How We Protect Your S/4HANA Connection
When you connect a live S/4HANA tenant, security is non-negotiable. Here is exactly how Clean-Core.io handles your credentials, data, and access — with full transparency.
Read-Only Scope
No write operations — ever.
Every tenant connection is strictly limited to read-only OData metadata requests and test executions. Clean-Core.io never writes, modifies, or deletes any data on your S/4HANA system.
What We Read
- ✓ OData service metadata ($metadata endpoints)
- ✓ ABAP Unit test results from test execution
- ✓ Custom code analysis reports (ATC/SCI)
What We Never Do
- ✕ No POST, PUT, PATCH, or DELETE operations
- ✕ No transport releases or workbench changes
- ✕ No data exports or bulk reads from business tables
Secure Storage & Stateless Transit
Encrypted credentials and transient business data.
Your connection credentials are encrypted using AES-256-GCM and stored securely on Google Cloud Platform in Europe (completely blocked from direct client SDK access). All actual business data (such as transactional records or metadata lists) retrieved from your S/4HANA OData tenant is processed transiently and never persisted, cached, or logged on our servers. Uploaded code files are stored in your encrypted, user-isolated project workspace, which you can permanently delete at any time.
Credential Isolation
Credentials are decrypted only within the server-side proxy at execution time. They are never exposed to client-side APIs or browser storage.
Stateless Business Transit
The backend OData transit layer is fully stateless. No business records or transaction responses are stored after execution.
EU-Region Hosting
All processing happens in the GCP europe-west1 (Belgium) region, ensuring GDPR-compliant data residency within the European Union.
Admin Onboarding Gate
Manual review and approval for every connection request.
To prevent misuse during the Free Community Edition, every tenant connection request is manually reviewed and approved by our admin team before activation. There is no self-service provisioning — this is by design.
How the Approval Process Works
You Submit a Connection Request
After signing in, navigate to your project settings and submit a tenant connection request with your system details (hostname, client, communication user).
Admin Review
Our team receives a notification and manually reviews the request. We verify the legitimacy of the connection details and the requesting user account.
Approval or Feedback
Once approved, your tenant connection is activated and you receive an email confirmation. If we have questions, we reach out before activation.
Active Monitoring
Connected tenants are monitored for unusual activity. Access can be revoked at any time if misuse is detected.
Questions about tenant security? Reach out anytime.