Unifying SAP Commerce Backends & Security Compliance for a Global Automotive Manufacturer

Product Owner, Project Manager, 4 Developers, Solution Architect
Commerce Platform: SAP Commerce Cloud (Hybris)
Backend: Java, Spring Boot, MySQL
Messaging & Orchestration: ActiveMQ, Kubernetes
Security & Monitoring: DataDog, Prisma, BlackDuck, SecHub
CI/CD & Cloud Infrastructure: Jenkins, AWS
Challenge
Our client, a global automotive manufacturer, operated multiple e-commerce platforms across different regions, each running separate SAP Commerce Cloud (Hybris) codebases. This fragmented architecture led to:
- Operational inefficiencies – Maintaining five different backend systems increased development costs and slowed down market rollouts.
- Security & Compliance Risks – The client required a robust security framework to pass an external Security Audit and align with GDPR and industry standards.
- Slow Market Expansion – Deploying a new e-commerce site to a different country required significant time and effort, delaying international growth.
To address these challenges, our company led a backend transformation initiative to unify multiple SAP Commerce codebases into a single scalable backend while ensuring security compliance for the upcoming audit.
Solution
Our team executed a two-pronged approach: Backend Unification & Security Hardening, ensuring the client had a scalable, compliant, and high-performance architecture for global e-commerce expansion.
Unifying SAP Commerce Backends for multi-country deployment
- Consolidated five different SAP Commerce codebases into one centralized backend, enabling a multi-country, multi-store architecture.
- Designed a modular architecture that allowed each regional store to have unique configurations while maintaining a shared core system.
- Standardized APIs & microservices, reducing maintenance complexity and improving time-to-market for new deployments.
- Integrated ActiveMQ & Kubernetes-based orchestration to optimize scalability and fault tolerance.
Security audit readiness & Compliance implementation
- Implemented end-to-end encryption for data in transit, backups, and sensitive information storage.
- Developed a secure containerization policy to manage access controls and audit logs across environments.
- Established a Free and Open Source Software (FOSS) security process, integrating automated vulnerability scanning using BlackDuck & SecHub.
- Defined security roles, permissions, and an incident response process to enhance risk management.
- Implemented a structured patching process to ensure timely updates and eliminate security vulnerabilities.
- Assisted in GDPR readiness by automating compliance-related tasks, including data anonymization scripts and user consent tracking.
Deployment & Business impact
- Successfully navigated the Security Audit, meeting all compliance requirements and resolving pre-identified vulnerabilities.
- Optimized deployment pipelines, enabling the client to launch e-commerce websites in new markets within 1 month (previously taking several months).
Results
Enabled rapid global expansion – New country deployments reduced from several months to just 1 month.
Passed the Security Audit – Ensured full compliance with security best practices & GDPR.
Reduced operational overhead – Eliminated redundant systems, simplifying maintenance and improving cost efficiency.
Scalable & secure architecture – Enabled long-term sustainability with a centralized, future-proof SAP Commerce backend.
Other Case Studies
With the Right Software, Great Things Can Happen
Re-Platforming an E-Commerce Website from Oracle ATG to Microservices
Transforming WordPress to Next.js & Contentstack CMS
Migrating custom functionality from SAP Commerce Product Cockpit to Backoffice PCMT
QA Audit for EMEA bank
Facet Search for E-Commerce
Voice Interface for Warehouse Employees
Warehouse Management APP
POS Check Constructor
Temperature Monitoring System for Warehoses
HR Helper Bot
Flexible work formats
For convenience we offer several standard models of work with our clients.
Time and material
Model works best when you don’t have a clear scope and want to be deeply involved in the development process.
Choose it if:
- you want to follow agile methodologies
- you need to be flexible due to quickly changing requirements and taste hypothesis time to time.
- you don’t have strict deadlines
All of that doesn’t mean you go in blind. Just like in the fixed-price model, you start your cooperation with planning, but only for the upcoming week or two. So instead of determining and fixing requirements for the whole project, you start fast and can further adjust the scope and priorities.
Fixed-capacity
This model focuses on ensuring the efficiency and velocity of the team. To achieve this, the supplier must ensure that different skill sets of members are assigned to a development squad to effectively deliver the project.
Choose it if:
- you want to follow agile methodologies
- you would like to have a fixed budget for a certain period, but don't have a clear idea on the defined scope of work or specifications
- you understand further support steps and define continued predictable costs
We need to work with the client to clarify the scope of work and prioritize the backlogs before the next iteration starts. As the project progresses, it allows the client to mold the project along the way to take advantage of newly released features.
Fixed-price
Model works best when you don’t have a clear scope and want to be deeply involved in the development process.
Choose it if:
- you want to follow agile methodologies
- you need to be flexible due to quickly changing requirements and taste hypothesis time to time.
- you don’t have strict deadlines
All of that doesn’t mean you go in blind. Just like in the fixed-price model, you start your cooperation with planning, but only for the upcoming week or two. So instead of determining and fixing requirements for the whole project, you start fast and can further adjust the scope and priorities.
The discount is applied annually for a period of 6 months.
We provide discount system for long-term cooperation customers. If the threshold is reached for the sum of all orders from one customer, a discount applies to all new subsequent projects.
