Zero Agents
Nothing installed, nothing transported. The security review your Basis team will actually approve.
Your SAP systems run the money, the payroll and the supply chain - and your security tools cannot see them. Peltarix reads the whole estate over interfaces SAP already exposes, and turns what it finds into ranked risks, real attack alerts and audit-ready proof.
No agent to install, no transport to approve, no change window to book. Onboarding a system is a read-only user and a network route.
Read-only, over the interfaces SAP already publishes. Nothing is installed on your hosts.
191 checks run across the estate. Every result is a timestamped record you can point an auditor at years later.
68 rules turn scattered findings into the attack story behind them - tagged with MITRE ATT&CK your SOC already speaks.
The same evidence answers the auditor. Your next audit becomes an export instead of a project.
On-premise, cloud and SaaS in a single console - not three tools that never agree.
Same product, three operating modes - including landscapes with no internet at all.
In your own datacentre or private cloud. Core scanning needs no outbound connection at all.
We operate it, you use it. Tenant isolation and SSO are built into the product, not bolted on.
Fully offline. Threat intelligence and CVE data arrive as signed bundles you carry in yourself.
Twelve things your team can use from the first scan - no tuning project, no professional services engagement.
Nothing installed, nothing transported. The security review your Basis team will actually approve.
ABAP, HANA, Java, BTP, cloud and SaaS in one catalog - and one list of what to fix first.
68 rules connect the dots between findings and events, so you see the attack instead of the noise.
Every alert carries a tactic and technique - your existing SOC playbooks finally cover SAP.
Violations refined to the exact authorization - a report your business owners will actually read.
405 controls across 10 frameworks, each backed by the check and the date that proves it.
Ask the question that matters: if this one system falls, what else does the attacker reach?
Finds injection and missing authority checks in your ABAP - and shows the exact path the data takes.
Cannot patch before the next window? The hole becomes a monitored trap instead of an open door.
No internet path required. Everything updates from signed bundles you bring in yourself.
Alerts land in your SIEM, tickets in ServiceNow or Jira, notifications in Teams or Slack.
Every anomaly shows the numbers behind it. When an auditor asks how, you have an answer.
Open any area below for the full capability list. Skip it if you would rather just see a demo.
Everyone asks a different question. They all get answered from the same data.
See your estate's real attack paths.
Onboard a system in an afternoon - no transport, no downtime.
Get SAP detections your playbooks already understand.
Turn your next audit into an export.
One console, every customer's estate.
Buy the modules you need today and switch the rest on later - it is the same product, configured differently.
This is what makes Peltarix more than a scanner. It watches the events and configuration your checks collected, connects activity across systems and across time, and tells you the story: not "this parameter is weak", but "someone is walking through your landscape, and here is the path".
Every alert is tagged with MITRE ATT&CK, so your SOC treats SAP like any other source. And every rule is readable SQL you can inspect - no vendor magic, no unexplainable score.
The 191-check catalogue - your continuous SAP security assessment.
Segregation of duties, access reviews and emergency-access oversight.
Ten frameworks scored live from evidence you already collected.
Exposed endpoints, RFC trust paths and blast radius across the landscape.
Your own ABAP, UI5 and SQLScript checked for real vulnerabilities.
Catch risky code before it reaches production, and spot bypassed process.
BTP, SAP AI services, Azure, Google Cloud and your SAP SaaS tenants.
CVEs, Patch Day notes and exploit signatures - offline-capable end to end.
Who reads sensitive data, is it encrypted, and does retention hold up?
Ask questions in plain language - or use the presets that need no AI at all.
Auditors do not want a configuration list. They want proof that a control held, on this system, on this date. That is exactly what comes out of the scan you were already running.
Ten frameworks · 405 mapped controls · 1,233 mappings, each with a written rationale
Three actions in the entire product can change anything - all three are for stopping an attacker mid-incident, and all three ship switched off.
One named user, on one named client. Never in bulk.
The same guardrails, in reverse.
Cut an active intruder off, with a two-step human confirmation.
Peltarix cannot change a password, create or modify a user or role, alter a system parameter, write to a table, or run a report - by construction, not by policy.
Our own posture, before you have to ask for it.
We map only what a technical SAP audit can actually evidence, and we say so per framework. A tool that reads SAP tables cannot "cover ISO 27001" - so we tell you exactly which clauses we prove, and leave the rest where it belongs.
What you usually get, and what you get here.
| The usual approach | Peltarix |
|---|---|
| Installs an agent or a transport, so the project stalls before it starts | Installs nothing. Read-only access, live the same day |
| Hands you another findings list to triage | Connects them into attack chains your SOC can act on |
| Shows an unexplainable "self-learning" risk score | Shows its work. Every number is recomputable by you |
| Claims to "cover" a whole standard | Names the exact controls it evidences - and what it does not |
| Keeps cloud and on-premise in separate consoles | One view of ABAP, HANA, BTP, Azure, GCP and SaaS |
| Needs an internet connection to work | Runs fully air-gapped on signed offline bundles |
Counted from the product, not from a brochure.
Tell us what you run. We will show you what it exposes - read-only, with nothing installed.
Read-only · No agent installed · We will reply shortly