CONTROL VS RESPONSIBILITY MODEL

SagaID Security Ownership Model

SagaID is designed as a managed email and identity platform, but security is not fully outsourced. Instead of a generic shared model, Saga follows a “Control vs Responsibility” approach: Saga secures what we build and operate; Customers secure what they configure and control.

Operating PlatformSagaID (Email, Domain, Archiving & Backup)
CompanySagasoft Technologies Private Limited
Effective DateMarch 2026
Security Contactsecurity@sagaid.com

1. Why This Matters

SagaID is designed as a managed email and identity platform, but security is not fully outsourced.

Instead of a generic shared model, Saga follows a “Control vs Responsibility” approach:

Saga secures what we build and operate: Cloud infrastructure, server virtualization, OS updates, and core mail delivery engines.
Customers secure what they configure and control: Access credentials, MFA enforcement, email routing destinations, DNS authentication, and communication content.

2. Core Principle

FOUNDATIONAL SECURITY AXIOM
Saga Promise
“If Saga controls it, Saga secures it.”
Customer Obligation
“If you configure it, you are responsible for it.”

3. Ownership Breakdown by Product Layer

Security accountability across SagaID is delineated by the degree of control each party exercises over each layer of the technology stack:

3.1 Infrastructure Layer

Fully Owned by Saga

Saga owns and manages:

Managed by Saga
  • Cloud infrastructure and networking
  • Storage systems (email, archive, backup)
  • OS patching and system updates
  • Platform uptime and availability
Customer Involvement
❌ None: Customers have no access or operational burden over physical/virtual server infrastructure.

3.2 Platform Layer

Saga-led, Customer-aware
Saga Provides
  • Authentication systems (SSO, OAuth, MFA support)
  • Email routing, delivery, and filtering
  • Archiving and backup systems
  • Domain management interfaces
Customer Responsibilities
  • Enable and enforce security features
  • Configure policies correctly
  • Monitor administrative access

3.3 Configuration Layer

Customer-Controlled
Customers Control
  • User access and permissions
  • Email routing rules and forwarding
  • Domain DNS settings (SPF, DKIM, DMARC)
  • Retention and archiving policies
Saga Responsibility
  • Provide secure tools
  • Prevent platform-level vulnerabilities

3.4 Usage Layer

Fully Customer-Owned
Customers are Fully Responsible For
  • Email content and communications
  • Spam, phishing, or misuse from their accounts
  • Compliance with industry regulations
  • Internal security practices
Saga Role
Detect and act on abuse patterns

4. Service-Specific Responsibilities

4.1 Email Services

Saga Ensures:
  • Reliable email delivery infrastructure
  • Spam and abuse detection systems
Customer Must:
  • Avoid spam and bulk misuse
  • Configure proper email authentication
  • Secure user accounts

4.2 Forward-only Email (Special Case)

Saga:
Routes emails securely
Customer:
  • Controls destination systems
  • Is responsible for downstream storage and compliance

4.3 Domain Services

Saga:
Provides domain registration and management tools
Customer:
  • Maintains domain ownership data
  • Prevents misuse (phishing, impersonation)
  • Renews domains on time

4.4 Archiving & Backup

Saga:
  • Provides storage infrastructure
  • Enables retrieval systems
Customer:
  • Defines retention policies
  • Initiates recovery
  • Ensures compliance (e.g., audit requirements)

5. What Makes Saga Different

Unlike traditional providers, SagaID re-engineers identity and email architecture to give customers greater autonomy and smaller threat profiles:

Reduced Risk Surface

Forward-only email reduces storage risk surface by never maintaining unneeded downstream copies.

Flexible Storage Models

Modular storage options across shared, dedicated, or pooled tiers to fit precise business compliance.

Customer-Controlled Retention

Customer-controlled retention policies instead of forced vendor-side lock-in or premature deletion.

Built-in Abuse Monitoring

Comprehensive real-time abuse monitoring integrated deeply across both the email and domain stack.

6. Security Boundaries

To maintain strict operational boundaries, Saga does NOT control:

Customer data input or email content
Weak passwords or compromised accounts
Misconfigured DNS or email routing
Customer-side integrations (e.g., Gmail, Outlook)

7. Incident Responsibility

In the event of an operational anomaly, security alert, or breach, accountability is assigned by incident source:

ScenarioResponsibility
Infrastructure breach Saga
Account compromise (weak password) Customer
Spam sent from account Customer
Platform vulnerability Saga
Misconfigured DNS (SPF/DKIM) Customer

8. Recommended Security Practices

Customers should actively implement the following safeguards:

1
Enable MFA for all users
2
Use strong password policies
3
Configure SPF, DKIM, and DMARC
4
Monitor login and email activity
5
Train users on phishing awareness

9. Collaboration Model

Security is strongest when both parties operate in continuous alignment:

Saga provides secure infrastructure: Hardened cloud architecture, encrypted transport, proactive spam filtering, and 24×7 service monitoring.
Customers actively manage configurations: Enforcing least-privilege administrative access, updating forwarding targets, and configuring anti-spoofing DNS records.
Both parties must cooperate during incidents.

10. Contact Information

For queries regarding security ownership, control boundaries, or to report vulnerabilities:

TeamSecurity Team
OrganizationSagasoft Technologies Private Limited
Security Emailsecurity@sagaid.com