Our story
We built CERPASS because we lived the problem firsthand
Years working inside SAP environments showed us how broken traditional GRC was — complex for IT, incomprehensible for the business, and far too expensive for mid-market organisations to justify. So we built something different.
SAP version compatible
Works with ECC6, S/4HANA, RISE with SAP — no upgrades required.
Live in days, not months
Our guided onboarding means most customers are using CERPASS within a few business days.
Business-owned GRC
CERPASS moves risk ownership to Finance and Compliance — not just the IT security team.
How we got here
From idea to global platform
Title
Description text.
Title
Description text.
Title
Description text.
Title
Description text.
Title
Description text.
Title
Description text.
What we stand for
Core values that show up in everything we do
Business first, always
Every feature is designed for the CFO and Compliance Manager, not just the Basis team. If your Finance Director cannot use it independently, we have not done our job.
Radical simplicity
We strip away complexity wherever we find it — in the UI, in the implementation process, and in our commercial terms. Simple is not easy, but it is the right standard.
Honest conversations
We tell you when CERPASS is and is not the right fit. We publish honest comparisons. We price transparently. Trust is a long-term game and we play it that way.
Customer momentum
We measure success by how quickly a new customer gets their first real insight from CERPASS — not by how many modules they have signed up for. Time to value is sacred.
Partnership over transaction
Our customers stay because the product keeps earning their trust — not because of contract clauses. We invest in long-term relationships with both customers and partners.
Want to join us?
We are building a team that cares about making SAP GRC genuinely better. See open roles.
Our mission
“Make SAP access risk visible, manageable, and owned by the business — not buried in IT.”
We believe effective GRC is measured not by how sophisticated the technology is, but by how clearly a CFO, Compliance Manager, or Business Process Owner can understand the access risk in the business and take action. That belief drives every feature we build.
NEW — Security Trust Centre
We protect your SAP data as seriously as you do.
For a GRC vendor, security is not just a feature — it is a fundamental expectation. Here is how CERPASS protects your data and maintains compliance with international security standards.
- SOC 2 Type II
- ISO 27001
- Encrypted at rest & in transit
- Annual penetration testing
- Data residency options
- GDPR compliant
Careers
Help us make SAP GRC better for everyone
We are a remote-friendly team of [X] people who care deeply about making complex compliance problems approachable. We are growing and looking for people who share that mission.
[X]
Team members across [X] countries
Remote
Work from anywhere policy
[X]
Open roles right now
[X]%
Internal promotions last 12 months