Also, if it's in house / on prem you can do a change freeze and actually mean it. With a SaaS that's a joke. You never know what the SaaS engineers might be doing. An in house system's downtime is more likey to be correlated with your other systems' downtime, so total downtime is going to be higher with a SaaS, especially since authz/authn is so critical to everything.
I don't understand why this is a SaaS and not just a software product you buy and run on prem. (In terms of business risk, buying this as an on prem product seems perfectly reasonable -- after this startup is bought by someone like Microsoft that can actually guarantee the features will stay around.)