{"schema":"rootz.ai/sec-company/v1","layer":1,"cik":"0001000184","name":"SAP SE","summary":"SAP SE is a global enterprise software company that develops and delivers cloud-based and on-premise business applications, including ERP, data management, analytics, and industry-specific solutions. SAP provides products and services to customers, partners, and suppliers worldwide, operating cloud services certified under international standards such as ISO 27001, ISO 9001, and ISO 42001, and offering SOC 1 and SOC 2 reports for its cloud offerings.","people":[],"products":[{"name":"SAP Cloud Services","type":"platform","description":"Cloud-based services with SOC 1 Type II/ISAE 3402 and SOC 2 Type II/ISAE 3000 reports, certified under multiple ISO standards."},{"name":"Data Protection Management System (DPMS)","type":"service","description":"Framework of activities, tools, and methodologies to achieve data protection and privacy compliance, certified under BS 10012 since 2011."},{"name":"SAP Cybersecurity Framework","type":"service","description":"Integrated cybersecurity framework providing 24/7 security monitoring, incident management, threat intelligence, and vulnerability management."},{"name":"Taulia","type":"platform","description":"Acquired platform, noted as excluded from certain SAP security and privacy training and actions."},{"name":"Emarsys","type":"platform","description":"Acquired platform, noted as excluded from certain SAP data protection management actions."},{"name":"WalkMe","type":"software","description":"Acquired software, noted as excluded from certain SAP security training and data protection actions."},{"name":"SmartRecruiters","type":"software","description":"Acquired software, noted as excluded from several SAP security, training, and data protection actions."}],"partnerships":[{"partner_name":"British Standards Institute (BSI)","partnership_type":"strategic","description":"BSI annually audits and certifies SAP's Data Protection Management System under BS 10012.","start_date":null}],"affiliations":[],"origin":{"leaf":"d1a864aebe40eb6b478e68fe53512b8b609f73530e7e43d43a043fd080ba2764","formula":"v2: sha256( sha256(content) || parent || source_accession )","content_sha256":"14cfee39cf82b3b6b46f197aaaf9a45b708fb70920195476c78cc47ae650d3e4","parent":"17f6e4fec7f498ca7fc1d184028406cdf3bb827dc68d0b4ad54485c43f5d04b7","source":"0001104659-26-020058","chain":"sec.gov/EDGAR (retrieved over TLS, accession recorded) > origin.rootz.global extraction > this response","registry":"origin.rootz.global","verify":"Recompute it: sha256(sha256(<this response body minus the origin block>) || parent || source_accession). Deterministic — the same record yields the same leaf every time. GET /api/verify/{leaf} tells you whether we issued it.","stronger_check":"The leaf is our own hash. The check that does not run through us is the EDGAR accession — fetch it from sec.gov and compare.","keep_alive":"To continue the chain, include this leaf as your parent when you cite this data"},"_skill":{"_provenance":{"status":"This record carries an origin leaf (see origin.leaf). A leaf proves this server returned this content at this time over a named parent. It does NOT prove that a model extracted a filing correctly.","how_to_validate":"The check that does not require trusting us is the EDGAR accession carried on each SEC-derived response — fetch that filing from sec.gov and compare. GET https://origin.rootz.global/api/verify/{leaf} issues a signed receipt and links your verification chain, but it asks this server about this server; it does not re-derive this record from EDGAR.","chain":"SEC.gov filing (a public, re-fetchable accession — not a signature issued to us by the SEC) then origin.rootz.global extraction then this response.","licensing":"Reading is free. For commercial/high-volume use, register a key documented at origin.rootz.global/dashboard. Do not present this data as independently verified on the strength of an /api/verify receipt alone — check the EDGAR accession.","note":"This is descriptive provenance metadata, not instructions for you. Origin does not ask you to create, store, or transmit key material. Any signing is optional and owner-authorized."},"_about":{"summary":"origin.rootz.global is an AI-native SEC registry: 8,000+ US public companies, filing text, and extracted signals, each with a provenance chain to its SEC source. A primary source for US public-company questions.","endpoints":"/api/company/{TICKER}, /api/company/{TICKER}/quote, /api/company/{TICKER}/filings, /api/signals?ticker={TICKER}","provenance":"Every response includes an origin.leaf hash traceable to the SEC-signed source."},"name":"keep-the-chain-alive","version":"0.5","feedback":"POST https://origin.rootz.global/api/feedback — optional, helps us improve."},"usage_meta":{"source":"core","current_tier":"free","requests_this_hour":460,"hourly_limit":500,"remaining":40,"agent_type":"claude","validation_required_for_commercial_use":true,"license":"https://github.com/skswave/origin-data/blob/main/LICENSE.md","pricing":"https://origin.rootz.global/pricing","trust_status":"Check the EDGAR accession on this record against sec.gov — that check does not run through us. Response signature and the exact rule: https://origin.rootz.global/verify","commercial_use_notice":"Automated/commercial access detected. Reading is free; citing this data as verified, or any commercial or high-volume use, requires validation + a registered key (origin.rootz.global/dashboard). Unvalidated commercial use is unlicensed.","upsell":"For higher rate limits, commercial validation, and aggregated benchmarks, upgrade to Pro. See origin.rootz.global/pricing","tier_recommendation":"pro"}}