On-premise SAP security & compliance platform

One of these is a chat box.

Syntasec runs inside your own network and covers the SAP security domains your team already owns — user access, roles, segregation of duties, vulnerabilities, audit evidence and ABAP code. This is what it looks like.

CapabilityScreen
01Agent workspaceSEC.AGT → 02Vulnerability managementSEC.VUL →
03Segregation of dutiesShown live
04Audit & evidenceSEC.AUD →
05Role administrationShown live
06User administration and offboardingShown live
07Access requestsShown live
08ABAP code securitySEC.ABP → 09Security postureSEC.DSH → 10Threat detection and behavioural analysis3 screens →
11Firefighter log reviewShown live
12Natural-language queryThe part you have already seen →

The screens below are working Syntasec screens, populated with sample data from a non-production system. No customer data appears anywhere on this page.

Screen-by-screenSample data throughout
SEC.AGT.01

The agent workspace

Scheduled agents run on their own, work through multi-step tasks and stop at the point where a person has to decide. Nothing reaches SAP without an approval.

  • Audit — full security audit, narrated report, evidence pack
  • Inactive user — report only; never locks or changes an account
  • Role build — derives and proposes a role, you approve it
  • Segregation of duties — ruleset-grounded conflict analysis
  • Access request — parses the ticket, checks risk, drafts the request
syntasec / agentsSample data
Syntasec agent workspace showing tiles for the audit, inactive user, role build, segregation of duties and access request agents, each with a last-run time and status.
Agents run to a schedule and hand the decision back. Approval is a person, every time.
SEC.VUL.02

Vulnerability triage with the reasoning shown

Each finding carries the SAP Note, the affected system and client, the severity, and the reasoning behind the recommendation — so a reviewer can disagree with it.

  • Note — SAP Note reference and CVE where one exists
  • Scope — which SID and client the finding applies to
  • Evidence — the configuration value that triggered it
  • Decision — approve, reject or ask for more detail
syntasec / vulnerabilities / detailSample data
Vulnerability detail screen showing an SAP Note reference, affected system and client, severity, supporting evidence and approve or reject controls.
The recommendation is arguable because the reasoning is on screen. That is the point.
SEC.AUD.03

An audit run that ends in an evidence pack

The run is visible step by step, and it produces something an auditor can file: a narrated report plus before-and-after evidence, packaged and downloadable.

  • Timeline — each phase, its duration and its outcome
  • Findings — grouped by control area
  • Evidence — before / after captures per action taken
  • Export — a single pack for the workpaper file
syntasec / agents / audit / runSample data
Audit run screen showing a phase-by-phase timeline, findings grouped by control area and a downloadable evidence pack.
Audit teams do not buy dashboards. They buy the file they can hand to a reviewer.
SEC.ABP.04

ABAP code security down to the line

Custom code is where most SAP risk actually lives. Findings point at the program and the line, and say which check failed.

  • Location — program, include and line number
  • Class — missing authority check, injection risk, unsafe dynamic call
  • Provenance — whether a rule or the model raised it
syntasec / code-scans / findingsSample data
ABAP code scan findings list showing program names, line numbers, defect classes and severity.
Program names and line numbers are what make this credible to a developer.
SEC.DSH.05

Posture across every connected system

One view across the landscape: open findings by severity, systems in scope, patch position and when each system was last assessed.

  • Severity — open findings, critical through low
  • Systems — every connected SID and its last assessment
  • Trend — movement over the period
syntasec / dashboardSample data
Security posture dashboard showing open findings by severity, connected systems with last assessment dates and a trend chart.
Three or more systems in the list. One system reads like a pilot; three reads like a platform.
SEC.THR.06

Real-time threat patterns, not just logs

Every SAP security event is scored against a pattern library and triaged by severity, so the queue shows what actually needs a look — not a raw event feed.

  • Patterns — matched against a library of known SAP attack patterns
  • Severity — critical, high and new-unreviewed counts at a glance
  • Schedule — automated scans run on their own cadence
syntasec / threats / overviewSample data
Threat detection overview showing events analyzed in the last 24 hours, active threat patterns, and counts of critical, high and new unreviewed alerts.
The queue is triage-ordered, not just a firehose of raw events.
SEC.SAG.08

One place to start an investigation

Investigations, user risk and patrol history live in one workspace, so a reviewer can go from a risk score to the underlying evidence without switching screens.

  • Investigations — opened, active and closed, in one count
  • Risk score — a single landscape-wide average, trackable over time
  • Patrol log — when the last automated pass ran, and what it found
syntasec / security-agentSample data
Security Agent command center showing total and active investigations, critical risk user count, average risk score, and quick actions to investigate a user or run a patrol.
Investigate is a button, not a ticket to another team.
SEC.DRF.07

Behavioral drift, scored per user

User activity is compared against its own baseline over time, so an account that starts acting differently gets flagged before it becomes an incident — not after.

  • Baseline — each user compared against their own recent history
  • Risk score — a single number per user, per week
  • Alerts — critical and high counts surfaced separately from routine drift
syntasec / threats / driftSample data
Behavioral drift detection screen showing users monitored, users with drift, critical and high alert counts, and a per-user risk score table.
Drift is relative to the user's own baseline, not a landscape-wide average.

The last one

Syntasec Assist is the chat box, and only the chat box.

Assist answers SAP security questions in plain language and is the fastest way to get a feel for how Syntasec reasons. It is one capability out of nine — useful, but not the product. Everything above is the product.

Try Syntasec Assist →

See these screens against a live system.

A 30-minute walkthrough with our co-founder, who has spent eighteen years inside SAP security and GRC. No slides.

Request a walkthrough