Shared Responsibility Statement
Last updated
This statement says who is responsible for what when you run workloads on LBREEZE LIMITED infrastructure, or deploy our software into an environment you control. It forms part of our Terms of Service.
It exists because the most expensive misunderstanding in hosting is a customer believing a provider is watching something the provider has never looked at. The table below is written so that neither of us has to guess during an incident.
1. The dividing line
We are responsible for the platform: the hardware, the hypervisor, the physical network, the storage layer, the control plane and the automation that provisions your resources.
You are responsible for everything inside the environment we hand you: the operating system once it is running, every package on it, every application you or our automation installs, the configuration, the access control, and the data.
The line sits at the boundary of the instance. We keep the instance running. You decide what runs in it, and you keep that safe.
2. Who does what
| Layer | lbreeze | You |
|---|---|---|
| Data centre, power, cooling, physical security | Yes | — |
| Physical network, edge routing, upstream transit | Yes | — |
| Host hardware and hypervisor, including host patching | Yes | — |
| Isolation between customer environments | Yes | — |
| Control plane, provisioning automation, the customer portal | Yes | — |
| Platform backups of our own systems | Yes | — |
| Guest operating system patching and hardening | — | Yes |
| Firewall rules, open ports, network policy inside your environment | — | Yes |
| Application installation, configuration and updates | — | Yes |
| Application and database credentials, key rotation, MFA for your users | — | Yes |
| Your TLS certificates and their installation, unless managed by us | — | Yes |
| Your data, its lawful basis, its retention, and its encryption inside the instance | — | Yes |
| Backups of your data | Only where purchased as an add-on | Yes, otherwise |
| Monitoring of your application's health and behaviour | Only where purchased as an add-on | Yes, otherwise |
| Incident response inside your environment | Assistance on a best-efforts basis | Yes |
| Compliance of your own business and content with applicable law | — | Yes |
3. One-click deployments
Our automation can deploy software into your environment, including kstack, Standby and Zephyr, and third-party applications. That deployment is a convenience: it installs a working starting point so you do not have to.
Deploying something for you does not mean we then operate it. Once the deployment completes, the application is yours. We do not patch it, we do not monitor it, we do not tune it, and we do not secure it beyond whatever hardening the deployment applied on the day it ran. Default credentials generated during a deployment must be changed by you before the application is exposed to the internet.
Third-party and open-source applications deployed by our automation are covered by their own licences and their own security advisories. We do not warrant them and we are not responsible for vulnerabilities in them, though we will update a deployment recipe when we become aware that it produces an insecure result.
4. What we will do anyway
The division above is about responsibility, not about indifference.
If we see traffic that indicates your instance is compromised or attacking others, we will tell you, and we will act under the Acceptable Use Policy if it continues. If we are patching a hypervisor in a way that will restart your instance, we will tell you in advance under the Service Level Agreement's maintenance notice. If you have a problem inside your environment and ask for help, our support team will help on a best-efforts basis, within the hours in the Service Level Agreement, even where the problem is on your side of the line.
None of that transfers responsibility. Help given once does not become an obligation to give it again.
5. Managed services
Where you buy a managed service, specific items move from your column to ours, and the plan says which ones. Nothing moves by implication or by custom. If you think we are managing something, check that it is written down, because in an incident the written scope is what governs.
6. Data protection roles follow the same line
Because you decide what personal data goes into your environment and why, you are the controller for it and we are your processor for the hosting of it. Our Data Processing Addendum sets out that relationship, including our security measures, our sub-processors, and what happens to the data when the service ends.
For the data we hold about you as our customer, we are the controller, and our Privacy Policy applies.
7. If you are not sure
Ask before you need to know. Write to support@lbreeze.com describing what you are building and what you expect us to be watching, and we will tell you plainly which side of the line each part sits on, and what you would need to buy to move it.

