Freeze the same fixture in both models

Use a small synthetic CRUD workflow in equivalent authorised environments. Keep the application version, operator role, test data, and source-date cutoff constant. Then collect the following evidence in each environment.

Boundary Evidence needed
Application location Named service or customer environment and version
Business-data path Source, destination, attachment path, and recovery owner
Credential path Creation, storage, rotation, and emergency-access owner
Change path Artifact identity, actor, approver, and promotion evidence
Upgrade path Notice, test, decision, and rollback owner
Incident path Detection, response, provider handoff, and evidence location
Recovery path Separate application and business-data recovery procedure

Every row starts as not observed. A vendor document can explain a stated hosting model, but it does not prove the evaluator's selected plan, configuration, access path, or service relationship.

Compare responsibility instead of making a blanket claim

Editorial method: compare the specific task that changes hands rather than using the deployment label as a conclusion. A team may choose to operate some infrastructure in a customer environment while retaining vendor-operated elements elsewhere; equally, a managed service can leave the customer responsible for its application logic and data decisions.

Use What Self-Hosted Actually Means for the narrower deployment definition. Use Evaluate a BYOC Internal Application Vendor when a vendor claims a customer-cloud model. The narrower data-path procedure supplies the evidence request for the business data, files, credentials, logs, backups, and support paths in this parent method.

Stop condition

Do not call either model safer, simpler, compliant, or data-resident until the same fixture has equivalent observed records for all seven boundaries. If the team cannot authorise those environments or identify an owner, keep the draft as a method and do not convert vendor documentation into a recommendation.

Does self-hosting prove that all data stays in a company cloud?

No. Trace the application, business data, files, credentials, logs, backups, and support-access path for the chosen configuration.