Stop fraudulent SAP transactions

Your SAP credentials can be stolen. Your identity shouldn't be.

Stop unauthorized people from executing critical SAP transactions—even when they're using a valid account.

bioLock verifies the actual human behind high-risk SAP actions with biometric authentication, at the moment the transaction occurs.

  • SAP Certified since 2002
  • Installed on all continents
  • 25 years protecting real-world SAP environments

The problem

Your employee didn't steal the money. Their credentials did.

A login verifies a credential. It doesn't verify the human.

Illustration: an SAP security analyst at his desk says, ‘Good news. He passed all of our security controls.’ A colleague standing behind him, holding a laptop, asks, ‘Did anyone check if Bob is Bob?’ Beside them, the checklist for SAP account ‘Bob Smith’ shows passwordless MFA, SAP GRC check, single sign-on, zero trust access and SAP logon complete all ticked, and ‘identity actually verified’ marked with a red cross. Caption: We secured the SAP account. We forgot to verify the human.

Credential-based access

01Stolen credential
02SAP login
03Legitimate access
04$250,000 payment Unverified

bioLock, function-level

01Sensitive transaction
02Biometric challenge
03Human verified
04Transaction authorized Verified

Why now

AI makes stolen credentials
more dangerous—not less.

  • Passwords can be stolen.
  • MFA sessions can be hijacked.
  • Credentials can be shared.
  • Privileged accounts can be abused.
  • AI makes impersonation easier.

But one thing remains difficult to fake:

The verified human performing the action.

The demonstration

Watch what happens when someone tries
to change a $250,000 vendor payment.

Interactive SAP simulation.

Test drive the full online simulation (opens in a new tab)
FK02Change Vendor: Bank Details Simulation
Vendor100482 · Meridian Components
Next payment run250,000.00 USD
Bank accountDE89 •••• •••• 3241Protected function
Cancel Save

bioLock

Identity verification required

  • Fingerprint
  • Palm vein
  • Windows Hello

Human verified

Thomas Smith · Fingerprint

Transaction permitted

Allowed for the verified user. Everyone else is blocked.

Tamper-proof audit record

Human
Thomas Smith
SAP user
T. SMITH
Did what
FK02 · Vendor bank details
When
10:24:31
Result
Allowed after biometric verification

Real-time notification

To SAPSecurityTeam@realtimenorthamerica.com

Urgent bioLock alert: FK02 · Vendor bank details

SAP user ID
T. SMITH
Identified human
Thomas Smith
Result
Allowed after biometric verification
Terminal
WS-4471

See another scenario

  1. 01

    SAP transaction initiated

    Someone attempts to change vendor banking information.

  2. 02

    bioLock detects protected function

    The checkpoint is defined in advance: exactly which SAP transaction, button, table or field needs protection.

  3. 03

    Biometric challenge appears

    When someone attempts that action, bioLock steps in before SAP does.

  4. 04

    Human verified

    The user confirms who they are biometrically — fingerprint, palm vein, Windows Hello or similar — not just with a password.

  5. 05

    Transaction permitted

    Verified users proceed. Everyone else is blocked automatically.

  6. 06

    Tamper-proof audit event recorded

    Every attempt is written to bioLock's own tamper-proof log, ready to share directly with auditors.

  7. 07

    Supervisors notified in real time

    Any action bioLock authorizes or denies can be sent to supervisors and security teams immediately, so they can act while an attempt is still in progress.

Business risks

Five places where
identity matters most.

Fraud. Insider threat. Privileged access. Compliance. Each one comes back to the same question: who actually performed this action?

  1. 01

    SAP Logon

    • Compromised credentials
  2. 02

    Payments

    • Fraudulent payments
    • Financial loss
  3. 03

    Vendor Master Data

    • Unauthorized changes
  4. 04

    Privileged Functions

    • SAP privilege abuse
    • Segregation of Duties
  5. 05

    Shared Workstations

    • Insider threats
    • Audit findings

How bioLock works

Verify the human
at the point of action.

  1. 01

    Define the checkpoint

  2. 02

    Challenge the user

  3. 03

    Verify identity

  4. 04

    Allow, reject, and log

Authentication at the point of action.

Most security products authenticate at

  1. Device level
  2. Network level
  3. Application login
  4. Session level

bioLock can take identity verification down to

The transaction level.

Function-level authentication

“Are you really the human performing this action?”

Solution areas

Secure every function
that matters.

The mechanism is the same everywhere. What changes is which action is worth stopping, and what it costs when the wrong human takes it.

  • Verify the human at the point of entry. Logon to SAP and S/4HANA is checked against biometric identity, not just a credential someone happens to hold.

    • Perimeter access control
    • Administrative functions
    • Over-credentialing
    • Activity logging
  • Insider threats and Segregation-of-Duties violations are the costliest risks in enterprise finance. GRC rules separate the accounts, but a borrowed password or an unlocked screen can still put one person on both sides of a transaction. bioLock verifies the specific human behind every action, so Segregation of Duties cannot be circumvented that way.

    • SoD and GRC enforcement
    • High-value transactions
    • Regulatory compliance and AML
    • Mobile workflow approvals
  • Cashiers at the point of sale and call centre staff editing customer records are a daily exposure point. bioLock confirms identity at the exact moment it matters.

    • Cash register and shrinkage control
    • POS discounts, credits and returns
    • Call centre data privacy and KYC
    • Public sector benefits payments
  • A shared kiosk on the loading dock stays signed in under one generic SAP ID, so nobody loses the day logging in and out. Each action is confirmed with a fingerprint and recorded against the human who took it, and anyone without an enrolled credential — a visiting driver at an unattended screen — can do nothing at all.

    • Shared devices and kiosks
    • Movement of materials
    • Time and attendance
    • Inventory shrinkage
  • Attach a verified human identity to the documents and changes that carry consequence, so an approval can be traced to a human rather than to an account. It also cuts the digital signature itself from 15+ seconds of typing to about one second, including biometric bands for gloved environments.

    • High-value transactions
    • Transports and code changes
    • Activity logging
    • Regulatory compliance and AML
    • Change Process Order (Pharma)

Proof

Not new technology.
Proven technology.

Developed since 2001 – SAP Certified since 2002 – 25 years protecting real-world SAP environments.

  1. 2001 Original development On a customer request.
  2. 2002 SAP Certification realtime North America Inc. established in October. SAP AG certificate, Walldorf, March 1, 2002: bioLock validated as interface software for the mySAP.com platform, component SAP Basis 4.6. View certificate (opens in a new tab)
  3. 2005 SAP movie about the NASA installation Watch on YouTube (opens in a new tab)
  4. Today Reviewing 20 years of biometrics SAP Insider article. Read the article (opens in a new tab)

SAP News Center · January 2023

Sasol Ensures Zero Trust for SAP Financials with bioLock

The global chemicals and energy company uses bioLock biometric verification to secure payment approvals in SAP, so a shared password can no longer confirm a payment.

Read the article on SAP News (opens in a new tab)

“…only the intended SAP user, beyond any reasonable doubt, can confirm payment.”

Lungile Mginqi, Group CIO, Sasol

SAP News Center · March 2025

Palm-vein Biometric Kiosks Secure SAP at Transnet Engineering

Seven factories and 150 depots at South Africa’s state-owned rail and port operator run shop-floor SAP through kiosks built by partner Linx-AS, with Fujitsu PalmSecure palm-vein verification and bioLock. Nobody signs in and out all day, and every transaction still belongs to a named human.

Read the article on SAP News (opens in a new tab) Watch the installation (opens in a new tab)

“Palm-vein technology is ideal for industrial environments as sub-dermal biometrics do not wear out over time.”

Thomas Neudenberger, COO, realtime North America

In production

Numbers from live
SAP landscapes.

  1. 01

    0

    employees at Transnet Engineering, where shop-floor SAP runs behind palm-vein kiosks

  2. 02

    0+

    cashiers protected at a national retail chain

  3. 03

    0+

    users covered in a manufacturing workflow rollout

  4. 04

    0%

    annual SAP fraud reduction, measured by a major government organization after deploying bioLock

Trusted by Global Fortune 500 companies, central banks, governments, and leading public and private sector organizations worldwide.

Case studies

Ten deployments,
quietly at scale.

Technology

Built into SAP.
Not bolted onto it.

Security that lives where the SAP transaction happens.

bioLock is embedded within the SAP environment, allowing identity verification to occur at the point where a sensitive SAP function is executed—not merely when the user logs in.

Integrated into SAP's ABAP code, in our own SAP namespace/realtime

  1. 01

    Embedded in the SAP workflow

    The user doesn't have to leave the SAP environment to prove identity.

  2. 02

    Triggered by the SAP function

    Authentication can be tied to the specific business action, rather than treating every SAP session the same.

  3. 03

    Identity follows the transaction

    The important question becomes: Who actually performed this action? Not simply: who logged in?

  4. 04

    Designed for the SAP environment

    bioLock becomes part of the SAP security architecture rather than another disconnected security layer.

Standard SAP security

  1. LoginUser authenticates
  2. SAP session
  3. User performs 47 different functions
  4. Who actually performed the critical transaction?

“We verified that this account can access SAP.”

bioLock

  1. LoginUser authenticates
  2. SAP session
  3. High-risk SAP function
  4. bioLock verifies human
  5. Transaction authorized
  6. Identity + transaction recorded

“We verified that the human performing this SAP action is the authorized user.”

WhoDid whatIn SAPWhenAfter biometric verification

A tamper-proof, indisputable audit log.

The standard SAP log file shows only the logged-in credentials: the SAP User ID. bioLock also records the uniquely identified human, by biometric ID, in its own tamper-proof log that can be shared directly with auditors.

Call bioLock Log FileExample entries

Date SAP User ID Biometric ID user · full name Protection status Controlled SAP activity
DateUser NamebioLK UserFirst nameLast nameNTextFuncText
10.02.2024SMITHSMITHThomasSmith1was accepted471Execute the Payment Run – F110
10.02.2024SMITHSnowdenEdwardSnowden3not authorized375Exporting Sensitive NSA DATA
11.02.2024AJ3765AJ3765AmandaJONES3not authorized470Automatic Payment Transaction
12.02.2024MATHIASnoneHackerHacker2was rejected471Execute the Payment Run – F110
12.02.2024ADMINMILLERJoeMiller3not authorized412Create a Vendor – FK01

What a standard SAP log showsWhat bioLock adds: the human

Where does authentication happen?

ApproachWhat is verified?Where?
PasswordCredentialLogin
MFACredential + second factorLogin
SSOUser identityApplication access
PAMPrivileged accountAccess/session
SAP authorizationUser's permissionsSAP
bioLockThe human performing the actionSAP function/transaction / Enter Button

Authentication tells you who entered SAP. bioLock helps establish who performed the critical action.

SAP knows the transaction.
bioLock knows the human.

Together, they establish trusted execution.

  1. SAP transaction
  2. Risk detected
  3. Human verified
  4. Transaction authorized
  5. Identity recorded

What does bioLock replace?

bioLock doesn't replace your security stack.
It closes the gap between access and action.

Already have MFA, GRC, SSO or PAM?

  • “Don't we already have MFA?”
  • “We already have SAP GRC.”
  • “We already have SSO.”
  • “We already have Windows Hello.”
  • “We already have privileged access management.”
Existing securityWhat it doesbioLock adds
SSOIdentifies accountVerifies human
MFAProtects loginProtects critical function
SAP GRCManages internal controlsPrevents circumvention of internal controls
PAMControls privileged accessAdds biometric identity
SIEMRecords eventsEstablishes verified identity

Show us your highest-risk SAP transaction. We'll show you how bioLock can protect it.