> For the complete documentation index, see [llms.txt](https://legal.dispel.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://legal.dispel.com/security-and-data-protection/shared-security-model/shared-responsibilities.md).

# Shared Responsibilities

The differences in shared responsibilities in the Dispel Zero Trust Engine

{% hint style="info" %}
This page describes the standard Dispel and Customer shared responsibility model. Please refer to your applicable Purchase Orders for customizations.
{% endhint %}

This document describes the obligations and differences of the shared responsibility model for deploying and maintaining the Dispel Zero Trust Engine. It discusses the challenges and nuances of the shared responsibility model. This document also describes how we partner with our customers to address security challenges.

Understanding the shared responsibility model is important when determining how to best protect your data and environments behind Dispel. The shared responsibility model describes the tasks that you have when it comes to security in remote access and how these tasks are different between on-premises, customer cloud, and SaaS deployments.

## Shared responsibility <a href="#h_1c3e78a61b" id="h_1c3e78a61b"></a>

You're the expert in knowing the security and regulatory requirements for your business, and knowing the requirements for protecting your confidential data and resources. When you use Dispel, you must identify the security controls that you need to employ around Dispel and during sessions to help protect your confidential data and environments. To decide which security controls to implement, you must consider the following factors:

* Your regulatory compliance obligations
* Your organization's security standards and risk management plan
* Security requirements of your customers and your vendors

***

### Defined by deployment method <a href="#h_9a295af0aa" id="h_9a295af0aa"></a>

Traditionally, responsibilities are defined by the type of deployment method you elect to use, and the Dispel services you require.

| Deployment Method | Text                                                                                                                                                                                                                                                                                                                                                           |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SaaS              | <p>Fully managed, cloud-hosted deployment where Dispel handles infrastructure, security, and maintenance.<br></p><p>Runs in Dispel’s secure cloud environments.<br></p><p>Best for organizations seeking a hands-off, scalable, and fast-to-deploy solution.</p>                                                                                               |
| Customer Cloud    | <p>Deployed within a customer’s own cloud environment.<br></p><p>Customers maintain direct control over cloud security settings, with Dispel providing platform support.<br></p><p>Best for organizations with strict data sovereignty, compliance, or integration needs.</p>                                                                                  |
| On-Premises       | <p>Fully contained, on-premise deployment within a customer’s industrial or enterprise network.</p><p></p><p>Runs on dedicated hardware or virtualized environments within the customer’s facility.</p><p></p><p>Best for highly regulated industries (e.g., defense, utilities, critical infrastructure) that require air-gapped or offline environments.</p> |

The following diagram shows the cloud services and defines how responsibilities are shared between Dispel and customer.

***

### Defined by component

#### Central Management Dashboard, Region, & Virtual Desktops

Dispel is responsible for the security of our software components. Responsibility for the underlying infrastructure on which these components are deployed varies by deployment method.

<figure><img src="https://296964698-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeaTtZGqF91dQEZ2NDaYg%2Fuploads%2FwFfZl31jBr70xMiVYREY%2Fimage.png?alt=media&amp;token=a51c2fff-0241-494e-8b6e-1a617749cfaf" alt=""><figcaption></figcaption></figure>

#### Wicket ESI

Dispel is responsible for the security of the Wicket ESI software, including development, security updates, and application security.

The Customer is responsible for maintaining the environment where Wicket ESI is deployed, including hardware, OS updates, network security, and compliance.

<figure><img src="https://296964698-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeaTtZGqF91dQEZ2NDaYg%2Fuploads%2FrwpN3VqdbJeZLF7PL6DD%2Fimage.png?alt=media&amp;token=f24cc36e-fbeb-40b0-8df2-93d80cebc7c7" alt=""><figcaption></figcaption></figure>

| Hardware                   | Provisioning & Maintenance             | N/A                                          | Deploying Wicket ESI on physical/virtual hardware         |
| -------------------------- | -------------------------------------- | -------------------------------------------- | --------------------------------------------------------- |
|                            | Physical Security                      | N/A                                          | Securing physical access to the device                    |
|                            | Performance & Resource Allocation      | N/A                                          | Ensuring sufficient CPU, RAM, and storage                 |
| Operating System           | OS Patching & Updates                  | N/A                                          | Keeping OS up to date with security patches               |
|                            | OS Hardening                           | N/A                                          | Applying security baselines and CIS benchmarks            |
|                            | User Access Management                 | N/A                                          | Managing OS admin/user accounts and access policies       |
| Network                    | Firewalls                              | N/A                                          | Managing network firewalls, VLANs, and routing            |
|                            | Uptime & Availability                  | N/A                                          | Maintaining Internet connectivity and reliability         |
|                            | Monitoring & Logging                   | Generates network activity logs              | Monitoring and responding to events and incidents         |
| Tunnel Security            | Encryption                             | Cipher implementation                        | N/A                                                       |
|                            | Routing & SD-WAN                       | Provisioning and connectivity                | N/A                                                       |
| Software Security          | Application-Level Security             | Secure coding, security testing, and reviews | N/A                                                       |
|                            | Software Updates & Vulnerability Fixes | Providing Wicket ESI patches and updates     | N/A                                                       |
|                            | Software Patching                      | Available with Support                       | Applying Wicket ESI patches and updates                   |
|                            | Configuration Security Guidance        | Offering security best practices for setup   | Applying recommended security configurations              |
| Backup & Disaster Recovery | Data Protection & Recovery             | N/A                                          | Implementing backup and restore procedures for Wicket ESI |

***

### Defined by industry and regulatory framework

Various industries have regulatory frameworks that define the security controls that must be in place for operational technology (OT) and industrial control systems (ICS). When deploying your secure remote access and data streaming within Dispel’s Zero Trust Engine, it is essential to understand:

* Which security controls are your responsibility
* Which security controls are provided as part of the Dispel platform
* Which security controls are inherited from Dispel’s infrastructure

Inherited security controls—such as Dispel’s default encryption, secure development lifecycle, and disaster recovery/business continuity—can be used as evidence of compliance when engaging with auditors and regulators.

When deploying within Dispel, compliance responsibilities are shared between your organization and Dispel. Please see [Complementary User Entity Controls](/security-and-data-protection/shared-security-model/complementary-user-entity-controls.md) for more details.

Other industries—such as utilities, maritime, and healthcare—have regulations that define how data must be secured, processed, and stored. For more details on how Dispel supports compliance in these sectors, refer to our [Compliance Resource Center](https://dispel.com/security).

***

#### Defined by location

Depending on your industry and operational needs, you may need to evaluate your security responsibilities based on the location of your business, your customers, and your data. Various countries and regions enforce regulatory requirements that dictate how data must be processed, stored, and accessed.

For example, if your organization serves customers in the European Union (EU), you may be required to comply with the General Data Protection Regulation (GDPR) and ensure that customer data remains within EU-based infrastructure. In this case, you are responsible for enforcing data residency policies, ensuring that collected data remains in Dispel's EU cloud regions or within your own EU-based infrastructure if deployed in a private cloud or on-premises environment.

To better understand regional compliance requirements, refer to Dispel’s Compliance Offerings. If your compliance needs are complex—such as cross-border data transfer restrictions, industry-specific mandates, or hybrid deployments—we recommend speaking with Dispel’s [security and compliance team](https://dispel.com/book) or one of our [partners](https://dispel.com/partners/directory) to help you evaluate your responsibilities.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://legal.dispel.com/security-and-data-protection/shared-security-model/shared-responsibilities.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
