SAP Security & Data Handling
How Artificio works with SAP. Securely.
Written for the people who have to approve us: your SAP Basis, security and compliance teams. Exactly how Artificio connects to SAP, what it can and cannot touch, where your data goes, and the documentation your reviewers will ask for.
- ISO 27001:2013
- SOC 2 Type II
- GDPR
- HIPAA
- ISO 27001:2013
- SOC 2 Type 2
- GDPR
- HIPAA
- Connects over OData, BAPI and RFCinterface
- Runs against ECC and S/4HANAscope
- Acts under its own service useridentity
- Every posting carries an audit trailrecord
SAP connection
Standard interfaces, no screen-scraping.
Artificio connects to SAP the way your own integrations do (through published, supported interfaces), so there's nothing brittle or unsupported in the path to production.
- Documentsemail · PDF · scan · EDI
- Artificio AI layerextract · validate
- Standard interfaceOData · BAPI · RFC
- Your SAPECC · S/4HANA
- Connects through OData, BAPI, and RFC. The same standard, supported interfaces your SAP team already trusts.
- No screen-scraping and no custom ABAP installed in your system.
- Reads live master data (vendors, POs, goods receipts) to validate before posting, read-only wherever a process only needs to read.
- Connection secured with TLS in transit and OAuth, with credentials held in a secrets vault, never embedded in the application.
- Brokered through SAP Cloud Connector, so SAP is never exposed directly to the internet and your team controls exactly what's reachable.
Deployment
Runs wherever your security policy requires.
Many SAP-adjacent tools force your data into a vendor cloud. Artificio doesn't. Choose the model your policy allows. The automation is the same either way.
- On-premises
Inside your data center
Deploy entirely within your own infrastructure. Data never leaves your perimeter. The strictest option for regulated or air-gapped SAP landscapes. - Your cloud
In your own cloud tenant
Run Artificio in your AWS, Azure, or GCP account. Your data stays in your cloud, under your controls, keys, and residency, with none of it held by us. - Artificio cloud
Fully managed SaaS
Let us host and operate it. Fastest to start, with the same certifications, encryption, and isolation, ideal when a vendor cloud is acceptable.
Data handling
Where your data lives, and for how long.
Clear answers to the data-residency and retention questions in every enterprise security review.
- Hosting & region
- You choose where it runs: on-prem, Artificio's cloud, or your own cloud tenant. In your own environment, data residency is fully under your control. In Artificio's cloud, region can be provisioned to match your residency requirements.
- Deployment options
- Deploy on-premises, in Artificio's cloud, or in your own cloud tenant (AWS, Azure, or GCP). Your data can stay entirely within your environment.
- Encryption
- Encrypted in transit with TLS and at rest with AES-256.
- Document retention
- Retention is customer-configurable. Documents are processed to run your automation and retained only per your configured policy; in your own environment, retention is entirely under your control.
- Tenant isolation
- Customer data is logically isolated per tenant, with dedicated environments available for enterprise deployments.
- Sub-processors
- A current sub-processor list is available to customers and prospects under review on request.
Access & control
Your roles, your approvals, your audit trail.
Artificio is designed to sit inside your existing control model, not around it.
- Role-based access: separate view, edit, approve, and post permissions, with SSO via SAML.
- Respects SAP authorizations: posting is performed under the connected service account's authorizations, so it can never exceed the roles and segregation-of-duties rules your SAP team has granted.
- Human-in-control posting: clean documents can post straight-through, or you can require approval on any type; nothing posts blindly.
- Complete audit trail, who did what and when, AI value vs. human edit, traceable to the SAP document number.
- Written rationale. Every automated decision is explainable, not a black box.
Certifications
Independently audited.
The compliance foundation behind the SAP-specific controls above.
- ISO 27001:2013
- Certified information security management system: risk assessment, controls, and continuous improvement.
- SOC 2 Type II
- Independently audited over time across security, availability, processing integrity, confidentiality, and privacy. Report available under NDA.
- GDPR
- Lawful processing, data-subject rights, data protection by design, and secure international transfers.
- HIPAA
- Physical, technical, and administrative safeguards for PHI, with BAAs where required.
For your security team.
Everything a vendor security review typically needs: request the package and we'll turn it around quickly, under NDA where appropriate.
SOC 2 Type II report
Full report available under NDA.
ISO 27001 certificate
Certificate and scope statement.
DPA & BAA
Data Processing Agreement and Business Associate Agreement available on request.
Penetration test summary
Third-party penetration test; summary available on request under NDA.
Sub-processor list
Current list available on request.
Security questionnaire
We complete standard questionnaires (SIG / CAIQ / custom).
Architecture / data-flow diagram
How data moves from capture to SAP posting.
Security contact
security@artificio.ai for reviews & disclosure.
The short version
Three principles behind how we connect.
- Least footprint
Nothing installed in your SAP core
Artificio runs as an external AI layer and connects through standard SAP interfaces. No add-on inside your core, no custom ABAP. Your clean-core strategy stays intact. - Least privilege
Scoped access that honors SAP roles
Artificio connects through a dedicated service account with least-privilege authorizations and respects your SAP roles and segregation-of-duties rules. It can't do in SAP what its authorization doesn't allow. - Full accountability
Every action logged
Extraction, each manual correction, approval, and posting are captured with user, timestamp, and before/after value, traceable to the SAP document for a complete audit trail.
Security & compliance
Enterprise security across every solution
ISO 27001:2013 certified, SOC 2 Type 2 compliant, GDPR and HIPAA ready. Every agent action is logged, auditable, and runs in isolated environments.
- ISO 27001:2013
- SOC 2 Type II
- GDPR ready
- HIPAA ready
Security review
Bring your security team to the conversation.
We'll walk your Basis, security, and compliance reviewers through the connection model, data handling, and controls, and hand over the documentation to move the review forward.