Trust center · updated 2026-07-31

Controls an SAP modernization buyer can verify before enforcement.

Adranum is designed for internal SAP teams that need analysis, remediation, testing, and migration decisions to remain tied to source evidence. This trust center summarizes the implemented controls and the boundaries a security, procurement, architecture, or program owner should validate during a representative pilot.

Security architecture

Every stateful query is scoped to an organization. Sessions, API keys, and SCIM tokens are one-way hashed. SAP source artifacts, snapshots, findings, generated proposals, approvals, validation outcomes, and exports retain tenant boundaries and their operational history.

Uploads are size-bounded and inspected before analysis. Archive paths, expansion limits, supported file types, and malformed inputs are checked so an uploaded ZIP cannot silently write outside its assigned workspace or expand without a defined limit.

Enterprise identity

The inherited factory supports OIDC Authorization Code flow with PKCE, signed identity-token validation, domain restriction, encrypted client secrets, and SCIM user provisioning.

Buyers should test the exact identity configuration they intend to enforce, including domain restrictions, role mapping, deprovisioning, session revocation, and the behavior when the identity provider is unavailable. A configured integration should be distinguished from an implementation plan or a logo in a catalog.

SAP artifact and evidence handling

Adranum records source hashes, parser and rule versions, coverage boundaries, analysis results, proposed changes, reviewers, customer-run validation, and export identities. Generated code is a proposal until it is reviewed and validated against the exact package. Changed package content invalidates the earlier evidence relationship.

The product separates observed evidence, deterministic analysis, model-assisted suggestions, and human decisions. Missing source, unsupported dynamic behavior, incomplete test coverage, and unverified execution remain visible limitations rather than being converted into false certainty.

Integrations and billing

Stripe webhooks are signature-verified and replay-protected. Managed OAuth brokers provider authorization so Adranum stores workspace-scoped connection identifiers rather than raw provider credentials.

Customer-side operators can keep raw service data and execution credentials inside customer infrastructure while sending bounded commands, hashes, and aggregate attestations to the control plane. Validate each required SAP, source-control, test, and deployment connection with representative non-production data before relying on it.

Infrastructure

The deployment supports a non-root container behind TLS with a read-only filesystem, dropped capabilities, health checks, resource limits, and encrypted off-box backup support.

Recovery should be tested, not inferred from a backup setting. Procurement review should confirm backup scope, encryption responsibility, retention, restore verification, regional requirements, incident contacts, and the recovery objective appropriate to the buyer's program.

Procurement documents

Data processing addendum · Security architecture · Privacy notice · Service terms

Assurance status

Adranum does not claim SOC 2, ISO 27001, official SAP certification, or another assurance without current independent evidence.

Adranum is not SAP, and SAP does not sponsor or certify the analyses described on this site. Clean-core scores are transparent readiness signals, not an official SAP clean-core certification. Migration estimates are planning ranges, not delivery quotes or guaranteed forecasts.

Recommended buyer verification

Use a representative, non-production SAP snapshot and one bounded change. Confirm tenant isolation, upload rejection behavior, analysis coverage, source provenance, proposal review, package binding, customer-run validation, evidence export, deletion and retention handling, and recovery expectations. Record every unsupported input and credential-dependent connection before approving a production rollout.