Security & confidentiality

Exactly what we do — and what we don't.

The audit begins with a local, read-only extraction. No remote access, no residual agents, no business data.

The technical extractor: KODEextractor

The audit starts by running KODEextractor locally, a tool built to guarantee the confidentiality of your system. It operates strictly read-only and requires no direct remote connection to your production environment — your own team deploys it through a Transport Request (TR).

It operates under these harmlessness parameters:

  • Metadata only: it reads code syntax, structured custom data dictionaries (Z/Y) and dependency trees.
  • Zero sensitive data: no access to transaction records, accounting balances, client information or financial data.
  • No alterations: it leaves no components installed on your SAP system, avoiding performance issues or voiding vendor support policies.

Encryption & permanent deletion protocol

Once the structural metadata is extracted into local flat files, the information is processed securely by the KODEassay analytical engine. Data is transferred encrypted and stored in dedicated environments with strict access restrictions (forced HTTPS, JWT sessions, CSP).

When the visibility and management questionnaire have been delivered, the permanent deletion protocol activates. KODE guarantees the permanent erasure of all extracted metadata from its servers and issues the corresponding Data Destruction Certificate within a maximum of thirty days.

Request a Quote