Security

Your SAP stays the system of record — and the system of trust.

Workflow Pilot is deliberately thin. It presents SAP work items on a phone and sends decisions back. It does not become a second copy of your business data.

Per-user named SAP authentication

Every approver signs in with their own SAP user. There is no shared technical or service account behind the app, so authorisations, release strategies and audit trails behave exactly as they do in SAP GUI — and you avoid the indirect / digital-access exposure that shared-account integrations can create.

TLS with certificate validation

All traffic between the app and your SAP system runs over TLS, with certificate validation enforced on the device. Connections are made across your network path — reverse proxy, gateway or VPN — as your team prefers.

Device secure keystore and biometric gate

Session credentials are held only in the platform secure keystore (iOS Keychain / Android Keystore) on the approver's own device, and the app can be gated behind Face ID or fingerprint before the inbox is shown.

Approval data never leaves your SAP

Documents, amounts, requesters, comments and decisions travel directly between the device and your SAP system. That business data is never routed through, copied to, or stored on our infrastructure.

No analytics, ads or tracking SDKs

The app ships without third-party analytics, advertising or behavioural tracking libraries. There is no profile of your approvers to leak, sell or subpoena.

Minimal backend footprint

Our backend exists only to activate organisations and manage licensing. It holds no SAP credentials and no approval content.

Certifications

We do not claim third-party security certifications we have not completed. If your procurement process requires a security questionnaire, penetration-test summary or architecture review, contact us at hello@workflowpilot.app and we will work through it with your team.

Talk to us about your requirements