Skip to content
AI SOC for SAP · An Xiting product

Your SIEM sees logs.
Falcora sees business risk.

Falcora is the AI SOC for SAP — a Human-in-the-Loop Security Operations Center and SOAR platform built specifically for SAP. It translates technical SAP events into business impact, triages alerts with AI, maps every finding to SAP MITRE ATT&CK, and orchestrates remediation across your SAP estate — so your analysts spend their time on the threats that actually matter.

Built by Xiting — SAP security specialists since 2008 · Hosted on Microsoft Azure · EU data residency · global availability
70%
reduction in SAP investigation effort
100%
AI alert classification rate
MTTD ↓
massively faster threat detection
MTTR ↓
dramatically faster incident response
Plays nicely with
Specialized SOC & SOAR intelligence for SAP

Falcora is not a SIEM. It's the layer that finally makes SAP make sense to your SOC.

SAP systems are the backbone of business-critical operations — yet they're invisible to generic SIEMs, where SAP signals get lost in millions of log lines. Falcora adds the business context, the SAP know-how and the AI triage that turn noisy events into prioritized, actionable risk.

Request a demo →
Capabilities

Built for SAP. Trusted by SOC.

Six capabilities working together to turn SAP noise into business-aligned action — without taking the human out of the loop.

01 — HUMAN-CENTERED AI

AI does the heavy lifting. Analysts stay in control.

Artificial intelligence plays a central role across Falcora — always as a supporting capability, never an autonomous decision-maker. Our Human-in-the-Loop model ensures analysts validate every consequential step, so AI accelerates the work without replacing the judgment.

  • AI-supported investigation guidance, not black-box verdicts
  • Every prompt, decision and action is logged and reproducible
  • Standardized, auditable workflows your auditors will recognize
02 — SAP SECURITY OPERATIONS DASHBOARD

One pane of glass — for SAP-aware SOC.

The Falcora dashboard visualizes active alerts with prioritization, SLA tracking, AI-generated insights and operational KPIs in a single interface. Risk heatmaps highlight business-critical areas, so you spend your time where exposure is highest — not where logs are loudest.

  • Risk-based prioritization aligned with business impact
  • SLA tracking + AI insights for every active case
  • Operational KPIs your CISO can actually read
03 — AI-ASSISTED ALERT PROCESSING

End-to-end triage that filters noise before your team ever sees it.

Falcora analyzes and filters alerts for false positives using AI-assisted evaluation, then enriches the real ones with contextual information before they ever reach an investigator. The result: massive reductions in MTTD and MTTR, and an analyst experience that scales beyond the supply of SAP experts.

  • Up to 70% reduction in SAP investigation effort
  • Improved detection accuracy with fewer false positives
  • Reduced dependency on scarce SAP security specialists
04 — SAP MITRE ATT&CK MAPPING

SAP attack patterns, mapped to the framework your team already speaks.

Falcora maps SAP-specific attack patterns to the MITRE ATT&CK framework, correlating SAP transactions and behavioral indicators with tactics and techniques. Coverage is transparent, growing, and finally puts SAP signals on the same map as the rest of your enterprise security telemetry.

  • SAP-specific detections mapped to MITRE ATT&CK — coverage grows continuously
  • SAP activities, transactions & behavioral indicators correlated to tactics and techniques
  • Transparent coverage map — know exactly what's covered and where the gaps are
05 — FALCORA RESPOND · SOAR

Orchestrate response across your entire SAP estate.

Run security-response playbooks natively against your enterprise applications — GRC, IAM, IGA and more — or in combination with your existing SOAR like FortiSOAR. AI agents propose the next action; humans approve it; every step is queued, audited, and reversible.

  • Native connectors into GRC, IAM, IGA & enterprise apps
  • Or orchestrate through your existing SOAR (FortiSOAR & others)
  • AI agents with immutable, role-gated prompt versioning
  • Per-tenant kill switch & full execution audit log
06 — SAP SECURITY NOTES

Every SAP Note. Every system. One source of truth.

Falcora pulls every SAP Security Note into one place, enriches each with CVE / CWE / CVSS context, and connects to your SAP landscape to show live per-system implementation status — so you finally know what's patched, where, and what isn't.

  • Continuously synced SAP Security Note catalog
  • CVE enrichment with CWE, CVSS breakdown & references
  • Live per System × Client implementation status — workbench & customizing
  • Audit log of every status change & implementation event
Model Context Protocol

Bring your favorite AI into the SOC.

Falcora ships with a production-grade MCP server over Streamable HTTP. Authorization, tenant scoping, audit logging and PII masking all run through the same services as the HTTP API — MCP is just a new transport, not a back-door.

Microsoft Copilot SAP Joule Claude (claude.ai & Claude Code) Cursor mcp-inspector Your own agent
  • Ask, act, decide — query cases, kick off AI analysis, add notes, submit feedback and finalize verdicts, all in natural language
  • Same security model as the rest of Falcora — every call is role-gated, PII-masked and audit-logged. MCP is a transport, not a back-door.
  • Tied to a real identity — your analyst signs in with Entra; rate-limited per user and never anonymous
  • No vendor lock-in — works with any MCP-compatible agent, today and tomorrow
Built for MSPs

Operate a SOC for your entire customer base — from one console.

Falcora is purpose-built for Managed Service Providers. Onboard or offboard a customer in minutes, run one SOC across your entire book of business, and move between tenants seamlessly when you're authorized — without ever crossing the isolation line.

  • Self-service tenant lifecycle — provision, onboard, suspend & offboard customers independently
  • Strict per-tenant isolation — own database, own keys, own audit trail, own role assignments
  • Authorized cross-tenant access — your SOC analysts move between customers seamlessly, every action audit-logged
  • Org-scoped admin APIs & role model purpose-built for MSP operations
Architecture

From SAP event to closed case — in one auditable pipeline.

Azure Function Apps with strict privilege separation, hardened for the realities of SAP estates. Every step is logged, every LLM prompt is reproducible, every action is role-gated.

1

Ingest

SIEM connector POSTs alerts to a dedicated endpoint. OAuth or Basic Auth.

2

Triage

Worker masks PII, retrieves the matching SOP, asks the LLM for a verdict.

3

Case

Real threats become cases; false positives are closed and learned from.

4

Respond

JIRA incident + Teams notification + playbook actions, fully role-gated.

5

Audit

Every prompt, decision and action lands in the tenant audit log.

Security & compliance

Built for the people who get audited.

Falcora was designed by SAP security specialists for SAP security teams — and it shows in every default.

  • SAP IAS federation via Workforce Entra. Customers don't configure Falcora in their own Entra. We broker the trust.
  • GDPR Article 4(5) pseudonymization. PII is salted and hashed per-tenant before any LLM call.
  • 36 granular RBAC roles. No umbrella "admin" — every capability is granted per resource.
  • Per-tenant Cosmos DB + Key Vault. Data isolation is physical, not just logical.
  • EU data residency, global availability. Defaults to Azure Switzerland-North / West-Europe; Falcora can run in any Azure region on request.
  • Full audit trail. Every prompt, verdict and action is logged at tenant scope.
  • Fail-early startup. Misconfigured environments refuse to boot — silent drift can't happen.
  • Reproducible LLM reasoning. SOP + prompt + model version + output are stored together.
ISO/IEC 27001 certified
Information security management aligned with ISO 27001 — 93 controls across organizational, technological, physical and personnel security. Certified at the Xiting organization level.
View full Trust Center →
FAQ

Common questions about Falcora.

Quick answers to what buyers, SOC leads and SAP security teams ask before booking a demo.

Is Falcora a SIEM?

No. Falcora is the layer that sits on top of your SIEM and gives it SAP context. Your SIEM collects logs; Falcora translates them into business risk, prioritizes them against SAP-specific patterns, and triages them with AI grounded in your own SOPs.

How is Falcora different from Onapsis?

Falcora and Onapsis solve overlapping but distinct problems. Onapsis is primarily an SAP vulnerability and risk-management platform — it identifies misconfigurations and exposures. Falcora is an SAP-focused SOC and SOAR — it triages security alerts and orchestrates response. They can coexist; many customers run both.

How is Falcora different from SecurityBridge?

SecurityBridge is a comprehensive SAP security platform focused on real-time threat detection, vulnerability scanning and custom-code analysis. Falcora is the AI-driven SOC and SOAR that sits on top — it ingests alerts (from SecurityBridge, SAP ETD, Sentinel, Splunk and others), triages them with Human-in-the-Loop AI, grounds the reasoning in your own SOPs, and orchestrates the response across your SAP estate. The two are complementary; many customers run both.

Does Falcora replace SAP Enterprise Threat Detection (ETD)?

No. Falcora consumes alerts from SAP ETD — and from Microsoft Sentinel, Splunk, FortiSIEM, Elastic and others — then adds AI triage, SOP-grounded reasoning, and orchestrated response on top.

What is a Human-in-the-Loop SOC?

It's the explicit design choice that AI does the heavy lifting — analysis, summarization, recommendations — but a human analyst approves every consequential action. The opposite is fully-autonomous AI agents acting without oversight. For SAP, where a bad action can stop a business, Human-in-the-Loop is the only responsible model today.

How does Falcora's MCP server work?

Falcora exposes its data and actions through the Model Context Protocol so AI assistants like Microsoft Copilot, SAP Joule and Claude can natively query cases, run analysis, and submit verdicts. Authorization, audit logging and PII masking run through the same services as the rest of Falcora — MCP is a transport, not a back-door.

What's the difference between SOC and SOAR for SAP?

A SAP SOC (Security Operations Center) detects and triages SAP-specific security events. A SAP SOAR (Security Orchestration, Automation, Response) orchestrates the response — disabling users, opening incidents, notifying owners, blocking patterns. Falcora is both, purpose-built for SAP.

Is Falcora ISO 27001 certified?

Falcora's parent organization, Xiting, is ISO/IEC 27001 certified — 93 controls across organizational, technological, physical and personnel security. See the Xiting Trust Center for the latest certificates and resources.

Is Falcora suitable for MSPs (Managed Service Providers)?

Yes — Falcora is purpose-built for MSPs. You can provision, onboard, suspend and offboard customer tenants independently and operate one SOC across your entire book of business. Tenants are strictly isolated (own database, keys, audit trail and role assignments), but authorized MSP analysts can move between tenants seamlessly, with every action audit-logged.

Can Falcora work with Splunk, Microsoft Sentinel, or FortiSIEM?

Yes. Falcora ingests alerts from any compliant SIEM via OAuth or Basic Auth, and it can orchestrate response back through your existing SOAR (e.g. FortiSOAR) or run native actions against your enterprise apps (GRC, IAM, IGA).

An Xiting product

Made by the team that has secured SAP for two decades.

Xiting is a global specialist in SAP authorization, identity and security, headquartered in Switzerland and trusted by 850+ international customers worldwide. Our consultants have shipped authorization and security concepts, IAM integrations and security automation for some of the largest SAP estates in the world. Falcora is what happens when that operational expertise meets modern AI — productized, multi-tenant, and built to scale.

Visit xiting.com → Talk to the team
Request a demo

Ready to elevate your SAP security operations?

30-minute demo with the team that built Falcora. We'll bring sample SAP alerts and the dashboard live — you bring your hardest false-positive backlog.

  • See Falcora triage real SAP alerts in real time
  • Walk through the MITRE ATT&CK mapping for your stack
  • Try the MCP server from Microsoft Copilot or Claude
  • Get a tailored rollout estimate for your environment
Prefer email? hello@falcora.ai Falcora is a product of Xiting · EU data residency · global availability