For IT and Security
Built for the peoplewho have to approve it.
This is the page Operations forwards to you. No marketing, just how APXR connects to SAP, what it does and does not touch, how worker data is handled, and what your network needs to provide. Pilots begin in read only shadow mode, so review runs in parallel with proving the worker experience.
Shadow
mode
Live SAP write access triggers a security review that no VP of Operations can waive, typically 4 to 10 weeks at an enterprise. We design around it: pilots start in read only shadow mode, needing only minimal access while we prove the worker experience. An IT prerequisites pack ships with the LOI, so your review starts on signature day instead of after kickoff.
SAP connectivity
How APXR reaches your SAP system.
APXR runs in its own AWS environment and connects to your SAP warehouse system across a tunnel your network team controls. Task data flows out, confirmations flow back, and the connection is scoped to the SAP function modules the copilot uses.
Supported today
Site to site VPN
An IPsec tunnel between your network and APXR's AWS environment. The SAP connection runs inside that tunnel rather than across the public internet, and your team holds both ends of it.
During the pilot
Read only to start
The same tunnel carries read only traffic until your security review clears write back. Nothing about the connection changes when it does; the permissions on the SAP side do.
Anything else
Other patterns
If your security team requires a different connectivity model, we will scope it with you. Ask us before you assume the answer is no.
Data flow
- SAP stays the system of record on your side of the tunnel.
- Barcode verification runs on the device, not in the cloud.
Supported SAP scope
What APXR integrates with, and how.
- Deep SAP warehouse integration across SAP EWM and classic WM (LE-WM), configured per environment.
- Native RFC, BAPI, and OData, the same integration layer used by certified SAP partner applications.
- Bidirectional: pick lists pull from SAP, confirmations write back in real time.
- No middleware and no custom server side development required.
- Never touches the database directly and never bypasses SAP business logic.
- SAP remains the system of record at all times.
- Pilots begin in read only shadow mode. Write back is enabled after your security review.
- Supported releases are confirmed per environment. Tell us the SAP release you run and we will confirm support for it.
The LLM boundary
The model changes how guidance reads, never what it says.
SAP task data and the verification rules are deterministic. The LLM adapts the presentation of guidance and nothing else.
Deterministic
What comes from SAP and the rules
The task itself: the bin, the SKU, the quantity, the sequence, and the barcode verification that confirms them.
Adaptive
What the LLM does
How much guidance a worker sees and in which language, at the depth their current tier calls for.
Never
What the LLM cannot do
Generate a SKU, a quantity, a bin, or a confirmation back to SAP. None of those pass through the model.
Offline behaviour
A dropped connection delays synchronization. It does not lose a pick.
- Workers keep picking against the cached active pick list when connectivity is interrupted.
- Barcode verification runs on the device, so a wrong bin and a wrong item are still caught offline.
- Confirmations queue locally and synchronize to SAP automatically when connectivity returns.
- SAP remains the system of record throughout. A connectivity loss is a temporary delay in synchronization, not a gap in your SAP data.
Control status
Where each control actually stands today.
SOC 2
Readiness underway. APXR does not hold SOC 2 today. A DPA is available on request.
SSO
Targeted Q4 2026, with your identity provider.
MDM and remote wipe
On the roadmap, after the pilot.
BI export
A REST API for exporting metrics to external BI tools is on the roadmap, after the pilot. The supervisor dashboard ships today as a standalone web application.
Data handling
What we store, and what we deliberately do not.
- Worker activity data, meaning picks per hour, error frequency and guidance interactions, is stored in APXR's AWS US East (us-east-1) environment, encrypted in transit and at rest.
- No facial recognition, and no individual worker shaming. Analytics are aggregate first.
- No personally identifiable information beyond what worker login and SAP user mapping require.
- Retention is configurable per customer.
- Workers authenticate by PIN or barcode scan at device login, configurable per site. Devices are registered to your APXR tenant and cannot be used outside your environment without re-authorization.
Founding Pilot
$9,999. Ninety days. Your data decides.
Three founding pilot slots. We bring the glasses, configure the SAP connector, and run baseline versus APXR measurement with success criteria agreed before signature. The fee is fully creditable to your first rollout contract. If the numbers do not convince your team, you keep the report and walk away.
Prefer email? felipe@apxr.com
- Glasses loaned at no charge
- SAP connector configured for your landscape, WM or EWM
- Read only shadow mode start, IT friendly
- Founder level support throughout
- Measured performance report, yours either way