Skip to content

AI for SAP security,

human-in-the-lead.

As SAP moves toward the Autonomous Enterprise, the question is no longer whether AI belongs in SAP security – but what kind, governed how, and signed by whom.

Please accept marketing-cookies to watch this video.

The picture today

The richest reserves of enterprise data sit in SAP.

Financials, payroll, supply chain, master data, and IP. That value is exactly why the threat model is changing – and why generic AI bolted onto SAP is not enough.

The question is no longer whether AI belongs in SAP security.
It is what kind of AI, governed how, signed by whom.

What we deliver today

AI where it makes SAP security measurably easier

Available today

AI-powered insight for every line of custom ABAP

Data-flow taint analysis pinpoints the sink; the Companion explains what the vulnerability does, why it’s risky, and how to fix it – in plain language. It explains and recommends. The developer decides.

Available today

Answers grounded in your environment

Natural-language search across SAP Notes, configuration guidance, and SecurityBridge threat intelligence – the documentation hunt compressed to a question, with the context that makes an answer trustworthy.

From Finding to Fix - Faster

Detect. Explain. Remediate. Respond

Security Dashboard – the SAP-native fundamentals the AI layer sits on top of: patch
compliance, open findings, and posture trend across the landscape. Switch the AI off
tomorrow and your posture is still intact.

Four principles we won't compromise on

How we build with AI - and where we draw the lines.

Roadmap

Your model. Your perimeter. Your choice

Connect your trusted LLM through the MCP Server and Skills. The model belongs to you, the data never leaves your environment, and we never train on it or aggregate it across tenants.

Available today

Recommendations, not verdicts

Every recommendation is weighted, linked back to its sources, and inspectable – and you can switch the AI off entirely. 

Roadmap*

AI-assisted patching & code

Rule-based SNote validation identifies which systems need a patch; AI extends it where SAP Notes carry unstructured context. CVA applies code-specific models to data-flow reasoning in custom ABAP.

* Images are for illustrative purposes only. Final product features, functionality, and user interface may differ.

Our design principle

Human-in-the-lead.

The industry calls this human-in-the-loop. We call it human-in-the-lead – and the difference is accountability. A loop is a process step. A lead is a named person who directs the agent, authorizes the action, and signs an audit trail an auditor can verify against what actually happened.

Approval queue: a named person approves a scoped, time-windowed agent action; the signed record matches what the agent did

The approval queue in practice: the agent has no standing permissions. A named person approves a scoped, time-windowed action – and the signed audit record corresponds to exactly what the agent did.

Roadmap

Recommend-not-execute

The Companion surfaces recommendations and people decide – recommend-not-execute, with scoped approvals and a full audit trail. Every recommendation links back to the underlying data and context, so the reasoning is inspectable.

Roadmap

Intent-bound, just-in-time permissions

Approval becomes the permission grant itself: scoped to the approved intent, time-windowed, revoked on completion. The agent receives permissions only for the action the human approved, only for as long as needed – so a compromised prompt cannot expand the agent’s authority beyond what was already signed for.

Where we stand in the market

SAP security isn't won by
the loudest AI claim. It's won by depth.

Some vendors lead with AI as the product – agentic gateways, AI-native scanners, autonomous response as
the headline. That’s a legitimate strategy, and it produces good press. Our position is different, and we think
stronger over time.

The Pattern We See Our Position

Agentic gateways, autonomous response, self-healing SAP as the headline.

Autonomy in production ERP is dangerous. Agentic capability ships when we can defend it to an auditor – not on a marketing clock.

Generic security AI extended to SAP.

SAP-native depth takes years to build: ABAP, transports, auth objects, SAP Notes. AI sits on top of that depth – not in place of it.

AI announcements as the headline.

The Autonomous Enterprise will multiply the volume of activity inside SAP. Attackers will hide in that noise. Detecting them takes SAP-native depth, not louder AI claims.

“Human-in-the-loop” as a process checkpoint – approval bolted on top of an agent that already holds the permissions.

Human-in-the-lead. Approval is the permission grant – scoped, time-windowed, tied to a specific intent. Not a soft checkpoint.

JIT permissions on roadmap. We will not ship agentic features we cannot defend to an auditor
– because we built SecurityBridge to be the auditor’s evidence.

Five questions to ask any SAP security vendor with AI.

Useful whether or not you’re evaluating us. If a vendor can’t answer these cleanly, that tells you something.

If the AI requires customer SAP data to leave the perimeter, you’ve introduced a new attack surface.

If the answer is “we’re not sure” or “everything,” stop.

Always a human. By name. With a timestamp. And the signature should bind to the exact action the agent took – not a generic approval. That’s the difference between human-in-the-loop and human-in-the-lead.

The platform must still defend without the AI. If you switched the AI off tomorrow, your SAP security posture should still be intact.

Joule, BTP agents, and embedded copilots are privileged actors. Monitor them like any other.

Roadmap

Who approved this - and can you prove it?

Each major framework ultimately asks the same question: who is the accountable natural person for this decision, and can you prove what they approved? Human-in-the-lead is designed to answer it as an audit artifact.

To be precise

SecurityBridge does not certify compliance. 
The auditor signs.

What we do is make preparing for an audit considerably less painful – particularly where the underlying check involves SAP-specific context that’s hard to articulate without deep platform knowledge. A named person directs the agent, authorizes the action, and signs – and the signature corresponds to exactly what the agent did.

Roadmap

Published, stable - and shipped as it matures, not on a clock

Roadmap

Watch the agents inside SAP.

As the Autonomous Enterprise matures, Joule and BTP agents become privileged actors. We monitor them like any other – their actions, their scope, and the anomalies that matter.

Roadmap

Intent-bound, just-in-time access.

The agent holds permission only for the approved action, only as long as needed – granted on approval, revoked on completion. A compromised prompt cannot expand authority beyond what was already signed for.

“Like having a SecurityBridge expert on call 24/7 - grounded in your environment, surfacing recommendations your team can inspect and act on.”

Holger picture

Holger Hügel

CTO, SecurityBridge

SAP-native depth · AI as force multiplier

The Autonomous Enterprise needs
autonomous security - not
uncontrolled security.

The latest resources

CVE 2026 44756 OVERPASS
CVE-2026-44756 (OVERPASS): A Pre-Authentication SAP Kernel RCE
CVE-2026-44756 (OVERPASS) is a CVSS 10.0 pre-authentication memory-corruption vulnerability in the SAP kernel. Our research shows how quickly it can...
JTI
From Strategy to Scale: How JTI Built Continuous SAP Security with SecurityBridge
JTI is expanding continuous SAP security across a growing landscape. See how SecurityBridge supports 50+ systems, privileged access, and SOC...
From Patch Day to PoC in 96 Hours
CVE-2026-58240: From Patch Day to PoC in 96 Hours
From SAP Patch Day to Working PoC in 96 Hours: What CVE-2026-58240 Teaches Us About Modern Threat Timelines