Security and operations: where Ovenca runs and who has access

You decide where Ovenca is operated and where your procurement and supplier data resides: on-premise in your infrastructure or as a private cloud in a data centre in Germany.

This page summarises for information security, data protection and IT operations what applies to both operating models, and names the topics we answer individually during an evaluation.

On-premise
Your data centre or your own cloud environment
Private cloud
Separate instance in a data centre in the EU, located in Germany
Single sign-on
Sign-in through your identity provider with SAML 2.0 or OpenID Connect.
Multi-factor authentication
TOTP via an authenticator app.

Operating models and responsibilities

Both models use the same software. They differ in who operates the instance and where the data resides.

Responsibilities per operating model
CriterionOn-premisePrivate cloud
Location of the instanceYour data centre or your own cloud environmentSeparate instance in a data centre in the EU, located in Germany
Operation of the instanceYour ITOnveda
Technical and operational controlEntirely with youWith Onveda, on an instance operated for you alone
Data residencyEntirely within your infrastructureIn the EU, located in Germany
Interfaces to the ERPRun within your infrastructure between Ovenca and your ERPRun between the private cloud instance and your systems. The connection path is defined during the evaluation.
Data protection agreementProcessing is your responsibility and stays in your infrastructureData processing agreement under the GDPR with Onveda

Hybrid operation is also possible. We agree the split with you in a technical discussion.

Access control

Roles determine who may see and change what. Sign-in runs through your identity provider.

Roles and permissions
Permissions are granted per role, separately for read, create, update and delete.
Objects and relations
Permissions apply per object, such as suppliers, catalogs or products, and per relation between objects.
Legal entities and plants
Legal entities and plants are part of the permission structure and reflect your organisation.
Single sign-on
Sign-in through your identity provider with SAML 2.0 or OpenID Connect.
Multi-factor authentication
TOTP via an authenticator app.
Admin Area, permissions of a role: table with the columns Read, Create, Update and Delete for objects such as Vendors, Catalogs and Products and their relations, including Legal Entities and Plants
  1. Four permissionsRead, create, update and delete are granted individually.
  2. Object or relationEach row is marked as an entity or a relation.
  3. OrganisationLegal entities and plants appear as relations of their own.

View from the product: permissions of a role in the Admin Area.

Traceability

Changes to catalogs, approvals and users are logged in the audit trail.

Catalogs
Changes to catalogs are logged. In Catalog Management each catalog has its own history.
Approvals
Approval decisions are logged.
Users
Changes to users are logged.

Glossary: audit trail

Data protection and data residency

The place of processing follows the operating model you choose.

Data processing
For operation in the private cloud, Onveda concludes a data processing agreement under the GDPR with you.
Data location
On-premise within your infrastructure. In the private cloud in the EU, located in Germany.
Separate instance
In the private cloud, Ovenca runs for you as a separate instance.
Transport encryption
TLS for the web interface and the interfaces.

Glossary: GDPR in procurement

What we provide during an evaluation

This page makes no general statements on the following topics. The answers depend on the operating model. We give them individually and in writing through your security questionnaire.

Topics answered individually during an evaluation
TopicWhat we answer for your operating model
Availability and supportAgreements on availability, support hours and escalation paths.
Backup and recoveryBackup concept and recovery, in your responsibility or ours depending on the model.
Vulnerability and patch managementHandling of vulnerabilities and the provision and installation of updates.
Security testingStatus of security testing and the evidence available.
CertificationsStatus of certifications for Onveda and for the data centre.

Send us your questionnaire. We answer it for the operating model you are assessing.

Related pages

  • Platform

    Integration and architecture

    Order flow, punchout, interfaces and the connection to SAP and other ERP systems.

  • Reference

    LANXESS case study

    In production worldwide since 2014, with SAP contracts and material numbers in product search.

Send your security questionnaire or request a technical discussion

Send your security questionnaire to info@ovenca.de or announce it through the form. Three details help us place your request.

  • Preferred operating model: on-premise, private cloud or hybrid
  • Identity provider and protocol for single sign-on
  • Internal requirements on data residency and data processing

Request a demo or a technical discussion

Tell us briefly about your system landscape and what prompted your enquiry. Your contact is Jens Bohl.

* Required field