CUTO · SAP Transformation Management

Enterprise security. European data protection. Built in from the start.

Security and data protection were not added to CUTO after the fact; they are part of the platform architecture. CUTO is designed for the data protection and security requirements of enterprise SAP environments.

Trust signals

Evidence instead of blanket claims

CUTO is a product of CUTO Technology, LLC in San Francisco, California, and is developed with European data protection requirements in mind. CUTO must confirm the exact status of certifications and compliance evidence before publication.

01

GDPR

The platform is designed for GDPR-compliant use and European data residency; binding documentation can be requested during procurement.

02

Developed by CUTO Technology, LLC

CUTO is developed by CUTO Technology, LLC in San Francisco, California.

03

EU data hosting

The exact cloud platform and data center region still require confirmation and will be identified in the security documentation.

04

Certifications

The status of SAP certification and any ISO 27001 or SOC 2 evidence still requires confirmation. No such certification is claimed until supporting evidence is approved.

Security pillars

Protection for sensitive SAP project data

01

Data Encryption

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Project data such as task lists, cutover plans, migration catalogs, and steering reports is protected at every layer. The cloud provider and hosting region still require confirmation.

02

EU Data Hosting

Customer data is intended to be stored exclusively in EU data centers, without transfer to third countries. The specific provider and region must be confirmed before publication.

03

Role-Based Access Control (RBAC)

Granular access rules apply across all apps. Admins define who can view, edit, and approve within each project, from full project manager access to view-only access for steering committee members. SSO is supported through SAML 2.0 and OpenID Connect.

04

Immutable Audit Trail

Every action is logged: who changed what, when, and from which value to which value. The immutable audit trail supports internal compliance reviews, regulatory audits, and post-project governance requirements.

05

Automated Backups

Daily automated backups with point-in-time recovery protect project data from loss. Specific RPO and RTO values still require confirmation.

06

Third-Party Penetration Testing

CUTO undergoes regular independent penetration testing. Findings are triaged by severity and remediated within defined SLAs. Enterprise customers can request a summary under NDA.

Deployment model

Maximum control: CUTO On-Premise.

Enterprise customers with strict data residency requirements or internal hosting mandates can deploy CUTO in their own infrastructure. The option is available for Enterprise plans. Contact us to discuss your environment and requirements.

Data protection

CUTO and the GDPR.

CUTO acts as a data processor under the GDPR. A Data Processing Agreement is offered to all customers as standard. Data subject rights, including access, erasure, and portability, are supported through the platform's export and deletion functions. Our Data Protection Officer is available to customers with specific compliance requirements. Full details are available in our Privacy Policy.

Direct answers

Security questions? We'll answer them directly.

Enterprise procurement teams can request our security documentation, DPA, and penetration-test summary. Contact us and we will provide the materials you need within one business day.

CUTO

Security questions? We'll answer them directly.