Report a vulnerability
sapctl runs a Coordinated Vulnerability Disclosure (CVD) program. Report privately via our security policy or email [email protected]. We acknowledge within 72 hours and credit reporters who follow CVD.
Certifications & attestations
Trust Services Criteria · audit window in progress
Type I attestation (controls design) is in its audit window with an AICPA-licensed firm. Type II (operating effectiveness) follows after the observation period. Draft control narratives available under NDA.
Information security management · roadmap
Targeted scope: design, development, and operation of sapctl cloud services. Certification is planned to follow the SOC 2 audit; ISMS controls are being implemented in parallel.
Not in scope
Cardholder data is processed by Stripe; sapctl never stores PAN. SAQ-A applies to our merchant relationship.
Software bill of materials
Every signed release publishes a CycloneDX 1.7 and SPDX 3.0.1 SBOM, plus SLSA L3 provenance attestations and a cosign signature. The list below is pulled live from the latest GitHub release:
Loading latest release evidence…
- sapctl-0.1.0.cdx.json (CycloneDX 1.7)
- sapctl-0.1.0.spdx.json (SPDX 3.0.1)
- sapctl-0.1.0.intoto.jsonl (in-toto attestation)
Verify with cosign verify-blob against our public Fulcio identity. Every signature is logged in the public Rekor transparency log.
Penetration testing
Annual third-party penetration test, with a retest after material architecture change. Executive summary available on request; the full report is available under NDA.
Regulatory mapping
sapctl does not make you compliant — it gives you the evidence primitives auditors ask for. Each regulation below maps to a concrete command or artefact.
Cyber Resilience Act
SBOM (CycloneDX 1.7), SLSA L3 provenance, and a CVD policy on every release feed Annex IV technical documentation and the vulnerability-handling requirement.
Digital Operational Resilience Act
The ed25519 hash-chained audit log gives tamper-evident records of every SAP API call for ICT-risk reporting; the air-gap bundle format supports resilience testing on isolated networks.
sapctl audit verifySarbanes-Oxley, ITGC
Signed journal extracts (--use-case sox-journal) produce an auditor-verifiable evidence chain for financial-reporting controls, independent of SAP GUI screenshots.
sapctl s4 audit-exportFDA electronic records
The hash-chained log provides the audit trail, record integrity, and signature linkage Part 11 requires for regulated life-sciences SAP data. Retention gating ties evidence to a defined retention window.
sapctl audit-export --retainEU CRA Annex IV statement
From 11 December 2027 the EU Cyber Resilience Act applies in full to sapctl as a “product with digital elements”. Our Annex IV technical documentation includes: product description, intended use, risk assessment, threat model, secure development lifecycle, vulnerability handling, applied harmonised standards, and a CE marking statement.
Latest draft Annex IV pack is available to customers and conformity assessors: [email protected].
Sub-processors
See the full sub-processor list and subscribe to the change feed.
Contact
[email protected] · for security disclosures, security policy.