Trust
What we hold, and who we have held it for
Most vendor trust pages are a wall of badges. This one is a list: the SAP partnership behind the product, the SAP work already delivered under it, and the parts of the architecture your own team can go and check rather than take our word for.
The partnership
Where we actually are
AnrilX is new. The practice it comes out of is not, and for an early-stage vendor that is the part of the file worth reading first.
SAP PartnerEdge, Silver tier: KO Innovation
The tier is held by KO Innovation, the parent organisation, and AnrilX is built inside that practice rather than next to it. Naming the holder matters because SAP polices how its tiers are described and an SAP licensee reads partner status precisely.
SAP Certified Service Partner
A services accreditation, which is worth separating from a product one: it says the practice is recognised to deliver SAP work, not that this software has been certified against an SAP interface. We would rather you heard that distinction from us than assumed more from a badge.
50+ SAP consultants, certified on the modules
SD, MM, FI/CO, PP, EWM, QM, PM and HCM: the practice covers each module the platform reads. The partnership is a commercial tier; these are the people it is a tier over, and they are the reason the questions on this site were written by somebody who has answered them by hand.
500+ clients served by KO Innovation
Delivered by the parent practice over the life of the business. None of it is an AnrilX deployment; the roster below is KO Innovation's SAP work, and it is presented as evidence about the people, not about this product.
Delivered by KO Innovation
SAP landscapes the practice already supports
These are the parent organisation's SAP engagements, not AnrilX deployments; the platform has shipped to none of them. They are here because the consultants who delivered this work are the ones who wrote the questions the product answers.
- Almadeena
- Maqadhe
- Fahhad Alharfash
- Tata Elxsi
- Napeso
- Safa
- Tamdeen Mall Management
- Weekendz
- Al-Anud Cold
- Shamel
A selection. 500+ is the figure KO Innovation publishes for the clients it has served, and it is quoted here as theirs. Engagement scope differs by client and is described on KO Innovation's own site.
What you can inspect instead
The architecture is the part that is strong
None of this is a substitute for an attestation and it is not offered as one. It is the set of properties your team can verify directly, which for an early vendor is a better use of a review than reading our intentions.
Runs inside your landscape
On-premise, in your environment. There is no shared multi-customer store, so cross-customer exposure is not a control we operate; it is a thing that has nowhere to happen.
Your authorisations govern it
No access model of our own. A person reaches exactly what their SAP account permits, so the design your team already approved is the one in force.
No unattended write
Every write stops for a named person showing the exact payload and the exact call. No confidence threshold releases it and there is no setting that turns it off.
No bulk copy of your ERP
Reads are row-capped and made at question time. What is indexed is the shape of your system, not the transactions inside it.
Everything is recorded
Every tool call, model call and SAP read: what was asked, what came back, what was refused and why. A refused call is as visible as a successful one.
Fail-closed
If the policy engine cannot answer, the call does not happen. “Could not determine” is never treated as permission.
What running it in your own landscape changes for your review →
Being straight about it
Where this leaves you
Worth knowing before a procurement cycle rather than three weeks into one.
-
The clients listed on this page are KO Innovation's SAP engagements, not AnrilX deployments. If you want a reference call about this product specifically, there is not one to give you yet, and that is a fair thing to weigh.
-
We will not answer a questionnaire with aspirations. Where the honest answer is “not yet” you will get “not yet”, which is slower to hear and faster than discovering it in month three.
-
Retention terms, sub-processor detail and model-provider arrangements depend on how your deployment is configured, so they are answered against your actual design rather than asserted here in general.
What a security team asks
Can we speak to one of the clients listed?
Ask, and we will tell you which of those engagements we can arrange an introduction for; they are KO Innovation's SAP projects, so the conversation is about how the practice delivers rather than about running this platform. Nobody on that list is an AnrilX reference, and we will not present them as one.
What will you give us for a security review?
Ask and you will get what exists: the deployment topology, the data-flow description, which interfaces are called, the approval and audit design, and our development and review process. Where we do not have an artifact you have asked for, you will be told that rather than sent something adjacent.
Who sees our SAP data?
It stays in your landscape. For support we need an access path to your environment when you want one: scoped, logged and revocable by you. We would rather state plainly that such a path exists than imply nobody can ever connect, which would not be true of any supported software.
Is our data used to train models?
Ask us for this in writing against your specific deployment and you will get a direct answer, including what the arrangement is with any model provider involved. It is too important to answer with a generic sentence on a marketing page, and the configuration differs by deployment.
Who do we contact about security?
Write to hello@anrilx.com and say it is a security matter. A person reads it and it reaches the people who build the thing, because there is no separate function to route it to yet.
Bring your security team to the demo
The governance model is the part worth pressure-testing, and we would rather they asked the hard questions on the first call than the fifth.