Data Security and Service Continuity Criteria When Choosing SaaS

Picture the accounting manager of a mid-sized manufacturing company: every inventory movement, customer balance and purchase order now lives not on the company’s own server but on a data centre belonging to a software vendor somewhere across town. When the system goes down at month-end close, what does she do? That question sits at the heart of every SME manager’s hesitation about the software-as-a-service model. The number of companies choosing to subscribe to software over the internet rather than buying and installing it locally is growing, and so is the very real concern about what happens to their data when they hand it over to a third party.

In a SaaS arrangement the vendor hosts both the application and your data. This creates a fundamentally different risk profile compared with traditional on-premise software. When a program runs on your own server, you control the data; if the server fails you fall back on your local backup. With SaaS the data is physically out of your hands. What happens if the vendor goes out of business, if their servers go down, or if a billing dispute locks you out of your own records? Getting clear answers to these questions before signing a contract costs far less than dealing with the consequences afterwards.

The most solid starting point for any evaluation is the vendor’s data centre infrastructure. An ISO 27001 information security certification shows that an independent body has audited the vendor against defined standards — ask for the certificate and verify that it is current. Physical security matters too: ask about fire suppression systems, uninterruptible power supplies and access controls at the facility. If a vendor responds to these questions with discomfort or vague reassurances, that reaction itself is a warning sign worth taking seriously.

On the service continuity side, the most critical criterion is how redundancy is built into the architecture. Is your data stored in a single physical location, or does a geographically separate backup copy exist? How frequently are backups taken — daily, hourly? If a failure occurs, how long does recovery take? The answers need to be specific; phrases like ‘we have a secure infrastructure’ are not sufficient. The Service Level Agreement, or SLA, is where these commitments should appear in writing. Look at what percentage uptime the vendor guarantees and do the arithmetic: a figure that sounds reassuring can translate into dozens of hours of potential downtime per year when calculated carefully.

Data portability is the issue most SMEs overlook at the contract stage. If you decide to stop working with the vendor, in what format can you retrieve your data, and within how many days? Some vendors store data only in proprietary formats, making migration to another system genuinely difficult. Being able to export your records in a standard format — a spreadsheet or delimited text file, for instance — significantly reduces your dependence on any single vendor. Having this clause written explicitly into the contract prevents the kind of disputes that become very expensive to resolve later.

In practice, the most common difficulty is that SMEs often lack the technical background to negotiate these criteria confidently when sitting across from a sales-focused vendor representative. The local SaaS market is still maturing, and some vendors offer contracts with vague language that falls well short of internationally accepted SLA standards. There is also a connectivity dimension that sits entirely outside the vendor’s control: even if the vendor’s infrastructure is exemplary, your own internet connection is the link between you and the system, and in parts of Turkey that link is not yet uniformly reliable. Having a contingency plan for periods when you simply cannot reach the system is a practical necessity, not an edge case.

For an SME manager working through a SaaS evaluation, the practical decision criteria come down to four concrete checkpoints. First, request ISO 27001 certification or an equivalent independent audit document in writing. Second, look for an uptime commitment of 99.5 percent or higher in the SLA and clarify what compensation applies when that threshold is breached. Third, confirm that daily backups are taken and stored at a separate physical location. Fourth, have the contract specify that you can retrieve your data in a standard format within a defined number of days after termination. These four criteria address the most common risks in vendor selection. The SaaS model, with the right vendor and the right contractual protections in place, offers SMEs genuine cost and flexibility advantages — but securing those advantages depends entirely on asking the right questions before the contract is signed.

This article was originally written in Turkish by Gökhan MERCANOĞLU on March 16, 2009 and has been automatically translated into English and other languages using machine translation.


real-time production data creates lasting value only when user behavior, executive ownership, and data quality are handled together. Technology does not create transformation by itself; it only makes the need for transformation more visible. Success is less about the system working and more about the organization learning to work with it.


Gökhan Mercanoğlu
MRP, Üretim ve Tedarik Zinciri