+150 XP

How SaaS advertising claims get regulated when the product keeps changing

In 2020, Zoom's website and security white paper described meetings as "end-to-end encrypted." The software that shipped used transport encryption: Zoom held the keys and could in principle reach meeting content. The FTC's November 2020 complaint was not really about cryptography. It was about a sentence on a marketing page that the product did not support. Zoom settled, accepting a security program and years of outside assessments, and later paid around $85 million to close a related private class action.

That gap is what this module opens on. Marketing publishes a claim on Tuesday, engineering changes the thing the claim describes on Thursday, and nobody re-reads the page. A pricing page saying "99.9% uptime, guaranteed" in January is still saying it in March after two migration outages, and by then no one can produce the logs that made it true in the first place. Regulators, competitors and plaintiffs' lawyers all know where to look.

This lesson sets out what counts as a regulated claim in software marketing, what substantiation means when the product is a moving target, and who polices the distance between the roadmap and the ad.

Why SaaS claims are a regulatory special case

Advertising law grew up around products that stop changing when they leave the factory: a car, a mattress, a shampoo. The ad and the object stay in sync because the object cannot move. SaaS ships weekly. A "save 10 hours a week" claim resting on a Q1 feature set may describe a workflow that was refactored out of the product by Q3.

Regulators grant no exception for this. In the US, the Federal Trade Commission (FTC) enforces Section 5 of the FTC Act, which bans "unfair or deceptive acts or practices." The standard: a claim must be truthful, not misleading, and backed by evidence *at the time you make it and for as long as you keep making it*. A live web page is a claim made today, not a claim made on the day the copywriter wrote it. Leaving it up is republishing it.

In the EU, the Unfair Commercial Practices Directive (UCPD) does the equivalent work, enforced by national consumer authorities, alongside the Digital Services Act (DSA) for online platform duties and the Digital Markets Act (DMA) for designated gatekeepers. The UK runs a parallel system: the Advertising Standards Authority (ASA) applies the CAP Code to non-broadcast ads, and the Competition and Markets Authority (CMA) gained direct consumer-law enforcement powers under the Digital Markets, Competition and Consumers Act (DMCCA), which took fuller effect in 2025.

The common thread: evidence has to be contemporaneous with the claim, not assembled after a complaint lands.

The two claim types that get SaaS companies in trouble

Start with what a claim is. A claim is anything a reasonable customer would read as a statement of fact about the product, whether stated outright or implied by the surrounding material. Express: "reduces ticket volume by 30%." Implied: "set up in minutes" beside a screenshot of a single-field form tells the reader that typical customers finish in minutes, and that is the claim you have to stand behind. Regulators judge the net impression of the whole asset, headline plus image plus footnote, not the footnote alone.

Puffery sits outside this. Subjective boasting nobody would treat as measurable ("the friendliest helpdesk in software") is not actionable. Specificity is what tips a boast into a claim: "loved by teams everywhere" is puffery, "loved by 40,000 teams" is a number you now have to produce.

1. Quantitative performance claims. "99.9% uptime." "Save 10 hours a week." "50% faster." These are objective and testable, and the expectation is a stated methodology: how it was measured, over what period, on what sample, under what conditions.

2. Comparative and superiority claims. "The #1 CRM for small business." "More secure than the incumbent." These attract two audiences. Regulators, and the competitor you named, who in the US can sue directly under the Lanham Act with no regulator involved.

Uptime deserves its own note because it appears on almost every SaaS pricing page. "99.9%" allows roughly 8.7 hours of downtime a year. If your logged downtime exceeds that, the claim is already false, and your own public status page is the evidence anyone would use against you.

What "substantiation" actually means in practice

Substantiation is the file that existed *before* the claim ran and supports it at the level of proof the claim invites. The FTC calls this a "reasonable basis," and the required rigor scales with the assertion: a security claim or a savings figure needs more than a tagline does. For SaaS, a workable file holds:

  • The raw data source (uptime monitoring logs, product analytics, study results)
  • The methodology: sample size, measurement window, and the definitions used, including what counts as "downtime" or as an hour "saved"
  • Who produced it, internal team or independent auditor, and any conflict of interest
  • The build or release the data describes, and the date range the claim is valid for

The FTC's own advertising substantiation policy statement sets out the reasonable basis test in plain language and is worth reading once in full.

The part specific to software: substantiation has a shelf life measured in releases, not years. A benchmark run against version 4.2 stops supporting the claim when 5.0 changes the code path it measured. The practical fix is to attach each live claim to a release trigger and a named owner, so that deprecating a feature raises a flag on the pages that sell it. Annual reviews are always three deploys behind.

Who polices the gap between the roadmap and the ad

Four groups, and they work on different timescales.

Regulators come last and slowest, usually after complaints accumulate: the FTC and state attorneys general in the US, national consumer authorities coordinating through the Consumer Protection Cooperation (CPC) Network in the EU, the ASA and CMA in the UK.

Competitors move faster and hurt sooner. Lanham Act suits, ASA complaints and national unfair-competition actions are cheap to start and are often filed by the sales team's opposite number. Germany's Wettbewerbszentrale, an industry body that brings unfair-competition cases, took Tesla to court over its Autopilot marketing and won a Munich ruling in 2020 that the German wording was misleading.

Class-action plaintiffs read the same pricing pages. Zoom's $85 million settlement came from private litigation, not from the regulator.

Enterprise buyers police it in procurement. Security questionnaires and MSA warranties pull the marketing claim into the contract, at which point an unsupported uptime number is a breach question rather than an advertising one. Renewal is the enforcement mechanism there, and it is the one your CFO feels first.

One boundary: the money-and-consent side (auto-renewal disclosure, trial conversion, cancellation friction) is governed by a separate body of rules covered in the free trials and cancellation lesson. This lesson is about capability claims.

Roadmap claims: advertising a version that does not exist yet

SaaS marketing routinely sells the next release. Feature announcements, waitlists and "coming in Q3" language all describe a product nobody can use yet, which puts a second kind of pressure on substantiation: you cannot measure what has not shipped.

Tesla is the reference case, and the naming is the whole problem. "Full Self-Driving" described an ambition while the delivered software required a supervising driver. The California DMV filed accusations in 2022 alleging that the Autopilot and Full Self-Driving names constituted misleading advertising, and Tesla renamed the option "Full Self-Driving (Supervised)" in 2024. The label promised the destination; the product was somewhere on the way.

The transferable rule is that a capability claim is judged against what a buyer can do on the day they pay. If the feature is in beta, say beta and say what beta means here. If the date is a plan, mark it as a plan and do not attach a price to it. Charging today for a capability promised later is the version of this that turns an advertising question into a refund question.

🎬 [VIDEO: "FTC Explains Deceptive Advertising Rules" - youtube.com/@FTCvideos - the FTC's own consumer-facing explainer on what counts as a deceptive claim, useful as a plain-language baseline before reading formal guidance]

Knowledge check

1. Why does the FTC's Section 5 standard create a distinct compliance burden for SaaS companies compared to physical product makers?

2. A SaaS company's 'save 10 hours a week' claim was true in Q1 based on a specific feature set. By Q3, that feature has been significantly changed. What is the regulatory implication?

3. What is the core reason the uptime guarantee scenario (claim still live after outages, no logs to prove the original claim) is legally risky?

MULTIPLE CHOICE

4. Select ALL correct answers about the regulatory bodies/frameworks relevant to SaaS advertising claims described in the lesson.

Select all the correct answers.

MULTIPLE CHOICE

5. Select ALL correct answers about why traditional advertising law's assumptions don't map cleanly onto SaaS products.

Select all the correct answers.

What happens when it goes wrong

The fine is rarely the expensive part. Zoom paid the FTC nothing directly; what it accepted was an order running for two decades, with a mandated security program and biennial third-party assessments. That is a permanent tax on how the company builds and how quickly it can say anything about security in an ad.

The current growth area is AI-washing. The FTC's Operation AI Comply, announced in September 2024, brought actions against companies overstating what their AI products could do, and the agency has been explicit that inflated AI capability claims get treated like any other unsubstantiated performance claim under Section 5. For SaaS in 2026, where nearly every release note leads with AI, that is the claim category most likely to outrun its evidence.

Volkswagen marks the outer bound of the same failure. The defeat-device software behaved one way under test conditions and another on the road, and the "Clean Diesel" advertising described the tested behavior. The FTC sued over those ads in March 2016; US settlements exceeded $14 billion. The point for a software marketer is not the scale but the mechanism: the claim was true of a configuration customers never ran.

Below the headline numbers sit corrective advertising, years of monitoring, and B2B buyers who now diligence vendor claims as a standard procurement step.

Key takeaways

  • A claim is anything a reasonable buyer reads as fact, express or implied, judged on the net impression of the whole asset. Specificity turns a boast into a claim you must prove.
  • Substantiation is a "reasonable basis" file that exists before publication: source data, methodology, definitions, author, and the release it describes.
  • A live page republishes its claim every day. Evidence tied to a shipped build expires when the build does, so attach review triggers to releases rather than to the calendar.
  • Four constituencies police the gap, and regulators are the slowest of them. Competitors, class-action firms and enterprise procurement usually arrive first.
  • Forward-looking capability claims are measured against what a customer can do the day they pay, which is why Tesla's naming, not its engineering, produced the advertising case.