Skip to main content
    Updated 3 October 2026
    Original data · records checked through 3 October 2026

    Security attestations, free trials and offline support across QHSE software: what 209 profiles document

    Three questions come up early in almost every QHSE software evaluation: does the vendor hold a security attestation, can we try the product without paying, and does it work without a connection. This page counts what our 209 researched profiles document on each, overall and by category. 118 profiles (56%) name SOC 2 or ISO 27001, 48 (23%) document a free trial, and 39 (19%) document an offline workflow. Every attestation is a statement by the vendor that we did not verify, and a missing statement is not evidence that a certification does not exist.

    Editorial responsibility: Dimitris Mitsios (Founder of The QHSE Standard; product marketing at Tekmon) · Tekmon pays for sponsored placements on this site (disclosure) · How pages are made · LinkedIn · Content date: 3 October 2026

    What the records show

    1. More than half of the profiles name a security attestation. 118 of 209 (56%) name SOC 2 or ISO 27001. SOC 2 appears in 77 profiles and ISO 27001 in 75; 34 name both. Of the 77 that name SOC 2, 59 name a Type II report, 3 name Type I only and 15 do not say which type.
    2. 83 profiles have no certification entry. That is 40% of the records. It means we recorded none, not that the vendor holds none: the records come from vendor pages, so a vendor that shares its reports only after a sales conversation, or whose trust portal was not among the pages reviewed, shows up here as a blank. A further 8 profiles name only other schemes, such as an ISO 9001 quality certificate, without SOC 2 or ISO 27001.
    3. The share varies by category, but the categories are small. Among the 12 categories with at least 5 profiles, the share naming SOC 2 or ISO 27001 is lowest in Occupational Health (4 of 11, 36%) and highest in Asset Management (6 of 7, 86%) and Construction Safety (6 of 7, 86%). With between 5 and 43 profiles in a category, one added or corrected record moves a percentage by several points, so treat the spread as a pattern in this sample and not as a property of a software type.
    4. A documented free trial is the minority position. 48 of 209 (23%) document a free trial, 41 of 209 (20%) offer a trial or demo only on request, and for 120 of 209 (57%) we could not establish either. By category, the share with a documented free trial is lowest in Emergency Management (0 of 6, 0%) and highest in Audits & Inspections (11 of 15, 73%).
    5. Offline support is the least classified of the three. 39 of 209 (19%) have a documented offline workflow and 51 of 209 (24%) a partial one. 1 is recorded as needing a connection for the workflow we assessed, 1 is not applicable (document templates, where offline use is not a meaningful question), and 117 of 209 (56%) are not yet classified. Among the 91 profiles that have been classified, 39 of 91 (43%) are documented as working offline and 51 of 91 (56%) partly.
    6. Few profiles document all three, partly because the offline field is incomplete. 7 profiles name SOC 2 or ISO 27001, document a free trial and document an offline workflow. 28 combine an attestation with a free trial and 24 combine an attestation with a documented offline workflow. A documented free trial is about as common among profiles that name an attestation (28 of 118 (24%)) as among those that do not (20 of 91 (22%)), so in these records the two are not linked.

    Security attestations named by the vendor

    A certification counts here when a vendor page names it. We read the name of each entry: "SOC 2" matches any SOC 2 report, "Type II" is counted separately when the entry says Type II or Type 2, and "ISO 27001" matches every edition of the standard, with or without the "IEC" prefix. 260 entries are recorded across 126 profiles; 231 of them say in so many words that the report or certificate was not reviewed, and none records a document that was.

    Share of profiles naming each attestationBars show how many of 209 profiles name SOC 2, SOC 2 Type II, ISO 27001, either SOC 2 or ISO 27001, or have no certification entry.SOC 2 (any type)77 of 209 (37%)SOC 2 Type II59 of 209 (28%)ISO 2700175 of 209 (36%)SOC 2 or ISO 27001118 of 209 (56%)No certification entry83 of 209 (40%)
    Share of all 209 profiles. Each attestation is the vendor's own statement and was not verified.
    Text version of this chart
    1. SOC 2 (any type): 77 of 209 (37%).
    2. SOC 2 Type II: 59 of 209 (28%).
    3. ISO 27001: 75 of 209 (36%).
    4. SOC 2 or ISO 27001: 118 of 209 (56%). Highlighted in the chart.
    5. No certification entry: 83 of 209 (40%).
    Number of profiles by attestation named
    Named by the vendorProfilesShare of 209
    SOC 2, any type7737%
    SOC 2 Type II or Type 25928%
    SOC 2 Type I only31%
    SOC 2 with the type not stated157%
    ISO 270017536%
    Both SOC 2 and ISO 270013416%
    SOC 2 or ISO 2700111856%
    Only other certifications84%
    No certification entry8340%

    Other schemes appear less often. Each row counts a profile once, however many of the listed schemes it names, and a profile can appear in several rows:

    Number of profiles naming other certification families
    Other schemes namedProfilesShare of 209
    ISO 9001, 14001, 45001, 13485 or 223012713%
    ISO/IEC 27017, 27018, 27701 or 4200194%
    SOC 1, SOC 3 or ISAE 3000126%
    CSA STAR63%
    FedRAMP, TX-RAMP or CMMC105%
    HIPAA or HITRUST84%
    Cyber Essentials or Cyber Essentials Plus94%

    The schemes answer different questions. SOC 2 is an audit report written by an independent accounting firm about a described system and a set of trust criteria; a Type I report looks at how controls are designed on one date, a Type II report at whether they operated over a period, commonly three to twelve months. ISO 27001 is a certificate for an information security management system, issued by a certification body after an audit, and it covers the scope written on the certificate. ISO 9001, 14001 and 45001 concern quality, environmental and safety management and say little about how a software product protects customer data. Neither SOC 2 nor ISO 27001 is a government certification, and a profile that names one has not thereby said which of its products or hosting locations the report covers.

    Free trials

    Each profile carries one of three trial states. "Free trial documented" means the vendor's own pages advertise a free trial. "Trial or demo on request" means access follows a request or registration form, or a conversation with the vendor, which does not by itself establish that the product is free to try. "Not established" means our research did not find a statement either way; it is not a finding that no trial exists.

    Number of profiles by trial status
    Trial statusProfilesShare of 209
    Free trial documented4823%
    Trial or demo on request4120%
    Not established12057%

    A trial that the vendor documents is worth using early in a shortlist, because it lets a team test the workflows that matter before a contract exists. Ask what the trial includes: a trial limited to a sandbox with sample data will not show how imports, permissions or the integrations you need behave in your own environment, and a trial may leave out single sign-on and the administrator features that a security review depends on.

    Offline support

    The offline classification is the one used in the directory filter. "Documented" means the reviewed pages describe an offline workflow for the assessed use. "Partial" means some functions work offline and others do not. "Connection required" means the assessed workflow needs a connection. "Not yet classified" means the profile has not been through the offline review, which is a statement about our coverage, not about the product.

    Number of profiles by offline classification
    Offline classificationProfilesShare of 209
    Documented offline workflow3919%
    Partial offline workflow5124%
    Connection required for the assessed workflow10%
    Not applicable (document templates)10%
    Not yet classified11756%
    Share of profiles by free-trial status and offline classificationBars show how many of 209 profiles document a free trial, offer a trial on request, document an offline workflow, document a partial one, or are not yet classified for offline use.Free trial documented48 of 209 (23%)Trial or demo on request41 of 209 (20%)Offline workflow documented39 of 209 (19%)Partial offline workflow51 of 209 (24%)Offline not yet classified117 of 209 (56%)
    Share of all 209 profiles. The offline classification is not yet complete, so the unclassified bar is large.
    Text version of this chart
    1. Free trial documented: 48 of 209 (23%).
    2. Trial or demo on request: 41 of 209 (20%).
    3. Offline workflow documented: 39 of 209 (19%).
    4. Partial offline workflow: 51 of 209 (24%).
    5. Offline not yet classified: 117 of 209 (56%).

    For field work the useful questions are narrower than the label. Ask the vendor to show the exact task your inspectors perform, starting with no connection, including photos and signatures, and then reconnecting; ask what happens when two people edit the same record offline. The guide to offline inspection apps sets out that demonstration step by step.

    By category

    The charts below use the 12 categories with at least 5 profiles, which together hold 180 of the 209 profiles. The other 12 categories hold 29 profiles between them and are pooled in the table and the CSV, so that no row describes one or two products. A profile belongs to one category, the one shown in the directory.

    Share of profiles naming SOC 2 or ISO 27001, by categoryBars show, for each of the 12 categories with at least 5 profiles, how many profiles name SOC 2 or ISO 27001.EHS Management (43)19 of 43 (44%)ESG & Sustainability (30)21 of 30 (70%)Quality Management (22)13 of 22 (59%)QHSE Management (16)11 of 16 (69%)Audits & Inspections (15)7 of 15 (47%)Safety Management (12)7 of 12 (58%)Occupational Health (11)4 of 11 (36%)Asset Management (7)6 of 7 (86%)Construction Safety (7)6 of 7 (86%)Emergency Management (6)4 of 6 (67%)Environmental Management (6)3 of 6 (50%)Chemical Management (5)3 of 5 (60%)
    Categories are listed by number of profiles, largest first, not by share. The bar label gives the count behind each percentage.
    Text version of this chart
    1. EHS Management (43): 19 of 43 (44%).
    2. ESG & Sustainability (30): 21 of 30 (70%).
    3. Quality Management (22): 13 of 22 (59%).
    4. QHSE Management (16): 11 of 16 (69%).
    5. Audits & Inspections (15): 7 of 15 (47%).
    6. Safety Management (12): 7 of 12 (58%).
    7. Occupational Health (11): 4 of 11 (36%).
    8. Asset Management (7): 6 of 7 (86%).
    9. Construction Safety (7): 6 of 7 (86%).
    10. Emergency Management (6): 4 of 6 (67%).
    11. Environmental Management (6): 3 of 6 (50%).
    12. Chemical Management (5): 3 of 5 (60%).
    Attestation, free trial and offline workflow by categoryGrid of the categories with at least five profiles against three measures. Each cell gives the count and share, tinted by band: under 25 percent, 25 to 49 percent, 50 percent or more.Names SOC 2 or ISO27001Free trialdocumentedOffline workflowdocumentedEHS Management (43)19 of 43 (44%)5 of 43 (12%)7 of 43 (16%)ESG & Sustainability (30)21 of 30 (70%)2 of 30 (7%)1 of 30 (3%)Quality Management (22)13 of 22 (59%)5 of 22 (23%)1 of 22 (5%)QHSE Management (16)11 of 16 (69%)3 of 16 (19%)10 of 16 (63%)Audits & Inspections (15)7 of 15 (47%)11 of 15 (73%)10 of 15 (67%)Safety Management (12)7 of 12 (58%)6 of 12 (50%)1 of 12 (8%)Occupational Health (11)4 of 11 (36%)3 of 11 (27%)0 of 11 (0%)Asset Management (7)6 of 7 (86%)4 of 7 (57%)3 of 7 (43%)Construction Safety (7)6 of 7 (86%)2 of 7 (29%)2 of 7 (29%)Emergency Management (6)4 of 6 (67%)0 of 6 (0%)0 of 6 (0%)Environmental Management(6)3 of 6 (50%)2 of 6 (33%)1 of 6 (17%)Chemical Management (5)3 of 5 (60%)2 of 5 (40%)0 of 5 (0%)
    Each cell is the number of profiles in the category that name SOC 2 or ISO 27001, document a free trial, or document an offline workflow. The tint groups the share into a band; it does not rate a category.
    • Under 25% of the category
    • 25% to 49%
    • 50% or more
    Text version of this grid
    Category: EHS Management (43)
    Names SOC 2 or ISO 27001: 19 of 43 (44%) (25% to 49%); Free trial documented: 5 of 43 (12%) (Under 25% of the category); Offline workflow documented: 7 of 43 (16%) (Under 25% of the category).
    Category: ESG & Sustainability (30)
    Names SOC 2 or ISO 27001: 21 of 30 (70%) (50% or more); Free trial documented: 2 of 30 (7%) (Under 25% of the category); Offline workflow documented: 1 of 30 (3%) (Under 25% of the category).
    Category: Quality Management (22)
    Names SOC 2 or ISO 27001: 13 of 22 (59%) (50% or more); Free trial documented: 5 of 22 (23%) (Under 25% of the category); Offline workflow documented: 1 of 22 (5%) (Under 25% of the category).
    Category: QHSE Management (16)
    Names SOC 2 or ISO 27001: 11 of 16 (69%) (50% or more); Free trial documented: 3 of 16 (19%) (Under 25% of the category); Offline workflow documented: 10 of 16 (63%) (50% or more).
    Category: Audits & Inspections (15)
    Names SOC 2 or ISO 27001: 7 of 15 (47%) (25% to 49%); Free trial documented: 11 of 15 (73%) (50% or more); Offline workflow documented: 10 of 15 (67%) (50% or more).
    Category: Safety Management (12)
    Names SOC 2 or ISO 27001: 7 of 12 (58%) (50% or more); Free trial documented: 6 of 12 (50%) (50% or more); Offline workflow documented: 1 of 12 (8%) (Under 25% of the category).
    Category: Occupational Health (11)
    Names SOC 2 or ISO 27001: 4 of 11 (36%) (25% to 49%); Free trial documented: 3 of 11 (27%) (25% to 49%); Offline workflow documented: 0 of 11 (0%) (Under 25% of the category).
    Category: Asset Management (7)
    Names SOC 2 or ISO 27001: 6 of 7 (86%) (50% or more); Free trial documented: 4 of 7 (57%) (50% or more); Offline workflow documented: 3 of 7 (43%) (25% to 49%).
    Category: Construction Safety (7)
    Names SOC 2 or ISO 27001: 6 of 7 (86%) (50% or more); Free trial documented: 2 of 7 (29%) (25% to 49%); Offline workflow documented: 2 of 7 (29%) (25% to 49%).
    Category: Emergency Management (6)
    Names SOC 2 or ISO 27001: 4 of 6 (67%) (50% or more); Free trial documented: 0 of 6 (0%) (Under 25% of the category); Offline workflow documented: 0 of 6 (0%) (Under 25% of the category).
    Category: Environmental Management (6)
    Names SOC 2 or ISO 27001: 3 of 6 (50%) (50% or more); Free trial documented: 2 of 6 (33%) (25% to 49%); Offline workflow documented: 1 of 6 (17%) (Under 25% of the category).
    Category: Chemical Management (5)
    Names SOC 2 or ISO 27001: 3 of 5 (60%) (50% or more); Free trial documented: 2 of 5 (40%) (25% to 49%); Offline workflow documented: 0 of 5 (0%) (Under 25% of the category).
    Counts by category: attestation, trial and offline workflow
    CategoryProfilesSOC 2ISO 27001EitherFree trialTrial on requestOffline documentedAll three
    EHS Management439141951270
    ESG & Sustainability301615212110
    Quality Management22710135610
    QHSE Management16491132101
    Audits & Inspections15627113103
    Safety Management125376110
    Occupational Health113143300
    Asset Management74464032
    Construction Safety76462120
    Emergency Management63340100
    Environmental Management63132311
    Chemical Management52132200
    Other categories (12)2998143630
    All profiles20977751184841397

    How many profiles document all three

    7 of 209 profiles (3%) name SOC 2 or ISO 27001, document a free trial and document an offline workflow. This page gives the count and not the names, because the offline classification covers only 91 profiles, and such a list would show which products we have reviewed furthest, not which suit a buyer. The full split of the 209 profiles over the three yes-or-no questions is below; the "offline workflow documented" column counts only the documented classification, so a partial workflow is counted as no.

    Number of profiles for each combination of attestation, free trial and documented offline workflow
    Names SOC 2 or ISO 27001Free trial documentedOffline workflow documentedProfiles
    YesYesYes7
    YesYesNo21
    YesNoYes17
    YesNoNo73
    NoYesYes6
    NoYesNo14
    NoNoYes9
    NoNoNo62

    How to read these numbers

    • Named by the vendor, not reviewed by us. Every attestation counted here is a statement on a vendor page. We did not read an audit report or inspect a certificate for any of them, so none is verified, and the counts say how many vendors claim a certification, not how many hold a valid one.
    • A blank is not a negative. A profile with no certification entry may hold a certification that its public pages do not mention, share its report only under a non-disclosure agreement, or be a newer product. Ask the vendor; do not treat a blank as a failed check.
    • A named attestation is not a security assessment. It does not say what the report covers, whether the audit period is current, whether the exceptions are material, or whether the product you would use sits inside the audited system. A SOC 2 report can cover one product of a vendor and not another.
    • The trial and offline fields have different coverage. The trial status was recorded for every profile, with "not established" where the pages are silent. The offline classification has been done for fewer profiles, so every offline figure and the three-way count depend on that coverage and are likely to rise as more profiles are classified.
    • Categories are small. Percentages in a category of five to twelve profiles are shaky; read the counts. The categories are the directory's own, and a product that serves several is counted in one.
    • These are counts of profiles, not of the market. The 209 profiles are the products we have researched, not every QHSE product, and a vendor with a public security page is more likely to show an attestation here than one without.

    What to ask when a profile names an attestation

    1. Which product, service and hosting environment does the report or certificate cover, and is the product you will use inside that scope?
    2. For SOC 2, which type, which period and which trust criteria were audited, and were any exceptions reported? For ISO 27001, which certification body issued the certificate, what is its scope statement and when does it expire?
    3. Can the full report be shared before signature, under a non-disclosure agreement if needed, and who inside your organisation will read it?
    4. What is not covered: subprocessors, customer-specific configurations, mobile apps, integrations and any artificial intelligence features that send data to a third party?
    5. How and when are you told if the certification lapses or the audit finds a significant issue? Put the answer in the contract, not only in the sales deck.

    The RFP template and the demo checklist turn these questions into written requirements and demonstration tasks.

    How the figures were computed

    The figures are computed by a script from the structured profile records, and the page and the CSV are rebuilt from the same output, so a count can change only when a record changes. The certification field holds the name of each certification the vendor states, with a note on where it was found. The script reads the name before the first bracket, so a source note that mentions another scheme is not counted. Free-trial status is the field recorded on each profile. The offline classification is the one the directory uses; a profile that has not been reviewed counts as "not yet classified", and the document-template product counts as "not applicable". A profile's category is its own category, or the catalogue category where the profile has none. Percentages are rounded to whole numbers. Records were checked through 3 October 2026.

    No score, rating, price or payment is an input, and the page does not rank or name any product. The profile set is described in the methodology, and the same records feed the 2026 report on vendor transparency.

    Disclosure. One of the 209 profiles belongs to a vendor that pays for sponsored placement on this site, and the editor works at that vendor. Its record was read by the same rules as every other, it is counted in every figure above like any other profile, and it is not named on this page.

    Download and cite

    One row for all profiles, one for each category with at least 5 profiles and one pooled row for the rest: the counts behind every figure on this page, with no product names. Our compilation is available under CC BY 4.0. The certifications themselves are the vendors' statements and remain unverified in any reuse.

    Download the CSV

    Suggested citation: The QHSE Standard. (2026). Security attestations, free trials and offline support across QHSE software: what 209 profiles document (records checked through 3 October 2026). https://qhsetech.com/qhse-software-security-and-trial-evidence-2026

    Related: the pricing index, search demand, all datasets.