Home > Products > Vendor Checklist
What should you look for in a SaaS vendor?
Your Success = Our Success.
Success is built on trust and trust starts with transparency.
Replicon has a 99.5% proven uptime, so your data is there when you need it.
We are the first timesheet vendor in the Software-as-a-Service industry to make
time data transparent. Visit
http://uptime.replicon.com to see if we are worthy of your trust.
Our track record speaks for itself.
15 Questions to Check the Health of Your SaaS Vendor
How do we guarantee uptime?
- We host your service in state-of-the-art data centers with carrier-level support
in the United States, Canada, United Kingdom and Australia.
- All our infrastructure is monitored live, continuously (24/7/365) by our Global
Operations team. Our servers have more than 200 data points, all of which are actively
monitored to ensure we take action before potential problems become actual problems.
- We have dedicated and fully redundant storage systems to ensure performance and
reliability of your data in any situation including:
- Data tier clustering - automatic failover for high availability and reliability
in many different scenarios
- Load balancing/failover capabilities on both the data and the application tier -
to spread the load over a farm of servers while maintaining high availability
- Inbound/Outbound connection load-balancing and failover - for a fully redundant,
high capacity configuration that scales to provide consistently high performance
- We use dedicated carrier-class bandwidth and multi-gigabit IP transit for external
customer traffic ensure that network issues don’t impact availability.
- We adhere to the Information Technology Infrastructure Library (ITIL) and a number
of other processes and guidelines to ensure we are following the best practices
for incident, problem, change and release management.
- Our rigorous release and change management cycles ensure minimal disruption of service.
Changes to our systems and products are tested thoroughly tested in a variety of
pre-production labs by different teams including Development, Quality Assurance
and Operations. These tests ensure that only high-quality, well-developed changes
make it into the “live” environments and minimize the impact and downtime you experience.
- Our SaaS operations and Research teams regularly investigate and assess new technologies
and methodologies to give you the best possible experience:
- Our database is clustered, any failure is automatically recovered
- We run a storage area network device
- We have an array of application servers with load balancing
- We use multiplier services for built-in redundancy
Do you have financial institutions
using your SaaS software?
Yes. Financial institutions require the highest level of security to protect their data
from all forms of threat: unauthorized access, unauthorized modification, and environmental
factors such as fire or flood. If there is evidence that large financial institutions
are using the software, you can feel confident the vendor's operations are reliable
and secure.
Here are some of the large financial institutions that trust Replicon with their
data:

How will you keep my data secure?
At Replicon, we understand the confidential nature of your data. It is our
responsibility to keep your data safe and secure, and we take this responsibility
very seriously.
- We currently maintain SAS 70 Type II compliance, as well as adhere to a variety
of other well recognized standards such as Sarbanes-Oxley and Defense Contract Audit
Agency (DCAA).
- We take a multi-layered security approach at the physical, environmental, network
and application level.
- Our SaaS software is accessed through a secure connection using SSL certificates
generated from VeriSign
- System security includes rich authentication, authorization and accounting (AAA)
mechanisms.
- Our service provides protection from a wide variety of attacks and spoofing mechanisms
such as cross site scripting (XSS), SQL injection, and a wide variety of other threatening
activities.
- Segregation of duties is defined and enforced by security mechanisms (i.e., Only
operations has access to production systems, and the level of access is further
filtered by role/job function).
- We conduct regular vulnerability scanning of our network, application and system
through internal and third-party testing and assessments.
- Our Information Security department monitors internal systems alerts and notifications
from various sources to identify and manage threats.
Is there a disaster recovery plan?
Yes. We are very diligent about keeping your data safe, reliable and accessible to you
at all times. We prepare for every potential disaster.
Disaster Recovery
- All facilities are identical and transactions are mirrored almost instantly, making
interruption of service related to hardware problems or data issues virtually impossible.
- If one of these facilities goes down-because of a natural disaster, for example-
the software will automatically fall back to the mirrored site with minimal interruption.
Backups
- All data is protected through regularly scheduled full and incremental backups.
- Backup data is shipped to a secure offsite backup location via secure connections
on a regular (scheduled) basis.
Is your company financially sound? Are
you going to be around for a long time?
Yes. To minimize your risk, you want to make sure that the vendor you're working
with today will still be around in the future. Replicon has more than 1.2
million users in 68 countries worldwide. We have always been profitable, with
no debt and a strong balance sheet. For over a decade, we have enabled companies
of all sizes to improve their billing, time and expense tracking, project tracking,
and time and attendance tracking.
Our valued customers include:

Replicon and its solutions were featured in Red Herring, Wall Street Journal, Fortune,
Dow Jones, Information Week and Business Week. The company has been recognized
for the last three consecutive years by Profit Magazine (equivalent to Inc.
magazine in Canada) as one of the fastest growing companies in Canada. Replicon
has been listed on the prestigious Deloitte Technology Fast 50 and most recently
it was selected as a finalist for Ernst Young's Entrepreneur of the Year Award.
How often will the application be
updated?
Rapid Innovation - The days of 18-month or 3-year release cycles are over.
You need to make sure that you will not be stuck with static software that does
not deliver value over the long term. We listen to customers and invest heavily
in research and development. In 2009 alone, we have had:
- 6 major upgrades with new features (version 8.5, 8.7, 8.8, 8.9, 8.10, 8.11)
- 8 updates
- Several minor updates
Replicon customers are always on the latest version, so they can take advantage
of our latest innovations from our Product Development team.
What operational practices do you
have to ensure upgrades happen without disruption?
Most companies who have gone through software upgrade would rather live without
it. We relieve that headache for you by ensuring we provide seamless upgrades
without disruption to your business.
Best-of-Breed Release and Change Management
We adhere to the Information Technology Infrastructure Library (ITIL) and a number
of other processes and guidelines to ensure we are following best practices for
incident, problem, change and release management.
Changes to our systems and products are thoroughly tested in a variety of pre-production
labs by different teams, including Development, Quality Assurance, and Operations.
These tests ensure that only high-quality, well-developed changes make it into the
"live" environments, and minimize the impact and downtime you experience.
What are the integration capabilities?
The SaaS software needs to work with your existing systems. With our Application
Programming Interface (API), you can integrate with any existing project management,
accounting, payroll, HR or ERP system. Our seamless upgrades will not break
your integration.
How will you support my users 24/7?
We believe in fast, reliable and friendly customer service. You get free,
unlimited support with our world-class support team working (24/7) to provide you
the help you need when you need it.
Your users can log customer service requests directly within the software using
the “Customer Portal”, which allows you to communicate with our Customer Support
team and monitor the status of all your requests/inquiries.

To ensure the system is available to you anytime, from anywhere, our entire infrastructure
is monitored live by our Global Operations team (24/7/365) – not by a single individual
who sleeps under a desk and gets alerts via a pager. Our servers are constantly
monitored so we can be proactive – addressing potential issues before you notice
any problems
Please check http://uptime.replicon.com for live uptime status.
Are training programs available?
Yes. While most users will adapt very quickly to our software, we want to make sure you
have the support you need to get up and running smoothly. We provide free
end-user training documentation and free, unlimited online implementation webinars
for all customers. We offer personalized training as part of implementation. Please contact
sales@replicon.com.
Will the SaaS application scale?
Yes. As your business grows, you need to be able add users without any disruption to
your service. Also, as the SaaS vendor grows, and adds more and more customers it
should not affect your service level.
Is the vendor is Multi-tenant SaaS or ASP
"Multi-tenancy" – pioneered by Salesforce.com – is the most significant
paradigm shift in providing scalability, and is the main differentiator between
a true SaaS solution and an ASP solution.
So what does this mean to you?
|
Multi-tenant
|
ASP
|
|
One instance of the software across all customers ensures maintenance and upgrades
are painless.
|
Each customer's solution is run on a separate instance, making the software
difficult to maintain and upgrade. This causes more disruption to your service.
|
|
Customizations are easy, as the software usually includes a configurable interface.
This means less time and cost for you to implement and start seeing value.
|
Customizations are time-consuming and costly, with little or no easy-to-use configuration
options. Implementation is painful, and it takes some time before you start
to see value.
|
|
Configurations and customizations are upgraded seamlessly.
|
Each instance is upgraded individually. Errors are common, and it's likely
that many customizations have to be redone.
|
|
Costs are lower for the vendor to operate, which translates to lower prices for
customers.
|
Costs are higher for the vendor, resulting in higher pricing as more customers are
added.
|
|
It's easy to adhere to the Service Level Agreement, monitoring your service
and fixing problems long before they impact your business.
|
It's nearly impossible to adhere to the Service Level Agreement, as it's
a nightmare to monitor individual instances. Disruptions in service are highly
likely.
|
|
Support is available for tens of thousands of users, making it easy for the vendor
to become a market-leader.
|
Support is good when the customer base is small – typically in the hundreds, forcing
the vendor to limit the number of customers if they want to continue providing quality
service.
|