Features

Everything an SAP HANA landscape needs to stay recoverable and healthy

Nine modules, 89 task types, one console. Each task can run ad hoc or as a scheduled job with retries, dependencies, maintenance windows and notifications.

Backup management

CertiHANA executes and monitors all SAP HANA data backup types: complete, differential and incremental backups, to file systems or to third-party backup tools through the SAP Backint interface. Backups run asynchronously with live progress and are tracked to completion in the HANA backup catalog.

  • Destination check before every scheduled backup, with automatic verification that the destination is writable
  • Backup catalog browser with every entry, file, size, duration and state, a log-backup timeline and CSV export
  • Log backup monitoring: age of the last log backup, gaps in the redo-log sequence, failed log backups and daily volume
  • Backup size estimation, parameter editor (log mode, log backup timeout, buffer sizes) and encryption status
  • Storage snapshot integration: prepare and close data snapshots for storage-based backups
  • Verification with SAP tools: hdbbackupcheck on the latest full backup, hdbbackupdiag on the complete recovery chain
  • Export of encryption root keys so encrypted backups remain recoverable on another system

A backup job, as CertiHANA runs it

02:00  destination check  /hana/backup/SBO_PROD  writable, 1.9 TB free
02:00  BACKUP DATA FOR SBO_PROD USING FILE ('FULL_2026-10-07')
02:11  finished · 148.2 GB · catalog id 1759795200123
02:12  hdbbackupcheck   OK
02:12  encryption root keys exported · retention preview: 9 entries
02:13  offsite sync queued · report mailed · audit entry written

Full backup with cleanup New in 1.3

One scheduled task combines the complete data backup with the removal of everything older. Only after the backup finished successfully does it delete all older data and log backups from the catalog and from the backup location, file system or Backint.

  • Keep a number of previous full backups with their log chain
  • Run against one database or against the SYSTEMDB and every registered tenant
  • Preview the deletion as a dry run before the first scheduled execution
  • A failed backup deletes nothing

Why it matters

Backup disks fill up because cleanup is a separate script that nobody dares to touch. Coupling the cleanup to a verified successful backup keeps storage predictable without ever shortening the recovery chain.

Retention and catalog housekeeping

A retention policy engine keeps the backup catalog and the backup storage under control. Policies combine the number of full backups to keep, a retention period in days, grandfather-father-son rules for weekly, monthly and yearly generations, and a minimum number of full backups that must always remain.

  • Resolves a policy to the exact SAP HANA catalog statement and previews what would be deleted and how much space is freed
  • Deletes catalog entries and files, or Backint copies, in one operation
  • Orphaned-file sweep removes backup files that are no longer referenced by the catalog
RuleExample
Keep last N fulls3
Keep days14
Weekly / monthly / yearly4 / 6 / 2
Minimum fulls2
ResultBACKUP CATALOG DELETE ALL BEFORE BACKUP_ID 1759… COMPLETE

Offsite and cloud copies

Local backup files protect against logical errors, not against the loss of the HANA host or its storage. CertiHANA maintains a second copy of every data and log backup file on a storage target of your choice and manages it independently.

  • Storage targets: SMB/CIFS, FTP/FTPS, SFTP, WebDAV (Nextcloud, ownCloud, Synology), S3-compatible object storage (AWS S3, MinIO, Wasabi, Backblaze B2, Ceph, Hetzner, IONOS), Azure Blob Storage, Microsoft OneDrive and SharePoint, Google Drive, Dropbox, local or UNC paths, and through rclone any further provider
  • Two transfer engines: the native engine streams files from the HANA host and uploads them itself; the rclone engine runs on the HANA host for maximum throughput
  • Resumable synchronisation: hourly, driven by the backup catalog; files already stored are skipped, failed files retried, every upload verified by size and SHA-256, a manifest written next to the files
  • Independent retention: last N fulls, days, weekly/monthly/yearly generations and a minimum; a deletion in the HANA catalog never removes an offsite copy
  • Verification: scheduled existence and size checks, a deep check that downloads the newest full and compares its hash, a daily coverage report
  • Client-side encryption: AES-256-GCM with an exportable key and a standalone decryption script, so the offsite data is never locked in
  • Restore path: the fetch task brings a backup with its log backups back to the HANA host, decrypts and verifies it, ready for the recovery planner

Offsite coverage, as the dashboard shows it

TargetNewest fullLogsStatus
s3://certicons-backups2 h ago15 minverified
SharePoint · Backups2 h ago15 minverified
\\nas01\hana2 h ago15 minverified

Recovery planning and test restores

The recovery planner computes, for "latest" or for any point in time, the chain of full, differential, incremental and log backups that a recovery needs. It validates the redo-log continuity, reports gaps, and generates the complete SAP HANA RECOVER statements, the SYSTEMDB recovery commands and a step-by-step runbook for the operator.

  • Tenant recoveries can be executed from the console under a typed confirmation phrase
  • The automated test restore creates a sandbox tenant, transfers the backup encryption root keys, recovers the latest full backup into it, verifies the sandbox and drops it again
  • Schedule it quarterly; the result is recorded like any other job and reported by e-mail

Generated for a point in time

RECOVER DATABASE FOR SBO_PROD UNTIL TIMESTAMP '2026-10-07 09:30:00'
  USING CATALOG PATH ('/hana/backup/log/DB_SBO_PROD')
  USING DATA PATH ('/hana/backup/data/DB_SBO_PROD/')
  USING LOG PATH ('/hana/backup/log/DB_SBO_PROD/')
  USING BACKUP_ID 1759795200123 CHECK ACCESS USING FILE;
-- chain: FULL + 2 DIFF + 37 LOG · continuity OK · gaps 0

Housekeeping and maintenance

CertiHANA implements the housekeeping operations recommended by SAP for stable HANA systems, each as a task that can be run ad hoc or scheduled.

  • Persistence: reclaim log segments, defragment data volumes when fragmentation is high, row store reorganisation, MVCC version space reclaim, savepoints
  • Diagnosis files: old trace files, backup log capping, core and crash dumps on the host, active trace types
  • Repositories and histories: alert history, statistics service retention and reactivation of disabled checks, repository object history, configuration change history, SQL plan cache, audit trail
  • Column store: delta merge of candidate tables with configurable thresholds, compression optimisation, table load and unload, table and catalog consistency checks
  • Security: unlocking users, extending validity, disabling password lifetime for technical users, privilege audit of sensitive roles and grants

Recommended schedule in one click

A schedule based on SAP guidance is applied to a system in one click and adjusted afterwards: daily log reclaim and delta merges, weekly trace cleanup and consistency samples, monthly defragmentation inside a maintenance window.

Monitoring and health

The console shows a dashboard per system and for the whole fleet: memory, disks and persistence, services, alerts, blocked transactions, log segments, backup status and trend charts. Detail pages cover memory, disks, sessions, workload, tables, alerts, security, traces and Business One companies.

  • Health check with about 55 rule-based checks in seven categories, each with a severity, a recommendation and the relevant SAP Note; a score from 0 to 100 with history
  • RPO compliance: age of the last data backup, age of the last log backup and integrity of the recovery chain against your objectives, with alerts
  • Daily HTML report, weekly fleet digest, Prometheus endpoint for Grafana
0–100health score with history per system
7check categories, from backups to certificates
19e-mail templates for jobs, alerts, reports and licence events
24/7RPO watch with instance and service probes

Schema Manager

On SAP Business One a schema is a company; on any HANA system schemas are the unit of ownership, growth and change. CertiHANA manages that level with an enterprise Schema Manager.

  • Inventory and insight: kind, company name, version and localisation, memory and disk footprint, delta share, table and row counts, growth over 7 and 30 days, capacity forecast
  • Lifecycle: export with row-count manifest and optional offsite copy, import under the same or a new name, one-step clone, scheduled production-to-test refresh with masking, archive and restore, single-table recovery, guarded drop
  • Data masking: built-in rule sets for SAP Business One personal data plus custom rules (fake names from the business key, hashed identifiers, shifted dates, generated e-mails and phone numbers); keys stay intact
  • Change control: structural comparison of two schemas, nightly DDL snapshots with drift alerts, row-count integrity baselines for upgrades and migrations
  • Safety: protected schema patterns, typed confirmation phrases, production overrides, export requirement before a drop, complete audit trail

Exports are written to any directory on the HANA host and compressed into one ZIP archive like the SAP Business One backup service; import, clone and restore keep existing objects by default (IGNORE EXISTING) or replace them on request.

Lifecycle at a glance

OperationGuard
Export / importrow-count manifest, verification
Clonetarget name check, registry
Test refreshmasking preview, production override
Archive / restoreoffsite copy, deregistration
Droprecent export required, typed phrase

Scheduling, notifications and integration

Every task can be scheduled as a job with a cron expression, per-job notifications, retries, dependencies on other jobs and maintenance windows for high-risk operations. Run history shows every execution with a live log, result data and the option to cancel a running backup.

  • Notification channels: SMTP e-mail, Microsoft Teams, Slack and generic webhooks, per job or as defaults
  • Prometheus endpoint for Grafana dashboards and alerting on job results, backup age and health scores
  • REST API with interactive documentation; command-line interface for headless operation from external schedulers
  • Configuration export and import for migrations and disaster recovery of the CertiHANA server itself

From the command line

certihana run backup.full --system SBO_PROD --wait
certihana run offsite.sync --target s3-eu
certihana license --file CERTICONS-479aa2d3.lic
certihana export-config --out certihana-config.json

Security and governance

  • Local users with three roles: viewer, operator and administrator; high-risk operations require the operator role and an explicit confirmation
  • Self-service password reset on the login screen with a six-digit e-mail code, valid for fifteen minutes and usable once, rate limited and stored hashed
  • Credentials for HANA and SSH stored encrypted with a per-installation master key; no configuration or database content is sent to CERTICONS
  • Every login, configuration change and executed operation written to an audit trail
  • HTTPS with a self-signed or purchased certificate, login lockout after repeated failures, session expiry
  • Least-privilege operation: a dedicated technical HANA user with a documented, scripted set of system privileges; no software inside HANA
  • Licence keys signed with ES256; the product verifies signature, issuer, Hardware ID and validity offline

See it on your own landscape

A 45-minute demo on your systems or ours. We bring the recommended schedule, you bring the questions.