for it > security

Liquid UI: Enterprise-Grade Security, Built Into Every Layer

Liquid UI is architected so that security is never a retrofit. From encrypted connections to centralized governance, every component is designed to satisfy enterprise security requirements

End-to-End Encryption That Meets Your Standards

TLS 1.3

Every connection between Liquid UI and SAP is encrypted using the same standard required by banks, defense contractors, and government agencies. No exceptions.

SAPCRYPTO (CommonCryptoLib)

Liquid UI speaks SAP's own cryptographic library natively, operating both as server and client. Your security team evaluates one encryption standard, not two.

Mutual TLS

Client certificates ensure both endpoints authenticate each other before any data flows. No anonymous connections, ever.

Zero data at rest on devices

By default, no SAP data is stored on end-user devices. Screens render in real time from the server. A lost or stolen device is a hardware loss, not a data breach.

TLS 1.3
on every connection
Zero
data stored
Single SSO
100%
audit trail coverage

How Liquid UI Secures Access Across Every Device

How Liquid UI Secures Access Across Every Device
Zero SAP data stored on devices with Liquid UI security

Zero SAP Data on Devices

The most effective endpoint security is ensuring there's nothing to breach. By default, Liquid UI stores no SAP data on user devices. Screens render in real time from the server, with no local databases, cached credentials, or offline data stores.

A lost or stolen device is a hardware loss, not a data breach. This holds across every deployment context — desktop, browser, or mobile.

Flexible authentication that integrates with existing IT infrastructure

Authentication and Identity

Liquid UI integrates with your existing identity infrastructure, including SAP Secure Login, so users authenticate with the credentials they already use. No separate user accounts, duplicate credentials, or proprietary authentication methods are required.

For Kerberos environments, Liquid UI supports secure Single Sign-On (SSO) without storing user passwords. Users are authenticated to SAP as themselves, preserving existing SAP authorizations, audit trails, and security policies.

Supported authentication methods

  • Kerberos / Active Directory
  • SAP Secure Login (X.509)
  • MYSAPSSO2
  • SAP Trust
No new protocols required for Liquid UI integration

No New Protocols to Approve

Liquid UI doesn't ask your security team to make exceptions or learn a new encryption stack. Every protocol it uses — TLS 1.3, SAPCRYPTO, SNC, mTLS — is one your team already requires and understands. Connections between Liquid UI Server and SAP run over SNC via SAPCRYPTO, eliminating cleartext DIAG traffic entirely. 

More for IT teams

architecture

Architecture

What Liquid UI connects to, what it doesn't touch, and why there's no middleware to manage.

See Architecture
Deployment

Deployment

One console to manage everything. See what getting Liquid UI running in your infrastructure actually involves

See Liquid UI deployment
compatibility

Compatibility

Compatible with SAP R3 to S/4HANA, on-prem or in the cloud, you can run Liquid UI easily. 

See Liquid UI compatibility

Let's Talk About Your Device Security

Book a technical walkthrough and we'll show you exactly how Liquid UI's encryption, authentication, and governance layers use the standards your security team already requires.