Corporate Governance
Packet Labs maintains a formal governance and control environment appropriate to clients in regulated industries, government and multinational procurement, within the framework set by Packet Holdings Ltd.
Principles applied across the company
Group governance
Packet Labs has its own board with a mandate approved by the board of Packet Holdings Ltd., and reports against it on a scheduled basis. Company policy is consistent with Group policy and the Group code of conduct.
Verifiable representations
Certifications and licences are published with their current status and supported by documentary evidence on request. Representations made in tender responses are consistent with that register.
Professional independence
The company maintains independence in its assurance work and operates licensed services in accordance with the applicable regulatory framework.
Information security and data residency
A formal control environment aligned to ISO/IEC 27001 governs the company’s platforms. Client data is held on Malaysian infrastructure under Malaysian jurisdiction unless a client directs otherwise.
Operational controls
Packet Labs platforms are operated to the following control baseline, which is subject to review and available in detail for supplier assessment.
- Models, prompts and documents processed on client premises or Group infrastructure in Malaysia.
- Role-based access, audit logging and retention controls on every platform deployment.
- Redaction and policy enforcement at the PacketX gateway before any call reaches a commercial model.
- Enforced HTTPS with automated certificate renewal across company domains.
- SPF, DKIM and DMARC published across company domains.
- Scheduled backups with a documented and tested restoration procedure, operated with Packet Cloud Services.
Vulnerability disclosure
Security issues identified in any Packet Labs system may be reported to the company directly, or to the Group at compliance@packetholdings.com. Reports are acknowledged, the reporter is kept informed of remediation, and no action is taken against good-faith security research.
Business conduct
The company does not offer or accept improper payments and requires the same standard of its suppliers and partners. Conduct expectations form part of engagement letters and supplier agreements.
Supplier questionnaires
Completed vendor assessment questionnaires and a named point of accountability are provided on request.
