Shared Responsibility Model
SagaID Security & Responsibility Model
This document outlines the shared responsibility model between Sagasoft Technologies Private Limited and its customers for security, data protection, and service management.
Operating EntitySagasoft Technologies Private Limited
PlatformSagaID (Email, Domain, Archive & Backup)
Effective DateSeptember 7, 2026
Security Reportingsecurity@sagaid.com
1 Overview
This document outlines the shared responsibility model between Sagasoft Technologies Private Limited (“Saga”) and its customers (“Customer”) for security, data protection, and service management.
Security in SagaID is a shared responsibility.
2 Responsibility Model Summary
| Area | Saga Responsibility | Customer Responsibility |
|---|---|---|
| Infrastructure | Manage servers, networking, storage, uptime | Not applicable |
| Platform Security | Patch systems, monitor threats, secure services | Use features correctly |
| Account Security | Provide authentication mechanisms | Manage passwords, enable MFA |
| Email Usage | Maintain email infrastructure | Prevent spam, misuse |
| Domain Management | Provide domain tools | Maintain accurate domain data |
| Data Storage | Secure storage systems | Define retention & access |
| Compliance | Provide compliant platform | Meet regulatory requirements |
| Backup & Archive | Provide tools & systems | Configure policies |
3 Saga Responsibilities
Saga is responsible for securing the platform and infrastructure, including:
3.1 Infrastructure Security
- Data center and cloud infrastructure security
- Network protection and monitoring
- System patching and updates
3.2 Platform Security
- Secure application architecture
- Vulnerability management
- Threat detection and prevention
- Logging and monitoring
3.3 Data Protection (Platform Level)
- Encryption in transit
- Encryption at rest (where applicable)
- Access control enforcement
3.4 Service Availability
- Maintaining uptime and reliability
- Performing maintenance and updates
3.5 Abuse Prevention
- Monitoring for spam, phishing, and malicious activity
- Enforcing anti-spam and abuse policies
3.6 Backup Infrastructure
- Providing backup and archiving capabilities
- Ensuring system-level data protection mechanisms
4 Customer Responsibilities
Customers are responsible for how they use the platform, including:
4.1 Account Security
- Using strong passwords
- Enabling multi-factor authentication (MFA)
- Managing user access and roles
4.2 Email Usage
- Preventing spam and abuse
- Following Anti-Spam and Usage Policies
- Monitoring sending behavior
4.3 Domain Management
- Maintaining accurate WHOIS information
- Renewing domains on time
- Preventing misuse of domains
4.4 Data Management
- Configuring retention policies
- Managing data access permissions
- Ensuring data accuracy
4.5 Backup & Archiving
- Configuring backup schedules
- Defining retention periods
- Verifying backup integrity
4.6 Compliance
- Meeting regulatory requirements (e.g., NBFC, financial regulations)
- Implementing internal policies
5 Shared Responsibilities
Responsibilities shared between Saga and the Customer:
- Incident response coordination
- Security best practices implementation
- Monitoring suspicious activities
- Ensuring proper configurations
6 What Saga Does NOT Control
Saga does not control:
- Customer data input or content
- Customer internal policies
- Misuse of accounts due to weak credentials
- External systems integrated by the customer
7 Security Best Practices (Recommended)
Customers should:
- Enable MFA for all users
- Regularly review access logs
- Use domain authentication (SPF, DKIM, DMARC)
- Monitor email activity
- Train employees on phishing awareness
8 Incident Response
- Saga will respond to platform-level incidents
- Customers must report suspicious activity promptly
- Cooperation is required for investigation and resolution
9 Updates
This responsibility model may be updated as services evolve.
10 Contact Information
For inquiries regarding security or this responsibility model: