Security

Secure by design.

A tool that reaches into SAP, databases and servers must be at least as well protected as the systems it looks after. These measures are built in for every customer, not sold as an extra.

Built in for every customer

Your own environment

A separate OPS4 instance per customer: its own application, database and encryption keys. Secrets are stored encrypted and never shown again.

Who gets in

Multi-factor authentication, an optional allowlist of locations checked on every request, and rights per user group. Running an automation is a separate right.

Everything recorded

An audit trail of every change: who, what, when and from where. Sealed in a hash chain, countersigned outside the instance and kept for two years.

Signed agent updates

Agents only connect outward. Before installing an update, an agent checks its signature against the OPS4 release registry and refuses it if it does not match.

Automation under your control

Off by default and allowed twice: when the agent is installed and per server. Every job passes an approval step and is logged step by step.

Write-once log archive

Optional: the logs of your servers and devices in an archive nobody can change or delete before the retention ends. Tripwires, gap detection, destruction only by two people.

Private Mode: OPS4 behind your own tunnel

For organisations that want no internet-facing access at all. You get a dedicated OPS4 instance in its own network segment in our European datacenter, reachable only through an IPsec site-to-site tunnel from your network.

1

One way in

Only HTTPS through the tunnel, from the subnets you agree with us. From the internet there is nothing to see.

2

Your servers need no internet

Agents, the Worker and the log archive all deliver through the tunnel. Even the signature check on agent updates runs via a licence proxy in your segment.

3

Connections start on your side

OPS4 opens nothing into your network, apart from exceptions you choose yourself, such as your own mail relay.

4

Outbound: default deny

Your instance only reaches a fixed list of destinations agreed with you. Everything else is refused and logged.

Wallboards and the phone app outside your network work through an optional read-only relay that OPS4 feeds and that has no way back in.

Downloads

For your security officer, your network team and your audits.

See it on your own landscape, not on a demo environment

Request a demo and we set up your own cloud instance in Europe for you. Install the agent, approve the host, and your first servers are on screen within half an hour. Without opening your firewall.

Request a demo →
www.ops4.nl · S/4HANA RISE Monitoring