01 / DATA OWNERSHIP
Ownership must come with usable access.
A customer-ownership clause should come with a way to retrieve and reuse the data. That means documented access to business records, their relationships and the files attached to them. An export should make clear which fields, history and corrections it includes, and what it leaves behind.
Data portability should preserve enough structure to use the result in another system. A pile of reports that requires rebuilding every relationship leaves the customer doing the migration work twice.
02 / THIRD-PARTY ACCESS
Choose your tools, including your AI.
Customers should be able to authorize qualified third parties through documented interfaces. A connector, consultant or AI assistant should face clear security requirements, with scoped permissions and access the customer can revoke. Vendor review should have stated criteria and a predictable process.
AI access needs explicit terms. Using customer data for an authorized task and training a model on it are different uses; vendors should state which they permit. A built-in AI feature shouldn’t give the vendor an exclusive claim over every AI workflow a customer wants to run.
03 / EXTERNAL ACTION
Your system of record should work with your system of action.
Reading data is one capability. Creating a work order, updating a customer record or posting an approved transaction is another. Customers should be able to perform supported operations from their chosen applications, under their own permissions.
Write access needs named operations, an identifiable actor and an audit trail. Safe retries and clear failure results belong in the interface. Customer control includes the ability to approve an action and find out whether it happened.
04 / CONTEXT AND BUSINESS LOGIC
The meaning of your data should travel with it.
Record IDs, field definitions and relationships make data usable. So do customer-created formulas, mappings and workflow rules. Vendors should let customers inspect and export that context, with enough documentation to understand the result outside the original application.
Vendor software can remain proprietary. Customer-authored business logic needs clear ownership and reuse terms of its own. Reconstructing years of operational decisions from screenshots shouldn’t be the exit strategy.
05 / CUSTOMER-BUILT SOFTWARE
Build the application your business needs.
Customers should be able to build interfaces and workflows on top of the systems they already use, through authorized APIs. Document query capabilities, including filters, joins and aggregations, so customers can ask new questions without commissioning a new endpoint for each one. That includes applications written by developers and applications built with AI coding tools. Vibe coding still needs documented schemas, permissions and a dependable way to test.
Custom applications should have a path to run outside the vendor’s app builder. Code, configuration and customer-created rules need explicit export and reuse terms. A new interface is useful only if the customer can keep using and maintaining it.
06 / API PRICING AND TERMS
Basic access belongs in the basic plan.
Structured access to customer records should be included on the lowest paid plan, free or priced for light usage without a fixed access surcharge. Publish which objects and operations it covers, and which integrations need separate approval. State setup fees, recurring charges and usage limits before customers commit. An API listed on a product page tells buyers little if its usable scope is hidden in a later contract.
Vendors can charge for services they provide. Charges for an export or connection should identify the service, its cost and its limits. Customers need enough information to compare the full cost of staying, connecting and leaving. State the steps and expected time to first usable access, including agreements, security reviews and pilot testing. A nominal API entitlement can still be unusable when activation takes an open-ended project.
07 / CONTINUITY
Access should be dependable.
A working integration becomes part of a business’s operations. Vendors should document rate limits, change feeds and recovery behavior, and give notice before changing interfaces or access terms. Security incidents may need immediate intervention; routine commercial changes need a migration path.
Customers should know what happens to their data and connections if a product shuts down, a partner is removed or an account is suspended. Continuity belongs in the agreement before an interruption occurs.
08 / VENDOR LOCK-IN
Leaving should be a supported workflow.
Document the export process, retrieval window and assistance costs before cancellation. Customers should be able to take a usable copy to a destination they control, verify what arrived and understand what will be deleted. Retaining a backup for thirty days doesn’t give the customer thirty days of retrieval access.
SaaS can offer convenience and still preserve customer choice. The customer should be able to replace one part of the stack without losing the records and rules needed to run the business.
What does data sovereignty mean in SaaS?
Data sovereignty concerns the legal authority over data; data residency describes where it is stored. Hosting location alone doesn’t settle which laws apply. Read the distinction ↗
With software as a service (SaaS), practical control also depends on the provider’s interfaces and terms. Free Your Stack asks how much control you can exercise: ownership, API access and the ability to leave each need their own proof. Our grades assess those capabilities; they don’t certify jurisdiction or legal compliance.
These are the standards we want SaaS vendors to meet (not a claim that every customer already has these rights). They apply whether you buy a hosted service or run software yourself.
Hold vendors to concrete answers.
We turn these standards into questions about specific products, plans and access routes. Our scoring methodology links each documented answer to its source and derives grades across six dimensions. Unresolved inputs stay visible; documentary grades don’t stand in for testing export completeness or reliability.
Start with the software vendor directory or compare the property-management software reviews. Read the terms behind the grade. Ask for missing answers before you buy.
Related ideas
These manifestos and essays address control from other angles: the User Data Manifesto, Zero Data App, File over app and Bring Your Own Client.