Trust , Security & Compliance

Your finance and master data never leave your SAP system

Most vendor security reviews ask how a supplier protects customer data on the supplier’s infrastructure. Promenta does not hold customer data on any infrastructure. The software is installed into the customer’s own SAP system and operates entirely within it, which changes what a security review needs to examine.

Where the data sits, and who can reach it

Journal values, vendor bank details, customer records and material data are among the most sensitive objects in an enterprise. In a Promenta process, none of them are copied out of SAP to be prepared, routed or approved. The request, the validation, the approvals and the posting all take place inside the same system that holds the record.

Promenta is therefore not a processor of customer finance or personal data in the course of normal operation. Data residency and retention follow whatever policy already applies to the customer's SAP landscape, whether that landscape is on-premises or in SAP private cloud.

Data residency

Data residency

Data remains in the customer's SAP system throughout the process. There is no transfer to a Promenta environment, so no additional jurisdiction enters scope.

Data in transit

Data in transit

Traffic is from browser-to-SAP application server on the customer's own network, using the transport security already configured for SAP access.

Data at rest

Records are stored in the customer's SAP database under existing encryption, backup and retention arrangements.

Personal Data

Personal data

Personal data held in vendor, customer and business partner records stays within SAP, which keeps it inside the customer's existing data protection controls.

Authorisation runs on the SAP security model already in place

Promenta introduces no second identity store and no parallel authorisation model. Access to a Promenta process is governed by the customer’s existing SAP security profiles, and SAP authorisation checks remain in force throughout the transaction.
The workflow strengthens the control position rather than widening it. Because journals and master data records are raised through a controlled request, organisations can restrict powerful posting and maintenance transactions that would otherwise need to sit with end users, which reduces standing-access risk and supports segregation of duties by rule.
01

Authentication

Users authenticate to SAP as they do for any other SAP process. No separate credential set is created or held by Promenta.

02

Authorisation

SAP authorisation checks apply in full. Approval authority is configured by fields such as company code, value, account group, and account.

03

Segregation of duties

Enforced by the workflow, so a requester cannot approve their own request. Approval group membership is maintained by the customer's own teams, and the changes are audited.

04

Code integrity

Delivered as an SAP-certified ABAP add-on and imported through the customer's existing transport path, so it moves through the customer's own change control.

Evidence produced by the process, not assembled after it

SOX and comparable internal control frameworks certify organisations and their controls rather than the software they run, so no software vendor holds a SOX certification. What software can do is make a control operable and evidenced, which is where Promenta sits in a regulated environment.
Every request, approval, rejection, amendment and posting is captured inside SAP and reportable there, with supporting documentation attached to the record it belongs to. Internal and external audits examine a single population in a single system, which reduces the compliance risk that arises when control evidence is spread across a platform and the ledger.
Requirement
What Promenta provides
Audit trail
A complete, reportable record of who raised, reviewed, approved, rejected, and posted each request, and when.
Supporting evidence
SAP authorisation checks apply in full. Approval Attachments held against the request rather than in mailboxes or shared folders.
Control consistency
Configured approval matrices apply the same rules across entities, regions and company codes.
Reporting
Process reporting on outstanding, approved, rejected and completed requests, available to process controllers during the financial close.
Audit trail
A complete, reportable record of who raised, reviewed, approved, rejected, and posted each request, and when.
Supporting evidence
SAP authorisation checks apply in full. Approval Attachments held against the request rather than in mailboxes or shared folders.
Control consistency
Configured approval matrices apply the same rules across entities, regions and company codes.
Reporting
Process reporting on outstanding, approved, rejected and completed requests, available to process controllers during the financial close.

Availability, change and support access stay under customer control .

Because the solution runs on the customer's SAP application servers, availability aligns with the customer's existing SAP service levels and uptime arrangements rather than a separate vendor status page. Business continuity, disaster recovery and backup are the customer's established SAP procedures, unchanged.
Product updates arrive as SAP transports and pass through the customer's own development, quality and production path, with testing performed in the customer's landscape before production release. Promenta consultants access a customer system only where the customer grants and controls that access under its own policy.

Frequently Asked Questions

No. Requests, approvals and postings take place inside the customer’s own SAP system, and no copy of finance or master data is transferred to a Promenta environment. Data residency, retention, encryption and backup follow whatever policy already governs that SAP landscape.
Through the customer’s existing SAP security profiles. Users authenticate to SAP as they do for any other process, SAP authorisation checks remain in force, and approval authority is configured against fields such as company code, value and account. Promenta creates no separate credential store.
Those certifications assess how a service organisation operates the infrastructure on which it hosts customer data. Promenta hosts no customer data and operates no such infrastructure, since the software runs on the customer’s own SAP servers. The security controls that apply are the customer’s existing SAP and infrastructure controls, and the relevant product credential is SAP certification of the add-on itself.
As SAP transports, imported through the customer’s existing development, quality and production path. Updates are tested in the customer’s own landscape before reaching production, so they follow the change control process already approved for SAP rather than a separate vendor release cycle.
Only where the customer grants it. Access is requested, scoped, and revoked under the customer’s own policy, and any activity performed in the system is subject to the customer’s SAP logging and authorisation control

Request the security and installation documentation

Promenta provides the installation, authorisation and audit documentation that IT security, procurement and internal audit reviews call for, ahead of any commercial conversation.