Skip to content

Extended maintenance to 2030 does not cover Solution Manager monitoring.Read what SAP actually says

Architecture

Where your data goes. And where it doesn’t.

LynxOps was built for teams that answer to auditors, regulators, or an air gap. Here is exactly what runs where — two diagrams and one redaction example, no hand-waving. Built to be forwarded to your CISO.

Scenario A — AI off (default)
SAP / HANALynxOps agentLynxOps server
  • Rolling Z-score anomaly detection
  • Rule-based SAP event correlation
  • Alerting · dashboards · reports

No LLM. No cloud call. This is the out-of-the-box product.

Scenario B — AI on (you opt in)
Alert contextRedactorAI provider you chose

You pick the provider. You hold the key. The prompt is redacted before it leaves, and the suggestion waits for an operator.

Redaction, shown

What actually leaves when AI is on

Before

ST22 dump on host sap-prd-01 (10.34.12.31), user MMUELLER, short dump TSV_TNEW_PAGE_ALLOC_FAILED in program ZFI_POST

Sent to the AI

ST22 dump on host HOST_1 (IP_1), user USER_1, short dump TSV_TNEW_PAGE_ALLOC_FAILED in program ZFI_POST

Secrets are removed; hostnames, IPs, users and emails become consistent pseudonyms — the same one every time, so correlation across alerts still works. The dump type and program name are kept because they are what makes the diagnosis possible, and they identify nothing.

On by default. Auditable in the codebase.

Deploy it your way

On-prem, on Kubernetes, or air-gapped

Kubernetes
Helm chart, HPA, ingress, migration job
Docker
Compose for a single node or a lab
Bare metal
systemd units, Linux + Windows service
Air-gapped
Offline bundle path for disconnected sites*

* Air-gap AI bundling is on our roadmap; today the core platform runs air-gapped with AI disabled.

Security & governance

The controls a review will ask about

Data residency
Everything runs in your network. Core monitoring makes zero external calls.
AI data handling
Prompts redacted before any provider call: secrets removed, identifiers pseudonymized. On by default.
Access control
3-role RBAC with separation of duties — run and approve are distinct permissions.
Authentication
Per-tenant SAML SSO.
Auditability
Immutable audit log of every action.
Encryption
Stored credentials encrypted (MultiFernet).

Send this page to your CISO.
Then let’s talk through your landscape.