Where QHSE software profiles say data is hosted: what 209 profiles state
Incident photos, worker health notes, audit evidence and supplier files all end up on a server somewhere, and a buyer's IT, legal and procurement teams may ask where. This page counts what our 209 researched profiles state about the way the product is delivered, who hosts it, in which region, and what the vendor says about backups, exit and deletion. 83 profiles (40%) state a delivery model, 30 (14%) name a cloud provider and 21 (10%) name a region. Each statement is the vendor's own claim and was not tested by us. A record that says nothing about hosting reflects what we gathered; it does not show that the product has no answer.
Editorial responsibility: Dimitris Mitsios (Founder of The QHSE Standard; product marketing at Tekmon) · Tekmon pays for sponsored placements on this site (disclosure) · How pages are made · LinkedIn · Content date: 3 October 2026
What the records show
- Most records do not describe the delivery model. 126 of 209 (60%) state none. Hosting is not a structured field in the records, so a statement appears only when a cited vendor page or a note raised it. A further 44 records contain a hosting word without stating a model, provider or region for the product:16 only ask the buyer to confirm hosting or location, 8 mention the cloud only as the destination of offline synchronisation, and the other 20 use the word in a different sense, such as a price line, a document library or a product name, or name no model, provider or region. 12 records say outright that hosting, region, provider or service levels are not described on the pages reviewed.
- Where a model is stated, it is usually cloud. 72 of the 83 profiles with a delivery-model statement describe a cloud-hosted or SaaS service or component. 14 state an on-premises, self-hosted or client data-centre option, 8 a private-cloud, private-edition or single-tenant option, 3 a hybrid one, and 9 describe software installed on the customer's own computers. 21 state two or more of these kinds, whether for one product or for separate editions inside the profile.
- Few records name a hosting provider. 30 of 209 (14%) name one: AWS (18), Microsoft Azure (7), Google Cloud (1), Another named provider or platform (5). A named cloud provider describes the infrastructure under the service. It does not say who operates the application, which certificates cover which layer or which customer data is held there.
- Fewer name a region, and fewer still state a choice. 21 of 209 (10%) name a region: Europe or an EU country (15), the United States, Canada or North America (9), the United Kingdom (2), Australia or Asia-Pacific (3) and the Middle East (1); some name more than one. 10 state a choice of region or a data-residency option, and 14 contain a residency or storage-location statement.
- Many cloud statements stop at the word cloud. 44 of the 72 profiles that describe a cloud-hosted or SaaS service name no provider, no region, no residency statement and no choice of region. For those, the record answers how the product is delivered but not where.
- Service-level, backup and exit statements are rarer than location statements. 2 records give an uptime or availability figure (99.9% in every case), 8 describe backups or a recovery site, 3 say what the customer can take at exit and 10 give a deletion or retention rule. 16 profiles contain a GDPR, DPA or subprocessor statement. These are vendor statements, and a number in a record is not a contractual commitment.
What counts as a statement
A record counts when it says, in its own words or in the words of a vendor page it cites, how the product is delivered, where it is hosted or what the vendor does with the data. A request to the buyer, such as an instruction to ask for the hosting region, does not count, and neither does the word hosting when it describes a document library or a price line. Where a record describes a cloud connection only to explain offline synchronisation, we leave it out of the delivery-model count. Web or browser access alone is not counted as a delivery model either, because it does not say who hosts the service. A profile can appear in several rows.
| Topic | What it covers | Profiles | Share of 209 |
|---|---|---|---|
| Delivery model | The record says the product, an edition or a component is cloud-hosted or SaaS, private or single-tenant, on-premises, installed on the customer's computers, hybrid, or built on another platform. | 83 | 40% |
| Named cloud provider | The record names AWS, Microsoft Azure, Google Cloud or another hosting provider or platform. | 30 | 14% |
| Named hosting region | The record names a region, country or data centre location where the service or its data sits. | 21 | 10% |
| Choice of region or residency option | The record words it as a choice of region, or as a data-residency option offered to the customer or on a plan. | 10 | 5% |
| Residency or storage-location statement | The record uses residency wording, or says that customer data is stored or processed in a stated place or in a location fixed by contract. | 14 | 7% |
| GDPR statement | A vendor page, as the record reports it, mentions GDPR, states compliance or alignment, or describes GDPR settings. | 10 | 5% |
| Data processing agreement | The record says that the vendor publishes or describes a DPA. | 4 | 2% |
| Subprocessors | The record says that the vendor lists subprocessors or that subcontractors may handle customer content. | 4 | 2% |
| Uptime or availability figure | The record gives a percentage for uptime or availability. | 2 | 1% |
| Backup | The record says that the vendor runs backups or a disaster-recovery site. | 8 | 4% |
| Export or data return at exit | The record says what the customer can export or download when the contract ends. | 3 | 1% |
| Deletion or retention | The record gives a deletion rule or a retention period for customer or trial data. | 10 | 5% |
| Hosting stated as not described | The record says in so many words that hosting, region, provider or service levels are not described on the pages reviewed. | 12 | 6% |
Text version of this chart
- States a delivery model: 83 of 209 (40%). Highlighted in the chart.
- Names a cloud provider: 30 of 209 (14%).
- Names a hosting region: 21 of 209 (10%).
- States a region choice or residency option: 10 of 209 (5%).
- Residency or storage-location statement: 14 of 209 (7%).
- Gives an uptime figure: 2 of 209 (1%).
A choice or an option counts only where the record words it that way ("choice of region", "residency options", a list of alternative hosting set-ups). A list of regions with no word about choice counts as naming a region and not as a choice. Where a record says that locations are fixed by the contract, we count a residency statement and no named region.
Delivery models the records state
The 9 groups below follow the record's words. A multi-tenant statement is counted only where a record says so about the service itself, not where the word describes a feature for several tenants of a building. The records contain no statement that a product is available only as a mobile app, so that group is empty and is not shown. For the responsibilities that change between cloud and on-premises delivery, see the guide to cloud and on-premise QHSE software.
Text version of this chart
- Cloud-hosted or SaaS (tenancy not stated): 72 of 209 (34%).
- Multi-tenant service: 1 of 209 (0%).
- Private cloud, private edition or single-tenant: 8 of 209 (4%).
- On-premises, self-hosted or client data-centre option: 14 of 209 (7%).
- Software installed on the customer's computers: 9 of 209 (4%).
- Hybrid: 3 of 209 (1%).
- Processing on a device or hub at the customer's site: 2 of 209 (1%).
- Built on a named third-party business platform: 5 of 209 (2%).
- Record says there is no on-premises or local-server option: 2 of 209 (1%).
| Delivery model | Profiles | Share of 209 |
|---|---|---|
| Cloud-hosted or SaaS (tenancy not stated) | 72 | 34% |
| Multi-tenant service | 1 | 0% |
| Private cloud, private edition or single-tenant | 8 | 4% |
| On-premises, self-hosted or client data-centre option | 14 | 7% |
| Software installed on the customer's computers | 9 | 4% |
| Hybrid | 3 | 1% |
| Processing on a device or hub at the customer's site | 2 | 1% |
| Built on a named third-party business platform | 5 | 2% |
| Record says there is no on-premises or local-server option | 2 | 1% |
The count of 21 profiles with two or more kinds mixes two situations: one product offered in several set-ups, and a vendor with separate products or editions that are delivered differently. A buyer should read the record for the edition in the proposal, since a model stated for one edition says nothing about another. Where a record names a single option, such as private cloud only, the other options are not stated for that product and the page does not infer them.
Providers, regions and residency
30 profiles name a provider and 21 name a region. The two overlap only in part: 41 profiles state at least one of a provider, a region, a residency statement or a choice of region. A region is counted by the place the record names, with a country counted under its region. A record that says data sits in Canada, for instance, is counted under North America.
Text version of this chart
- AWS (Amazon Web Services): 18 of 209 (9%).
- Microsoft Azure: 7 of 209 (3%).
- Google Cloud: 1 of 209 (0%).
- Another named provider or platform: 5 of 209 (2%).
Text version of this chart
- European Union or Europe: 15 of 209 (7%).
- United Kingdom: 2 of 209 (1%).
- United States, Canada or North America: 9 of 209 (4%).
- Australia or Asia-Pacific: 3 of 209 (1%).
- Middle East: 1 of 209 (0%).
| Named in the record | Profiles | Share of 209 |
|---|---|---|
| AWS (Amazon Web Services) | 18 | 9% |
| Microsoft Azure | 7 | 3% |
| Google Cloud | 1 | 0% |
| Another named provider or platform | 5 | 2% |
| European Union or Europe | 15 | 7% |
| United Kingdom | 2 | 1% |
| United States, Canada or North America | 9 | 4% |
| Australia or Asia-Pacific | 3 | 1% |
| Middle East | 1 | 0% |
Naming a region describes what the vendor says about where data sits. It does not show that a customer can choose it, and it does not show that the location satisfies any rule that applies to the buyer. Whether an arrangement meets a buyer's legal or contractual duties is a question for the buyer's own data-protection and legal advisers. For the European angle, the EU EHS software guide is the regional buying guide, and the article on GDPR and EHS data looks at how the GDPR applies to records such as incident logs.
Data-protection documents, service levels and exit
16 profiles contain at least one data-protection statement: 10 a GDPR statement, 4 a data processing agreement and 4 a subprocessor statement. The records report these as claims on vendor pages and in vendor documents. We did not read the agreements and the page does not say whether any of them is sufficient for a buyer. Security certifications are counted in the security, trial and offline study and are not repeated here.
Text version of this chart
- Uptime or availability figure: 2.
- Service-level agreement described: 2.
- Backups or recovery site: 8.
- Export or data return at exit: 3.
- Deletion or retention rule: 10.
The uptime figures that appear are 99.9% in every case, and the record of at least one of them says that the figure is a published target that applies only where the agreement carries the service-level terms and its exclusions. A figure on a vendor page and a remedy in a contract are different things, and the buyer needs the executed terms, which the records do not contain. The exit statements describe what the vendor says can be exported, downloaded or extracted at the end of a contract, and they differ in how much they specify. We tested no restore and no export.
By category
The charts below use the 12 categories with at least 5 profiles, which together hold 180 of the 209 profiles. Categories with fewer than 5 profiles are merged into one row of the table and the CSV (12 categories, 29 profiles), so that no row stands for one or two products. Each profile has a single category, the one the directory shows.
Text version of this chart
- EHS Management (43): 16 of 43 (37%).
- ESG & Sustainability (30): 4 of 30 (13%).
- Quality Management (22): 15 of 22 (68%).
- QHSE Management (16): 6 of 16 (38%).
- Audits & Inspections (15): 3 of 15 (20%).
- Safety Management (12): 5 of 12 (42%).
- Occupational Health (11): 4 of 11 (36%).
- Asset Management (7): 3 of 7 (43%).
- Construction Safety (7): 3 of 7 (43%).
- Emergency Management (6): 2 of 6 (33%).
- Environmental Management (6): 4 of 6 (67%).
- Chemical Management (5): 3 of 5 (60%).
- No profile in the category
- Under 25% of the category
- 25% or more
Text version of this grid
- Category: EHS Management (43)
- Any delivery model: 16 of 43 (37%) (25% or more); Cloud or SaaS: 12 of 43 (28%) (25% or more); On-premises or self-hosted: 3 of 43 (7%) (Under 25% of the category); Names a provider: 8 of 43 (19%) (Under 25% of the category); Names a region: 3 of 43 (7%) (Under 25% of the category); GDPR, DPA or subprocessors: 3 of 43 (7%) (Under 25% of the category); Backup, exit or deletion: 4 of 43 (9%) (Under 25% of the category).
- Category: ESG & Sustainability (30)
- Any delivery model: 4 of 30 (13%) (Under 25% of the category); Cloud or SaaS: 4 of 30 (13%) (Under 25% of the category); On-premises or self-hosted: 0 of 30 (0%) (No profile in the category); Names a provider: 2 of 30 (7%) (Under 25% of the category); Names a region: 4 of 30 (13%) (Under 25% of the category); GDPR, DPA or subprocessors: 4 of 30 (13%) (Under 25% of the category); Backup, exit or deletion: 2 of 30 (7%) (Under 25% of the category).
- Category: Quality Management (22)
- Any delivery model: 15 of 22 (68%) (25% or more); Cloud or SaaS: 13 of 22 (59%) (25% or more); On-premises or self-hosted: 5 of 22 (23%) (Under 25% of the category); Names a provider: 5 of 22 (23%) (Under 25% of the category); Names a region: 3 of 22 (14%) (Under 25% of the category); GDPR, DPA or subprocessors: 0 of 22 (0%) (No profile in the category); Backup, exit or deletion: 4 of 22 (18%) (Under 25% of the category).
- Category: QHSE Management (16)
- Any delivery model: 6 of 16 (38%) (25% or more); Cloud or SaaS: 5 of 16 (31%) (25% or more); On-premises or self-hosted: 0 of 16 (0%) (No profile in the category); Names a provider: 2 of 16 (13%) (Under 25% of the category); Names a region: 2 of 16 (13%) (Under 25% of the category); GDPR, DPA or subprocessors: 1 of 16 (6%) (Under 25% of the category); Backup, exit or deletion: 1 of 16 (6%) (Under 25% of the category).
- Category: Audits & Inspections (15)
- Any delivery model: 3 of 15 (20%) (Under 25% of the category); Cloud or SaaS: 3 of 15 (20%) (Under 25% of the category); On-premises or self-hosted: 0 of 15 (0%) (No profile in the category); Names a provider: 0 of 15 (0%) (No profile in the category); Names a region: 2 of 15 (13%) (Under 25% of the category); GDPR, DPA or subprocessors: 3 of 15 (20%) (Under 25% of the category); Backup, exit or deletion: 2 of 15 (13%) (Under 25% of the category).
- Category: Safety Management (12)
- Any delivery model: 5 of 12 (42%) (25% or more); Cloud or SaaS: 5 of 12 (42%) (25% or more); On-premises or self-hosted: 1 of 12 (8%) (Under 25% of the category); Names a provider: 5 of 12 (42%) (25% or more); Names a region: 4 of 12 (33%) (25% or more); GDPR, DPA or subprocessors: 3 of 12 (25%) (25% or more); Backup, exit or deletion: 4 of 12 (33%) (25% or more).
- Category: Occupational Health (11)
- Any delivery model: 4 of 11 (36%) (25% or more); Cloud or SaaS: 4 of 11 (36%) (25% or more); On-premises or self-hosted: 1 of 11 (9%) (Under 25% of the category); Names a provider: 1 of 11 (9%) (Under 25% of the category); Names a region: 1 of 11 (9%) (Under 25% of the category); GDPR, DPA or subprocessors: 1 of 11 (9%) (Under 25% of the category); Backup, exit or deletion: 2 of 11 (18%) (Under 25% of the category).
- Category: Asset Management (7)
- Any delivery model: 3 of 7 (43%) (25% or more); Cloud or SaaS: 3 of 7 (43%) (25% or more); On-premises or self-hosted: 0 of 7 (0%) (No profile in the category); Names a provider: 2 of 7 (29%) (25% or more); Names a region: 1 of 7 (14%) (Under 25% of the category); GDPR, DPA or subprocessors: 1 of 7 (14%) (Under 25% of the category); Backup, exit or deletion: 0 of 7 (0%) (No profile in the category).
- Category: Construction Safety (7)
- Any delivery model: 3 of 7 (43%) (25% or more); Cloud or SaaS: 3 of 7 (43%) (25% or more); On-premises or self-hosted: 0 of 7 (0%) (No profile in the category); Names a provider: 2 of 7 (29%) (25% or more); Names a region: 1 of 7 (14%) (Under 25% of the category); GDPR, DPA or subprocessors: 0 of 7 (0%) (No profile in the category); Backup, exit or deletion: 0 of 7 (0%) (No profile in the category).
- Category: Emergency Management (6)
- Any delivery model: 2 of 6 (33%) (25% or more); Cloud or SaaS: 2 of 6 (33%) (25% or more); On-premises or self-hosted: 0 of 6 (0%) (No profile in the category); Names a provider: 0 of 6 (0%) (No profile in the category); Names a region: 0 of 6 (0%) (No profile in the category); GDPR, DPA or subprocessors: 0 of 6 (0%) (No profile in the category); Backup, exit or deletion: 0 of 6 (0%) (No profile in the category).
- Category: Environmental Management (6)
- Any delivery model: 4 of 6 (67%) (25% or more); Cloud or SaaS: 3 of 6 (50%) (25% or more); On-premises or self-hosted: 0 of 6 (0%) (No profile in the category); Names a provider: 1 of 6 (17%) (Under 25% of the category); Names a region: 0 of 6 (0%) (No profile in the category); GDPR, DPA or subprocessors: 0 of 6 (0%) (No profile in the category); Backup, exit or deletion: 0 of 6 (0%) (No profile in the category).
- Category: Chemical Management (5)
- Any delivery model: 3 of 5 (60%) (25% or more); Cloud or SaaS: 2 of 5 (40%) (25% or more); On-premises or self-hosted: 1 of 5 (20%) (Under 25% of the category); Names a provider: 0 of 5 (0%) (No profile in the category); Names a region: 0 of 5 (0%) (No profile in the category); GDPR, DPA or subprocessors: 0 of 5 (0%) (No profile in the category); Backup, exit or deletion: 0 of 5 (0%) (No profile in the category).
| Category | Profiles | Delivery model | Cloud or SaaS | On-premises | Provider | Region | Residency |
|---|---|---|---|---|---|---|---|
| EHS Management | 43 | 16 | 12 | 3 | 8 | 3 | 3 |
| ESG & Sustainability | 30 | 4 | 4 | 0 | 2 | 4 | 3 |
| Quality Management | 22 | 15 | 13 | 5 | 5 | 3 | 0 |
| QHSE Management | 16 | 6 | 5 | 0 | 2 | 2 | 1 |
| Audits & Inspections | 15 | 3 | 3 | 0 | 0 | 2 | 1 |
| Safety Management | 12 | 5 | 5 | 1 | 5 | 4 | 4 |
| Occupational Health | 11 | 4 | 4 | 1 | 1 | 1 | 0 |
| Asset Management | 7 | 3 | 3 | 0 | 2 | 1 | 1 |
| Construction Safety | 7 | 3 | 3 | 0 | 2 | 1 | 1 |
| Emergency Management | 6 | 2 | 2 | 0 | 0 | 0 | 0 |
| Environmental Management | 6 | 4 | 3 | 0 | 1 | 0 | 0 |
| Chemical Management | 5 | 3 | 2 | 1 | 0 | 0 | 0 |
| Other categories (12) | 29 | 15 | 13 | 3 | 2 | 0 | 0 |
| All profiles | 209 | 83 | 72 | 14 | 30 | 21 | 14 |
The share of profiles with a delivery-model statement is lowest in ESG & Sustainability (4 of 30, 13%) and highest in Quality Management (15 of 22, 68%). The share naming a provider is highest in Safety Management (5 of 12, 42%); 3 of the 12 categories have no profile that names one and 3 have none that names a region. With between 5 and 43 profiles in a category, a single corrected record shifts a percentage by several points at these sizes, so the spread describes this sample rather than the products in a category.
How to read these numbers
- Vendor claims, untested. Each provider, region and figure comes from a vendor page or from a reviewer's note. Nobody here inspected a data centre, read a contract or traced a request, so none of it is verified.
- Silence is not absence. A record with no hosting statement may belong to a product whose vendor documents hosting in detail on a page we did not cite. Hosting enters a record only where a source or a note raised it, so a gap here is a gap in our evidence, not in the product.
- A location is not a legal conclusion. A region, a provider or a residency option tells a buyer where the vendor says data sits. Whether that arrangement is suitable for a given buyer, sector or country depends on the contract, the data and the law, and nothing on this page assesses it.
- Product, edition and component differ. A statement can belong to the platform, to one edition or to one component such as a dashboard or a lone-worker service. The counts treat the profile as the unit and say that a profile states something when any of its parts does.
- Statements can disagree. Some records note that two vendor pages describe hosting differently. We count the statement and leave the disagreement to the reader of the record. 12 records say that hosting details are not described; each is tallied once under that heading and nothing is inferred for it.
- The unit is the profile. Our 209 profiles cover part of the market, and each figure reflects a record on the day it was checked, not a product's current terms.
What to ask when hosting matters
- Which delivery model applies to the exact edition in the proposal, and does the model differ for the mobile app, the analytics layer and any AI function?
- Who hosts the service, in which region, and are the primary and the recovery locations both named in the contract?
- Can the customer choose the region at signature, and what does a later change of region involve and cost?
- Which subprocessors handle customer content, where are they based, and how is a change in that list notified?
- What service-level terms apply, how is availability measured, and what remedy does the contract give if the target is missed?
- How often is data backed up, how long are backups kept, and has a restore been tested for this customer?
- At the end of the contract, what can the customer export, in which formats, for how long after termination, and when is the remaining data deleted?
Put the answers in writing in the RFP template and check the claims that matter against the vendor's own documents. The questions are practical prompts, not legal advice.
How the figures were computed
Hosting is not a structured field in the profile records, so the record text was read once and each statement was written into a table beside the exact words that support it. A script turns that table, with each profile's category, into the counts, the page figures and the CSV. It stops when any quoted words have left the record, which forces a re-read after an edit, and a test scans every record for hosting, deployment and data-location words and fails when a record carries one without a counted statement or a reasoned exclusion. 106 statements were recorded for 106 profiles, and 49 records were reviewed and set aside with a reason. Each profile takes the category on its record, or the catalogue's category where it has none. Percentages are whole numbers after rounding. Record check date: 3 October 2026.
The inputs contain no score, rating, price or payment, and nothing here ranks or names a product. The methodology explains how the profile set was built, and the same records feed the 2026 report on vendor transparency.
Disclosure. The editor works at one of the vendors in this set, and that vendor pays for sponsored placement on this site. We read its record by the same rules as every other, count it in every figure like any other profile, and do not name it on this page.
Download and cite
The CSV holds the counts behind every figure above and no product names: a row for all profiles, a row for each category of 5 profiles or more, and a merged row for the remainder. We release the compilation under CC BY 4.0; the underlying hosting claims belong to the vendors and stay untested when reused.
Download the CSVSuggested citation: The QHSE Standard. (2026). Where QHSE software profiles say data is hosted: what 209 profiles state (records checked through 3 October 2026). https://qhsetech.com/qhse-software-hosting-and-data-location-2026
Related: the capability map, security, trial and offline evidence, the integrations ecosystem, all datasets.