Security

Security built around your SAP landscape

BasisPilot is designed so your SAP credentials stay within your environment while operational telemetry moves outward to the BasisPilot platform.

Customer SAP LandscapeYour systems stay in your environment.
BasisPilot ConnectorInstalled on a host that can see SAP.
Outbound HTTPSSignals leave. Passwords do not.
BasisPilot CloudOperational picture and investigation.

Credentials stay with you

SAP passwords and RFC connection details remain on your host. They are not sent to BasisPilot.

Outbound by design

The connector talks out over HTTPS. You do not open inbound access from BasisPilot into SAP.

Read-only first

Monitoring starts by observing. Change actions stay off unless you explicitly turn them on.

AI doesn't take control

When AI investigation is used, it can propose. A person still has to approve the next step.

Honesty

Clear about what exists. Clear about what doesn't.

We do not claim certifications, compliance frameworks, encryption standards, or tenant isolation. Those are not implemented here.

Implemented

What you can hold us to today

  • SAP credentials stay on the customer-side connector.
  • The platform does not receive RFC passwords or SAP connection fields.
  • The connector posts outbound. Evidence is bounded — not dump bodies or passwords.
  • Monitoring is read-only first. Governed change stays off by default.
  • AI is not an execution authority. A human still approves the next step.

Planned

Not live yet — and we will not pretend otherwise

  • Login, sessions, and a public SaaS authentication wall
  • Authenticated connector communication
  • Organizations and tenant isolation
  • Trial and subscription enforcement
  • A public cloud TLS edge, rate limits, and a locked CORS allowlist
  • Authenticated customer documentation

The verified technical model is docs/SECURITY.md in the BasisPilot repository. Until public technical docs exist, this link opens Resources.