AWRA OpsHub Search

Ten Questions to Ask Any ERP Vendor About Where Your Data Lives

The questions that tell you how a vendor really holds your records, what a good answer sounds like, and how we answer each one ourselves. Take it into every sales call, ours included.

Security & Compliance Washingtone Aura 9 min read

Why this list

Vendor demos are about features. Where your records live is decided in a different conversation, and usually not one the buyer starts. Ten questions are enough to find out how a vendor holds your data, and every one of them has an answer a good vendor can give in a sentence or two.

Ask them in this order. The first three tell you how your records are kept apart from everyone else’s. The middle four tell you who and what can reach them. The last three tell you whether you can leave, and whether you can grow without leaving.

Are my records in a database shared with other customers?

Why ask: it is the plainest question and the one most often answered with a diagram instead of a yes or a no. A good answer is a yes or a no, followed by what that means. Ours: on the shared service, yes, and the software keeps organizations apart. On a dedicated instance, no: the database holds your organization alone.

If it is shared, what keeps it apart, and what happens when that fails?

Why ask: separation in software is sound, but its failure mode matters. A good answer says what the system does when it cannot tell whose request it is serving. Ours: every request is tied to its organization, and a request that cannot establish one gets nothing back, rather than everything.

Are my records encrypted with a key that is mine?

Why ask: “encrypted at rest” is common; “with a key used for no one else” is not. A good answer says how many organizations share the key. Ours: the shared service uses one key for the whole service. A dedicated instance has a key generated for it alone.

Which region are my records hosted in, and can that go in the contract?

Why ask: some obligations name a country or region. A good answer names the region and says whether it is a setting or a deployment. Ours: region belongs to the deployment rather than to an account, which where your data lives explains in full. A region set in your contract is something we scope as its own piece of work.

Who are your sub-processors, and where are they?

Why ask: your vendor’s vendors hold your data too. A good answer is a published list with each provider’s region and purpose, not a promise to send one. Ours: the register is published, and a dedicated instance uses the same list unless your contract trims it.

Who on the vendor’s side can see my records, and is it recorded?

Why ask: support staff need some access to help you, and that access should be limited and visible. A good answer names the roles that can reach customer data, the reason they would, and where that access is logged. Ask to see the policy, not only to hear it.

How often are my records backed up, and where do the backups live?

Why ask: a backup that has never been restored is a hope. A good answer gives a frequency, a location separate from the live system, and when a restore was last tested. On a dedicated instance, also ask whether your backups are a set of their own. Ours are.

Can I get everything out, in a usable format, without asking permission?

Why ask: the day you need to leave is not the day to discover your data is hostage. A good answer describes a self-service export of your records and what follows it. Ours: an export of your organization’s records, and removal afterwards if you ask for it.

What happens to my records if I stop paying?

Why ask: a missed payment should not become a lost archive. A good answer describes a grace period and says plainly what is and is not deleted. Ours: nothing is deleted for non-payment. The billing lifecycle sets out what happens, step by step.

If I need my own system later, can I have one without changing product?

Why ask: requirements change when a new funder, regulator or board arrives. A good answer is a dedicated option on the same product, so moving does not mean retraining everyone. Ours: yes. A dedicated instance runs the same code as the shared service, and shared or dedicated sets out what actually changes.

A vendor who answers all ten in a sentence each has nothing to hide. A vendor who answers with a slide deck usually does.

The straight answer

What AWRA OpsHub does today

  • A published sub-processor register with each provider’s region and purpose.
  • A shared service that returns nothing to a request it cannot tie to an organization.
  • A dedicated instance with its own database, encryption key, storage and backup set.
  • An export of your records, and nothing deleted for non-payment.

More we can add to your workspace

  • A hosting region of your choosing, set in the contract.
  • A sub-processor list trimmed to your contract on a dedicated instance.
  • Your current workspace moved to a dedicated instance with its full history.

Where we point you to a specialist

  • We do not answer a vendor risk assessment on your behalf. Your reviewer should check our answers against your own policy, and we will put them in writing.

Each of these can be scoped into a dedicated-instance quote.

More we can add

When an answer needs to change

If one of our ten answers does not meet your requirement, these are the ways we change it for your organization.

Your region

Hosting in the country or region your obligation names, set in the contract.

Your provider list

Optional services switched off so the sub-processor list matches your policy.

Your history, moved across

An existing shared workspace moved to a dedicated instance with its records intact.

How it works: tell us which answer needs to change and why, and we return a written scope and cost.

See the dedicated instance

Reading the answers

Any question

If you hear

“We will get back to you on that.”

It usually means

Nobody has asked before. Get it in writing before you sign.

Region

If you hear

“You can choose in settings.”

It usually means

Check what actually moves. Region usually belongs to the deployment.

Export

If you hear

“Raise a ticket and we will send it.”

It usually means

Leaving depends on the vendor’s goodwill.

Your own system

If you hear

“That would be a different product.”

It usually means

Growing into it will mean starting again.

Ask us all ten

We will answer each one in writing, and show you the dedicated option if your answers need to be shorter.

See the dedicated instance

Frequently asked questions

What should I ask an ERP vendor about data hosting?

Whether your records share a database, what keeps them apart, whose key encrypts them, which region hosts them, who the sub-processors are, who on the vendor side can see them, how they are backed up, how you get them out, what happens if you stop paying, and whether you can move to your own system without changing product.

What is a good answer about data separation on a shared system?

One that says what the system does when it cannot tell which organization a request belongs to. The safe behaviour is to return nothing rather than everything.

Can I choose my hosting region in a settings screen?

Usually not in a meaningful way. Region normally belongs to the deployment, so a region requirement is met by the deployment you are on and written into the contract.

What happens to AWRA records if a payment is missed?

Nothing is deleted for non-payment. The billing lifecycle page sets out the grace period and what happens at each step.

Share this article

LinkedIn X WhatsApp

Help Center

Need a quick answer while you read?

Run inventory, procurement, assets, sales, and field work with approved AWRA guidance for setup, migration, integrations, security, pricing, and support.

Search all approved AWRA public help articles.

Open Help Center