River
Y CombinatorBacked by Y Combinator

Software & TechnicalFree

SaaS Vendor Technical Review and Exit Cost

River reads the vendor's own API limits, status history and draft contract, then computes what leaving costs in engineer-days and calendar days.

Start here

Every guide on page one for this query hands you the same object: a weighted scorecard, eight or ten categories, scored one to five, with the weights locked before the first demo. Switching cost is one of those categories, worth five or ten percent, and the question underneath it is whether you can export your data. Most vendors can, and publish an API that proves it, so most vendors score four there. That four is the most expensive number on the sheet.

Kelvedon, a parcel logistics operator, was three signatures from a three-year contract with Verrick, a support platform, at 41,000 euros a month. Both are illustrative. At renewal Verrick would be holding 91.7 million records and 10.9 million attachments, and every attachment is one authenticated request against a documented limit Kelvedon shares with its own production traffic. That extraction runs 26 days. The draft contract gives 30 days of retrieval after termination.

Built for whoever has to sign, and for the engineer asked whether the thing will actually work. Run it on one vendor, on a shortlist, or on the incumbent you are about to renew unread. Whether the platform holds your load is a load test, and what the bill does as you grow is a cloud cost analysis. The questionnaire they send back to you is a security questionnaire response, and the shape of their own API is an API design review.

Three numbers the scorecard has no cell for

The first is how long the data takes to come out, and the vendor has already published it. A rate limit is a documented property you can read before signing: Stripe, to take one that states it plainly, caps individual API endpoints at 25 requests per second unless otherwise noted. Divide your projected record count at renewal by the vendor's figure, not your count today, and the extraction acquires a duration. Kelvedon's records took 6.4 days. The attachments took 25.6, one request each, off a limit production was already using.

The second is the window that duration has to fit inside. Verrick's draft offered 30 days of retrieval, which is a floor rather than a norm. The EU Data Act requires a switching clause to carry the mandatory maximum transitional period of 30 calendar days and then a retrieval period of at least 30 more, so the shape a well-drafted contract now takes is 60. Kelvedon's 26 days left four days of slack against the draft. Against the statutory shape it leaves 34.

The third is what has no export path at all. Verrick's API returns tickets, contacts and events. It does not return the 186 business rules, 74 macros, 38 custom field definitions or nine permission groups, because those exist only in the admin console. They get rebuilt by hand, and the floor on that estimate is not a guess. It is the 14-week onboarding Verrick had already quoted at 129,500 euros, which is the same configuration paid for in the other direction.

How it works

  1. Name the vendor

    The company, the product, and the job it would take over from whatever runs it now.

  2. Point at the docs

    Developer documentation, status page, trust centre and pricing. The export endpoints matter most here.

  3. Give it your volumes

    Record counts today and the growth rate, because the exit happens at renewal volume rather than this one.

  4. Read the exit first

    Extraction days against the contract window, then the rebuild, the call sites, and the recommendation.

What you get

  • Extraction time computed from the vendor's published rate limits and your record count at renewal
  • That duration set against the retrieval window the draft contract actually gives you
  • Everything with no export path listed and counted, because that part gets rebuilt by hand
  • A rebuild floor taken from the vendor's own onboarding quote rather than from an estimate
  • Call sites counted and split into the ones that can dual-run and the ones that cannot
  • The published SLA set against the status history, and the credit against what an outage costs
  • SOC 2 scope mapped to what you need, naming the sub-processors carrying no report of their own
  • The metered price line projected forward, because the dimension that meters you is the one growing

Common questions

We already run a weighted scorecard.

Keep it, and keep the weights locked before the demos, which is the part those guides get right. This fills one cell of it with arithmetic instead of an impression. Kelvedon's switching cost score of four became a 26-day extraction, 307 objects with no export path and 181 engineer-days, and none of that touched the other nine categories.

Is the exit cost not hypothetical?

Only the leaving is. The configuration is not, because you are about to pay for it in the other direction. Verrick quoted 14 weeks of onboarding at 129,500 euros to build 307 rules, macros, fields and permission groups. Rebuilding those elsewhere without the vendor helping is not cheaper than that, so the floor is a price you already hold in writing.

The SOC 2 came back clean.

Clean against whatever it scoped. A report covers whichever of the criteria for security, availability, processing integrity, confidentiality and privacy the vendor chose to be examined on. Verrick's covered security alone, its period ended eight months before signature, and five of its 14 sub-processors had no report of their own.

They publish 99.9%, and the status page is public.

Then the two are comparable, which is the point of publishing both. Verrick's history resolved to 99.87% over 24 months. Four of those months breached, each earning a 10% credit, so 16,400 euros in total. The same outages cost Kelvedon 149,985 euros in idle agent time alone. An SLA returning eleven percent of the loss is a price rather than a remedy.

What about the fee for leaving?

Verrick's draft carried an 18,000 euro migration assistance fee. The term runs past 12 January 2027, and from that date providers of data processing services shall not impose any switching charges on the customer for the switching process. So it is a redline that costs nothing to win, and the review flags every clause in that class.

We are not in Europe.

Then the Data Act is a benchmark rather than a right, and it is still the most useful one going, because it describes what a well-drafted switching clause now looks like. Ask for the shape. Thirty days of transition with the service still running, then 30 more of retrieval, and no charge for either. Vendors selling into Europe have already built it.

What do we actually get back?

A document covering the integration effort, the operational risks and the exit, plus a sheet with one row per requirement carrying the vendor's answer, the evidence behind it and the constraint attached. Kelvedon's summary line was 181 engineer-days and 26 days of wall clock nobody can compress. What the growth underneath it does is a capacity plan.

SaaS Vendor Technical Review and Exit Cost

Fill in the form and your workspace opens with the work already underway.