Purpose

This matrix defines the allocation of responsibilities between Convesio and its Customers across infrastructure, platform services, applications, and business operations.

DESIGNED FOR:

This document does not modify contractual obligations defined in MSAs, BAAs, or payment agreements.

Section 1

Responsibility Model Overview

LayerDescriptionPrimary Responsibility
InfrastructureHosting, compute, networking, physical systemsConvesio
Platform ServicesPayments, scaling, orchestration, toolingShared
Application / WebsiteCMS, plugins, code, integrationsCustomer
Business & ComplianceData use, claims, workflows, legal complianceCustomer

Section 2

Control vs Influence vs Responsibility

To eliminate ambiguity:

Infrastructure, platform security

Convesio

Tools, APIs, integrations

Shared

Website logic, content, workflows

Customer

Enablement does not imply ownership or liability.

Section 3

Infrastructure & Platform Responsibilities

Section 4

Application & Website Responsibility Layer

Section 5

Product-Specific Responsibility Overlays

Section 6

HIPAA Responsibility Summary

Section 7

PCI DSS Responsibility Summary

Section 8

Payment Ecosystem Dependencies

ConvesioPay operates within a broader financial ecosystem.

Section 9

Compliance Is Use-Dependent

Platform capability does not equal compliance. A compliant infrastructure can be used in a non-compliant way.

Customer Responsibility Includes:

Section 10

Compliance Is Use-Dependent

Increase Customer responsibility

Certain use cases increase compliance and operational risk:

Section 11

Monitoring, Incident Response & Breach Notification

Section 12

Backups & Recovery Clarification

Section 13

Key Clarifications

Section 14

Intended Use

This matrix is for:

Responsibilities may vary based on:

Section 15

Strategic Takeaway

The majority of real-world risk does not originate in infrastructure.

Convesio provides a secure foundation. Customers are responsible for what they build on top of it.