Security & data

Read-only by design. AI only with your authorization.

What the export reads, what leaves your system, and how the app is protected. Stated plainly; no badges we do not hold.

In short

Six facts for your security and data-protection teams.

Export

Read-only export

One ABAP report with no database INSERT, UPDATE, MODIFY, DELETE or COMMIT. Its only output is the export files, written to a directory you choose.

Product: Display authorizations S_DEVELOP and S_TABU_NAM / S_TABU_DIS, plus S_DATASET to write the files (or S_GUI for a PC download). Tables the user may not display are skipped and logged.

Data

No user names, no transactional data

Author, changed-by and every other user-name column are removed. It reads code, dictionary definitions and configuration, never orders, invoices or postings.

Stated limit: IDoc partner profiles are included by default and contain partner numbers (customer, vendor and bank numbers). One checkbox, “Include IDoc partner profiles”, leaves them out. The documentation never writes partner numbers.

AI

AI only with your recorded authorization

The graph, the catalogue and the process map are built without AI. Validation Packages and Ask AI run only with your explicit, recorded authorization; Ask AI is off by default.

Product: Each Validation Package run needs a recorded authorization naming an approver.

Redaction

Personal data in comments and strings redacted before any AI step

Names after author labels, SAP user IDs, e-mail addresses, phone numbers and IBAN-like numbers in comments and strings are redacted line by line.

Product: Code stays unchanged, so citations still resolve. Each redaction is recorded for approval.

Access

Sign-in required, accounts created by an administrator

Every page and API of the web app requires sign-in. There is no self-registration.

Product: One-time passwords are valid for 72 hours and must be replaced at first sign-in. Sessions end after 12 hours idle or 7 days.

Verification

Every citation re-checked by a deterministic auditor

A script, not an AI, re-checks every tag on every catalogue page.

Product: The app shows the result next to each citation: checked, or a warning.

01The export

What the export reads and never reads

One ABAP report, installed as a local object. It changes nothing in your system: its source contains no database INSERT, UPDATE, MODIFY, DELETE or COMMIT, and the only DELETE statements act on internal tables. Its only output is the export files, written to a server directory (AL11) or a PC folder that you choose.

What the export reads
AreaWhat exactly
Custom source codePrograms and includes (reports, module pools, user-exit includes), classes and interfaces (every include), function groups and their function modules, enhancement implementations, and CDS view sources.
ABAP Dictionary definitionsStructure, not table contents: customer tables, views, structures, appends, data elements, domains with fixed values and table types. Also the definitions of the SAP tables your code uses.
The SAP where-used indexBoth directions: who calls your code from SAP, and what your code references.
TransactionsCustomer transaction codes with their program, screen, parameters and text.
ScreensFlow logic and field names.
Background jobsJobs that run customer programs: job name, step, program, variant name, number of runs in the period (default 90 days), last run date, periodic flag and statuses. No user names.
Process configurationCustomizing tables: IDoc process codes; IDoc partner profiles (included by default; one checkbox leaves them out); payment methods and payment medium formats; customer DMEE trees; CMOD projects; classic and new BAdI implementations; table maintenance dialogs (SM30); the SAP modification log (names of modified SAP objects only).
TextsObject, package and message texts: in the selected language, then the master language, then English.
InventoryA list of every customer object of the selection, of all object types, flagged with whether its content was exported.
What the export never reads
Never readDetails
User namesAuthor, scheduler, changed-by and every other user-name column are removed from every file. The object inventory has no user column either. Source code is exported as written, so a comment can still contain a name or an SAP user ID; before any AI step, personal data in comments and string literals is redacted.
Transactional business dataNo orders, invoices, postings or similar data. It reads code, dictionary definitions and configuration.Note 1
SAP standard source codeNever read. The one exception is the user-exit includes listed on the selection screen, which hold customer code inside SAP frames.
Contents of customer tablesOnly their dictionary definitions are read, not their rows. An optional field, “Extra config tables (content)”, reads only the tables you add to it; it is empty by default.

Installing and running it

Installation
As a local object (package $TMP), so no transport is needed. About 5 minutes: create, paste, save, activate.
Authorizations
Display authorizations only, plus permission to write the files: S_DEVELOP display, S_TABU_NAM / S_TABU_DIS display, S_DATASET write for the output directory, and S_GUI for a PC download. Tables the user may not display are skipped and logged.
Run
In the background. A system with a few thousand custom objects takes minutes. A manifest and a log record what was exported, what was skipped and why.
Selection
All customer objects (Z*, Y*) by default. You can add your own namespace, for example /ABC/*, and narrow by package.

02Data flow

What leaves your system

You hand over the export archive for analysis. AI steps send code facts and redacted source excerpts to external AI providers (OpenAI or Anthropic), and only with your recorded authorization. The product takes nothing else from your SAP system: there is no live connection to it.

  1. You run it in the background

    In your SAP system

    The read-only export report

    Writes the export files to a directory you choose. Changes nothing in your system.

  2. You hand over the export archive

    Analysis, without AI

    Evidence graph, catalogue, process map

    Built from the export alone. Served in the web app, behind sign-in.

  3. Only with your explicit, recorded authorization

    External AI providers

    AI steps

    Code facts and redacted source excerpts, for writing and reviewing Validation Packages, their Spanish translation and Ask AI.

The path of your data, from the export to the optional AI steps.
What leaves your SAP system, and where it goes
What leavesWhere it goes, and whenYour control
The export archiveHanded over to us for analysis: for the initial assessment, and again for each refresh after a release.You run the report, choose the output directory and hand over the archive.
Code facts and redacted source excerptsTo external AI providers (OpenAI or Anthropic), through their APIs, for the three AI uses described below.Each use runs only with your explicit, recorded authorization. Ask AI is off by default.
Nothing else is taken from your SAP systemThere is no live connection to it.A refresh means running the export again.

03AI

AI processing

The evidence graph, the catalogue in English and Spanish, and the process map are built without any AI, from the export alone. AI is used for three things only, and each one runs only with your explicit, recorded authorization.

Built without AI

  • The evidence graph
  • The catalogue, in English and Spanish
  • The process map
  • The re-check of every citation: a deterministic script, not an AI

AI, only with your recorded authorization

  1. Writing and reviewing Validation Packages. Each run needs a recorded human authorization naming an approver.

  2. Translating Validation Packages into Spanish. Runs only with a recorded authorization.

  3. Ask AI. Off by default. It stays off until your authorization is recorded.

Redaction before any AI step

Before any source code goes to an AI provider, personal data in comments and string literals is redacted line by line:

  • names after author labels
  • SAP user IDs
  • e-mail addresses
  • phone numbers
  • IBAN-like account numbers

Code is left unchanged, so citations still resolve. Each redaction is recorded for human approval.

AI providers

The AI engines are external providers, reached through their APIs. The roles that write and review Validation Packages run on Anthropic Claude or on OpenAI, and the verified Spanish translations of Validation Packages use OpenAI. Ask AI uses OpenAI, and each request is sent with the provider’s do-not-store setting (store=false). What each provider itself retains, for example for abuse monitoring, is set by its own terms; ask us: hello@codegraphai.com.

04Access

Access to the web app

Sign-in
Every page and API requires sign-in.
Accounts
Created by an administrator. There is no self-registration.
First sign-in
New users get a one-time password, valid for 72 hours. They must replace it at first sign-in with a password of at least 10 characters.
Passwords
Hashed with scrypt.
Sessions
Random tokens, of which only a hash is stored. A session expires after 12 hours idle or 7 days absolute.
Failed sign-ins
Throttled per account and per network address, without letting strangers lock out the owner.
Outside readers
For readers outside your company, the source viewer can redact names and user IDs.
Publication
For publication, the app runs behind HTTPS. It accepts only its configured public address, uses Secure cookies and HSTS, refuses cross-origin POSTs and sends a strict content-security policy. Pages are marked not to be cached.

05Hosting

Hosting, residency and retention

Not yet published on this site: where the web app and your export archive are hosted, in which region, how long the archive is kept after the engagement, and which agreements cover it (for example a non-disclosure or data processing agreement). Ask us before you hand over an export: hello@codegraphai.com.

06Independence

Trademarks and independence

CodeGraphAI is an independent product. SAP names on this site describe the SAP systems and objects the product works with; they are not the names of our features.

A guided demo with our team: the web app, the evidence graph and a cited catalogue page.