Security and deployment

Security and deployment for SAP test data, inside your own boundary

Synthesized runs in your environment, reads SAP with a read-only user and writes only to non-production systems. Nothing is installed in SAP, no data is sent to Synthesized, and your identity provider, keys and logs stay in charge.

Security at a glanceSecurity pack
Runs inside your boundary
A server, Kubernetes or OpenShift
Your network
No data sent to Synthesized
No outbound calls with the AI assistant off
No egress
Only protected output lands
Masked, subsetted or synthetic data
Irreversible
No datasets kept at rest
Metadata, workflows and audit only
Not stored
Air-gap capable
Built for the SAP & Enterprise QA toolchain
SAP S/4HANASAP AribaSAP HANASalesforceUiPathTricentis

At a glance

Four facts decide data exposure, vendor access and audit scope

0
Outbound calls at runtime, with the optional AI assistant off
Read-only
Access to your SAP source; writes go only to non-production
Your IdP
Sign-in through SAML, OIDC, LDAP or Kerberos
Your SIEM
Audit records and logs stay in your own tools

Architecture

Every component runs inside your network

Synthesized ships the runtime: a web UI, an API and a pool of workers. The database, identity, secrets and logs are yours.

Your usersBrowser, API or CI/CD
SAP sourceProduction or test, read-only
Synthesized runtimeUI, API and workers. Data is transformed in memory and never stored.
Metadata databaseYour PostgreSQL: workflows, audit, no rows
SAP targetNon-production: protected output only
Your identity, secrets and SIEMSSO, keys and audit logs stay yours
Synthesized or the internetNo runtime connection
Your network · on-premise or private cloud
read-only
masked
AI assistant off: no outbound calls, no telemetry
Everything runs inside your network. Synthesized ships the runtime; the database, identity, keys and logs are yours.
Validation or one teamSingle serverDocker Compose or Podman on one Linux server: 8 vCPU, 32 GB RAM and 100 GB SSD, with your PostgreSQL 13+ database. RHEL with SELinux is supported.
Production and several teamsKubernetes or OpenShiftA Helm chart deploys the UI, API and workers; add workers for parallel runs. TLS at your ingress, optional mutual TLS inside.
No internetAir-gappedImages and the chart arrive once through your registry mirror, the licence key is applied offline, and upgrades follow the same route.

Also available through AWS Marketplace and Google Cloud Marketplace.

Connecting to SAP

Two ways to connect, both inside your boundary

RecommendedSAP OData servicesReads and writes through SAP's application layer with an SAP service user over HTTPS. No database access, so it works on RISE with SAP and wherever database access isn't allowed.
AlternativeSAP HANA via JDBCA dedicated HANA user, read-only on the source schema and writing only to a non-production target, with TLS and certificate validation. For SAP HANA 2.0 and later that you run yourself.

Both routes read full metadata and keep referential integrity across standard and custom Z-tables. Supported landscapes: S/4HANA and ECC, including RISE with SAP.

Controls

Your identity provider, your keys, your logs

Sign-inIdentitySAML 2.0, OIDC, LDAP or Active Directory, or Kerberos, through your IdP. MFA and conditional access stay there; the platform never sees passwords.
Separation of dutiesRolesOwner, Admin and Member across the platform, plus Viewer, Editor and Admin per project, so auditors can look without changing anything.
In transit and at restEncryptionTLS 1.2 or later in transit. Connection credentials are encrypted with your key, or fetched from HashiCorp Vault, AWS Secrets Manager or GCP Secret Manager.
EvidenceAuditEvery authenticated API call and every run: who, when and what changed. Written to your database and sent to your SIEM.
Nothing keptData minimisationSource and transformed datasets aren't persisted in the platform, and no source values reach the logs.
SAP accessLeast privilege on SAPRead-only on the source, write only to non-production, with separate technical users per environment.

Shared responsibility

You run the environment. We build, secure and support the software.

AreaYouSynthesized
InfrastructureProvide, patch and harden servers or clustersPublish sizing, prerequisites and hardening guidance
Install and updatesInstall releases and apply updates on your scheduleShip tested, vulnerability-scanned releases with notes
Identity and accessRun the IdP, MFA, groups and access reviewsProvide SSO, roles and group-to-role mapping
Keys, secrets and backupsHold encryption keys, secrets and database backupsIntegrate with Vault and cloud secret managers
SAP access and scopeApprove technical users, clients and table scopeAdvise on least-privilege access
Masking rulesOwn and sign off the rules applied to your dataProvide SAP-aware templates and guidance
Logs and SIEMCollect, retain and monitor audit records and logsEmit audit records and structured logs
Vulnerabilities and incidentsReport issues and install fixesFix to stated timelines; notify confirmed incidents

No standing access: support is remote by default, and Synthesized staff get access only if you grant it.

Assurance

Evidence for your review

AttestationSOC 2 Type 2Audit in progress, with the report expected in December 2026.
Under NDASecurity assurance packTen documents, from access control and secure development to incident response and business continuity, shared under NDA.
DisclosureReport a vulnerabilityWrite to security@synthesized.io. Confirmed issues are fixed to stated timelines, and you install the update.

Synthesized for SAP: key facts

SAP systems
S/4HANA and ECC, including RISE with SAP (through OData); SAP HANA 2.0+ directly
Deployment
Inside your boundary: a server, Kubernetes or OpenShift, on-premise or private cloud, air-gap capable
Integrations
Tricentis Tosca, UiPath, API and CLI
Where to buy
SAP Store, AWS Marketplace and Google Cloud Marketplace, or direct

We've got you covered

Questions security reviewers ask first

Does any of our data leave our environment?

No. The platform runs inside your boundary and sends nothing to Synthesized. With the optional AI assistant off, it makes no outbound calls.

Can masked data be reversed?

No. Masked output can't be decrypted or reversed to source values, and unmasked values never land in the target.

Do Synthesized staff need access to our systems?

No. Support is remote by default and your team keeps the keyboard. Staff get access only if you choose to grant it.

Can it run fully air-gapped?

Yes. Images and the Helm chart arrive once through your registry mirror, and upgrades follow the same offline route.

Which SAP landscapes are supported?

S/4HANA and ECC, including RISE with SAP, through OData. SAP HANA 2.0 and later can also connect directly through JDBC.

Next step

Get the security pack

We send the architecture, data flows and controls, plus the assurance documents under NDA, so your review starts on day one.

Runs in your environmentNothing installed in SAPRead-only access to SAPSecurity and deployment
Updated October 2026

SAP, S/4HANA, SAP HANA, SuccessFactors, Ariba, Concur and other SAP products and services mentioned herein, as well as their respective logos, are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. All other product and service names mentioned are the trademarks of their respective companies.