SaaS Ranking

Blog

Where 8,324 SaaS vendors say their data sits, and which certifications 8,355 name

Hosting locations and certifications named on public pages at over 8,300 vendors: the most named values, who each sentence is about, and how often we are wrong.

Published · 2,194 words · by SaaS Ranking

The short answer

Roughly one vendor in four says where its data sits, and one in four names a certification. At 1,955 of the 8,324 companies we could measure (23%) we found a hosting location stated on a public page; at 1,953 of 8,355 (23%) a certification named for the vendor itself. The most named place is the United States, at 1,281 vendors; the most named certification is SOC 2 Type II, at 491. Both figures count sentences we read, not audits we ran; this piece is about that difference.

Every figure here comes from one snapshot, r126.107528: 107,528 source-backed results from run 126 and earlier, newest measurement 2026-09-21, read from the live pages on 2026-09-21. The commands at the end pull the current ones.

The snapshot behind this piece. 8,324 measured, location, 8,355 measured, certification, 22 location pages, 14 certification pages, 97.6% precision, location, 97.1% precision, certification. 8,324 measured, location 8,355 measured, certification 22 location pages 14 certification pages 97.6% precision, location 97.1% precision, certification
Figure 1. The two criteria behind this piece: how many companies we could measure for each, how many values have a page of their own, and how often a published finding was right when read by hand. Snapshot r126.107528.

A detail page opens once we find the same value at 8 or more vendors; on 2026-09-21 there were 643 such pages across 7 kinds of detail. A vendor can appear under more than one value, so the counts on a page belong to that value and do not add up to a number of vendors. The 22 location pages sum to 2,946 mentions at 1,955 companies, the 14 certification pages to 1,691 mentions at 1,953.

Where vendors say their data sits

The criterion Data location stated asks whether a public page names a place where customer data is held. The share is computed against the 8,324 companies at which we could read the relevant pages at all; a company that blocked our crawler is in neither the numerator nor the denominator. Of the 22 places with a page, the twelve most named are in Figure 2.

The twelve most named hosting locations, as a share of the vendors we could measure. United States: 1,281 of 8,324; European Union: 350 of 8,324; Germany: 189 of 8,324; Canada: 160 of 8,324; European Economic Area: 158 of 8,324; Ireland: 139 of 8,324; Australia: 133 of 8,324; United Kingdom: 84 of 8,324; Frankfurt: 79 of 8,324; India: 50 of 8,324; Netherlands: 45 of 8,324; Virginia: 43 of 8,324. United States 1,281 of 8,324 European Union 350 of 8,324 Germany 189 of 8,324 Canada 160 of 8,324 European Economic Area 158 of 8,324 Ireland 139 of 8,324 Australia 133 of 8,324 United Kingdom 84 of 8,324 Frankfurt 79 of 8,324 India 50 of 8,324 Netherlands 45 of 8,324 Virginia 43 of 8,324
Figure 2. Vendors that name each place as somewhere their data sits, the twelve most named of 22, against the 8,324 vendors measured. The grey track is 100%. Snapshot r126.107528.

The United States leads at 1,281 vendors (15%), more than the next four places together: the European Union at 350, Germany at 189, Canada at 160 and the European Economic Area at 158. The list mixes levels on purpose: the page keeps the word the vendor used rather than folding it into a region we chose. Eleven of the 22 values are European places or regions, and a buyer who needs data in the EEA reads them together, with the caveat that the same vendor may appear under several of them.

The remaining 10 places carry between 40 and 11 vendors each. Three of the 22 are not countries or cities but names a hosting provider uses for a region; they stand on the list because vendors wrote them that way.

Which certifications vendors name

The criterion Certifications named asks whether a public page names a security or privacy certification for the vendor itself. The bar is deliberately low: we look for the name, not the certificate, and the criterion carries the lowest weight in the transparency score. All 14 values with a page are in the table and in Figure 3.

All 14 certifications with a page, the vendors that name each for themselves, and the share of the 8,355 vendors measured.
Certification namedVendorsShare of measured
SOC 2 Type II 491 6%
ISO/IEC 27001 424 5%
SOC 2 285 3%
HIPAA 155 2%
PCI DSS 70 1%
Cyber Essentials 43 1%
ISO/IEC 27701 39 0%
ISO 9001 37 0%
ISO/IEC 27017 37 0%
CSA STAR 35 0%
FedRAMP 22 0%
ISO/IEC 27018 21 0%
HITRUST CSF 17 0%
ISO 22301 15 0%
Certifications named for the vendor itself, as a share of the vendors we could measure. SOC 2 Type II: 491 of 8,355; ISO/IEC 27001: 424 of 8,355; SOC 2: 285 of 8,355; HIPAA: 155 of 8,355; PCI DSS: 70 of 8,355; Cyber Essentials: 43 of 8,355; ISO/IEC 27701: 39 of 8,355; ISO 9001: 37 of 8,355; ISO/IEC 27017: 37 of 8,355; CSA STAR: 35 of 8,355; FedRAMP: 22 of 8,355; ISO/IEC 27018: 21 of 8,355; HITRUST CSF: 17 of 8,355; ISO 22301: 15 of 8,355. SOC 2 Type II 491 of 8,355 ISO/IEC 27001 424 of 8,355 SOC 2 285 of 8,355 HIPAA 155 of 8,355 PCI DSS 70 of 8,355 Cyber Essentials 43 of 8,355 ISO/IEC 27701 39 of 8,355 ISO 9001 37 of 8,355 ISO/IEC 27017 37 of 8,355 CSA STAR 35 of 8,355 FedRAMP 22 of 8,355 ISO/IEC 27018 21 of 8,355 HITRUST CSF 17 of 8,355 ISO 22301 15 of 8,355
Figure 3. Vendors that name each certification for themselves, all 14 values with a page, against the 8,355 vendors measured. The grey track is 100%. Snapshot r126.107528.

SOC 2 Type II at 491 vendors (6%) and ISO/IEC 27001 at 424 (5%) are the only two above one vendor in twenty. "SOC 2" without the type stands as its own value with 285, because that is what those vendors wrote, and a Type I report and a Type II report are not the same document. Below the top three, every value is named by fewer than one vendor in fifty. A vendor can hold a certificate and mention it only in a trust portal behind a request form, and then it is not on this list.

A name is not a certificate, and the sentence has a subject

Since 4 September 2026 every certification quote carries a subject: the vendor itself, their data centres or infrastructure, a named provider of theirs, a name without a certification claim, or unclear. Only the first is counted on a value page. The other four stay on the vendor's profile with their wording, and the value page says how many there are. For the two largest values the split looks like this.

Who the sentence is about, for every mention of SOC 2 Type II and ISO/IEC 27001 we found. SOC 2 Type II: the vendor itself: 491 of 732; SOC 2 Type II: unclear from the sentence: 211 of 732; SOC 2 Type II: a named provider: 14 of 732; SOC 2 Type II: no certification claim: 11 of 732; SOC 2 Type II: their data centres: 5 of 732; ISO/IEC 27001: the vendor itself: 424 of 675; ISO/IEC 27001: unclear from the sentence: 223 of 675; ISO/IEC 27001: no certification claim: 14 of 675; ISO/IEC 27001: a named provider: 11 of 675; ISO/IEC 27001: their data centres: 3 of 675. SOC 2 Type II: the vendor itself 491 of 732 SOC 2 Type II: unclear from the sentence 211 of 732 SOC 2 Type II: a named provider 14 of 732 SOC 2 Type II: no certification claim 11 of 732 SOC 2 Type II: their data centres 5 of 732 ISO/IEC 27001: the vendor itself 424 of 675 ISO/IEC 27001: unclear from the sentence 223 of 675 ISO/IEC 27001: no certification claim 14 of 675 ISO/IEC 27001: a named provider 11 of 675 ISO/IEC 27001: their data centres 3 of 675
Figure 4. Every mention we found of the two most named certifications, by who the sentence is about. Only the first bar of each group is counted on the value page; the others are shown on the profiles with their wording. 732 mentions of SOC 2 Type II, 675 of ISO/IEC 27001. Snapshot r126.107528.

For SOC 2 Type II, 491 of 732 mentions (67%) are about the vendor itself; 211 are unclear from the sentence, 14 are about a named provider, 11 name the standard without claiming it, and 5 are about the vendor's data centres. For ISO/IEC 27001 the counted share is 63%. "Our data centres are ISO 27001 certified" says nothing about the vendor's own management system; before the subject existed, it was counted as if it did. Where the sentence leaves the subject open, we count nothing.

How a sentence becomes a finding, and when it stops counting

A finding on a value page is a sentence, its address and its date. Four questions decide whether it counts, in the order below. A row that fails one of them is not deleted: it stays on the vendor's profile with its wording and counts in no list, no figure and no requirement page.

How a sentence read on a vendor page reaches a value page. A sentence read at a fixed address. Does the sentence make the claim? If no: on the profile, not counted. Is it about the vendor itself? If no: shown with its subject. Same value at 8 or more vendors? If no: on the profile, no page yet. Read again in the current snapshot? If no: stands until read again; if yes: on the value page, with sentence and date. A sentence read ata fixed address Does the sentencemake the claim? no on the profile,not counted yes Is it about thevendor itself? no shown withits subject yes Same value at 8 ormore vendors? no on the profile,no page yet yes Read again in thecurrent snapshot? no stands untilread again yes on the value page,with sentence and date
Figure 5. The order in which a finding is admitted to a value page. A question, a negation, a definition, an announcement, a postal address, a company seat, a law or a transfer framework fails the first question; a sentence about a data centre, a provider or a reader fails the second. Nothing on this path changes the transparency score.

The first question is the one that changed on 11 September 2026. Until then a sentence that named a standard was a finding; since then the sentence has to carry the claim itself. "We are not SOC 2 audited" names the standard and denies the claim; "stored outside the European Economic Area" names the region and excludes it. Both had been counted. The data quality page lists the kinds of sentence the classifier now rejects and the ones it still lets through.

How often we are wrong

461 findings that stood on value pages on 11 September 2026 were read by hand, one by one, and judged. Against that set, the classifier v2-2026-09-11 is right 97.6% of the time for hosting locations and 97.1% for certifications; it finds 86.0% and 90.5% of what a person found. The same set run against the classifier as it stood before that day gave 73.1% and 74.6%: every fourth published finding was wrong, in both directions.

What that costs in the live data is counted, not estimated: every stored finding is re-read against its own quote.

Findings held in the snapshot that do not count, for the two kinds of detail with a hand-read set. Certification named: 2,836 of 5,654; Hosting location named: 120 of 3,084; All ten kinds of detail: 2,956 of 127,045. Certification named 2,836 of 5,654 Hosting location named 120 of 3,084 All ten kinds of detail 2,956 of 127,045
Figure 6. Findings held in snapshot r126.107528 whose own quote does not carry the finding, as a share of all findings of that kind. Grey, because it describes our reading and not a vendor. The track is 100%.

For certifications, 2,836 of 5,654 findings (50%) do not count; for hosting locations 120 of 3,084 (4%). Across all ten kinds of detail it is 2,956 of 127,045. The first estimate for certifications, made from the quotes shown on the value pages, was about a quarter; those quotes are the first hundred per page, sorted by score, the best-written part of the stock. The tail is worse than its head.

The six largest classes of mistake the classifier now catches in the hand-read set are outside the region (17), no claim (13), postal address (11), company seat (9), reader or staff (9), navigation (8). Eight findings in the set are judged wrong and still get through; they are listed on the quality page with their sentence. For the eight kinds of detail without a hand-read set there is no accuracy figure, and we do not print an estimate.

One more number belongs next to every share above: the oldest measurement behind the two criteria is 20 days old, because a nightly run covers part of the catalogue. A fresh figure and an old one look the same on a value page, and the date on each row is the only thing that tells them apart.

Using this for a shortlist

The value pages answer one question each: who has said this, in which sentence, and where.

  1. Start from the requirement, not the vendor. If your policy needs data in the EEA, open the pages for the European Economic Area, the European Union and the member states you accept, and read the sentences.
  2. Treat a certification name as a question to ask. A vendor on the SOC 2 Type II page has written that it holds a report; the next step is to ask for the report and the period it covers.
  3. Read the subject before the value. If the sentence is about a data centre or a provider, it is on the profile and not on the list. It is a different claim, and the page says which.
  4. Combine in the explorer. The explorer takes a category, criteria and detail values together and returns the vendors at which we found all of them. There is no "without" filter, because not finding a sentence is not the same as its absence.
  5. File the sentence with its date. Every row carries the address and the date it was read, and the API and the bulk download deliver the same rows with the snapshot identifier.

Questions buyers ask

Does "names ISO/IEC 27001" mean the vendor is certified?

No. It means a public page of the vendor names the standard in a sentence about the vendor itself, read at the address and on the date shown. Whether a certificate exists, who issued it and what it covers is a question for the vendor and the certificate itself.

Why does the same vendor appear under several locations?

Because the page keeps the words the vendor used. A vendor that writes "hosted in Frankfurt, in the European Union" appears under both; open the sentence rather than trust the label.

Why is the share for certifications lower than I would expect?

Two reasons, both on our side. We read fixed public addresses and never a trust portal behind a form, and since 11 September 2026 a sentence counts only if it makes the claim about the vendor itself. 2,836 of 5,654 certification findings in this snapshot fail that reading and are shown on the profiles instead.

Can a vendor correct a finding?

Yes. Every row on a value page and on a profile links to a correction form; a person reads it, and the vendor moves into the next nightly run. That run reads the same fixed addresses we check for every vendor, not the address that was sent.

Do these details change the score?

No. The transparency score is frozen as version v1 and counts twelve criteria with published weights. A location or a certification name is a detail behind a criterion, shown with its source, and a detail has never entered the score.

Method, snapshot and sources

Every figure above was read on 2026-09-21 from pages that render the live database, and each carried the snapshot r126.107528 in its footer. The criteria overview shows the two criteria for the snapshot the site serves today. These commands pull the same figures for that snapshot:

# the snapshot identifier
curl -s https://saas-ranking.com/api/v1/criteria | grep -o '"snapshot":"[^"]*"'

# both criteria: found of measured (the short answer)
curl -s https://saas-ranking.com/criteria/ | grep -oE '[0-9]+ of [0-9]+ publish it'

# every location and every certification with a page, with vendors and share (Figures 2 and 3)
for t in hosting certifications; do curl -s "https://saas-ranking.com/data/$t" | grep -oE '/data/'$t'/[a-z0-9-]+">[^<]+|<td class="mitte">[0-9]+( %)?' | paste - - -; done

# who the sentence is about, for the two largest certification values (Figure 4)
for v in soc-2-type-2 iso-27001; do curl -s "https://saas-ranking.com/data/certifications/$v" | grep -oE 'about something else: [^.]+' | sed 's/<[^>]*>//g'; done

# precision, recall and the findings that do not count (Figures 1 and 6)
curl -s https://saas-ranking.com/data/quality | grep -A4 -E '<th scope="row">(Hosting location named|Certification named)</th>'