Guide
Glossary: 40 terms every tech seller must know
ASTRA Ready editorial ·
Forty plain-English definitions cover cloud, security, AI, commercial and credential language that sales, presales, channel and customer-success professionals encounter in real technology deals worldwide.
Technology sellers do not need to become engineers, but they do need enough shared language to understand the customer’s question, recognise a boundary and involve the right specialist.
The definitions below are deliberately commercial and plain English. They are not substitutes for technical standards, contracts or customer-specific architecture.
Cloud and architecture
1. API
An application programming interface is a defined way for software systems to exchange requests or data; sales claims still need scope and test evidence.
2. Integration
The connection of systems so information or actions can move between them; documented compatibility does not prove the customer’s exact workflow works.
3. SaaS
Software delivered as a service rather than operated entirely by the customer; responsibilities still depend on the service agreement.
4. IaaS
Infrastructure delivered as a service, such as compute, storage or networking capacity, while customers retain responsibility for much of their configuration.
5. PaaS
A managed platform for building or running applications, with responsibilities still divided between supplier and customer.
6. Tenant
A logically separated customer environment inside a shared service; supplier controls do not prove every customer-managed setting is correct.
7. Workload
An application, service, process or set of computing tasks consuming technology resources. The workload matters because architecture, cost and security evidence can vary by workload.
8. Data residency
Where data is stored or processed according to the service design and relevant agreement. Residency should not be confused automatically with legal compliance or sovereignty.
9. Scalability
The ability of a system to handle changing demand; design claims are different from customer-specific load-test evidence.
10. Availability
Whether a service is accessible when required; targets, measurements and contractual commitments should not be treated as the same evidence.
Security and assurance
11. Authentication
The process of establishing that a user, device or service is who or what it claims to be.
12. Authorization
The decision about what an authenticated identity is allowed to access or do.
13. MFA
Multi-factor authentication uses more than one type of factor to strengthen identity verification. Support for MFA is not proof that a customer has enabled it correctly.
14. Zero trust
An approach that avoids granting implicit trust solely from network location or ownership. NIST describes access decisions around users, assets and resources. [Source: NIST, United States, 10 August 2020.]
15. Encryption
The transformation of readable data into protected form using cryptographic methods. Sellers should distinguish data at rest, data in transit and the exact scope documented.
16. Vulnerability
A weakness that could be exploited; its presence alone does not establish customer exposure or successful exploitation.
17. Penetration test
An authorised security test for exploitable weaknesses in a defined scope; its report should not be extended beyond that scope.
18. Assurance report
Formal evidence about defined controls, criteria, systems and periods, useful only within the report’s stated boundaries.
19. Security questionnaire
A buyer’s structured request about security practices, controls or evidence; answers should come from approved sources.
20. Shared responsibility
The division of security or operating duties among supplier, customer and partners, defined by the service, architecture and agreement.
Commercial and FinOps
21. Consumption model
A commercial model where charges depend partly or entirely on measured usage.
22. Meter
The unit used to measure billable usage, such as transactions, storage or compute time.
23. Commitment
A contractual amount, volume or term the customer agrees to consume or pay for under defined conditions.
24. Overage
Usage above an included or committed threshold that may be handled differently under the commercial terms.
25. FinOps
A collaborative practice for managing technology value and cost across engineering, finance and business teams. [Source: FinOps Foundation, United States, 2025 framework update.]
26. Unit economics
The relationship between a defined unit of activity and its cost or value.
27. Renewal
The point at which an entitlement or agreement continues into another term under stated conditions.
28. Entitlement
What the customer is allowed to use or receive under the governing commercial terms.
29. Scope
The explicit boundary of what a product, service, project, test or agreement includes.
30. SLA
A defined service commitment describing measures and conditions; marketing language is not automatically an SLA.
AI and evidence
31. AI assistant
A system that can generate, summarise or transform content from instructions and context. Its output is a draft unless separate evidence validates the claim.
32. Hallucination
A confident but unsupported or incorrect generated statement. Sellers should check the source behind every customer-facing factual claim.
33. Human review
A person checks an AI-generated output or proposed action before it is used. If review contributes to the result, keep that control visible.
34. Prompt
The instruction and context supplied to an AI system. A better prompt can improve structure but cannot create missing customer evidence.
35. Model output
The content generated by an AI model. It is not customer evidence simply because it is fluent or plausible.
36. Evidence boundary
The point where the supplied source stops supporting a claim. Good selling keeps conclusions inside that line.
Credentials and assessment
37. Credential
A formal claim by an issuer that a person met defined criteria or achieved a stated standard.
38. Certification examination
A controlled assessment used to determine whether a candidate meets an approved certification standard. Learning completion and examination performance are separate evidence.
39. Verification
Checking that a credential is authentic, issued by the stated issuer and still valid where status applies. 1EdTech distinguishes verification from judging whether the claim is suitable for a particular purpose. [Source: 1EdTech, United States, final Open Badges 3.0 specification published 2024.]
40. Validity period
The period for which a credential remains current under the issuer’s policy. A validity date does not guarantee that every underlying skill remains unchanged.
Why these terms matter in selling
CISA’s Secure by Demand guidance encourages buyers to ask software manufacturers about product-security practices during procurement. [Source: CISA, United States, 6 August 2024.] That is one reason customer-facing professionals increasingly need to understand technical and commercial language without turning themselves into the technical authority.
The point of a glossary is not memorisation. It is to help you recognise the next question.
If a buyer says “integration,” ask which workflow. If they say “compliant,” ask which requirement and evidence. If they say “zero trust,” ask which resource and access decision. If they say “credential,” ask what was assessed and how it can be verified.
Frequently asked questions
Do tech sellers need to know every technical definition in depth?
No. They need enough fluency to understand the customer question, avoid misusing terminology and involve the right specialist.
Is this glossary a technical standard?
No. It is a plain-English commercial reference. Formal definitions in standards, contracts and product documentation take precedence.
Should sellers explain security controls without pre-sales?
They can explain approved evidence and scope, but deeper technical validation should stay with the appropriate specialist or owner.
Can AI safely define unfamiliar terms during a customer call?
It can help draft an explanation, but the output should be checked against an approved source before becoming a customer-facing fact.
References
- NIST — Zero Trust Architecture · 10 August 2020 · United States
- CISA — Secure by Demand Guide · 6 August 2024 · United States
- FinOps Foundation — FinOps Framework · 2025 framework update; accessed 5 October 2026 · United States
- 1EdTech — Open Badges 3.0 Specification · Final specification published 2024; accessed 5 October 2026 · United States