The document discusses security considerations for Software as a Service (SaaS) application providers. It outlines key challenges including lack of visibility and control over how enterprise data is stored and secured in the cloud. The document then provides recommendations in three main areas: 1) Secure product engineering practices to integrate security into the development lifecycle. 2) Secure deployment strategies when using public or private clouds. 3) Governance and regulatory compliance audits as well as third-party security assessments to evaluate and validate security. Regular assessments are recommended to detect vulnerabilities before exploitation.