Artificio - Automation. See more. Do more.

SAP Security & Data Handling

How Artificio works with SAP — securely.

Written for the people who have to approve us: your SAP Basis, security, and compliance teams. Here's exactly how Artificio connects to SAP, what it can and can't touch, where your data goes, and the documentation your reviewers will ask for.

ISO 27001:2013SOC 2 TYPE IIGDPRHIPAAON-PREM · YOUR CLOUD · SAASNO ABAP IN YOUR CORE

The short version

Three principles behind how we connect.

Least footprint

Nothing installed in your SAP core

Artificio runs as an external AI layer and connects through standard SAP interfaces. No add-on inside your core, no custom ABAP — your clean-core strategy stays intact.
Least privilege

Scoped access that honors SAP roles

Artificio connects through a dedicated service account with least-privilege authorizations and respects your SAP roles and segregation-of-duties rules. It can't do in SAP what its authorization doesn't allow.
Full accountability

Every action logged

Extraction, each manual correction, approval, and posting are captured with user, timestamp, and before/after value — traceable to the SAP document for a complete audit trail.

SAP connection

Standard interfaces, no screen-scraping.

Artificio connects to SAP the way your own integrations do — through published, supported interfaces — so there's nothing brittle or unsupported in the path to production.

Documents
email · PDF · scan · EDI
Artificio AI layer
extract · validate
Standard interface
OData · BAPI · RFC
Your SAP
ECC · S/4HANA
Connects through OData, BAPI, and RFC — the same standard, supported interfaces your SAP team already trusts.
No screen-scraping and no custom ABAP installed in your system.
Reads live master data (vendors, POs, goods receipts) to validate before posting — read-only wherever a process only needs to read.
Connection secured with TLS in transit and OAuth, with credentials held in a secrets vault — never embedded in the application.
Brokered through SAP Cloud Connector, so SAP is never exposed directly to the internet and your team controls exactly what's reachable.

Deployment

Runs wherever your security policy requires.

Many SAP-adjacent tools force your data into a vendor cloud. Artificio doesn't. Choose the model your policy allows — the automation is the same either way.

On-premises

Inside your data center

Deploy entirely within your own infrastructure. Data never leaves your perimeter — the strictest option for regulated or air-gapped SAP landscapes.
Your cloud

In your own cloud tenant

Run Artificio in your AWS, Azure, or GCP account. Your data stays in your cloud, under your controls, keys, and residency — with none of it held by us.
Artificio cloud

Fully managed SaaS

Let us host and operate it. Fastest to start, with the same certifications, encryption, and isolation — ideal when a vendor cloud is acceptable.

The same connection model, controls, and audit trail apply in every deployment — only the hosting location changes.

Data handling

Where your data lives, and for how long.

Clear answers to the data-residency and retention questions in every enterprise security review.

Hosting & region
You choose where it runs — on-prem, Artificio's cloud, or your own cloud tenant. In your own environment, data residency is fully under your control. In Artificio's cloud, region can be provisioned to match your residency requirements.
Deployment options
Deploy on-premises, in Artificio's cloud, or in your own cloud tenant (AWS, Azure, or GCP) — your data can stay entirely within your environment.
Encryption
Encrypted in transit with TLS and at rest with AES-256.
Document retention
Retention is customer-configurable. Documents are processed to run your automation and retained only per your configured policy; in your own environment, retention is entirely under your control.
Tenant isolation
Customer data is logically isolated per tenant, with dedicated environments available for enterprise deployments.
Sub-processors
A current sub-processor list is available to customers and prospects under review on request.
The question every AI review asks

We don't train models on your data.

Artificio does not use your documents or data to train or fine-tune AI models — no exceptions. Your data is processed solely to run your automation, and nothing else.

Access & control

Your roles, your approvals, your audit trail.

Artificio is designed to sit inside your existing control model, not around it.

Role-based access — separate view, edit, approve, and post permissions, with SSO via SAML.
Respects SAP authorizations — posting is performed under the connected service account's authorizations, so it can never exceed the roles and segregation-of-duties rules your SAP team has granted.
Human-in-control posting — clean documents can post straight-through, or you can require approval on any type; nothing posts blindly.
Complete audit trail — who did what and when, AI value vs. human edit, traceable to the SAP document number.
Written rationale — every automated decision is explainable, not a black box.

Certifications

Independently audited.

The compliance foundation behind the SAP-specific controls above.

ISO 27001:2013
Certified information security management system — risk assessment, controls, and continuous improvement.
SOC 2 Type II
Independently audited over time across security, availability, processing integrity, confidentiality, and privacy. Report available under NDA.
GDPR
Lawful processing, data-subject rights, data protection by design, and secure international transfers.
HIPAA
Physical, technical, and administrative safeguards for PHI, with BAAs where required.

For your security team.

Everything a vendor security review typically needs — request the package and we'll turn it around quickly, under NDA where appropriate.

SOC 2 Type II report
Full report available under NDA.
ISO 27001 certificate
Certificate and scope statement.
DPA & BAA
Data Processing Agreement and Business Associate Agreement available on request.
Penetration test summary
Third-party penetration test; summary available on request under NDA.
Sub-processor list
Current list available on request.
Security questionnaire
We complete standard questionnaires (SIG / CAIQ / custom).
Architecture / data-flow diagram
How data moves from capture to SAP posting.
Security contact
security@artificio.ai for reviews & disclosure.

Security review

Bring your security team to the conversation.

We'll walk your Basis, security, and compliance reviewers through the connection model, data handling, and controls — and hand over the documentation to move the review forward.