We provide global standards of security and service management for over 48,000 customers
We provide global standards of security and service management for over 48,000 customers
Our Software-as-a-Service (SaaS) solutions are audited regularly for compliance with the following global standards of security and service management so our customers can have the assurance that data confidentiality, integrity, and availability is maintained at all times.
Certificates, Audits and SOC report request forms are made publicly available via the SAP Trust Center.
In conjunction with parent corporate SAP SE (the certificate covers all of SAP), we are audited to this privacy standard
ISO 27001 & 9001
ISO 27001 is the global standard for IT security management practices. SAP Concur has been BS 7799-certified since 2004 and undergoes multiple audits every year. We are also audited to ISO 9001 quality standards, in conjunction with parent corporate SAP SE (the certificate covers all of SAP)
PCI DSS
SAP Concur is a Visa® Registered CISP-Compliant Service Provider. As a Level 1 Service Provider, SAP Concur is audited annually by a PCI Qualified Security Assessor (QSA)
Sarbanes-Oxley Act
SAP Concur is audited once a year as part of its annual public audits
SOC1 Type II
SAP Concur transitioned to the SSAE18 and ISAE3402 standard in 2010 , with audits every six months
SOC2 Type II
SAP Concur has added a SOC2 security audit report, beginning in 2017, with audits every six months
Keeping your data secure, while providing a smooth user experience
Keeping your data secure, while providing a smooth user experience
SAP Concur conducts multiple internal audits as well as third-party audits on a scheduled basis. The written results of many of these audits are available on request
Single Sign-On (SSO) allows users to access multiple applications using one set of credentials. SAP Concur supports SAML-based SSO enabling client organizations to have a higher degree of control over user ID management and authentication policy
SAP Concur offers a number of different connectivity options supporting both the user experience and software integration needs of our customers