lbreeze

Shared Responsibility Statement

Last updated

This statement says who is responsible for what when you run workloads on LBREEZE LIMITED infrastructure, or deploy our software into an environment you control. It forms part of our Terms of Service.

It exists because the most expensive misunderstanding in hosting is a customer believing a provider is watching something the provider has never looked at. The table below is written so that neither of us has to guess during an incident.

1. The dividing line

We are responsible for the platform: the hardware, the hypervisor, the physical network, the storage layer, the control plane and the automation that provisions your resources.

You are responsible for everything inside the environment we hand you: the operating system once it is running, every package on it, every application you or our automation installs, the configuration, the access control, and the data.

The line sits at the boundary of the instance. We keep the instance running. You decide what runs in it, and you keep that safe.

2. Who does what

Layer lbreeze You
Data centre, power, cooling, physical security Yes
Physical network, edge routing, upstream transit Yes
Host hardware and hypervisor, including host patching Yes
Isolation between customer environments Yes
Control plane, provisioning automation, the customer portal Yes
Platform backups of our own systems Yes
Guest operating system patching and hardening Yes
Firewall rules, open ports, network policy inside your environment Yes
Application installation, configuration and updates Yes
Application and database credentials, key rotation, MFA for your users Yes
Your TLS certificates and their installation, unless managed by us Yes
Your data, its lawful basis, its retention, and its encryption inside the instance Yes
Backups of your data Only where purchased as an add-on Yes, otherwise
Monitoring of your application's health and behaviour Only where purchased as an add-on Yes, otherwise
Incident response inside your environment Assistance on a best-efforts basis Yes
Compliance of your own business and content with applicable law Yes

3. One-click deployments

Our automation can deploy software into your environment, including kstack, Standby and Zephyr, and third-party applications. That deployment is a convenience: it installs a working starting point so you do not have to.

Deploying something for you does not mean we then operate it. Once the deployment completes, the application is yours. We do not patch it, we do not monitor it, we do not tune it, and we do not secure it beyond whatever hardening the deployment applied on the day it ran. Default credentials generated during a deployment must be changed by you before the application is exposed to the internet.

Third-party and open-source applications deployed by our automation are covered by their own licences and their own security advisories. We do not warrant them and we are not responsible for vulnerabilities in them, though we will update a deployment recipe when we become aware that it produces an insecure result.

4. What we will do anyway

The division above is about responsibility, not about indifference.

If we see traffic that indicates your instance is compromised or attacking others, we will tell you, and we will act under the Acceptable Use Policy if it continues. If we are patching a hypervisor in a way that will restart your instance, we will tell you in advance under the Service Level Agreement's maintenance notice. If you have a problem inside your environment and ask for help, our support team will help on a best-efforts basis, within the hours in the Service Level Agreement, even where the problem is on your side of the line.

None of that transfers responsibility. Help given once does not become an obligation to give it again.

5. Managed services

Where you buy a managed service, specific items move from your column to ours, and the plan says which ones. Nothing moves by implication or by custom. If you think we are managing something, check that it is written down, because in an incident the written scope is what governs.

6. Data protection roles follow the same line

Because you decide what personal data goes into your environment and why, you are the controller for it and we are your processor for the hosting of it. Our Data Processing Addendum sets out that relationship, including our security measures, our sub-processors, and what happens to the data when the service ends.

For the data we hold about you as our customer, we are the controller, and our Privacy Policy applies.

7. If you are not sure

Ask before you need to know. Write to support@lbreeze.com describing what you are building and what you expect us to be watching, and we will tell you plainly which side of the line each part sits on, and what you would need to buy to move it.