Trust
Security practices for enterprise SAP engagements.
Security controls are applied to how we access client environments, handle data and manage credentials during delivery.
Practices
- Secrets are held in managed secret stores, never in source control
- External inputs are validated and sanitized
- Access to client environments follows least privilege
- Client-side validation is never the only control for submissions
How this website is designed
- Designed to be served only over HTTPS
- No credentials or secret keys are included in the code delivered to your browser
- Enquiry forms fail closed: nothing is reported as sent unless a connected system confirms receipt
- Production releases are started manually by an authorised person, never automatically
- Development and production environments are kept separate
What we do not claim
- SMS SAPX does not claim any security certification, audit attestation or compliance status on this site
- No uptime or response-time guarantee is made by this website
Discuss your SAP priorities with a senior practitioner.
Start with the problem. We will tell you what we can substantiate and what needs to be assessed.