Freeze the same fixture in both models
Use a small synthetic CRUD workflow in equivalent authorised environments. Keep the application version, operator role, test data, and source-date cutoff constant. Then collect the following evidence in each environment.
| Boundary | Evidence needed |
|---|---|
| Application location | Named service or customer environment and version |
| Business-data path | Source, destination, attachment path, and recovery owner |
| Credential path | Creation, storage, rotation, and emergency-access owner |
| Change path | Artifact identity, actor, approver, and promotion evidence |
| Upgrade path | Notice, test, decision, and rollback owner |
| Incident path | Detection, response, provider handoff, and evidence location |
| Recovery path | Separate application and business-data recovery procedure |
Every row starts as not observed. A vendor document can explain a stated hosting model, but it does not prove the evaluator's selected plan, configuration, access path, or service relationship.
Compare responsibility instead of making a blanket claim
Editorial method: compare the specific task that changes hands rather than using the deployment label as a conclusion. A team may choose to operate some infrastructure in a customer environment while retaining vendor-operated elements elsewhere; equally, a managed service can leave the customer responsible for its application logic and data decisions.
Use What Self-Hosted Actually Means for the narrower deployment definition. Use Evaluate a BYOC Internal Application Vendor when a vendor claims a customer-cloud model. The narrower data-path procedure supplies the evidence request for the business data, files, credentials, logs, backups, and support paths in this parent method.
Stop condition
Do not call either model safer, simpler, compliant, or data-resident until the same fixture has equivalent observed records for all seven boundaries. If the team cannot authorise those environments or identify an owner, keep the draft as a method and do not convert vendor documentation into a recommendation.
Does self-hosting prove that all data stays in a company cloud?
No. Trace the application, business data, files, credentials, logs, backups, and support-access path for the chosen configuration.