Skip to content
TrustList
Blog

What buyers look for in new software when products change every month

Editorial

By TrustList Editorial

Products now launch and change monthly. What careful buyers check first: the operating company, a dated price, the data contract, exit terms, AI switches, notice periods and security evidence.

About What buyers look for in new software when products change every month

What buyers look for in new software when products change every month

In September 2026 our launch board recorded 60 launches dated that month: 28 new AI models and 32 new products. When we reviewed the product launches, a pattern repeated. Many were relaunches of something that already existed under another name. Many did not name the company that operates the product. Several published no price at all, only a button to book a call. A buyer looking at that month's launches would often have struggled to answer the two most basic questions about a supplier: who are you, and what will this cost?

Our news desk tracked a second pattern. In September we logged 28 changes that vendors announced to existing customers, each with a notice date and an effective date. The median notice was 31 days. Six gave a week or less, and three took effect on the day they were announced. Eight gave more than 90 days. Four of the 28 switched a feature on by default for customers who were already paying, so the customer had to find the setting and turn it off. And when we drew 1,000 company listings at random from our own catalogue on 24 September, 171 of their websites no longer led to the business as listed. They were parked, for sale, redirected somewhere else or gone.

Those three counts describe the conditions buyers now work in. Products appear quickly, change often, and sometimes disappear. This article sets out what careful buyers look for as a result, why each point matters, and what evidence to ask for. It ends with a checklist you can use on any shortlist, with or without us.

What we counted, and what it does and does not show

The figures above come from three places, and each has limits worth stating.

The launch board is our own record of launches we found and dated. It is not a census of every product released in September. It tells you what a buyer would see if they followed new releases closely, not what share of all software lacks a price.

The news desk figures cover 28 vendor changes where we could find both the date the vendor told customers and the date the change took effect. Changes announced without a clear effective date are not in the count, so the real spread of notice periods may be wider.

The dead-website sample is 1,000 company listings drawn at random from our catalogue, which includes many businesses first listed years ago. It says more about the churn of small firms over time than about this month's launches, but it makes the same point: a supplier you choose today may not be there in a few years.

One more figure from our own house is relevant. Our catalogue holds 5,092 software listings that still show prices from the original 2020 import with no date attached. In a sample of 30 checked against the vendors' own pages, only 6 still matched. We are working through those listings now. A price is only useful with a date next to it, and that applies to directories, including ours.

We add outside evidence below only where we opened the primary source, and we name it at the end.

Who is behind the product

The first thing a buyer needs is the name of the legal entity they will contract with. It sounds obvious, but a product website can run for months with no company name, no registered address and no company number, and a good share of new launches we reviewed looked like that.

It matters for four reasons.

  • Contracts. You cannot sign a data processing agreement, enforce a warranty or claim a refund from a brand name.
  • Continuity. A registered company with a trading history can still fail, but you can check its filings. A product with no named operator gives you nothing to check.
  • Relaunches. When a product is a relaunch, the old terms, old customers and old problems may still be attached to the operating company. Knowing the company lets you look back.
  • Jurisdiction. The operator's country decides which courts, which data protection law and which regulator apply if something goes wrong.

What to ask for: the full legal name, the country of registration and the company number. For UK companies you can then check the public register yourself, including the filing history and whether accounts are overdue. If a vendor will not tell you who operates the product before you pay, treat that as the answer.

A price you can read before the sales call

Buyers increasingly expect to see a price before they speak to anyone. The reason is less about impatience than about planning. A team comparing four tools needs to know whether each one costs tens, hundreds or thousands a month before it spends time on demos.

Several September launches on our board published no price, only a contact form. That is not always a warning sign. Some products are genuinely priced per deal, especially where the vendor has to set up integrations or migrate data. But a buyer should be able to find at least one of these:

  • a list price for a standard plan, with the unit (per user, per seat, per workspace, per transaction or per unit of usage);
  • a starting price or a range, with what drives the price up;
  • a statement of what is billed separately, such as onboarding, support tiers, storage, or usage of AI features.

The last point is where many surprises now sit. Products that add AI features often meter them separately, through credits, tokens or caps on actions per month. A plan that looks cheap can become expensive once people start using the parts that were advertised most. Ask what happens when a cap is reached: does the feature stop, slow down, or keep running and bill the overage? For more on how software products now charge, see our companion article on software product monetisation in 2026.

Whatever price you are given, write down the date and keep the page or quote.

Where the data lives, and the contract that governs it

For any product that will hold personal data about your staff or customers, UK GDPR makes you the controller and the vendor your processor. The Information Commissioner's Office sets out what the contract between you must contain. Its guidance lists eight minimum terms drawn from Article 28(3): the processor acts only on your documented instructions; its staff are bound by confidentiality; it applies appropriate security measures; it uses sub-processors only with your authorisation; it helps you respond to people exercising their rights; it helps you meet your own obligations on security, breach notification and impact assessments; it deletes or returns the data when the contract ends; and it allows audits and provides the information needed to show compliance. The ICO notes that the guidance is under review following the Data (Use and Access) Act, so check the current version before relying on details.

In practice, buyers now look for three things before a trial goes further than dummy data:

  1. A published data processing agreement (DPA) that you can read without negotiating. Established vendors usually publish one. If a vendor has none, you will have to draft one, which is slow and puts the burden on you.
  2. A list of sub-processors, including the hosting provider and any AI model provider that sees your data, with their locations. Ask how you will be told when the list changes and whether you can object.
  3. The data location, stated plainly: which country or region the data is stored in, and where it may be accessed from for support. If data leaves the UK, ask what transfer mechanism is used.

A new AI feature can quietly add a sub-processor. If a product starts sending your content to a model provider it did not use when you signed, that is a change to the processing, and it should come with notice under the DPA.

Getting out: export, exit and the switching rules

Given that 171 of 1,000 websites in our random sample no longer led to the business as listed, planning your exit is not pessimism. It is ordinary housekeeping.

Buyers should settle three questions before they commit:

  • Export. Can you get all your data out, in a documented, machine-readable format, without asking support? Try it during the trial. An export button that produces a partial CSV is not the same as a full export with attachments, history and relationships intact.
  • Notice and termination. How much notice must you give to leave, and is there a minimum term? What happens to annual prepayments if the vendor closes or is acquired?
  • After the end. How long does the vendor keep your data after termination, and will it confirm deletion in writing? The ICO's list of DPA terms already requires deletion or return at the end; ask how long that takes.

The law is moving in the buyer's direction here, at least in the EU. The European Commission's explainer on the EU Data Act says the regulation has applied since 12 September 2025 and sets rules to help customers switch between providers of data processing services, such as cloud services. It says switching charges, including charges for data egress, will be removed entirely from 12 January 2027. Until then, as a transitional measure, providers may still charge customers for the costs of switching and egress. The Data Act is EU law, and a UK buyer benefits from it directly only as a customer in the EU. Even so, it gives you a reasonable benchmark to ask any provider: what will it cost me, in money and time, to leave?

AI features you can switch off, and notice before changes

Four of the 28 vendor changes our news desk logged in September switched a feature on by default for existing customers. In each case the customer had to act to turn it off. That is the pattern buyers most want to avoid, because it means the product you are running is not the product you approved.

Two questions help here.

Can each AI feature be switched off at the organisation level? Not per user, and not by asking support, but by an administrator in settings. Ask separately whether your content is used to train or improve the vendor's models or its providers' models, and whether that can be refused in the contract rather than only in a settings page that could change.

What notice will you get before changes? Our median of 31 days is a useful yardstick, but the spread matters more than the middle. Six changes gave a week or less and three gave none. A contract that promises 30 days' notice of material changes, and the right to leave without penalty if you do not accept them, protects you against the tail. Ask where notices are published and whether you can subscribe to them.

These are not only preferences. The UK government's Cyber Security Breaches Survey 2025/2026 found that 31% of businesses were using AI, adopting it or considering it, and that among those, 24% reported having cyber security practices or processes in place to manage the risks from using AI. In other words, most organisations adopting AI do not yet have a process for it. A vendor that switches AI features on by default is putting that gap straight into your systems.

Security evidence, and what each badge actually proves

Security claims on a product page are easy to write. Buyers now ask for evidence, and they need to know what each piece of evidence covers.

The same government survey, published on 30 April 2026, found that 43% of UK businesses reported a breach or attack in the previous 12 months, rising to 65% of medium businesses and 69% of large ones. Yet only 15% of businesses said they reviewed the risks posed by their immediate suppliers, and 6% had looked at their wider supply chain. Among large businesses the figure for immediate suppliers was 48%. Most buyers are not checking, which is partly why vendors can get away with vague claims.

The common forms of evidence:

  • Cyber Essentials. The UK government-backed scheme covering five basic technical controls. The National Cyber Security Centre's supply chain playbook describes it as a baseline that protects against untargeted, commodity attacks. It says nothing about how the vendor handles your data in its application. The breaches survey found that 17% of businesses were aware of the scheme and 5% held certification, rising to 35% of large businesses. A small vendor that holds it has done something most of its peers have not. Check the certificate on the public search, and check the date.
  • ISO/IEC 27001. A certified information security management system. Ask for the certificate and the scope statement. A certificate whose scope covers only a head office, not the service you are buying, tells you little about that service.
  • SOC 2. An auditor's report on controls relevant to security, availability, processing integrity, confidentiality or privacy, under the AICPA's framework. Ask for the report itself, which vendors usually share under a non-disclosure agreement, and check which criteria and which period it covers. The NCSC's supply chain guidance sets out 12 principles in four stages: understand the risks, establish control, check your arrangements and keep improving. For a small buyer, that means deciding in advance what evidence you require at each level of risk, asking for it before you sign, and recording what you were given.

Integrations and the cost of connecting

New software rarely stands alone. Buyers want to know whether it connects to the tools they already run, how, and who maintains the connection.

Ask for specifics:

  • Native integrations listed by name, with who built them. An integration built and maintained by the vendor is different from one listed through a third-party automation service, which may add its own subscription and its own data processor.
  • An API with public documentation, rate limits and a statement of which plans include it. An API available only on the top plan changes the real price.
  • Single sign-on and user provisioning, again with the plan that includes them. Many vendors put SSO on higher tiers, which matters for offboarding: if leavers cannot be removed centrally, accounts linger.
  • Webhooks or event feeds, if you need other systems to react to changes.

Integrations also carry exit risk. Ask how long the vendor supports an integration after announcing its retirement, and treat that like any other change notice.

The same questions apply when the software is being built for you rather than bought off the shelf. If you are commissioning work from an IT service provider, see our companion pieces on how the provider and buyer relationship is changing and on offshore development in 2026.

A buyer's evaluation checklist

Use this on each product on your shortlist. Record the answer, the evidence you were given and the date. If a vendor cannot answer a line, note that too; a gap is information.

Identity and continuity

  1. Legal name, country of registration and company number of the operating company.
  2. Filing history checked on the relevant public register; accounts not overdue.
  3. If the product is a relaunch or rename, what it was before and who ran it.

Price

  1. A published or quoted price with the unit it is charged on, dated and saved.
  2. What is billed separately: onboarding, support tiers, storage, API access, SSO, AI usage.
  3. What happens when a usage cap is reached.

Data

  1. A readable data processing agreement covering the eight ICO minimum terms.
  2. The list of sub-processors, including any AI model provider, with locations.
  3. Where data is stored and where it can be accessed from; transfer mechanism if it leaves the UK.
  4. Whether your content is used for training, and a contractual right to refuse.

Change and control

  1. Organisation-level controls to switch off each AI feature.
  2. A contractual notice period for material changes (30 days is a sensible floor) and the right to leave without penalty if you reject them.
  3. Where change notices are published, and how to subscribe.

Exit

  1. A full export tested during the trial, in a documented format.
  2. Notice to terminate, minimum term, and treatment of prepayments.
  3. How long data is kept after termination, and written confirmation of deletion.

Security

  1. The evidence you require for this level of risk: Cyber Essentials, ISO/IEC 27001 with scope, a SOC 2 report, or a combination.
  2. Certificate or report checked for date, scope and the service you are buying.
  3. A published way to report vulnerabilities.

Integrations

  1. Named integrations and who maintains them; API documentation and the plan that includes it; SSO and provisioning; the support period after an integration is retired.

When you finish, sort the answers into three piles: settled, needs to go into the contract, and rules the product out. The middle pile is usually the longest, and that is where the work is.

If you want to see what has launched recently, our launch board and AI model tracker list new releases with the dates we recorded. Use them as a starting point, then run the checklist.

Sources

  • Cyber security breaches survey 2025/2026: breach rates by business size, supplier risk reviews, Cyber Essentials awareness and certification, AI adoption and AI risk practices. Department for Science, Innovation and Technology, 30 April 2026.
  • What needs to be included in the contract?: the eight minimum controller–processor contract terms under Article 28(3) UK GDPR, and the note that the guidance is under review. Information Commissioner's Office (read 25 September 2026).
  • The principles of supply chain security: the 12 principles in four stages. National Cyber Security Centre, 22 October 2025.
  • Cyber Essentials supply chain playbook: what Cyber Essentials assures for suppliers. National Cyber Security Centre, 12 December 2025.
  • Data Act explained: application date, switching between data processing services, removal of switching and egress charges from 12 January 2027 and the transitional period. European Commission, updated 15 December 2025.
  • SOC 2 resources: the SOC 2 examination and the criteria it reports on. AICPA and CIMA (read 25 September 2026).
  • TrustList launch board, September 2026: 60 launches dated September (28 AI models, 32 products), reviewed for operating company and price. TrustList Editorial, counted September 2026.
  • TrustList news desk, September 2026: 28 vendor changes with notice and effective dates; median notice, short-notice and opt-out counts. TrustList Editorial, September 2026.
  • TrustList catalogue sample: 1,000 company listings drawn at random and their websites checked; 5,092 software listings with undated 2020 prices and a sample of 30 checked against vendors' pages. TrustList Editorial, 24 September 2026.