The Peltarix dashboard: a posture donut over 191 checks run, findings by category as a bar chart, totals for correlation rules, mapped controls and frameworks, and a ranked severity list.
Agentless ApplicationRead-only RFC · SQL · HTTPS
Attack path foundMITRE ATT&CK tagged
SAP Security · Detection · Compliance

Find, correlate and prove SAP risk. Without installing anything.

Your SAP systems run the money, the payroll and the supply chain - and your security tools cannot see them. Peltarix reads the whole estate over interfaces SAP already exposes, and turns what it finds into ranked risks, real attack alerts and audit-ready proof.

  • No agent, no transport, no downtime
  • Live in an afternoon
  • Nothing written back to SAP
0 Security Checks
0 Correlation Rules
0 Compliance Frameworks
0 Agents Installed
Platform

From Blind Spot to Proof, in Four Steps

No agent to install, no transport to approve, no change window to book. Onboarding a system is a read-only user and a network route.

01

Connect

Read-only, over the interfaces SAP already publishes. Nothing is installed on your hosts.

02

Scan

191 checks run across the estate. Every result is a timestamped record you can point an auditor at years later.

03

Correlate

68 rules turn scattered findings into the attack story behind them - tagged with MITRE ATT&CK your SOC already speaks.

04

Prove

The same evidence answers the auditor. Your next audit becomes an export instead of a project.

One Platform Sees the Whole Estate

On-premise, cloud and SaaS in a single console - not three tools that never agree.

112ABAP / NetWeaver
14SAP HANA
9NetWeaver Java
13SAP BTP & SAP AI
15SuccessFactors · Ariba · Concur
18Web Dispatcher · PI/PO · Hybris
6Azure & Google Cloud
4CVE & patch exposure

Run It Your Way

Same product, three operating modes - including landscapes with no internet at all.

Self-hosted

In your own datacentre or private cloud. Core scanning needs no outbound connection at all.

Managed

We operate it, you use it. Tenant isolation and SSO are built into the product, not bolted on.

Air-gapped

Fully offline. Threat intelligence and CVE data arrive as signed bundles you carry in yourself.

  • It will not disturb production. Connection limits, circuit breakers and staggered scheduling keep the load off your systems.
  • It will not lock out your scan user. Failed logons back off automatically instead of retrying into a lockout.
  • A missing authorization is not a failed scan. You are told exactly which permission is needed and what to do next.
  • Findings, alerts and audit evidence agree. They all come from the same recorded observation - there is no second source to reconcile.
Features

What You Get on Day One

Twelve things your team can use from the first scan - no tuning project, no professional services engagement.

Zero Agents

Nothing installed, nothing transported. The security review your Basis team will actually approve.

191 Security Checks

ABAP, HANA, Java, BTP, cloud and SaaS in one catalog - and one list of what to fix first.

Attack Chains, Not Lists

68 rules connect the dots between findings and events, so you see the attack instead of the noise.

Speaks MITRE ATT&CK

Every alert carries a tactic and technique - your existing SOC playbooks finally cover SAP.

SoD Without the Noise

Violations refined to the exact authorization - a report your business owners will actually read.

Audit Evidence On Demand

405 controls across 10 frameworks, each backed by the check and the date that proves it.

Blast Radius

Ask the question that matters: if this one system falls, what else does the attacker reach?

Your Custom Code, Checked

Finds injection and missing authority checks in your ABAP - and shows the exact path the data takes.

Cover for Unpatched Gaps

Cannot patch before the next window? The hole becomes a monitored trap instead of an open door.

Works Air-Gapped

No internet path required. Everything updates from signed bundles you bring in yourself.

Fits Your Stack

Alerts land in your SIEM, tickets in ServiceNow or Jira, notifications in Teams or Slack.

No Black Box

Every anomaly shows the numbers behind it. When an auditor asks how, you have an answer.

Want the Detail?

Open any area below for the full capability list. Skip it if you would rather just see a demo.

Assessment & findings
  • 191 checks across ABAP, HANA, Java, BTP, cloud and SaaS - one catalogue, one result model.
  • Remediation names the fix: the exact transaction, parameter or table to change - not a generic advisory.
  • Findings open, get acknowledged and resolve themselves - and reopen automatically if the problem comes back.
  • A control passes only when every SAP client was actually assessed. Partial coverage never counts as green.
  • Accept a risk with an auditable note; the exception lapses by itself when the underlying facts change.
  • Parameter baselines, severity-based SLA timers, and a built-in simulated SAP system for demos and training.
Detection & response
  • 68 correlation rules covering event bursts, attack sequences, configuration drift and behavioural baselines.
  • 46 distinct MITRE ATT&CK techniques referenced across the rule set.
  • Behavioural baselines for off-hours activity, unusual velocity and peer-group outliers.
  • External web-attack signals joined to SAP context, and cloud findings promoted into the same alert plane.
  • A false-positive score that only advises - it never closes, hides or re-routes an alert behind your back.
  • Sanctioned activity is suppressed by rule, marked rather than deleted, and always reversible.
  • Related alerts group into a working case with a timeline and the attack narrative.
Access governance & SoD
  • 30 standard segregation-of-duties risks over 28 business functions, fully editable to your rulebook.
  • Violations refined below role level to the authorization object - the false positives disappear.
  • Mitigating controls with an owner, an approver and an expiry date; the violation reopens when it lapses.
  • Access review and recertification campaigns, with the evidence frozen at close.
  • Continuous monitoring raises a regression alert the moment a certified state drifts.
  • Emergency access (firefighter) review, and user-type versus licence classification insight.
Compliance & evidence
  • 10 frameworks, 405 controls and 1,233 control-to-check mappings, each with a written rationale.
  • Adjust any built-in mapping to your interpretation - and restore the shipped one at any time.
  • Upload a new framework version, preview the diff, apply it or roll it back.
  • Live posture per framework, per control and per client from the latest scan.
  • An unassessed control reads not assessed. It is never quietly counted as compliant.
  • Evidence export for the audit file, plus a data-residency policy that flags cross-border transfers.
Attack surface & interfaces
  • Inventory of your web endpoints: what is active, what is reachable anonymously, what is known-dangerous.
  • RFC allowlist governance - callback whitelists, UCON state and unprotected externally callable modules.
  • A trust graph of your landscape: which system can pivot to which, over stored credentials and trust.
  • Blast radius and hub scoring - the systems that concentrate the most risk, ranked.
  • Outside-in probes of Web Dispatcher, PI/PO, BODS, Hybris and the ABAP ICM - no credentials needed.
  • Gateway and message-server hardening reviewed from the inside, complementing the external probe.
Cloud, SaaS & custom code
  • BTP posture: subaccounts, entitlements, privileged roles, destinations, Cloud Connector and service keys.
  • Five dedicated checks for SAP's own AI services - exposure, data reach, identity binding and secrets.
  • Azure and Google Cloud: network exposure, storage and backup encryption, IAM on SAP-touching resources.
  • SuccessFactors, Ariba and Concur: over-privileged roles, admin concentration, password and IP policy, drift.
  • ABAP source-to-sink analysis for injection, directory traversal, missing authority checks and hardcoded secrets.
  • Clean-core visibility: modifications, classic enhancements and non-released API usage, plus UI5 and SQLScript.
  • Transports scanned at release with a block-on-critical verdict your change pipeline can consult.
Threat intelligence & compromise assessment
  • One authoritative CVE store with known-exploited flagging, and SAP Patch Day applicability per system.
  • Security notes triaged by dependency and risk, so the note list becomes a work list.
  • Signed, versioned exploit signatures delivered as catalog packs - never as code, never silently dropped.
  • An IOC catalog swept against your estate, plus STIX/TAXII interchange in both directions.
  • Six checks hunt for signs of active compromise: webshells, backdoor function modules and tampered standard objects.
  • Suspicious privileged accounts, rogue RFC destinations and persistence footholds surfaced with their own lifecycle.
Data protection & privacy
  • Is SAP logging who reads sensitive data - and is it logging the fields that actually matter?
  • HANA encryption at rest for data, redo log and backups, including how old the keys are.
  • Field masking configuration and how much of your sensitive data it really covers.
  • Retention rules and personal-data blocking posture for privacy-regulated records.
  • Cross-border transfer detection when an endpoint resolves outside your declared regions.
  • Inside Peltarix itself, sensitive values are masked by role - unmasking needs permission and is audited.
Reporting, AI & day-to-day operations
  • Board-ready PDF reports on a schedule, delivered to the right people automatically.
  • Optional AI narratives that are fact-checked against your data - if the model invents anything, it is rejected.
  • Ask questions in plain language; 13 ready-made investigations work with no AI model configured at all.
  • Bring your own model - including a fully local one for estates that permit no external inference.
  • One ranked inbox federates 14 sources of findings and alerts. One front door instead of fourteen.
  • Schedule everything from one screen, watch running scans live, and cancel any of them.
  • A public REST API with scoped tokens and published OpenAPI for whatever you want to automate.
Who It Is For

Five Teams, One Console

Everyone asks a different question. They all get answered from the same data.

CISO / SAP Security Lead

"Where are we actually exposed?"

See your estate's real attack paths.

SAP Basis / Platform

"Will this break my systems?"

Onboard a system in an afternoon - no transport, no downtime.

SOC / Detection Engineer

"I have no SAP telemetry."

Get SAP detections your playbooks already understand.

Compliance / Internal Audit

"Prove this control was met."

Turn your next audit into an export.

MSSP / Service Provider

"I run twenty estates."

One console, every customer's estate.

Modules

Start Small. Grow Without Replatforming.

Buy the modules you need today and switch the rest on later - it is the same product, configured differently.

Flagship

The Correlation & Fusion Engine

This is what makes Peltarix more than a scanner. It watches the events and configuration your checks collected, connects activity across systems and across time, and tells you the story: not "this parameter is weak", but "someone is walking through your landscape, and here is the path".

Every alert is tagged with MITRE ATT&CK, so your SOC treats SAP like any other source. And every rule is readable SQL you can inspect - no vendor magic, no unexplainable score.

Event bursts Attack sequences Configuration drift Cross-system fusion Behavioural baselines Cloud ↔ on-premise

Security Scanner

The 191-check catalogue - your continuous SAP security assessment.

Access Governance

Segregation of duties, access reviews and emergency-access oversight.

Compliance Engine

Ten frameworks scored live from evidence you already collected.

Attack Surface

Exposed endpoints, RFC trust paths and blast radius across the landscape.

Custom Code Security

Your own ABAP, UI5 and SQLScript checked for real vulnerabilities.

Transports & Change Control

Catch risky code before it reaches production, and spot bypassed process.

Cloud & SaaS Posture

BTP, SAP AI services, Azure, Google Cloud and your SAP SaaS tenants.

Threat Intelligence

CVEs, Patch Day notes and exploit signatures - offline-capable end to end.

Data Protection

Who reads sensitive data, is it encrypted, and does retention hold up?

AI Threat Hunting

Ask questions in plain language - or use the presets that need no AI at all.

And the Screens Your Team Lives In

Estate Dashboard Unified Work Queue Incidents & Cases Reports Scheduler Settings & Admin Public API Offline Audit
Compliance

Turn Your Next Audit Into an Export

Auditors do not want a configuration list. They want proof that a control held, on this system, on this date. That is exactly what comes out of the scan you were already running.

NIST SP 800-53 Rev. 5146 controls
SAP Security Baseline 2.694 controls
DSAG Prüfleitfaden40 controls
ISO/IEC 27001:202231 controls
KVKK (Law 6698)23 controls
NIST CSF 2.022 controls
SOX ITGC15 controls
GDPR (EU 2016/679)13 controls
DORA11 controls
NIS210 controls

Ten frameworks · 405 mapped controls · 1,233 mappings, each with a written rationale

Nothing Is Written Back to Your SAP Systems

Three actions in the entire product can change anything - all three are for stopping an attacker mid-incident, and all three ship switched off.

Lock a user

One named user, on one named client. Never in bulk.

Unlock a user

The same guardrails, in reverse.

End their sessions

Cut an active intruder off, with a two-step human confirmation.

Peltarix cannot change a password, create or modify a user or role, alter a system parameter, write to a table, or run a report - by construction, not by policy.

You Are Buying a Security Product. Audit It.

Our own posture, before you have to ask for it.

How Peltarix protects your data
  • Everything stays in your database. Findings, evidence and audit trail live in the PostgreSQL instance you operate.
  • Credentials are encrypted with AES-256-GCM and never returned by the API - not even to an administrator.
  • No outbound connection is required for core scanning. Optional feeds can each be switched off or replaced by a signed offline upload.
  • AI is opt-in. Nothing AI-related activates until you configure a model, personal data is redacted first, and a fully local model is supported.
  • Everything is logged. Ten categories of audit trail with configurable retention and export.
  • Sensitive values are masked by role inside the product itself; unmasking requires its own permission and is audited.
How access to Peltarix is controlled
  • Corporate SSO over OpenID Connect, SAML or LDAP - built on a certified library, not per-vendor hacks.
  • 60 granular permissions so each team sees only its own surface.
  • Multi-tenancy in the core - systems, incidents and cloud targets are scoped by explicit membership.
  • Modules you did not buy are genuinely off - their API returns 404 before authentication, so scope is provable in a tender.
  • Encrypted transport to SAP over SNC and SAProuter where your landscape uses them.
  • Backups are a documented shell procedure - there is deliberately no web endpoint that unpacks uploaded archives.
Agentless
Read-Only by Default
Air-Gap Capable
AES-256 at Rest
Full Audit Trail
Multi-Tenant + SSO

We map only what a technical SAP audit can actually evidence, and we say so per framework. A tool that reads SAP tables cannot "cover ISO 27001" - so we tell you exactly which clauses we prove, and leave the rest where it belongs.

Why Peltarix

Six Honest Differences

What you usually get, and what you get here.

The usual approachPeltarix
Installs an agent or a transport, so the project stalls before it startsInstalls nothing. Read-only access, live the same day
Hands you another findings list to triageConnects them into attack chains your SOC can act on
Shows an unexplainable "self-learning" risk scoreShows its work. Every number is recomputable by you
Claims to "cover" a whole standardNames the exact controls it evidences - and what it does not
Keeps cloud and on-premise in separate consolesOne view of ABAP, HANA, BTP, Azure, GCP and SaaS
Needs an internet connection to workRuns fully air-gapped on signed offline bundles

The Numbers

Counted from the product, not from a brochure.

191Security checks
68Correlation rules
46MITRE techniques
10Compliance frameworks
405Controls mapped
1,233Control-to-check mappings
30Segregation-of-duties risks
17Data sources, all scheduled
3Write actions, shipped disabled
0Agents on your SAP hosts

See Your Own Estate, Not a Slide Deck

Tell us what you run. We will show you what it exposes - read-only, with nothing installed.

Read-only · No agent installed · We will reply shortly

Head office

1317 Edgewater Dr #2439
Orlando, FL 32804
United States
+1 (302) 205-3966

Belgium office

Da Vincilaan 1
1930 Zaventem
België
+32 471 39 27 38