Security & data
Where your data lives, who can reach it, and what remains when you stop.
FAQ Questions
Security & data questions
Data protection, residency and the audit trail, in plain language.
Start a ConversationHow does it handle SAP authorizations?
Every action the platform performs in SAP runs under a real, named SAP user, never a shared technical super-user. On SAP BTP the platform supports per-user principal propagation, so SAP’s own logs show the actual person. A scope-aware policy engine constrains what each role can do on top of that.
Can the AI change our test or production systems?
No. Writes are structurally impossible outside a development system, and every change must pass syntax and ABAP Test Cockpit validation before anything is written. Test and production stay reachable only through transport release: the human sign-off moment SAP teams and their auditors already know, and one the AI cannot invoke at all.
Will using this expose my organisation? How is data protection handled?
The platform runs in your landscape; ETZ has no runtime access to your systems or data. The only material subprocessor in the data path is the AI provider you select and contract with yourself, which also puts data residency in your hands. The persistent artifact is the audit log, on your storage. Details: the security whitepaper.
Does the tool retain or export my data or logs, during use and when we stop?
The platform stores its audit log on storage you control and sends no telemetry to ETZ. When you stop, there is nothing for ETZ to hand over or delete: SAP data stayed in SAP and the audit log is already on your volume, yours to retain. Your licence ends and registry access is revoked.