Security
Security built around your SAP landscape
BasisPilot is designed so your SAP credentials stay within your environment while operational telemetry moves outward to the BasisPilot platform.
Credentials stay with you
SAP passwords and RFC connection details remain on your host. They are not sent to BasisPilot.
Outbound by design
The connector talks out over HTTPS. You do not open inbound access from BasisPilot into SAP.
Read-only first
Monitoring starts by observing. Change actions stay off unless you explicitly turn them on.
AI doesn't take control
When AI investigation is used, it can propose. A person still has to approve the next step.
Honesty
Clear about what exists. Clear about what doesn't.
We do not claim certifications, compliance frameworks, encryption standards, or tenant isolation. Those are not implemented here.
Implemented
What you can hold us to today
- SAP credentials stay on the customer-side connector.
- The platform does not receive RFC passwords or SAP connection fields.
- The connector posts outbound. Evidence is bounded — not dump bodies or passwords.
- Monitoring is read-only first. Governed change stays off by default.
- AI is not an execution authority. A human still approves the next step.
Planned
Not live yet — and we will not pretend otherwise
- Login, sessions, and a public SaaS authentication wall
- Authenticated connector communication
- Organizations and tenant isolation
- Trial and subscription enforcement
- A public cloud TLS edge, rate limits, and a locked CORS allowlist
- Authenticated customer documentation
The verified technical model is docs/SECURITY.md in the BasisPilot repository. Until public technical docs exist, this link opens Resources.