Blog
Where 8,324 SaaS vendors say their data sits, and which certifications 8,355 name
Hosting locations and certifications named on public pages at over 8,300 vendors: the most named values, who each sentence is about, and how often we are wrong.
Published · 2,194 words · by SaaS Ranking
The short answer
Roughly one vendor in four says where its data sits, and one in four names a certification. At 1,955 of the 8,324 companies we could measure (23%) we found a hosting location stated on a public page; at 1,953 of 8,355 (23%) a certification named for the vendor itself. The most named place is the United States, at 1,281 vendors; the most named certification is SOC 2 Type II, at 491. Both figures count sentences we read, not audits we ran; this piece is about that difference.
Every figure here comes from one snapshot, r126.107528: 107,528 source-backed results from run 126 and earlier, newest measurement 2026-09-21, read from the live pages on 2026-09-21. The commands at the end pull the current ones.
A detail page opens once we find the same value at 8 or more vendors; on 2026-09-21 there were 643 such pages across 7 kinds of detail. A vendor can appear under more than one value, so the counts on a page belong to that value and do not add up to a number of vendors. The 22 location pages sum to 2,946 mentions at 1,955 companies, the 14 certification pages to 1,691 mentions at 1,953.
Where vendors say their data sits
The criterion Data location stated asks whether a public page names a place where customer data is held. The share is computed against the 8,324 companies at which we could read the relevant pages at all; a company that blocked our crawler is in neither the numerator nor the denominator. Of the 22 places with a page, the twelve most named are in Figure 2.
The United States leads at 1,281 vendors (15%), more than the next four places together: the European Union at 350, Germany at 189, Canada at 160 and the European Economic Area at 158. The list mixes levels on purpose: the page keeps the word the vendor used rather than folding it into a region we chose. Eleven of the 22 values are European places or regions, and a buyer who needs data in the EEA reads them together, with the caveat that the same vendor may appear under several of them.
The remaining 10 places carry between 40 and 11 vendors each. Three of the 22 are not countries or cities but names a hosting provider uses for a region; they stand on the list because vendors wrote them that way.
Which certifications vendors name
The criterion Certifications named asks whether a public page names a security or privacy certification for the vendor itself. The bar is deliberately low: we look for the name, not the certificate, and the criterion carries the lowest weight in the transparency score. All 14 values with a page are in the table and in Figure 3.
| Certification named | Vendors | Share of measured |
|---|---|---|
| SOC 2 Type II | 491 | 6% |
| ISO/IEC 27001 | 424 | 5% |
| SOC 2 | 285 | 3% |
| HIPAA | 155 | 2% |
| PCI DSS | 70 | 1% |
| Cyber Essentials | 43 | 1% |
| ISO/IEC 27701 | 39 | 0% |
| ISO 9001 | 37 | 0% |
| ISO/IEC 27017 | 37 | 0% |
| CSA STAR | 35 | 0% |
| FedRAMP | 22 | 0% |
| ISO/IEC 27018 | 21 | 0% |
| HITRUST CSF | 17 | 0% |
| ISO 22301 | 15 | 0% |
SOC 2 Type II at 491 vendors (6%) and ISO/IEC 27001 at 424 (5%) are the only two above one vendor in twenty. "SOC 2" without the type stands as its own value with 285, because that is what those vendors wrote, and a Type I report and a Type II report are not the same document. Below the top three, every value is named by fewer than one vendor in fifty. A vendor can hold a certificate and mention it only in a trust portal behind a request form, and then it is not on this list.
A name is not a certificate, and the sentence has a subject
Since 4 September 2026 every certification quote carries a subject: the vendor itself, their data centres or infrastructure, a named provider of theirs, a name without a certification claim, or unclear. Only the first is counted on a value page. The other four stay on the vendor's profile with their wording, and the value page says how many there are. For the two largest values the split looks like this.
For SOC 2 Type II, 491 of 732 mentions (67%) are about the vendor itself; 211 are unclear from the sentence, 14 are about a named provider, 11 name the standard without claiming it, and 5 are about the vendor's data centres. For ISO/IEC 27001 the counted share is 63%. "Our data centres are ISO 27001 certified" says nothing about the vendor's own management system; before the subject existed, it was counted as if it did. Where the sentence leaves the subject open, we count nothing.
How a sentence becomes a finding, and when it stops counting
A finding on a value page is a sentence, its address and its date. Four questions decide whether it counts, in the order below. A row that fails one of them is not deleted: it stays on the vendor's profile with its wording and counts in no list, no figure and no requirement page.
The first question is the one that changed on 11 September 2026. Until then a sentence that named a standard was a finding; since then the sentence has to carry the claim itself. "We are not SOC 2 audited" names the standard and denies the claim; "stored outside the European Economic Area" names the region and excludes it. Both had been counted. The data quality page lists the kinds of sentence the classifier now rejects and the ones it still lets through.
How often we are wrong
461 findings that stood on value pages on 11 September 2026 were read by hand, one by one, and judged. Against that set, the classifier v2-2026-09-11 is right 97.6% of the time for hosting locations and 97.1% for certifications; it finds 86.0% and 90.5% of what a person found. The same set run against the classifier as it stood before that day gave 73.1% and 74.6%: every fourth published finding was wrong, in both directions.
What that costs in the live data is counted, not estimated: every stored finding is re-read against its own quote.
For certifications, 2,836 of 5,654 findings (50%) do not count; for hosting locations 120 of 3,084 (4%). Across all ten kinds of detail it is 2,956 of 127,045. The first estimate for certifications, made from the quotes shown on the value pages, was about a quarter; those quotes are the first hundred per page, sorted by score, the best-written part of the stock. The tail is worse than its head.
The six largest classes of mistake the classifier now catches in the hand-read set are outside the region (17), no claim (13), postal address (11), company seat (9), reader or staff (9), navigation (8). Eight findings in the set are judged wrong and still get through; they are listed on the quality page with their sentence. For the eight kinds of detail without a hand-read set there is no accuracy figure, and we do not print an estimate.
One more number belongs next to every share above: the oldest measurement behind the two criteria is 20 days old, because a nightly run covers part of the catalogue. A fresh figure and an old one look the same on a value page, and the date on each row is the only thing that tells them apart.
Using this for a shortlist
The value pages answer one question each: who has said this, in which sentence, and where.
- Start from the requirement, not the vendor. If your policy needs data in the EEA, open the pages for the European Economic Area, the European Union and the member states you accept, and read the sentences.
- Treat a certification name as a question to ask. A vendor on the SOC 2 Type II page has written that it holds a report; the next step is to ask for the report and the period it covers.
- Read the subject before the value. If the sentence is about a data centre or a provider, it is on the profile and not on the list. It is a different claim, and the page says which.
- Combine in the explorer. The explorer takes a category, criteria and detail values together and returns the vendors at which we found all of them. There is no "without" filter, because not finding a sentence is not the same as its absence.
- File the sentence with its date. Every row carries the address and the date it was read, and the API and the bulk download deliver the same rows with the snapshot identifier.
Questions buyers ask
Does "names ISO/IEC 27001" mean the vendor is certified?
No. It means a public page of the vendor names the standard in a sentence about the vendor itself, read at the address and on the date shown. Whether a certificate exists, who issued it and what it covers is a question for the vendor and the certificate itself.
Why does the same vendor appear under several locations?
Because the page keeps the words the vendor used. A vendor that writes "hosted in Frankfurt, in the European Union" appears under both; open the sentence rather than trust the label.
Why is the share for certifications lower than I would expect?
Two reasons, both on our side. We read fixed public addresses and never a trust portal behind a form, and since 11 September 2026 a sentence counts only if it makes the claim about the vendor itself. 2,836 of 5,654 certification findings in this snapshot fail that reading and are shown on the profiles instead.
Can a vendor correct a finding?
Yes. Every row on a value page and on a profile links to a correction form; a person reads it, and the vendor moves into the next nightly run. That run reads the same fixed addresses we check for every vendor, not the address that was sent.
Do these details change the score?
No. The transparency score is frozen as version v1 and counts twelve criteria with published weights. A location or a certification name is a detail behind a criterion, shown with its source, and a detail has never entered the score.
Method, snapshot and sources
Every figure above was read on 2026-09-21 from pages that render the live database, and each carried the snapshot r126.107528 in its footer. The criteria overview shows the two criteria for the snapshot the site serves today. These commands pull the same figures for that snapshot:
# the snapshot identifier
curl -s https://saas-ranking.com/api/v1/criteria | grep -o '"snapshot":"[^"]*"'
# both criteria: found of measured (the short answer)
curl -s https://saas-ranking.com/criteria/ | grep -oE '[0-9]+ of [0-9]+ publish it'
# every location and every certification with a page, with vendors and share (Figures 2 and 3)
for t in hosting certifications; do curl -s "https://saas-ranking.com/data/$t" | grep -oE '/data/'$t'/[a-z0-9-]+">[^<]+|<td class="mitte">[0-9]+( %)?' | paste - - -; done
# who the sentence is about, for the two largest certification values (Figure 4)
for v in soc-2-type-2 iso-27001; do curl -s "https://saas-ranking.com/data/certifications/$v" | grep -oE 'about something else: [^.]+' | sed 's/<[^>]*>//g'; done
# precision, recall and the findings that do not count (Figures 1 and 6)
curl -s https://saas-ranking.com/data/quality | grep -A4 -E '<th scope="row">(Hosting location named|Certification named)</th>'
- Snapshot r126.107528: 107,528 results from run 126 and earlier, newest measurement 2026-09-21. Read 2026-09-21 from saas-ranking.com/criteria/, /data/, /data/hosting, /data/certifications, two value pages and /data/quality.
- Criteria: Data location stated, 1,955 of 8,324 companies; Certifications named, 1,953 of 8,355. Both count companies, one per domain.
- Value pages: 22 locations and 14 certifications with at least 8 vendors each; 643 detail pages across 7 kinds of detail in total.
- Hand-read set: 461 findings, read on 11 September 2026; classifier v2-2026-09-11. Precision and recall as printed on saas-ranking.com/data/quality.
- Rounding: whole percent for shares, as on the value pages; one decimal for precision and recall, as on the quality page. Bars use unrounded values.
- No vendor is named. Every finding here is a sentence a vendor published, at the address and on the date we read it, and every negative describes what we found at the addresses we checked.