Overview
- Application-layer masking for SAP ECC, S/4HANA, and RISE. Asterisks, hidden dates, and authorized click-to-reveal with a full audit trail — managed centrally, deployed via connectors, built for DPDP, GDPR, and global privacy regimes.
- Mask Sensitive SAP Data at the Screen — Prove Every Reveal
Problems We Solve
- Database encryption and network security do not stop authorized users reading unrestricted PII on vendor, employee, or customer screens → Application-layer redaction on SAP GUI, Fiori, and Web Dynpro — independent of how SAP works underneath
- Screen access equals unrestricted field access for support, shared desktops, and contractor IDs → Need-to-know masking by role, ABAC, transaction context, and SoD-aware policy
- Regulators expect purpose limitation and evidence of who saw personal data — not only encryption at rest → Click-to-reveal with reason codes, session timeout, and field-access audit trail
- Custom ABAP masking projects per system slow compliance rollouts across ECC, S/4HANA, and RISE → Central rule management with connector deployment and industry vertical rule packs
Key Capabilities
- MASK_ASTERISK — **** for names, salaries, confidential amounts
- MASK_PARTIAL — ****1234 for bank accounts, IBAN, national IDs
- HIDE_DATE — **/**/**** for date of birth and hire dates
- Instant — approved roles with a clear business need
- Toggle — session-based show/hide
- Workflow — request + approval before reveal
- Role-based controls (e.g. /AIIGA/MASK_VIEW)
- ABAC (attribute-based access)
- Transaction-context rules by T-code or app
Outcomes
- UI Layer — Protection Where Users Look
- 100% — Reveal Accountability
- DPDP / GDPR — Purpose Limitation Ready
- Zero — Custom ABAP Per System
Use your browser's print dialog and choose "Save as PDF" to download this brief.