Security Scan for Your SAP CAP Extensions
Clean core moves custom logic to BTP. We scan it - with SAP context.
As custom code leaves the ABAP stack for CAP side-by-side extensions, a new risk surface arrives: CDS service exposure, authorization annotations, Node.js/Java injection and xsuaa config. ABAP tools do not understand it and generic SAST does not understand it in SAP context. RedRays scans the whole project in one pass - CDS, handlers and the security descriptor together - and returns findings with the exact file and line.
Get a free scan See what it findsWhy CAP needs its own scan
A different risk model
A CAP app is CDS models plus Node.js/Java handlers plus config (xs-security.json, mta.yaml) - authorization annotations, service exposure and injection. Not ABAP.
Silent over-exposure
A CDS entity or action exposed in a service with no @requires or @restrict is reachable by default - the classic CAP mistake.
Read together
Real posture is defined by the service, its handler and the security descriptor combined, so RedRays correlates them - not one file at a time.
Not a second tool
CAP findings flow through the same console, findings model and reports as your ABAP and CPI scans.
What RedRays finds in CAP projects
Same platform and findings model as ABAP and CPI - each finding carries the exact file, line and offending source line.
Real bugs in your BTP app code
Reads the handlers, controllers and services in your CAP and BTP apps - tenant isolation gaps, information disclosure, missing CSRF protection, injection and broken authorization - each mapped to the exact file it lives in.


Every finding, explained and scored
Each finding carries a CVSS score, the exact file and line, a plain-language explanation and a concrete fix - here a state-changing POST with no CSRF token, down to the controller line - ready to triage, assign and export.
Connect Cloud Foundry, or upload a ZIP
Register a Cloud Foundry credential (a technical user with Space Developer) to browse your apps and scan their source, or upload a CAP project ZIP directly. The credential is encrypted at rest, per tenant.

What it detects
CDS, Node.js/Java and configuration issues a CAP project ships with by default:
Also on the platform
FAQ
What does the RedRays CAP scanner check?
It scans a whole SAP CAP project - CDS models, Node.js/Java handlers and config - for missing authorization, injection in handlers, path traversal, SSRF, over-broad xsuaa scopes, wildcard redirect-uris, hardcoded secrets and mocked auth left on in production, with the exact file and line.
How do I submit a CAP project?
Two ways: register a Cloud Foundry credential to browse and scan your apps' uploaded source, or upload a CAP project ZIP directly. Credentials are encrypted at rest and scoped per tenant.
What makes it SAP-aware, versus a generic scanner?
It does a mandatory authorization pass over every CDS service, entity and action, and correlates the service, its handler and the security descriptor together - the combination that defines real CAP posture, which generic SAST does not understand.
Is it a separate tool from the ABAP scanner?
No. CAP findings use the same console, findings model and PDF/Excel reports as your ABAP and CPI scans - one platform.
How do I try it?
Book a demo, or upload a CAP project for a free scan. Run it as SaaS or inside your own landscape.
See it on your own CAP project
Book a demo or upload a CAP project - we'll show you the findings, on your own code.
