Reference

Rencore’s shared responsibility model

This is an explanation of Rencore’s shared responsibility model, in line with requirements for ISO 27017. This is an abridged version of Rencore’s Shared Responsibility Policy, which will be made available on Rencore’s Trust Center.

Roles & Responsibilities

Responsibilities of Rencore’s IaaS/PaaS provider, Microsoft Azure

Microsoft is responsible for certain security aspects pertaining to Microsoft Azure, as the infrastructure-as-a service/ platform-as-a-service provider for Rencore Governance. Microsoft Azure hosts Rencore Governance, as a Microsoft Azure web application, and stores data generated through the use of Rencore Governance, as well as providing logging services via Application Insights.

Microsoft details its own shared responsibility model here. The following list is in line with Microsoft’s concept of the shared responsibility model.

  • Implementing controls for the transmission, movement and removal of the underlying storage devices for its cloud hosting services where Rencore Governance resides
  • Restricting physical access to data center facilities, backup media, and other system components including firewalls, routers, and servers where Rencore Governance resides
  • Managing environmental protections within the data centers that house network, virtualization management, and storage devices for its cloud hosting services where Rencore Governance resides.
  • Patching the web application environment.
  • Responding in a timely manner to security issues that Rencore reports regarding the web application and storage environment.
  • Applying adequate security settings to Azure as a web application and storage environment, with regard to defaults or settings that Rencore cannot adjust
  • Taking measures to make sure its storage remains adequately locally redundant
  • Informing Rencore in the event of security incidents that third-parties have reported
  • Documenting all data transfers and informing Rencore of these data transfers
  • Maintaining all security certifications and accreditations featured in Microsoft’s Service Trust Portal, which involves taking adequate steps regarding incident response, disaster recovery, business continuity management, risk management, and access management. At the bare minimum, Rencore expects Azure to maintain ISO 27001 and ISO 27017 certifications and to achieve unqualified SOC 2 reports on an annual basis, or to obtain a bridging letter when timely renewal is not possible.

Responsibilities of Rencore as a SaaS provider

Rencore is responsible for the following security aspects under this shared responsibility model:

  • Deploying suitable configurations of Azure as a web application and storage environment, to ensure that this remains secure
  • Holding Microsoft to account with regard to the security controls it pledges to use, including but not limited to verifying that certifications and accreditations have been renewed on an annual basis, monitoring customer complaints posted by third parties online, and holding Microsoft to account regarding its SLAs. As stated above, Rencore expects Azure to maintain ISO 27001 and ISO 27017 certifications and to achieve unqualified SOC 2 reports on an annual basis, or to obtain a bridging letter when timely renewal is not possible.
  • Using an adequate SIEM on Rencore’s product infrastructure, to identify irregularities from multiple sources (logs, alerts, backup failures)
  • Monitoring availability of the product and having systems in place to alert to dips in availability. Availability should remain above 99.5%, calculated on a quarterly basis. Rencore enables customers to hold it to account regarding this availability rate through making a status portal available.
  • Ensuring appropriate data centres are selected from Azure’s choice of data centres, to maximise stability of the product and reduce compliance concerns.
  • Deploying secure development practices, to ensure that the code for the web application in Azure is secure
  • Reacting with appropriate urgency to security concerns reported by Microsoft or by third-parties, e.g. through adequate vulnerability and incident response management steps
  • Acquiring certifications and accreditations for Rencore Governance and for Rencore’s general business practices, at present SOC 2, ISO 27001 and ISO 27017
  • Creating contingency plans that allow Rencore to accommodate partial outages of Microsoft services, and that may allow Rencore some independence from Microsoft infrastructure in the future
  • Maintaining the technical and organisational measures listed in Rencore’s SaaS Agreement - individual measures may be changed, but the overall security standard of Rencore and Rencore Governance should remain on the same level or be enhanced over time.
  • Rencore must comply with any requirements of the EU Data Act with regard to returning data at the end of contracts and transferring data in a machine-readable format, particularly for new contracts after 12 September 2025.
  • Rencore must limit who has access to the admin portal (which can see limited categories of customer data) to those who have an overriding interest in timely access to the information, i.e., individuals involved in bug fixing. Levels of access should be differentiated based on duties performed, so that access is limited to that which is required to carry out specific tasks.
  • Rencore must provide adequate support services that respond to concerns and requests in a timely manner. Rencore currently has two ways for customers to contact support: [email protected] or via a chat icon embedded in Rencore Governance. Security issues should be sent to [email protected]. Response times and resolution goals are subject to sensible prioritization in accordance with the resources available to Rencore - security matters are treated with the utmost urgency and will result in out-of-hours alerts where appropriate.

Responsibilities of Rencore’s customer

As is also explained in the common user entity controls in Rencore Governance’s annual SOC 2 report, customers are also required to put some measures into place to ensure security, while also bearing in mind that the start-up requirements for using Rencore Governance are meant to be minimal. These are as follows:

  • Customers are responsible for understanding and complying with their contractual obligations to Rencore, including with regard to the use of Rencore Governance (e.g. committing not to reverse-engineer the product)
  • Customers are responsible for notifying Rencore of changes made to technical or administrative contact information, including channels for reporting issues
  • Customers are responsible for maintaining any record(s) regarding Rencore Governance that they are required to keep and which are supplementary to logs produced by Rencore Governance. Where the product logs are not adequate for these requirements, they must request these additional logs from Rencore.
  • Customers are responsible for ensuring the supervision, management, and control of the use of Rencore services by their personnel. This includes having appropriate security settings for Entra ID accounts that log into Rencore Governance, and properly managing these accounts, including implementing best practices for storing security credentials. Rencore Governance offers four different role types for Rencore Governance user accounts and the ability to create custom roles with custom access rights; these roles must be adequately assigned to internal users by the customer.
  • Customers are responsible for their decision to grant permissions to Rencore Governance to connect to individual components of Microsoft 365. Customers are also responsible for withdrawing these permissions if they no longer wish to grant access to a specific component of Microsoft 365 to Rencore Governance during the subscription period.
  • Customers are responsible for developing their own disaster recovery, incident response and/or business continuity plans that address the inability to access or utilize Rencore services.
  • Customers are responsible for keeping their list of approvers for security and system configuration changes for data transmission up to date, i.e. carrying out appropriate access management steps regarding roles within Rencore Governance
  • Customers are responsible for immediately notifying Rencore of any actual or suspected information security breaches, including compromised user accounts and including those used for integrations. These issues must be reported to [email protected]. They must cooperate in the event that Rencore asks for further information to resolve open issues.
  • The customer is responsible for vendor management processes pertaining to Rencore, e.g. asking Rencore to fill in security questionnaires when it deems appropriate, and asking Rencore to show evidence of certifications/accreditations on an annual basis
  • The customer is responsible for assessing risks associated with using Rencore Governance, and making the final decision as to whether use of Rencore Governance fits into their risk tolerance/appetite (although Rencore considers general use of Rencore Governance as low-risk)
  • The customer keeps ownership of their data at all times during the use of Rencore Governance. Rencore Governance can only process data present in the structural data of the connected Microsoft 365 tenant, so user data, and files and folder names (not their content). The customer must have a robust data classification policy that discourages users from putting confidential or otherwise sensitive data in file names or folder names, and otherwise minimizes the processing of sensitive data, to limit the likelihood that it will be processed by Rencore Governance. In general, the customer is responsible for assessing whether the individual features of Rencore Governance (e.g. access rights, provisioning) are consistent with internal security and data protection-related policies, including carrying out impact assessments, though Rencore will provide any required information for completing such assessments.
  • Customers must select the most compliant data center for their needs when connecting their workspace to their M365 tenant, e.g. the Germany West Central data center if they are based in Germany. The customer selects the data center on set-up, so this is entirely in the customer’s control and does not require intervention of Rencore or support staff.
  • Some support services in Rencore Governance can be deactivated or customised, i.e. internal messaging and connections to HubSpot/Userback/Pendo. Rencore provides step-by-step guides on deactivation/customisation steps, but it is the responsibility of the customer to follow these steps, if necessary on initial setup.

Rencore notes that since Rencore Governance is dependent on the use of Microsoft 365, most customers will have a certain level of tolerance for using cloud-based services. However, this does not lessen the requirements of this policy, and customers should still take a risk-based approach to using Rencore Governance, even though Rencore classes such risks as low.

Last updated: 11/10/2025