Deployment Responsibility Matrix

Version: 6.0  ·  Effective Date: June 15, 2026  ·  Last Updated: June 15, 2026

EXECUTIVE SUMMARY

brainCloud supports multiple deployment models designed to meet the operational, security, compliance, sovereignty, performance, and infrastructure requirements of customers ranging from independent developers to global publishers and enterprise organizations.

brainCloud currently supports two primary deployment models: Public BaaS and Customer-Owned Deployment (Private License / BYOC).

A key differentiator of the brainCloud platform is that Customer-Owned Deployments are generally not customer-operated deployments. Under Customer-Owned Deployments, customers typically own the cloud account, own cloud resources, pay cloud service costs, and control infrastructure residency, while brainCloud typically deploys the platform, operates the platform, performs DevOps activities, applies updates, applies security patches, performs monitoring, provides support, and performs maintenance.

Enterprise customers frequently require clarity regarding ownership, operational responsibilities, security obligations, compliance responsibilities, and support boundaries associated with cloud-hosted services. This Deployment Responsibility Matrix is intended to provide transparency regarding those responsibilities and support procurement, architecture, security, compliance, and operational review activities.

This document is intended to support procurement reviews, security reviews, architecture reviews, compliance reviews, enterprise evaluations, contract negotiations, and operational planning.

This document should be read together with the brainCloud Trust Center, Security Overview, Privacy Policy, Data Processing Agreement, Service Level Agreement, Public BaaS Support Agreement, and Subprocessor List.

Purpose

The purpose of this document is to clearly define operational responsibilities associated with each deployment model and reduce ambiguity regarding infrastructure ownership, platform operations, security responsibilities, compliance obligations, and customer responsibilities.

This document is intended to answer common questions including who owns the cloud account, who performs operating system patching, who performs monitoring, who responds to incidents, who performs backups, who is responsible for compliance, who owns customer data, and what BYOC means in the context of brainCloud deployments.

Intended Audience

  • Customers
  • Prospective Customers
  • Procurement Teams
  • Security Reviewers
  • Compliance Reviewers
  • Legal Teams
  • Solution Architects
  • Technical Operations Teams.

Scope

This document applies to Public BaaS Deployments and Customer-Owned Deployments, including Private License and BYOC deployments, unless otherwise specified in applicable agreements.

This document provides general guidance and may be supplemented or modified by Statements of Work, Support Agreements, Professional Services Agreements, managed services arrangements, and other commercial agreements.

Deployment Models

Public BaaS

Under the Public BaaS model, brainCloud owns, hosts, operates, secures, and maintains the infrastructure used to provide Services. Customers consume the Services through the shared brainCloud platform.

  • Infrastructure owned by brainCloud
  • Cloud costs paid by brainCloud
  • Infrastructure operated by brainCloud
  • Platform operated by brainCloud
  • Monitoring performed by brainCloud
  • Updates managed by brainCloud
  • Security patching managed by brainCloud

Customer-Owned Deployment (Private License / BYOC)

Under the Customer-Owned Deployment model, customers own or control the cloud account and associated cloud infrastructure. brainCloud deploys and operates the platform within the customer-controlled cloud environment.

Customer-Owned Deployments should not be interpreted as customer-operated deployments. Unless otherwise agreed, brainCloud remains responsible for operational management of the brainCloud platform itself.

  • Infrastructure owned by Customer
  • Cloud costs paid by Customer
  • Cloud account controlled by Customer
  • Platform operated by brainCloud
  • Monitoring performed by brainCloud
  • Updates managed by brainCloud
  • Security patching managed by brainCloud

Operational Philosophy

brainCloud’s deployment model is designed to separate infrastructure ownership from platform operations. This allows customers to maintain infrastructure ownership and governance while benefiting from brainCloud’s operational expertise, platform knowledge, and managed service capabilities.

  • Technical Controls
  • Administrative Controls
  • Operational Controls
  • Monitoring Activities
  • Process Improvements

Responsibility Framework

Responsibilities generally fall into five categories:

CategoryDescription
InfrastructureCloud resources, networking, storage, compute
PlatformbrainCloud software and services
SecurityMonitoring, patching, governance, incident response
Privacy & ComplianceRegulatory and data protection obligations
ApplicationsCustomer-developed software and integrations

Ownership Principles

  • Infrastructure ownership does not automatically transfer platform operational responsibility.
  • Platform ownership remains with brainCloud.
  • Customer applications remain the responsibility of the Customer.
  • Security is a shared responsibility.
  • Compliance is a shared responsibility

Shared Responsibilities

Certain activities require cooperation between brainCloud and Customers, including incident response, compliance activities, privacy requests, security reviews, disaster recovery activities, and regulatory requests.

Support Plan Considerations

Specific responsibilities may vary based upon Support Plans, commercial agreements, Statements of Work, Professional Services Agreements, managed services agreements, or other custom enterprise arrangements.

Responsibility Matrix Legend:

TermMeaning
brainCloudbrainCloud is primarily responsible
CustomerCustomer is primarily responsible
SharedResponsibility is shared between both parties
N/ANot applicable

Infrastructure & Hosting Responsibilities

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
Cloud Provider SelectionbrainCloudCustomer
Cloud Account OwnershipbrainCloudCustomer
Cloud Service CostsbrainCloudCustomer
Compute ResourcesbrainCloudCustomer
Storage ResourcesbrainCloudCustomer
Network ResourcesbrainCloudCustomer
DNS OwnershipbrainCloudCustomer
TLS / Certificate ManagementbrainCloudShared
Infrastructure Capacity PlanningbrainCloudShared
Infrastructure OperationsbrainCloudbrainCloud
Infrastructure MonitoringbrainCloudbrainCloud

Guidance

Infrastructure ownership and platform operations are intentionally separated within Customer-Owned Deployments. While customers own cloud resources and cloud accounts, brainCloud generally performs infrastructure operations necessary to support the platform.

Customer Considerations

  • Cloud account governance
  • Cloud service costs
  • Cloud provider relationship management
  • Data residency decisions
  • Infrastructure procurement requirements

Operational Notes

brainCloud generally performs operational management activities necessary to support platform availability and reliability.

Operating Systems & Platform Infrastructure

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
Operating System InstallationbrainCloudbrainCloud
Operating System HardeningbrainCloudbrainCloud
Operating System PatchingbrainCloudbrainCloud
Container Platform OperationsbrainCloudbrainCloud
Infrastructure ConfigurationbrainCloudbrainCloud
Deployment AutomationbrainCloudbrainCloud
Platform MonitoringbrainCloudbrainCloud
Platform LoggingbrainCloudbrainCloud

Guidance

brainCloud generally maintains responsibility for the operational integrity of the platform stack regardless of deployment model.

Customer Considerations

  • Customer personnel generally do not perform day-to-day platform administration unless otherwise agreed.
  • Customers should coordinate requested infrastructure-level changes with brainCloud.

Operational Notes

Operating system and platform infrastructure responsibilities may vary if a custom enterprise arrangement expressly assigns responsibilities differently.

brainCloud Platform Responsibilities

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
brainCloud SoftwarebrainCloudbrainCloud
Platform ReleasesbrainCloudbrainCloud
Platform UpdatesbrainCloudbrainCloud
Security UpdatesbrainCloudbrainCloud
Bug FixesbrainCloudbrainCloud
Feature ReleasesbrainCloudbrainCloud
Operational SupportbrainCloudbrainCloud

Guidance

brainCloud retains responsibility for platform software across all deployment models. Platform updates, bug fixes, enhancements, security improvements, and maintenance activities are managed by brainCloud subject to applicable agreements.

Customer Considerations

  • Customers should review release notes and update communications where applicable.
  • Customers remain responsible for testing customer applications against applicable platform changes where appropriate.

Operational Notes

Platform software remains a brainCloud responsibility regardless of whether infrastructure is owned by brainCloud or the Customer.

Security Responsibilities

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
Security GovernancebrainCloudShared
Vulnerability ManagementbrainCloudbrainCloud
Security MonitoringbrainCloudbrainCloud
Security LoggingbrainCloudbrainCloud
Security PatchingbrainCloudbrainCloud
Incident DetectionbrainCloudbrainCloud
Incident ResponseSharedShared
Customer IAM PoliciesCustomerCustomer
User Authentication ConfigurationCustomerCustomer
End User SecurityCustomerCustomer
Customer Security ConfigurationCustomerCustomer

Guidance

Security is a shared responsibility. brainCloud secures the platform while customers remain responsible for their applications, users, credentials, integrations, and business processes.

Customer Considerations

  • Application-level access controls
  • Customer user management
  • Credential hygiene
  • End user security
  • Third-party integrations
  • Business processes and workflows

Operational Notes

Incident response activities generally require cooperation between brainCloud and Customers. Roles and responsibilities may vary depending upon the nature of the incident and deployment model.

Security Governance

brainCloud maintains platform security controls, governance processes, operational safeguards, and security policies intended to support secure operation of Services. Customers remain responsible for security obligations associated with their applications, users, credentials, business processes, and regulatory requirements.

Incident Response

Incident response activities generally require cooperation between brainCloud and Customers. brainCloud may lead platform-level investigation and remediation, while Customers may be required to assist with application-level investigation, end-user communications, regulatory analysis, or customer-controlled infrastructure activities.

Encryption & Key Management

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
Encryption StandardsbrainCloudbrainCloud
Encryption in TransitbrainCloudbrainCloud
Encryption at RestbrainCloudbrainCloud
TLS ConfigurationbrainCloudShared
Cryptographic ControlsbrainCloudbrainCloud
Certificate ManagementbrainCloudShared
Key StoragebrainCloudCustomer
Customer KMS AdministrationN/ACustomer

Guidance

brainCloud utilizes cryptographic technologies intended to protect information during storage and transmission. Responsibility for encryption technologies and key management varies depending upon deployment model and the specific cloud services utilized.

Customer Considerations

  • Customer-controlled key management systems
  • Key governance
  • Key rotation
  • Key retention
  • Key recovery
  • Certificate ownership and renewal where applicable

Operational Notes

brainCloud remains responsible for platform-level cryptographic implementations and operational integration of cryptographic services. Where customer-controlled key management systems are utilized, Customers remain responsible for administration, governance, and lifecycle management of those systems.

Backup, Recovery & Resilience

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
Backup OperationsbrainCloudbrainCloud
Backup SchedulingbrainCloudbrainCloud
Recovery ProceduresbrainCloudbrainCloud
Restoration ActivitiesbrainCloudbrainCloud
Backup Storage CostsbrainCloudCustomer
Disaster Recovery PlanningSharedShared
Business Continuity PlanningSharedShared
Recovery TestingSharedShared

Guidance

brainCloud maintains operational practices intended to support resilience, recovery, and service continuity. Backup methods, schedules, retention periods, and recovery capabilities may vary depending upon deployment model, support plan, and applicable commercial agreements.

Customer Considerations

  • Customer-owned infrastructure dependencies
  • Third-party integrations
  • Customer application continuity
  • Customer organizational continuity planning
  • Cloud-provider-specific recovery requirements

Operational Notes

brainCloud generally performs platform backup and recovery operations. Customers may be required to participate in recovery efforts involving customer-owned infrastructure, cloud-provider services, third-party integrations, or customer-controlled systems.

Privacy & Data Protection

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
DPA Compliance SupportbrainCloudbrainCloud
Data Processing ControlsSharedShared
Privacy NoticesCustomerCustomer
Legal Basis for ProcessingCustomerCustomer
End User ConsentsCustomerCustomer
Data Subject RequestsSharedShared
Data ClassificationCustomerCustomer
Customer ContentCustomerCustomer
Customer Data OwnershipCustomerCustomer

Guidance

brainCloud supports customer privacy obligations through technical, operational, and administrative safeguards. Privacy compliance remains a shared responsibility.

Customer Considerations

  • What information is collected
  • Why information is collected
  • How information is used
  • Legal bases for processing
  • End user disclosures
  • End user consent mechanisms
  • Regulatory obligations

Operational Notes

Customer Content and Customer Data remain under Customer ownership and control subject to applicable agreements. brainCloud provides platform capabilities intended to support customer privacy and compliance obligations.

Applications & Integrations

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
Customer Application CodeCustomerCustomer
Cloud Code LogicCustomerCustomer
SDK IntegrationCustomerCustomer
Authentication ConfigurationCustomerCustomer
Third-Party IntegrationsCustomerCustomer
AI Feature ConfigurationCustomerCustomer
Business LogicCustomerCustomer
Content Moderation DecisionsCustomerCustomer

Guidance

Customers remain responsible for applications, business logic, integrations, and platform configuration decisions. brainCloud provides backend services and platform capabilities.

Customer Considerations

  • Application functionality
  • User experience
  • Business processes
  • Monetization logic
  • Content moderation decisions
  • Operational product decisions
  • AI-enabled feature configuration

Operational Notes

Customers remain responsible for ensuring that their use of third-party integrations and AI-enabled functionality complies with applicable laws, contractual obligations, and internal policies.

Compliance Responsibilities

Responsibility Matrix

ResponsibilityPublic BaaSCustomer-Owned Deployment
Platform Security PoliciesbrainCloudbrainCloud
Customer Compliance ProgramsCustomerCustomer
Customer Regulatory ComplianceCustomerCustomer
Regulatory Compliance ActivitiesSharedShared
GDPR Compliance ActivitiesSharedShared
UK GDPR Compliance ActivitiesSharedShared
Quebec Law 25 Compliance ActivitiesSharedShared
COPPA / Children’s Privacy ActivitiesSharedShared
Audit ResponsesSharedShared

Guidance

Compliance activities require cooperation between brainCloud and Customers. brainCloud provides platform-level controls intended to support customer compliance obligations, but Customers remain responsible for determining their applicable legal, regulatory, industry-specific, and internal governance requirements.

Customer Considerations

  • Applicable laws and regulations
  • Industry-specific requirements
  • Customer governance obligations
  • Children’s privacy requirements
  • Data residency requirements
  • Internal policy requirements

Operational Notes

Enterprise customers may request information regarding platform controls, operational practices, and security measures. Responses may be governed by applicable agreements, confidentiality obligations, and operational considerations.

Certifications and Attestations

brainCloud may provide information regarding platform security controls, operational practices, and governance processes to support customer due diligence activities. Customers remain responsible for determining whether such information satisfies their regulatory, contractual, or organizational requirements.

Frequently Asked Questions

Who owns the cloud account in Customer-Owned Deployments?

The Customer owns and controls the cloud account.

Who pays cloud service costs?

For Public BaaS deployments, cloud costs are generally borne by brainCloud. For Customer-Owned Deployments, cloud costs are generally borne by the Customer.

Does BYOC mean the Customer operates the platform?

No. Customer-Owned Deployments generally remain operationally managed by brainCloud unless otherwise agreed.

Who performs platform updates?

brainCloud generally performs platform updates, upgrades, bug fixes, and security patching across all deployment models.

Who performs backups?

brainCloud generally performs platform backup and recovery operations. Specific recovery capabilities may vary based on deployment model and commercial arrangements.

Who owns customer data?

Customers retain ownership and control of customer content and customer data subject to applicable agreements.

Who owns encryption keys?

In Public BaaS, brainCloud generally manages platform key storage and cryptographic controls. In Customer-Owned Deployments, Customers may control cloud-native key management systems depending upon architecture and agreement.

Who performs vulnerability remediation?

brainCloud generally performs platform vulnerability remediation. Customers remain responsible for vulnerabilities in their own applications, integrations, and business processes.

Who performs security monitoring?

brainCloud generally performs platform security monitoring in both deployment models.

Who manages cloud-provider relationships?

brainCloud manages cloud-provider relationships for Public BaaS. Customers generally manage cloud-provider relationships for Customer-Owned Deployments.

Who manages certificates?

Certificate responsibilities may be shared depending upon deployment architecture, DNS ownership, and customer-controlled infrastructure arrangements.

What happens if support services terminate?

Applicable agreements govern termination, transition, access, and support obligations. Customer-Owned Deployments may require transition planning due to customer-owned infrastructure.

Can customers access infrastructure directly?

Direct infrastructure access depends upon the applicable agreement, support model, security requirements, and operational considerations.

Can customers select their cloud provider?

For Customer-Owned Deployments, customers may select supported cloud providers subject to brainCloud technical requirements and commercial agreement.

Can data remain within a specific jurisdiction?

Customer-Owned Deployments may support data residency requirements depending upon cloud provider, architecture, and applicable agreement.

Key Deployment Principles

Infrastructure Ownership Does Not Equal Platform Operations

Ownership of cloud resources does not automatically transfer operational responsibility for the platform.

Security Is Shared

brainCloud secures the platform. Customers secure their applications, users, business processes, and operational decisions.

Privacy Is Shared

brainCloud provides platform capabilities and safeguards. Customers remain responsible for determining the legality of their processing activities.

Compliance Is Shared

Both parties play important roles in supporting applicable compliance obligations.

Customer-Owned Deployments Are Not Customer-Operated Deployments

This principle represents one of the primary differentiators of the brainCloud deployment model. Customers receive infrastructure ownership and flexibility while brainCloud continues to provide operational expertise and managed platform services.

Operational Expertise

brainCloud’s deployment model is intended to allow customers to focus on application development while brainCloud performs platform operational activities.

Related Documents

Appendix A – Public BaaS Example

A customer deploys a game using the shared brainCloud platform. brainCloud owns the cloud account, pays the cloud service costs, operates the infrastructure, performs monitoring, applies platform updates, applies security patches, manages platform backups, and provides operational support according to applicable agreements.

The customer remains responsible for application code, cloud code logic, gameplay functionality, end-user relationships, customer content, privacy notices, legal bases for processing, compliance obligations, third-party integrations, and application-specific security decisions.

Appendix B – Customer-Owned Deployment Example

A customer owns an AWS, Azure, or Google Cloud account and pays the associated cloud service costs. brainCloud deploys the brainCloud platform into the customer-controlled cloud environment and generally performs platform operations, DevOps activities, monitoring, patching, upgrades, maintenance, backups, restoration activities, and support according to applicable agreements.

This model allows the customer to maintain infrastructure ownership, data residency control, cloud-provider governance, and cloud account visibility while allowing brainCloud to operate and maintain the platform.

Appendix C – Enterprise Review Questions

Customers seeking additional information should review the Security Overview, Trust Center, Data Processing Agreement, Service Level Agreement, Public BaaS Support Agreement, and Subprocessor List. These documents provide additional information regarding security governance, privacy obligations, operational controls, support commitments, service availability, and vendor management.

DISCLAIMER

This Deployment Responsibility Matrix is provided solely for informational purposes.

Nothing contained in this document creates contractual commitments, warranties, certifications, service level guarantees, operational commitments, or representations beyond those expressly set forth in applicable agreements.

Specific responsibilities may vary based upon deployment model, contractual commitments, Statements of Work, Support Agreements, Professional Services Agreements, or custom enterprise arrangements.

In the event of any conflict between this document and an applicable agreement, the applicable agreement shall govern.

brainCloud may update this document from time to time as technologies, operational practices, legal requirements, and deployment models evolve.

Legal & Governance

Thanks for Connecting!

We’ll get back to you as soon as we can.