Security and deployment
Synthesized runs in your environment, reads SAP with a read-only user and writes only to non-production systems. Nothing is installed in SAP, no data is sent to Synthesized, and your identity provider, keys and logs stay in charge.







At a glance
Architecture
Synthesized ships the runtime: a web UI, an API and a pool of workers. The database, identity, secrets and logs are yours.
Also available through AWS Marketplace and Google Cloud Marketplace.
Connecting to SAP
Both routes read full metadata and keep referential integrity across standard and custom Z-tables. Supported landscapes: S/4HANA and ECC, including RISE with SAP.
Controls
Nothing keptData minimisationSource and transformed datasets aren't persisted in the platform, and no source values reach the logs.Assurance
We've got you covered

No. The platform runs inside your boundary and sends nothing to Synthesized. With the optional AI assistant off, it makes no outbound calls.

No. Masked output can't be decrypted or reversed to source values, and unmasked values never land in the target.

No. Support is remote by default and your team keeps the keyboard. Staff get access only if you choose to grant it.

Yes. Images and the Helm chart arrive once through your registry mirror, and upgrades follow the same offline route.

S/4HANA and ECC, including RISE with SAP, through OData. SAP HANA 2.0 and later can also connect directly through JDBC.
Next step
We send the architecture, data flows and controls, plus the assurance documents under NDA, so your review starts on day one.
SAP, S/4HANA, SAP HANA, SuccessFactors, Ariba, Concur and other SAP products and services mentioned herein, as well as their respective logos, are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. All other product and service names mentioned are the trademarks of their respective companies.