SAI 360 IBM x SAP

First-time setup

Both users are created now. Each user has three password fields - all three must be entered, in order, at every login. Choose words that are not guessable. Passwords are never sent to the server.

User 1 - full access (read, write, edit)
User 2 - view only

This runs once. It derives keys in your browser (PBKDF2-SHA256, 600,000 rounds), encrypts the entire findings database with AES-256-GCM, uploads only ciphertext, and deletes the plaintext seed from the server.

SAI 360
Risk
Status
Counts follow the departments selected in the top picker.

Change log

Update snapshots

Read-only history of every update file applied.
Locked after 5 minutes of inactivity.

Change my password

All three fields are replaced. Only the key wrapper changes - the data itself is not re-encrypted.