DesignKompanie

A studio service

Security, validation and working with your SAP partner.

Before a regulated plant lets an outside app near SAP, IT, QA and procurement each have questions. This page answers them in one place: how we connect to SAP, where the app and its data live, what documentation you get for validation, how AI is controlled, and where our responsibility ends and your SAP partner's begins.

Security and validation for apps beside SAP S/4HANA

N° 01Who we are, plainly

Independent, and clear about it.

DesignKompanie is an independent studio. We are not affiliated with, endorsed by or a partner of SAP SE. We build separate applications that sit beside SAP and talk to it only through the APIs SAP publishes for that purpose.

That is the approach SAP's own clean-core guidance recommends for portals, third-party services and AI: keep the core standard and build beside it. It also means your SAP partner stays in charge of SAP, and nothing we do blocks an SAP upgrade.

N° 02How we connect to SAP

Released APIs only, read-only first.

01

No changes inside SAP

No custom code in the SAP core and no direct database access. We use released OData and SOAP APIs, CDS views and events, through SAP Integration Suite where you run it.

02

Read-only Pilots

A Pilot reads from SAP and creates nothing in it. It can be switched off without leaving a trace in SAP.

03

Write-back by agreement

Two-way integration is switched on only after your SAP team approves the interfaces and your licence team confirms the Digital Access position.

04

Technical user, least privilege

One technical user per app with only the authorisations it needs, owned and reviewable by your SAP security team.

N° 03Security

Built for a vendor questionnaire.

01

Your tenancy, your region

Deployed in your SAP BTP, Azure or AWS account, with EU and Swiss data residency. We do not hold your production data.

02

Identity and access

Single sign-on with your identity provider, role-based access, and sponsor separation enforced in the data layer.

03

Audit trail

Who did what, when and why, on every record, unalterable and exportable.

04

Testing

Dependency and code scanning on every release, and support for your penetration test before go-live.

N° 04Validation

What QA gets from us.

01

GAMP 5 Category 5 lifecycle

User requirements trace matrix, functional and design specifications, and code review records.

02

Developer test evidence

IQ and OQ scripts with executed results, ready for your team to witness or repeat.

03

Records and signatures

EU Annex 11 and 21 CFR Part 11 controls for electronic records and signatures in the GxP-ready package.

04

Change control

Every later release goes through a documented change, with impact assessment and regression evidence.

N° 05AI controls

AI you can defend at inspection.

Each AI assist has a written intended use. Models that support a critical decision are static and versioned, tested on held-back data against agreed acceptance criteria, show their confidence, and are monitored in use; retraining is a change-controlled release. Generative AI is kept to non-critical work and always ends in a person confirming the result. This follows the draft EU GMP Annex 22, which is not yet final; we track it and update the controls when it is.

N° 06Questions

The answers we give most often.

Are you an SAP partner?
No. We are an independent studio. We build beside SAP using its released APIs and work with your SAP partner, who stays responsible for SAP itself. If you need the integration certified by SAP, we scope that into the project.
Who is responsible for what?
Your SAP partner and IT own SAP: configuration, authorisations, transports and licences. We own the app beside it: its code, its tests, its documentation and its releases. Your QA owns validation and the decision to use it in GMP work.
Will this add SAP licence costs?
Reading data from SAP does not. When an outside app creates documents in SAP, SAP's Digital Access licence can apply. Pilots are read-only for that reason, and before any two-way build we check the position with your SAP licence team.
Where does the app run and where is the data?
In your own SAP BTP, Azure or AWS tenancy, in the region you choose, including EU and Swiss residency. We do not host client production data in our own accounts.
Do you validate the system?
We deliver what a Category 5 custom application needs from its developer: requirements trace, design documents, code review records and executed IQ/OQ developer tests. Your QA and CSV team run and sign the validation.
How do you handle AI under GMP rules?
To the draft EU GMP Annex 22: static, versioned models with stated confidence for anything that supports a critical decision, and generative AI only in non-critical work where a person confirms the result. Models run in your environment and sponsor data is never used to train shared models.

Start your book

Have a vendor questionnaire?

Send it over. We'll answer it in full and tell you plainly where we don't yet meet a requirement.

Security, Validation & Working With Your SAP Partner