Security attestations, free trials and offline support across QHSE software: what 209 profiles document
Three questions come up early in almost every QHSE software evaluation: does the vendor hold a security attestation, can we try the product without paying, and does it work without a connection. This page counts what our 209 researched profiles document on each, overall and by category. 118 profiles (56%) name SOC 2 or ISO 27001, 48 (23%) document a free trial, and 39 (19%) document an offline workflow. Every attestation is a statement by the vendor that we did not verify, and a missing statement is not evidence that a certification does not exist.
Editorial responsibility: Dimitris Mitsios (Founder of The QHSE Standard; product marketing at Tekmon) · Tekmon pays for sponsored placements on this site (disclosure) · How pages are made · LinkedIn · Content date: 3 October 2026
What the records show
- More than half of the profiles name a security attestation. 118 of 209 (56%) name SOC 2 or ISO 27001. SOC 2 appears in 77 profiles and ISO 27001 in 75; 34 name both. Of the 77 that name SOC 2, 59 name a Type II report, 3 name Type I only and 15 do not say which type.
- 83 profiles have no certification entry. That is 40% of the records. It means we recorded none, not that the vendor holds none: the records come from vendor pages, so a vendor that shares its reports only after a sales conversation, or whose trust portal was not among the pages reviewed, shows up here as a blank. A further 8 profiles name only other schemes, such as an ISO 9001 quality certificate, without SOC 2 or ISO 27001.
- The share varies by category, but the categories are small. Among the 12 categories with at least 5 profiles, the share naming SOC 2 or ISO 27001 is lowest in Occupational Health (4 of 11, 36%) and highest in Asset Management (6 of 7, 86%) and Construction Safety (6 of 7, 86%). With between 5 and 43 profiles in a category, one added or corrected record moves a percentage by several points, so treat the spread as a pattern in this sample and not as a property of a software type.
- A documented free trial is the minority position. 48 of 209 (23%) document a free trial, 41 of 209 (20%) offer a trial or demo only on request, and for 120 of 209 (57%) we could not establish either. By category, the share with a documented free trial is lowest in Emergency Management (0 of 6, 0%) and highest in Audits & Inspections (11 of 15, 73%).
- Offline support is the least classified of the three. 39 of 209 (19%) have a documented offline workflow and 51 of 209 (24%) a partial one. 1 is recorded as needing a connection for the workflow we assessed, 1 is not applicable (document templates, where offline use is not a meaningful question), and 117 of 209 (56%) are not yet classified. Among the 91 profiles that have been classified, 39 of 91 (43%) are documented as working offline and 51 of 91 (56%) partly.
- Few profiles document all three, partly because the offline field is incomplete. 7 profiles name SOC 2 or ISO 27001, document a free trial and document an offline workflow. 28 combine an attestation with a free trial and 24 combine an attestation with a documented offline workflow. A documented free trial is about as common among profiles that name an attestation (28 of 118 (24%)) as among those that do not (20 of 91 (22%)), so in these records the two are not linked.
Security attestations named by the vendor
A certification counts here when a vendor page names it. We read the name of each entry: "SOC 2" matches any SOC 2 report, "Type II" is counted separately when the entry says Type II or Type 2, and "ISO 27001" matches every edition of the standard, with or without the "IEC" prefix. 260 entries are recorded across 126 profiles; 231 of them say in so many words that the report or certificate was not reviewed, and none records a document that was.
Text version of this chart
- SOC 2 (any type): 77 of 209 (37%).
- SOC 2 Type II: 59 of 209 (28%).
- ISO 27001: 75 of 209 (36%).
- SOC 2 or ISO 27001: 118 of 209 (56%). Highlighted in the chart.
- No certification entry: 83 of 209 (40%).
| Named by the vendor | Profiles | Share of 209 |
|---|---|---|
| SOC 2, any type | 77 | 37% |
| SOC 2 Type II or Type 2 | 59 | 28% |
| SOC 2 Type I only | 3 | 1% |
| SOC 2 with the type not stated | 15 | 7% |
| ISO 27001 | 75 | 36% |
| Both SOC 2 and ISO 27001 | 34 | 16% |
| SOC 2 or ISO 27001 | 118 | 56% |
| Only other certifications | 8 | 4% |
| No certification entry | 83 | 40% |
Other schemes appear less often. Each row counts a profile once, however many of the listed schemes it names, and a profile can appear in several rows:
| Other schemes named | Profiles | Share of 209 |
|---|---|---|
| ISO 9001, 14001, 45001, 13485 or 22301 | 27 | 13% |
| ISO/IEC 27017, 27018, 27701 or 42001 | 9 | 4% |
| SOC 1, SOC 3 or ISAE 3000 | 12 | 6% |
| CSA STAR | 6 | 3% |
| FedRAMP, TX-RAMP or CMMC | 10 | 5% |
| HIPAA or HITRUST | 8 | 4% |
| Cyber Essentials or Cyber Essentials Plus | 9 | 4% |
The schemes answer different questions. SOC 2 is an audit report written by an independent accounting firm about a described system and a set of trust criteria; a Type I report looks at how controls are designed on one date, a Type II report at whether they operated over a period, commonly three to twelve months. ISO 27001 is a certificate for an information security management system, issued by a certification body after an audit, and it covers the scope written on the certificate. ISO 9001, 14001 and 45001 concern quality, environmental and safety management and say little about how a software product protects customer data. Neither SOC 2 nor ISO 27001 is a government certification, and a profile that names one has not thereby said which of its products or hosting locations the report covers.
Free trials
Each profile carries one of three trial states. "Free trial documented" means the vendor's own pages advertise a free trial. "Trial or demo on request" means access follows a request or registration form, or a conversation with the vendor, which does not by itself establish that the product is free to try. "Not established" means our research did not find a statement either way; it is not a finding that no trial exists.
| Trial status | Profiles | Share of 209 |
|---|---|---|
| Free trial documented | 48 | 23% |
| Trial or demo on request | 41 | 20% |
| Not established | 120 | 57% |
A trial that the vendor documents is worth using early in a shortlist, because it lets a team test the workflows that matter before a contract exists. Ask what the trial includes: a trial limited to a sandbox with sample data will not show how imports, permissions or the integrations you need behave in your own environment, and a trial may leave out single sign-on and the administrator features that a security review depends on.
Offline support
The offline classification is the one used in the directory filter. "Documented" means the reviewed pages describe an offline workflow for the assessed use. "Partial" means some functions work offline and others do not. "Connection required" means the assessed workflow needs a connection. "Not yet classified" means the profile has not been through the offline review, which is a statement about our coverage, not about the product.
| Offline classification | Profiles | Share of 209 |
|---|---|---|
| Documented offline workflow | 39 | 19% |
| Partial offline workflow | 51 | 24% |
| Connection required for the assessed workflow | 1 | 0% |
| Not applicable (document templates) | 1 | 0% |
| Not yet classified | 117 | 56% |
Text version of this chart
- Free trial documented: 48 of 209 (23%).
- Trial or demo on request: 41 of 209 (20%).
- Offline workflow documented: 39 of 209 (19%).
- Partial offline workflow: 51 of 209 (24%).
- Offline not yet classified: 117 of 209 (56%).
For field work the useful questions are narrower than the label. Ask the vendor to show the exact task your inspectors perform, starting with no connection, including photos and signatures, and then reconnecting; ask what happens when two people edit the same record offline. The guide to offline inspection apps sets out that demonstration step by step.
By category
The charts below use the 12 categories with at least 5 profiles, which together hold 180 of the 209 profiles. The other 12 categories hold 29 profiles between them and are pooled in the table and the CSV, so that no row describes one or two products. A profile belongs to one category, the one shown in the directory.
Text version of this chart
- EHS Management (43): 19 of 43 (44%).
- ESG & Sustainability (30): 21 of 30 (70%).
- Quality Management (22): 13 of 22 (59%).
- QHSE Management (16): 11 of 16 (69%).
- Audits & Inspections (15): 7 of 15 (47%).
- Safety Management (12): 7 of 12 (58%).
- Occupational Health (11): 4 of 11 (36%).
- Asset Management (7): 6 of 7 (86%).
- Construction Safety (7): 6 of 7 (86%).
- Emergency Management (6): 4 of 6 (67%).
- Environmental Management (6): 3 of 6 (50%).
- Chemical Management (5): 3 of 5 (60%).
- Under 25% of the category
- 25% to 49%
- 50% or more
Text version of this grid
- Category: EHS Management (43)
- Names SOC 2 or ISO 27001: 19 of 43 (44%) (25% to 49%); Free trial documented: 5 of 43 (12%) (Under 25% of the category); Offline workflow documented: 7 of 43 (16%) (Under 25% of the category).
- Category: ESG & Sustainability (30)
- Names SOC 2 or ISO 27001: 21 of 30 (70%) (50% or more); Free trial documented: 2 of 30 (7%) (Under 25% of the category); Offline workflow documented: 1 of 30 (3%) (Under 25% of the category).
- Category: Quality Management (22)
- Names SOC 2 or ISO 27001: 13 of 22 (59%) (50% or more); Free trial documented: 5 of 22 (23%) (Under 25% of the category); Offline workflow documented: 1 of 22 (5%) (Under 25% of the category).
- Category: QHSE Management (16)
- Names SOC 2 or ISO 27001: 11 of 16 (69%) (50% or more); Free trial documented: 3 of 16 (19%) (Under 25% of the category); Offline workflow documented: 10 of 16 (63%) (50% or more).
- Category: Audits & Inspections (15)
- Names SOC 2 or ISO 27001: 7 of 15 (47%) (25% to 49%); Free trial documented: 11 of 15 (73%) (50% or more); Offline workflow documented: 10 of 15 (67%) (50% or more).
- Category: Safety Management (12)
- Names SOC 2 or ISO 27001: 7 of 12 (58%) (50% or more); Free trial documented: 6 of 12 (50%) (50% or more); Offline workflow documented: 1 of 12 (8%) (Under 25% of the category).
- Category: Occupational Health (11)
- Names SOC 2 or ISO 27001: 4 of 11 (36%) (25% to 49%); Free trial documented: 3 of 11 (27%) (25% to 49%); Offline workflow documented: 0 of 11 (0%) (Under 25% of the category).
- Category: Asset Management (7)
- Names SOC 2 or ISO 27001: 6 of 7 (86%) (50% or more); Free trial documented: 4 of 7 (57%) (50% or more); Offline workflow documented: 3 of 7 (43%) (25% to 49%).
- Category: Construction Safety (7)
- Names SOC 2 or ISO 27001: 6 of 7 (86%) (50% or more); Free trial documented: 2 of 7 (29%) (25% to 49%); Offline workflow documented: 2 of 7 (29%) (25% to 49%).
- Category: Emergency Management (6)
- Names SOC 2 or ISO 27001: 4 of 6 (67%) (50% or more); Free trial documented: 0 of 6 (0%) (Under 25% of the category); Offline workflow documented: 0 of 6 (0%) (Under 25% of the category).
- Category: Environmental Management (6)
- Names SOC 2 or ISO 27001: 3 of 6 (50%) (50% or more); Free trial documented: 2 of 6 (33%) (25% to 49%); Offline workflow documented: 1 of 6 (17%) (Under 25% of the category).
- Category: Chemical Management (5)
- Names SOC 2 or ISO 27001: 3 of 5 (60%) (50% or more); Free trial documented: 2 of 5 (40%) (25% to 49%); Offline workflow documented: 0 of 5 (0%) (Under 25% of the category).
| Category | Profiles | SOC 2 | ISO 27001 | Either | Free trial | Trial on request | Offline documented | All three |
|---|---|---|---|---|---|---|---|---|
| EHS Management | 43 | 9 | 14 | 19 | 5 | 12 | 7 | 0 |
| ESG & Sustainability | 30 | 16 | 15 | 21 | 2 | 1 | 1 | 0 |
| Quality Management | 22 | 7 | 10 | 13 | 5 | 6 | 1 | 0 |
| QHSE Management | 16 | 4 | 9 | 11 | 3 | 2 | 10 | 1 |
| Audits & Inspections | 15 | 6 | 2 | 7 | 11 | 3 | 10 | 3 |
| Safety Management | 12 | 5 | 3 | 7 | 6 | 1 | 1 | 0 |
| Occupational Health | 11 | 3 | 1 | 4 | 3 | 3 | 0 | 0 |
| Asset Management | 7 | 4 | 4 | 6 | 4 | 0 | 3 | 2 |
| Construction Safety | 7 | 6 | 4 | 6 | 2 | 1 | 2 | 0 |
| Emergency Management | 6 | 3 | 3 | 4 | 0 | 1 | 0 | 0 |
| Environmental Management | 6 | 3 | 1 | 3 | 2 | 3 | 1 | 1 |
| Chemical Management | 5 | 2 | 1 | 3 | 2 | 2 | 0 | 0 |
| Other categories (12) | 29 | 9 | 8 | 14 | 3 | 6 | 3 | 0 |
| All profiles | 209 | 77 | 75 | 118 | 48 | 41 | 39 | 7 |
How many profiles document all three
7 of 209 profiles (3%) name SOC 2 or ISO 27001, document a free trial and document an offline workflow. This page gives the count and not the names, because the offline classification covers only 91 profiles, and such a list would show which products we have reviewed furthest, not which suit a buyer. The full split of the 209 profiles over the three yes-or-no questions is below; the "offline workflow documented" column counts only the documented classification, so a partial workflow is counted as no.
| Names SOC 2 or ISO 27001 | Free trial documented | Offline workflow documented | Profiles |
|---|---|---|---|
| Yes | Yes | Yes | 7 |
| Yes | Yes | No | 21 |
| Yes | No | Yes | 17 |
| Yes | No | No | 73 |
| No | Yes | Yes | 6 |
| No | Yes | No | 14 |
| No | No | Yes | 9 |
| No | No | No | 62 |
How to read these numbers
- Named by the vendor, not reviewed by us. Every attestation counted here is a statement on a vendor page. We did not read an audit report or inspect a certificate for any of them, so none is verified, and the counts say how many vendors claim a certification, not how many hold a valid one.
- A blank is not a negative. A profile with no certification entry may hold a certification that its public pages do not mention, share its report only under a non-disclosure agreement, or be a newer product. Ask the vendor; do not treat a blank as a failed check.
- A named attestation is not a security assessment. It does not say what the report covers, whether the audit period is current, whether the exceptions are material, or whether the product you would use sits inside the audited system. A SOC 2 report can cover one product of a vendor and not another.
- The trial and offline fields have different coverage. The trial status was recorded for every profile, with "not established" where the pages are silent. The offline classification has been done for fewer profiles, so every offline figure and the three-way count depend on that coverage and are likely to rise as more profiles are classified.
- Categories are small. Percentages in a category of five to twelve profiles are shaky; read the counts. The categories are the directory's own, and a product that serves several is counted in one.
- These are counts of profiles, not of the market. The 209 profiles are the products we have researched, not every QHSE product, and a vendor with a public security page is more likely to show an attestation here than one without.
What to ask when a profile names an attestation
- Which product, service and hosting environment does the report or certificate cover, and is the product you will use inside that scope?
- For SOC 2, which type, which period and which trust criteria were audited, and were any exceptions reported? For ISO 27001, which certification body issued the certificate, what is its scope statement and when does it expire?
- Can the full report be shared before signature, under a non-disclosure agreement if needed, and who inside your organisation will read it?
- What is not covered: subprocessors, customer-specific configurations, mobile apps, integrations and any artificial intelligence features that send data to a third party?
- How and when are you told if the certification lapses or the audit finds a significant issue? Put the answer in the contract, not only in the sales deck.
The RFP template and the demo checklist turn these questions into written requirements and demonstration tasks.
How the figures were computed
The figures are computed by a script from the structured profile records, and the page and the CSV are rebuilt from the same output, so a count can change only when a record changes. The certification field holds the name of each certification the vendor states, with a note on where it was found. The script reads the name before the first bracket, so a source note that mentions another scheme is not counted. Free-trial status is the field recorded on each profile. The offline classification is the one the directory uses; a profile that has not been reviewed counts as "not yet classified", and the document-template product counts as "not applicable". A profile's category is its own category, or the catalogue category where the profile has none. Percentages are rounded to whole numbers. Records were checked through 3 October 2026.
No score, rating, price or payment is an input, and the page does not rank or name any product. The profile set is described in the methodology, and the same records feed the 2026 report on vendor transparency.
Disclosure. One of the 209 profiles belongs to a vendor that pays for sponsored placement on this site, and the editor works at that vendor. Its record was read by the same rules as every other, it is counted in every figure above like any other profile, and it is not named on this page.
Download and cite
One row for all profiles, one for each category with at least 5 profiles and one pooled row for the rest: the counts behind every figure on this page, with no product names. Our compilation is available under CC BY 4.0. The certifications themselves are the vendors' statements and remain unverified in any reuse.
Download the CSVSuggested citation: The QHSE Standard. (2026). Security attestations, free trials and offline support across QHSE software: what 209 profiles document (records checked through 3 October 2026). https://qhsetech.com/qhse-software-security-and-trial-evidence-2026
Related: the pricing index, search demand, all datasets.