I worked for a company that required security clearances. We used a SaaS to store some documents.
The SaaS gave our company a document outlining their security practices and we signed up to a system where their support is unable to access our instance unless we explicitly authorized it.
It was enough for our company.