When a vendor tells you your data is “in the cloud,” it’s easy to picture something abstract and weightless. It isn’t. Your data is on physical hard drives, in a specific building, in a specific city, owned or rented by a specific company, guarded (or not) by specific people. “The cloud” is just someone else’s computer in someone else’s data center.
For a small business or a healthcare practice, that matters more than it sounds. Every SaaS app you sign up for, every website host, every online backup, every EHR — each one is a decision to trust a data center you will never visit with data you are responsible for. This post is a plain-English guide to what actually protects data in those buildings, and the specific questions to ask a vendor so you can tell the serious ones from the ones hoping you won’t ask.
The cloud is someone else’s building¶
A data center is a warehouse full of servers, engineered so those servers never stop: redundant power with battery and generator backup, industrial cooling, thick network pipes, and physical security around the whole thing. The big providers — the ones most SaaS tools quietly run on — operate these at a scale and standard almost no small business could match on its own. That’s genuinely a reason to use the cloud, not avoid it.
But “runs in a great data center” and “handles your data well” are two different claims. A sloppy SaaS vendor can rent space in a world-class facility and still leave your data exposed through weak access controls, no encryption, or a database left open to the internet. The building is the floor, not the ceiling. So you have to ask about both: where the data lives, and how the vendor handles it there.
Why this is your problem, not just theirs¶
Here’s the part that surprises people: handing data to a vendor does not hand off the responsibility for it. If a SaaS provider you use gets breached and your clients’ information spills, your clients call you, not them. Under HIPAA, a practice stays accountable for protected health information even when a “business associate” is the one that lost it — which is exactly why a signed Business Associate Agreement exists. And when an enterprise client or an insurer sends you a security questionnaire, a chunk of it is really asking, “who are your vendors, and how do you know they’re safe?”
You don’t need to become an auditor. You need to ask a handful of pointed questions and keep the answers on file. That single habit turns a scary, invisible risk into something you can actually manage.
What data-center security actually covers¶
When people say “is the data center secure,” they’re really asking about a stack of separate things. In plain terms:
- Physical security. Who can walk in? Real facilities have badge access, cameras, guards, and logs of who entered. Servers holding your data shouldn’t be somewhere a stranger can reach.
- Power and cooling redundancy. Backup power and cooling so a local outage doesn’t take your data (or your access to it) offline. This is the “uptime” part of the promise.
- Network and tenant isolation. The provider hosts thousands of customers on shared hardware. Strong isolation keeps another customer — or an attacker who compromises one — from reaching your data.
- Encryption at rest and in transit. Data scrambled while it’s stored on disk (“at rest”) and while it’s moving over the network (“in transit”), so a stolen drive or a sniffed connection yields gibberish.
- Backups and geographic redundancy. Copies kept, and ideally in more than one location, so a fire, flood, or ransomware event in one facility doesn’t erase everything.
- Independent audits. Someone other than the vendor has checked all of the above and put their name on it — usually a SOC 2 Type II report or ISO 27001 certification.
You don’t have to understand the engineering. You just need to know these categories exist, so you can ask whether each one is handled.
The questions to ask a vendor¶
Here is the short, non-technical list. You can send these in an email to any hosting, SaaS, or cloud vendor before you trust them with anything sensitive.
- Where is my data stored and processed? Which country and region? For some regulated or contractual situations, the answer matters legally.
- Is my data encrypted at rest and in transit? The answer should be a clear yes to both.
- Who can access my data, and how is that controlled? Look for role-based access, MFA for their staff, and the principle that employees only see what they need to.
- Can you provide a current SOC 2 Type II report or ISO 27001 certificate? This is the single most useful question. A serious provider has one ready.
- Will you sign a BAA (for health data) or a data processing agreement? If you handle regulated data and they won’t sign, that’s often a dealbreaker.
- What are your backup and recovery commitments, and have they been tested? How often are backups taken, how fast can they restore, and can they prove a restore actually works?
- How and when would you notify me of a breach? You want a defined process and timeline in writing, not a shrug.
What good answers look like¶
A trustworthy vendor answers these easily, often by pointing you to a security page, a trust portal, or an audit report they can share under NDA. They’ll say things like “yes, encrypted at rest with AES-256 and in transit with TLS,” “here’s our current SOC 2 Type II,” and “we’ll sign a BAA.” They won’t be annoyed you asked; being asked is normal for them.
You’re not looking for perfection. You’re looking for a vendor who clearly takes this seriously and can prove it with an independent audit rather than just assuring you.
Red flags¶
A few answers should make you slow down. Vagueness (“don’t worry, it’s totally secure” with no specifics). No independent audit and no plan to get one. Refusal to sign a BAA or DPA when you handle regulated data. No clear breach-notification commitment. And “we don’t encrypt at rest because it’s not necessary” — in 2026, it’s table stakes. None of these is automatically disqualifying for a low-risk tool, but for anything touching sensitive data, they’re worth a hard second look.
How this ties to compliance¶
This isn’t just good hygiene — it’s increasingly required. HIPAA expects you to have BAAs with vendors that touch protected health information and to exercise reasonable diligence over them. Cyber insurance applications ask about your vendors. Enterprise clients bake vendor questions into the questionnaires they send you. Keeping a simple folder of each key vendor’s answers and audit reports means that when any of those asks arrive, you already have the receipts instead of a scramble.
Where to start¶
You almost certainly can’t re-audit your vendors, and you don’t need to. Start with the two or three that hold your most sensitive data — your EHR, your main SaaS platform, your backup provider — and send them the question list above. Save the answers. That’s a vendor-risk program a small business can actually sustain.
This is a core part of what we do for small and mid-sized businesses: helping you figure out which vendors matter, asking them the right questions, and writing down the answers so a future audit, insurer, or enterprise client is easy to satisfy. Our Cyber Essentials package includes a vendor-risk policy and a simple template for tracking exactly this, so “do we vet our vendors” has a real, written answer.
If you’re not sure which of your vendors actually protect your data, email support@breachsecurity.io with a rough list of the main tools you use. We’ll tell you which ones are worth a closer look and help you ask them the right questions.