is enabled.

Selected bounded packet context, analysis results, prompts, and model outputs.
03

OpenRouter and selected model provider

Optional gateway and underlying model for an administrator-selected, approved hosted AI route.

Selected bounded packet context, analysis results, prompts, and model outputs.
04

PostHog

Consent-gated browser analytics plus limited product measurement and error diagnostics.

Account or contact details, usage and device metadata, and evaluation-upload metadata; not packet-capture contents in normal analytics events.
05

Google Analytics

Consent-gated usage and interaction analytics for the public website and managed-SaaS frontend.

Routes, interaction events, browser and device data, and IP-derived metadata; not packet-capture contents.
06

Slack

Internal service operations, customer communications, and support collaboration.

Contact or account details, support messages, and deliberately shared diagnostics; not packet captures in the core processing path.
07

Cloudflare

Static hosting, delivery, TLS, availability, and security for the public website.

Visitor IP addresses, request URLs and headers, browser or device metadata, and delivery or security logs; not uploaded PCAPs.
08

lemlist

Consent-gated website visitor tracking and sales outreach.

Visitor, contact, company, and campaign-interaction data where available; not uploaded PCAPs.
09

Paddle

Checkout, subscriptions, payment processing, and billing activation.

Billing and subscription data; not uploaded PCAPs.
10

hosting.de

PacketSafari mailbox infrastructure.

Support, operational, and contact email data.

Contract and transfer details are maintained in the subprocessor and transfer summary.

04 / Retention and incident contact

Deletion has a defined clock.

Organization policy sets capture deadlines. Legal holds pause retention actions; on-premises customers set their own schedule.

01

Enterprise Shared SaaS

Archive eligible after 7 days; deletion scheduled at 14 days.

Configured by plan
02

Enterprise Dedicated SaaS

Archive eligible after 14 days; deletion scheduled at 30 days.

Configured by plan
03

On-premises

Retention, disposal, backups, and recovery are set by the customer.

Customer-operated

Scheduled retention processing records warning and purge audit events, honors legal holds, and applies configured grace periods. Live-system deletion can leave backup copies for up to three days while backup rotation completes.

Incident, privacy, and questionnairescontact@packetsafari.com

Current posture

Framework information, without certification theatre.

PacketSafari publishes current posture pages for enterprise review. It does not currently have a SOC 2 Type I or Type II report, certification, or audit attestation.