I understand your security concerns but, right at this moment, we have requirement for tomcat to be run as root.
There is a workaround that will assist you with the current version of SAC but when we release our next version, there will be some features that call commands which require root access.
You're not the first person to have these concerns but, due to the operation of some of our binaries, allowing them to be run by non-root users requires some re-architecture that isn't a quick fix.
If you still want me to post the workaround, please say so.
Cheers
Dave.