Council Post: The New Standard For Enterprise SaaS Security Is Customer Control

2026/08/21

Categories: business-finance

Bora Unlu is the co-founder and CEO of Teamflect, a performance management & employee engagement platform designed for Microsoft 365.

getty

​When we closed our first enterprise customers, the security review felt like a procurement step. A spreadsheet arrived with roughly 20 questions: encryption, backups, password policies, access controls, incident response. We answered, attached the documents we had and moved on.

The security reviews I see today are longer and more demanding. They arrive as Excel workbooks with hundreds of rows, multiple tabs and evidence requests. Customers want to know which roles can open sensitive employee notes. They ask whether access follows their own identity provider, how quickly access can be revoked, whether logs can be exported into their monitoring tools, where the data physically lives and whether any customer content trains an AI model.

I build software in a category that used to sit in a relatively quiet part of the enterprise stack: performance reviews, feedback, goals and development conversations. But these systems now hold some of the most sensitive language inside a company. A manager assessment, promotion note, compensation-related comment or career plan can affect someone's career.

The question that matters now is whether a vendor can prove that the customer remains in control.

Identity Has Replaced The Perimeter

Enterprise security used to begin with the network perimeter: Keep attackers outside the walls and trust what happens inside. That model no longer describes how work actually happens. Employees work through cloud applications, browsers, APIs, integrations, home networks, mobile devices and now AI agents. In that world, "inside" is an identity, a permission and a session.

Modern buyers ask whether the product respects the identity model they already use. Can access follow Microsoft Entra groups or another centralized identity provider? Can MFA and conditional access policies be enforced? Can a departing administrator be deprovisioned quickly?

In Microsoft-centered organizations, this matters even more. The buyer wants the SaaS product to work with the controls they already operate across Microsoft 365, Entra ID, admin consent, security groups and internal approval workflows.

The same principle applies inside the product. In HR software, the permission model has to govern reports, admin views, exports and integrations exactly as it governs the main interface. A manager should see only the reviews, goals, feedback and notes they are allowed to see.

A security question I come across repeatedly is: Show us which roles can open compensation-related notes, then show what happens when that data is exported. An export showing more than the product interface means a boundary has been moved.

Encryption And Compliance Are No Longer Enough

For years, "encrypted at rest and in transit" was one of the most reassuring sentences a SaaS vendor could say. Now it is the floor.

Enterprise customers increasingly understand that encryption is a chain of decisions: where keys are stored, who can access them, how they are rotated, whether they are managed by the vendor or the customer and what happens if access must be revoked.

The right architecture varies by customer. Customer-managed keys, dedicated environments and regional controls add cost and complexity, and for regulated industries and large global enterprises, they are becoming part of the procurement conversation.

SOC 2, ISO 27001, penetration tests and written security policies are mandatory in many enterprise sales cycles. They are the entry requirement, and the harder questions come after. An audit demonstrates that controls were tested during a prior period.

The customer's risk is today, and so are the questions from their auditors, board and regulators. That creates demand for continuous proof: current documentation, access reviews, audit trails, incident history and exportable logs.

'In The Cloud' Is No Longer A Location

Vendors used to answer hosting questions by saying they were "hosted in the cloud." That answer now sounds incomplete.

Enterprise customers want to know the region where their data is stored and processed, where backups live, whether support paths in other jurisdictions can reach production data and what happens if their legal or regulatory requirements change.

Gartner expects sovereign-cloud spending to reach $80 billion in 2026, with a fifth of workloads shifting from global providers to local ones.

Europe has advanced this conversation, and data residency and sovereignty are now global enterprise requirements. Doing this properly means regional hosting, regional backups, tenant-to-region mapping and operational processes that respect those boundaries.

The answer customers want is specific: which cloud, which region, which data, which backup location and which access path.

AI Has Made Governance More Specific

Nearly every SaaS company is adding AI features. The first enterprise question is predictable and fair: "Does our data train your models?"

The answer should be clear. Customer data belongs to the customer, and unless the customer has explicitly agreed otherwise, private business and employee data should not be used to train a vendor's general models.

Mature buyers are already going further. They ask which AI providers are used, what data is sent, whether prompts and outputs are logged, whether admins can disable the features and what retention and deletion rules apply.

IBM's 2025 report found 63% of organizations have no AI governance policy of their own, so the contract is where it now lands.

Many vendors treat AI as a product enhancement, while buyers increasingly treat it as a data compliance issue. The companies that handle this well will make AI governable: transparent inputs, clear boundaries, admin controls, no customer-data training by default and contractual language that matches the technical implementation.

For vendors, this raises the bar. Security now has to live in the product architecture, the operating process and the company culture, because that is where buyers experience it.

A product can satisfy the vendor's definition of secure and still fail the customer's need to govern it. The future of enterprise SaaS belongs to the vendors that can prove, continuously and concretely, that customers remain in control of their own data.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


>> Home