Understanding the Shared Responsibility Model in Cloud Services
Effective cloud service usage depends on a reliable partnership between the customer and the cloud service provider (CSP). At WafaiCloud, we place a high priority on being a transparent security partner, as this is crucial in building customer trust. We are dedicated to helping you secure your products and protect your customers' data.
You might ask, "Since my product is hosted with WafaiCloud, it's ready to go, right?" Not exactly. While WafaiCloud plays an important role, we are not the sole guardians of the data stored on our services. The responsibility for protecting your customers' data is shared between you, your customers, and WafaiCloud.
The Shared Responsibility Model (SRM) is a framework that defines the division of responsibilities between the cloud service provider (in this case, WafaiCloud) and the customer (you) to secure the cloud environment. WafaiCloud is responsible for securing the cloud infrastructure, including physical security and the security of the virtualization services we offer. On the other hand, you are responsible for securing what is within your cloud environment, such as the operating system (OS) on your virtual machines and managing access to your instance.
This model is applied differently across the three main types of cloud services:
1. Infrastructure as a Service (IaaS)
2. Platform as a Service (PaaS)
3. Software as a Service (SaaS)

Each type of service comes with a distinct allocation of responsibilities. Below is a visual representation that outlines the separation of responsibilities across these cloud service models.
The Shared Responsibility Model (SRM) also includes IT controls—policies and procedures necessary to meet standards, comply with regulations, and manage risks effectively. At WafaiCloud, we handle physical and environmental controls, providing foundational protections that you inherit from our services. Additionally, there are shared controls for which both WafaiCloud and your company are responsible, depending on the context. For example, while WafaiCloud provides internal security training, it is your responsibility to ensure that your employees are properly trained.
There are also controls that are entirely your responsibility to manage. One key area is identity and access management (IAM). In these areas, we recommend using frameworks such as the NIST Cybersecurity Framework to help identify and implement the necessary controls.
Data protection involves various components, which differ significantly based on your business needs and the importance of the data you store. Based on these factors, your safeguards may vary from those required by other companies.
These SRM guides are designed to help you use the security measures available within our product line to enhance the protection of your business.
Forensic Support & Legal Hold
As part of our commitment to transparency and compliance with applicable laws and regulations, WafaiCloud provides forensic support to customers in connection with legal proceedings, regulatory investigations, or internal investigations involving data and systems hosted on our infrastructure.
Forensic Support Obligation
Upon receipt of a valid written request from you or a competent legal authority, WafaiCloud will provide reasonable forensic support, including preservation of digital evidence, production of event logs, and generation of verified snapshots related to your tenancy.
Chain of Custody
WafaiCloud maintains a documented chain of custody for all digital evidence collected in response to a forensic support request. Evidence integrity is verified through cryptographic hashing (SHA-256) at the time of collection and upon delivery. Chain of custody records are retained for a minimum of three (12) months from the date of case closure.
Legal Hold
Upon receiving a valid forensic support request or legal order, WafaiCloud will suspend any automated deletion, archival, or modification processes affecting data within the scope of the request. The legal hold remains in effect for the duration of the legal proceeding or until written confirmation is received that the hold may be released.
How to Submit a Forensic Support Request
Forensic support requests must be submitted in writing and include: (a) the identity of your authorized representative, (b) a description of the legal or investigative matter, (c) identification of the specific data, systems, or time range of interest, and (d) a case reference number. WafaiCloud will acknowledge receipt within one (3) business day.
Send requests to: [email protected] with the subject line: FORENSIC SUPPORT REQUEST – [Your Company Name] – [Date]
Legal Authority Requests & Saudi Law Compliance
WafaiCloud is obligated to comply with valid legal orders issued by competent Saudi authorities, including law enforcement agencies, the Public Prosecution, the National Cybersecurity Authority (NCA), and courts of competent jurisdiction. In such cases, WafaiCloud may be legally prohibited from notifying you of the existence of the order. Obligations imposed by Saudi law take precedence over any conflicting customer instructions.
Scope
Forensic support is limited to data and systems within your own tenancy on WafaiCloud infrastructure. WafaiCloud will not provide forensic access to data belonging to other tenants. Forensic support does not extend to data permanently deleted prior to the receipt of the request, unless recoverable from existing backups within our standard retention procedures.