CUTO · SAP Transformation Management
Enterprise security. European data protection. Built in from the start.
Security and data protection were not added to CUTO after the fact; they are part of the platform architecture. CUTO is designed for the data protection and security requirements of enterprise SAP environments.
Trust signals
Evidence instead of blanket claims
CUTO is a product of CUTO Technology, LLC in San Francisco, California, and is developed with European data protection requirements in mind. CUTO must confirm the exact status of certifications and compliance evidence before publication.
GDPR
The platform is designed for GDPR-compliant use and European data residency; binding documentation can be requested during procurement.
Developed by CUTO Technology, LLC
CUTO is developed by CUTO Technology, LLC in San Francisco, California.
EU data hosting
The exact cloud platform and data center region still require confirmation and will be identified in the security documentation.
Certifications
The status of SAP certification and any ISO 27001 or SOC 2 evidence still requires confirmation. No such certification is claimed until supporting evidence is approved.
Security pillars
Protection for sensitive SAP project data
Data Encryption
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Project data such as task lists, cutover plans, migration catalogs, and steering reports is protected at every layer. The cloud provider and hosting region still require confirmation.
EU Data Hosting
Customer data is intended to be stored exclusively in EU data centers, without transfer to third countries. The specific provider and region must be confirmed before publication.
Role-Based Access Control (RBAC)
Granular access rules apply across all apps. Admins define who can view, edit, and approve within each project, from full project manager access to view-only access for steering committee members. SSO is supported through SAML 2.0 and OpenID Connect.
Immutable Audit Trail
Every action is logged: who changed what, when, and from which value to which value. The immutable audit trail supports internal compliance reviews, regulatory audits, and post-project governance requirements.
Automated Backups
Daily automated backups with point-in-time recovery protect project data from loss. Specific RPO and RTO values still require confirmation.
Third-Party Penetration Testing
CUTO undergoes regular independent penetration testing. Findings are triaged by severity and remediated within defined SLAs. Enterprise customers can request a summary under NDA.
Deployment model
Maximum control: CUTO On-Premise.
Enterprise customers with strict data residency requirements or internal hosting mandates can deploy CUTO in their own infrastructure. The option is available for Enterprise plans. Contact us to discuss your environment and requirements.
Data protection
CUTO and the GDPR.
CUTO acts as a data processor under the GDPR. A Data Processing Agreement is offered to all customers as standard. Data subject rights, including access, erasure, and portability, are supported through the platform's export and deletion functions. Our Data Protection Officer is available to customers with specific compliance requirements. Full details are available in our Privacy Policy.
Direct answers
Security questions? We'll answer them directly.
Enterprise procurement teams can request our security documentation, DPA, and penetration-test summary. Contact us and we will provide the materials you need within one business day.
CUTO