Software as a Service (SaaS) is software you use over the internet instead of installing and running yourself. The vendor hosts the application, keeps it updated and secures the infrastructure underneath it. It is most often sold as a recurring subscription, usually priced per user, though usage-based and other pricing models exist. Email and office suites, CRM, accounting, HR and help desk tools are all commonly bought this way.
At a glance
- The vendor hosts and runs the software; you use it over the internet, with no servers, upgrades or patches of your own.
- It is usually sold as a subscription, most often per user, billed monthly or annually; some products price by usage.
- The vendor protects its platform, but your data, users and settings are still your responsibility.
- Costs creep through unused seats, tier upgrades, price escalators and auto-renewals.
- Your exit terms (data export, notice periods) matter as much as the features.
What problem it solves
Before SaaS, running business software meant buying licenses up front, providing servers to run it on, and staffing the upgrades, patches and backups. Every new version was a project. SaaS moves that work to the vendor. A team can be using a new tool within days, the vendor ships updates continuously, and the cost becomes a predictable operating expense instead of a capital purchase plus maintenance.
It also makes software easy to buy, which creates the problems buyers deal with today. Any department with a credit card can sign up for an app, so companies end up with overlapping tools, accounts nobody owns, and company data sitting in services IT has never reviewed (often called shadow IT or SaaS sprawl).
How it works
Most SaaS runs as one service that many customers share (multi-tenant), with each customer’s data kept logically separate. You reach it through a browser, a desktop or mobile app, or an API.
Licensing. Most SaaS is priced per user (a “seat”), in tiers such as basic, standard and enterprise, with features like single sign-on, audit logs or longer data retention often reserved for higher tiers. Some products price by usage instead: records, API calls, storage, or transactions. Annual contracts usually carry a discount over monthly billing in exchange for a fixed commitment. Many contracts renew automatically unless you give notice within a set window, and some allow you to add users mid-term but not remove them until renewal, with a “true-up” charge if your actual use exceeded what you bought.
Shared responsibility. The vendor is responsible for the application, the infrastructure and keeping the service available. You remain responsible for who has access, how the service is configured and the data you put into it. Built-in retention and recycle bins are designed for convenience, not as a backup you control: once an item ages out of the vendor’s retention window, or an admin or attacker deletes it, it may be gone. That is why third-party backup for Microsoft 365, Google Workspace and similar platforms is a common add-on.
Identity. Most companies connect SaaS apps to a central identity provider. Single sign-on (SSO) lets people log in with one corporate account, and SCIM (System for Cross-domain Identity Management) provisioning creates and removes accounts automatically when people join or leave. Without these, offboarding depends on someone remembering every app a departing employee used.
When it matters for buyers
- At renewal. Renewal is where most SaaS overspend happens: auto-renewal at list price, seats bought for a headcount you no longer have, and an annual price escalator that compounds year after year. Review usage and give notice before the window closes.
- When tools multiply. If several teams pay for similar apps, consolidating them saves money and reduces the number of places company data lives.
- When data protection or compliance is in scope. Auditors, cyber insurers and customers increasingly ask where your data lives, who can reach it and whether you can restore it. “It’s in the cloud” is not an answer to any of those.
- When someone leaves or a company is acquired. Inherited apps, shared admin accounts and personal sign-ups are where access lingers.
- When choosing a vendor. Data residency (which country or region your data is stored in), export formats and termination terms decide how hard it will be to leave later.
Questions to ask vendors
- What is the renewal term and notice window, and is there a cap on price increases at renewal?
- Can we reduce seats during the term or at renewal, and how are true-ups calculated?
- Which features (SSO, SCIM provisioning, audit logs, data retention) require a higher tier?
- What is the uptime SLA, how is it measured, and what credit do we get if you miss it?
- Which independent security reports can you share, such as a SOC 2 Type II report or ISO 27001 certification, and do they cover the product we’re buying?
- Where is our data stored, and can we choose the region?
- How long do you keep deleted data, and can you restore a single user’s or item’s data on request?
- When we leave, how do we export all of our data, in what format, and how long do we have to do it?
How it differs from Security as a Service (SECaaS)
SaaS describes how software is delivered: the vendor hosts and runs it, and you use it over the internet. Security as a Service (SECaaS) is one category within that model, covering security tools such as email filtering, secure web gateways and managed detection delivered from the cloud. The two get mixed up because the acronyms look alike, but “SaaS” on its own refers to applications in general; security services delivered this way are SECaaS. SaaS also differs from Platform as a Service (PaaS), where the vendor provides the environment and you build and run your own applications on it.
