Skip to main content

SAP Security & Data Handling

How Artificio works with SAP. Securely.

Written for the people who have to approve us: your SAP Basis, security and compliance teams. Exactly how Artificio connects to SAP, what it can and cannot touch, where your data goes, and the documentation your reviewers will ask for.

  • ISO 27001:2013
  • SOC 2 Type II
  • GDPR
  • HIPAA
  • ISO 27001:2013
  • SOC 2 TYPE II
  • GDPR
  • HIPAA
  • ON-PREM · YOUR CLOUD · SAAS
  • NO ABAP IN YOUR CORE
In your landscapeNo core changes
  • ISO 27001:2013
  • SOC 2 Type 2
  • GDPR
  • HIPAA
  • Connects over OData, BAPI and RFCinterface
  • Runs against ECC and S/4HANAscope
  • Acts under its own service useridentity
  • Every posting carries an audit trailrecord

SAP connection

Standard interfaces, no screen-scraping.

Artificio connects to SAP the way your own integrations do (through published, supported interfaces), so there's nothing brittle or unsupported in the path to production.

  1. Documentsemail · PDF · scan · EDI
  2. Artificio AI layerextract · validate
  3. Standard interfaceOData · BAPI · RFC
  4. Your SAPECC · S/4HANA
  • Connects through OData, BAPI, and RFC. The same standard, supported interfaces your SAP team already trusts.
  • No screen-scraping and no custom ABAP installed in your system.
  • Reads live master data (vendors, POs, goods receipts) to validate before posting, read-only wherever a process only needs to read.
  • Connection secured with TLS in transit and OAuth, with credentials held in a secrets vault, never embedded in the application.
  • Brokered through SAP Cloud Connector, so SAP is never exposed directly to the internet and your team controls exactly what's reachable.

Deployment

Runs wherever your security policy requires.

Many SAP-adjacent tools force your data into a vendor cloud. Artificio doesn't. Choose the model your policy allows. The automation is the same either way.

  • On-premises

    Inside your data center

    Deploy entirely within your own infrastructure. Data never leaves your perimeter. The strictest option for regulated or air-gapped SAP landscapes.
  • Your cloud

    In your own cloud tenant

    Run Artificio in your AWS, Azure, or GCP account. Your data stays in your cloud, under your controls, keys, and residency, with none of it held by us.
  • Artificio cloud

    Fully managed SaaS

    Let us host and operate it. Fastest to start, with the same certifications, encryption, and isolation, ideal when a vendor cloud is acceptable.

Data handling

Where your data lives, and for how long.

Clear answers to the data-residency and retention questions in every enterprise security review.

Hosting & region
You choose where it runs: on-prem, Artificio's cloud, or your own cloud tenant. In your own environment, data residency is fully under your control. In Artificio's cloud, region can be provisioned to match your residency requirements.
Deployment options
Deploy on-premises, in Artificio's cloud, or in your own cloud tenant (AWS, Azure, or GCP). Your data can stay entirely within your environment.
Encryption
Encrypted in transit with TLS and at rest with AES-256.
Document retention
Retention is customer-configurable. Documents are processed to run your automation and retained only per your configured policy; in your own environment, retention is entirely under your control.
Tenant isolation
Customer data is logically isolated per tenant, with dedicated environments available for enterprise deployments.
Sub-processors
A current sub-processor list is available to customers and prospects under review on request.

Access & control

Your roles, your approvals, your audit trail.

Artificio is designed to sit inside your existing control model, not around it.

  • Role-based access: separate view, edit, approve, and post permissions, with SSO via SAML.
  • Respects SAP authorizations: posting is performed under the connected service account's authorizations, so it can never exceed the roles and segregation-of-duties rules your SAP team has granted.
  • Human-in-control posting: clean documents can post straight-through, or you can require approval on any type; nothing posts blindly.
  • Complete audit trail, who did what and when, AI value vs. human edit, traceable to the SAP document number.
  • Written rationale. Every automated decision is explainable, not a black box.

Certifications

Independently audited.

The compliance foundation behind the SAP-specific controls above.

ISO 27001:2013
Certified information security management system: risk assessment, controls, and continuous improvement.
SOC 2 Type II
Independently audited over time across security, availability, processing integrity, confidentiality, and privacy. Report available under NDA.
GDPR
Lawful processing, data-subject rights, data protection by design, and secure international transfers.
HIPAA
Physical, technical, and administrative safeguards for PHI, with BAAs where required.

For your security team.

Everything a vendor security review typically needs: request the package and we'll turn it around quickly, under NDA where appropriate.

  • SOC 2 Type II report

    Full report available under NDA.

  • ISO 27001 certificate

    Certificate and scope statement.

  • DPA & BAA

    Data Processing Agreement and Business Associate Agreement available on request.

  • Penetration test summary

    Third-party penetration test; summary available on request under NDA.

  • Sub-processor list

    Current list available on request.

  • Security questionnaire

    We complete standard questionnaires (SIG / CAIQ / custom).

  • Architecture / data-flow diagram

    How data moves from capture to SAP posting.

  • Security contact

    security@artificio.ai for reviews & disclosure.

The short version

Three principles behind how we connect.

  • Least footprint

    Nothing installed in your SAP core

    Artificio runs as an external AI layer and connects through standard SAP interfaces. No add-on inside your core, no custom ABAP. Your clean-core strategy stays intact.
  • Least privilege

    Scoped access that honors SAP roles

    Artificio connects through a dedicated service account with least-privilege authorizations and respects your SAP roles and segregation-of-duties rules. It can't do in SAP what its authorization doesn't allow.
  • Full accountability

    Every action logged

    Extraction, each manual correction, approval, and posting are captured with user, timestamp, and before/after value, traceable to the SAP document for a complete audit trail.

Security & compliance

Enterprise security across every solution

ISO 27001:2013 certified, SOC 2 Type 2 compliant, GDPR and HIPAA ready. Every agent action is logged, auditable, and runs in isolated environments.

  • ISO 27001:2013
  • SOC 2 Type II
  • GDPR ready
  • HIPAA ready

Security review

Bring your security team to the conversation.

We'll walk your Basis, security, and compliance reviewers through the connection model, data handling, and controls, and hand over the documentation to move the review forward.