1. Why This Matters
SagaID is designed as a managed email and identity platform, but security is not fully outsourced.
Instead of a generic shared model, Saga follows a “Control vs Responsibility” approach:
2. Core Principle
3. Ownership Breakdown by Product Layer
Security accountability across SagaID is delineated by the degree of control each party exercises over each layer of the technology stack:
3.1 Infrastructure Layer
Saga owns and manages:
- Cloud infrastructure and networking
- Storage systems (email, archive, backup)
- OS patching and system updates
- Platform uptime and availability
3.2 Platform Layer
- Authentication systems (SSO, OAuth, MFA support)
- Email routing, delivery, and filtering
- Archiving and backup systems
- Domain management interfaces
- Enable and enforce security features
- Configure policies correctly
- Monitor administrative access
3.3 Configuration Layer
- User access and permissions
- Email routing rules and forwarding
- Domain DNS settings (SPF, DKIM, DMARC)
- Retention and archiving policies
- Provide secure tools
- Prevent platform-level vulnerabilities
3.4 Usage Layer
- Email content and communications
- Spam, phishing, or misuse from their accounts
- Compliance with industry regulations
- Internal security practices
4. Service-Specific Responsibilities
4.1 Email Services
- Reliable email delivery infrastructure
- Spam and abuse detection systems
- Avoid spam and bulk misuse
- Configure proper email authentication
- Secure user accounts
4.2 Forward-only Email (Special Case)
- Controls destination systems
- Is responsible for downstream storage and compliance
4.3 Domain Services
- Maintains domain ownership data
- Prevents misuse (phishing, impersonation)
- Renews domains on time
4.4 Archiving & Backup
- Provides storage infrastructure
- Enables retrieval systems
- Defines retention policies
- Initiates recovery
- Ensures compliance (e.g., audit requirements)
5. What Makes Saga Different
Unlike traditional providers, SagaID re-engineers identity and email architecture to give customers greater autonomy and smaller threat profiles:
Forward-only email reduces storage risk surface by never maintaining unneeded downstream copies.
Modular storage options across shared, dedicated, or pooled tiers to fit precise business compliance.
Customer-controlled retention policies instead of forced vendor-side lock-in or premature deletion.
Comprehensive real-time abuse monitoring integrated deeply across both the email and domain stack.
6. Security Boundaries
To maintain strict operational boundaries, Saga does NOT control:
7. Incident Responsibility
In the event of an operational anomaly, security alert, or breach, accountability is assigned by incident source:
| Scenario | Responsibility |
|---|---|
| Infrastructure breach | Saga |
| Account compromise (weak password) | Customer |
| Spam sent from account | Customer |
| Platform vulnerability | Saga |
| Misconfigured DNS (SPF/DKIM) | Customer |
8. Recommended Security Practices
Customers should actively implement the following safeguards:
9. Collaboration Model
Security is strongest when both parties operate in continuous alignment:
10. Contact Information
For queries regarding security ownership, control boundaries, or to report vulnerabilities: