Security and operations: where Ovenca runs and who has access
You decide where Ovenca is operated and where your procurement and supplier data resides: on-premise in your infrastructure or as a private cloud in a data centre in Germany.
This page summarises for information security, data protection and IT operations what applies to both operating models, and names the topics we answer individually during an evaluation.
- On-premise
- Your data centre or your own cloud environment
- Private cloud
- Separate instance in a data centre in the EU, located in Germany
- Single sign-on
- Sign-in through your identity provider with SAML 2.0 or OpenID Connect.
- Multi-factor authentication
- TOTP via an authenticator app.
Operating models and responsibilities
Both models use the same software. They differ in who operates the instance and where the data resides.
| Criterion | On-premise | Private cloud |
|---|---|---|
| Location of the instance | Your data centre or your own cloud environment | Separate instance in a data centre in the EU, located in Germany |
| Operation of the instance | Your IT | Onveda |
| Technical and operational control | Entirely with you | With Onveda, on an instance operated for you alone |
| Data residency | Entirely within your infrastructure | In the EU, located in Germany |
| Interfaces to the ERP | Run within your infrastructure between Ovenca and your ERP | Run between the private cloud instance and your systems. The connection path is defined during the evaluation. |
| Data protection agreement | Processing is your responsibility and stays in your infrastructure | Data processing agreement under the GDPR with Onveda |
Hybrid operation is also possible. We agree the split with you in a technical discussion.
Access control
Roles determine who may see and change what. Sign-in runs through your identity provider.
- Roles and permissions
- Permissions are granted per role, separately for read, create, update and delete.
- Objects and relations
- Permissions apply per object, such as suppliers, catalogs or products, and per relation between objects.
- Legal entities and plants
- Legal entities and plants are part of the permission structure and reflect your organisation.
- Single sign-on
- Sign-in through your identity provider with SAML 2.0 or OpenID Connect.
- Multi-factor authentication
- TOTP via an authenticator app.

- Four permissionsRead, create, update and delete are granted individually.
- Object or relationEach row is marked as an entity or a relation.
- OrganisationLegal entities and plants appear as relations of their own.
View from the product: permissions of a role in the Admin Area.
Traceability
Changes to catalogs, approvals and users are logged in the audit trail.
- Catalogs
- Changes to catalogs are logged. In Catalog Management each catalog has its own history.
- Approvals
- Approval decisions are logged.
- Users
- Changes to users are logged.
Data protection and data residency
The place of processing follows the operating model you choose.
- Data processing
- For operation in the private cloud, Onveda concludes a data processing agreement under the GDPR with you.
- Data location
- On-premise within your infrastructure. In the private cloud in the EU, located in Germany.
- Separate instance
- In the private cloud, Ovenca runs for you as a separate instance.
- Transport encryption
- TLS for the web interface and the interfaces.
What we provide during an evaluation
This page makes no general statements on the following topics. The answers depend on the operating model. We give them individually and in writing through your security questionnaire.
| Topic | What we answer for your operating model |
|---|---|
| Availability and support | Agreements on availability, support hours and escalation paths. |
| Backup and recovery | Backup concept and recovery, in your responsibility or ours depending on the model. |
| Vulnerability and patch management | Handling of vulnerabilities and the provision and installation of updates. |
| Security testing | Status of security testing and the evidence available. |
| Certifications | Status of certifications for Onveda and for the data centre. |
Send us your questionnaire. We answer it for the operating model you are assessing.
Related pages
Platform
Integration and architecture
Order flow, punchout, interfaces and the connection to SAP and other ERP systems.
Reference
LANXESS case study
In production worldwide since 2014, with SAP contracts and material numbers in product search.
Send your security questionnaire or request a technical discussion
Send your security questionnaire to info@ovenca.de or announce it through the form. Three details help us place your request.
- Preferred operating model: on-premise, private cloud or hybrid
- Identity provider and protocol for single sign-on
- Internal requirements on data residency and data processing
Request a demo or a technical discussion
Tell us briefly about your system landscape and what prompted your enquiry. Your contact is Jens Bohl.