Where Does Your Data Actually Sit: A Manager’s Guide to Security in Hosted Software

Picture the accounting manager of a mid-sized manufacturing company: the firm’s revenue figures, customer receivables and inventory values no longer live on a server in the back office. They sit on a machine operated by a software vendor somewhere else entirely. As broadband connections spread and software companies start offering ‘internet-based access’ options, this arrangement is becoming more common. But where exactly is that data stored, who can reach it, and what happens in a dispute? Signing a service contract without knowing the answers to these questions creates real legal and operational exposure.

The internet-based delivery model that Turkish software vendors are now offering draws on what international practitioners call the ASP (Application Service Provider) approach. Instead of installing software on the company’s own server, users connect to a remote machine through a browser or a dedicated client application. That remote machine is either housed in the software vendor’s own premises or in a third-party data center the vendor rents. The distinction matters enormously: self-hosted infrastructure and co-located infrastructure carry different security standards and different chains of accountability, and a manager who does not know which one applies to their contract is flying blind.

The physical location of the data center is not merely a technical footnote; it is a legal question. Turkish commercial and tax law imposes specific record-keeping obligations, and storing data on servers abroad raises immediate issues: which country’s law governs the data, how Turkish courts exercise jurisdiction in a dispute, and how tax auditors access records when they need them. Before signing, ask the vendor to confirm in writing exactly which country and city the servers are located in. That single step eliminates a large category of ambiguity that many companies only discover when it is too late.

Physical security at the data center also deserves a place on the evaluation checklist. A professionally operated facility should have uninterruptible power supply (UPS) systems, redundant cooling, fire suppression and controlled physical access. Equally important are access logs: records of who entered the server room, who connected to which machine and when. These logs should be retained for a defined period, and the vendor should be willing to share them on request. Asking a vendor for documentation of their data center’s physical security standards is not an unreasonable demand; a manager who does not ask is the one failing in their duty. There is no mandatory certification framework for data centers in Turkey yet, but some vendors reference international standards in their marketing materials, and those references are worth verifying.

Access logs at the application level deserve separate attention. Who among the vendor’s technical staff can read your data, are those access events recorded, and will the vendor share those records if you ask? These questions should be answered explicitly in the contract, not left to goodwill. For accounting and financial data in particular, unauthorized access can constitute both a breach of commercial confidentiality and a problem under tax regulations. A vendor with mature internal procedures will be able to show that its own engineers operate under access restrictions when handling customer data.

The practical difficulty is that most Turkish SMEs sign contracts without asking any of these questions. Features and price dominate the conversation; data hosting conditions end up buried in the back pages of the agreement in small print. The situation is further complicated when a vendor subcontracts the data center function to a third party, creating a gap between what the main contract says and what actually happens in practice. If the service is interrupted or the vendor closes down, a company that has not established in advance how it will retrieve its data — and in what format — faces a genuinely serious operational problem with no clean remedy.

For a small or medium business evaluating an internet-based software service, the practical decision criteria come down to four things: get written confirmation of the physical location of the servers; make sure the contract specifies that access logs are kept and available on request; establish how often data is backed up and where those backups are stored; and nail down the format and timeline for data return when the service ends. A vendor who cannot satisfy these four requirements is asking the customer to absorb risks that no attractive feature list can offset. However compelling the price and the functionality, signing a contract without knowing where the data sits means the manager has left the most basic part of their job undone.

This article was originally written in Turkish by Gökhan MERCANOĞLU on July 3, 2006 and has been automatically translated into English and other languages using machine translation.


For platform economy, the critical question is not which system to use. The real question is which problem will be solved, which data can be trusted, and which action will be accelerated. Without these answers, solutions look modern but only digitize old habits.


Gökhan Mercanoğlu
Bulut, SaaS ve Platform Ekonomisi