|
Welcome to ServiceNow®
Vault
Are you ready to start your ServiceNow Vault journey? This guide gives you valuable information you can share with your team, including proven guidance and links to key resources—all designed to set you on the path to success. While this guide is primarily designed for ServiceNow platform owners and security administrators, it also contains useful information for various roles in your organization.
Let’s get started!
|
 |
Guide Overview
Here’s an overview of topics covered in this guide:
- What is ServiceNow Vault?
- Familiarize Yourself with Vault Capabilities
- Installing, Configuring, and Managing ServiceNow Vault
- Where Can I Install Vault?
- New Best Practices Library Assets added during June 2026
- Bookmark resources
|
What is ServiceNow Vault?
ServiceNow Vault is a premium bundle of security and privacy controls designed to help organizations strengthen their security posture and comply with regulatory requirements. It provides advanced security and privacy controls on the ServiceNow AI Platform that protect business-critical applications and sensitive data.
ServiceNow Vault includes five key products:
- Platform Encryption — A suite that includes Cloud Encryption (data-at-rest protection) and Field Encryption Enterprise with flexible key management options
- Data Privacy — Discover, classify, and anonymize sensitive personal information within your workflows and instances through Data Classification, Data Discovery, and Data Anonymization
- Zero Trust Access — Create policies to define and enforce additional flexible user and machine access levels based on network, location, authentication method, and identity provider attributes
- Log Export Service — Integrate ServiceNow system and application logs into near-real-time enterprise security analytics tools for improved visibility of security anomalies
- Code Signing Enterprise — Validate the authenticity and integrity of MID Server business logic before it executes using Circle of Trust to prevent software tampering
ServiceNow Vault is an account-level entitlement available on all current ServiceNow releases. Learn more about ServiceNow Vault and its benefits.
|
Securing the ServiceNow AI Platform
As organizations transition to the cloud, security and compliance risks remain a major barrier to adoption. Learn how ServiceNow approaches platform security and data protection.
Read the Platform Security White Paper (PDF)
|
Start by Familiarizing Yourself with ServiceNow Vault
Before you start on your ServiceNow Vault journey, take the time to learn the basics. This Introduction to ServiceNow Vault course will give you a brief introduction to Vault capabilities. Once you’ve finished the course, review the product documentation.
For a deeper dive into security, privacy, and compliance across all five products, explore the Privacy and Security Academy YouTube Playlist.
If you are new to ServiceNow, we recommend that you take the What is the ServiceNow Platform? course to learn the platform basics. A longer ServiceNow Fundamentals course is also available.
Recommended path for preparing for Vault deployment:
- Start with this Vault Welcome Guide. It is the single best starting point. It covers what Vault is, links to every capability-specific resource, and provides the recommended learning path.
- Review the Vault Recommended Implementation Sequence. This Best Practices Library asset defines the order in which Vault capabilities should be activated. Following the sequence avoids dependency conflicts and accelerates time-to-value.
- Review the Vault Implementation Guide. This asset helps implementers make key decisions by focusing on WHY certain options may deliver the best outcomes for their organization’s requirements.
- Complete the Vault Scoping Guide. Before configuring anything, work through this scoping exercise with your CISO and security and governance teams. It captures encryption key policies, data retention requirements, and use-case priorities.
- Use the capability-specific Implementation Guides, Process Workshops, and Process Guides. Each Vault capability has its own workshop deck and step-by-step guide on Best Practices Library. These are the same materials used by implementation partners.
Pro Tip: Don’t try to implement Vault by yourself! Get your CISO, Security, and Governance teams involved early. They know the answers regarding your organization’s encryption key policies and data retention requirements—information that’s critical for a successful implementation.
|
AI-Powered Security
Now Assist for Vault helps automate routine security tasks like scheduling data discovery jobs and creating custom regex patterns.
|
Installing, Configuring, and Managing ServiceNow Vault
Start your implementation journey with the Vault Recommended Implementation Sequence, the Vault Implementation Guide, and the Vault Scoping Guide in the Best Practices Library. These guides help you understand your organization’s requirements and plan your implementation approach.
With a Vault Suite subscription, installing the Vault Console plugin includes all of the Vault plugins (com.snc.vault_suite, as of Australia Patch 3). The Vault Console application helps you manage and monitor your Vault implementation from a single dashboard.
To make the most of each Vault product, review the resources available for each product below. The Flexibility Rating indicates how much customization is typically required during implementation (5 = highly flexible/customizable, 1 = less extensible).
Legend: 🎬 Academy Session | 🎯 Process Workshop | 📋 Process Guide
Have questions or want to find information about the latest release of ServiceNow Vault? Be sure to bookmark the Platform Privacy & Security Community.
|
Where Can I Install Vault?
Vault plugins and store apps are available across different ServiceNow environment types, but availability varies. Use the table below to determine which components you can install in your specific environment. Note that some products are platform plugins activated through the plugin framework, while others are store applications installed from the ServiceNow Store. This information is accurate as of the Zurich release.
ServiceNow Vault component availability across PDI, Entitled Customer Production, and Evaluation Customer Sub-Production environments
| Plugin / Feature |
Type |
PDI |
Entitled Customer Production |
Evaluation Customer Sub-Production |
| Platform Encryption |
Cloud Encryption com.glide.platform.cloud_encryption |
PLUGIN |
No |
Yes |
No |
Field Encryption Enterprise com.glide.field.encryption.enterprise |
PLUGIN |
Yes |
Yes |
Yes |
| Data Privacy |
Data Privacy sn_dp_store_app |
STORE |
Yes* |
Yes |
Yes* |
| Zero Trust Access |
Policy Based Session Access com.snc.zero_trust_session_access |
PLUGIN |
Yes |
Yes |
Yes |
Location Based Access com.snc.zero_trust_location_access |
PLUGIN |
Yes |
Yes |
Yes |
Continuous Authentication com.snc.zero_trust_continuous_authentication |
PLUGIN |
Yes |
Yes |
Yes |
| Log Export Service |
Log Export sn_logstoanalytics |
STORE |
Yes† |
Yes |
Yes |
| Code Signing Enterprise |
Code Signing Enterprise com.glide.code_signing_enterprise |
PLUGIN |
Yes |
Yes |
Yes |
| Vault Console |
Vault Console sn_vault_console |
STORE |
Yes |
Yes |
Yes |
* 30-day trial — Store app installs with a 30-day evaluation period on non-entitled environments.
† Plugin only, no data streaming — The Log Export Service application can be installed on a PDI, but data streaming to external analytics tools is not available.
Type Key: PLUGIN = Platform plugin (activated via Plugins) STORE = Store application (installed from ServiceNow Store)
Availability shown is for ServiceNow commercial data centers. Government and regulated-sector data center availability may differ.
|
|
New Best Practices Library Assets added during June 2026
The following Implementation Guides and Recommended Implementation Sequences are now available in the Best Practices Library. Each explains the strategic decisions behind a deployment rather than step-by-step configuration, and pairs with the product documentation linked throughout this guide.
- ServiceNow Vault — Implementation Guide — Provides a strategic roadmap for implementing all five Vault components through a Foundation, Crawl, Walk, Run, and Fly maturity model. It focuses on the tradeoffs behind security-model choices, deployment sequencing, and governance frameworks rather than configuration steps, so teams move beyond feature activation to auditable, regulation-aligned controls.
- Authentication — Implementation Guide — Guides the transition from password-only access to phishing-resistant authentication, covering Multi-Factor Authentication, adaptive policies, and federated SSO integration. It addresses the strategic questions that determine success, including factor selection, enforcement model, and phased rollout, so teams balance security, user experience, and operational complexity.
- Authentication — Recommended Implementation Sequence — A four-stage roadmap covering Foundation and MFA Baseline, Workforce MFA Adoption, Phishing-Resistant Authentication, and Zero Trust Authentication Maturity. Each stage carries entry activities, exit criteria, and success measures that let teams pace enrollment while protecting highest-risk users first.
- Access Management Modernization — Implementation Guide — Helps teams modernize ServiceNow ACL architectures, moving from complex legacy controls to simplified, auditable patterns such as Deny-Unless decision types, Query-Range ACLs, and Security Data Filters. It explains why these patterns reduce risk and how to migrate incrementally without disrupting business operations, and it addresses the query-level ACL security enhancements introduced for CVE-2025-3648.
- Access Management Modernization — Recommended Implementation Sequence — A six-phase roadmap from Current State Baseline through Foundation, Crawl, Walk, Run, and Fly, sequencing ACL inventory, risk assessment, pilot migration, phased rollout, and AI-assisted access review. It defines the activities and success criteria for each phase, including the recommended application order by risk and value.
- Log Export Service — Implementation Guide — Frames the Log Export Service implementation around the connectivity decision that defines it: Dedicated MID Server, Log Analytics Kafka Connector, or Direct Kafka System. It reasons through the infrastructure, operational, compliance, and cost tradeoffs of each method, and explains how the 36-hour Hermes retention window and licensing tiers shape the architecture before any resources are provisioned.
- Log Export Service — Recommended Implementation Sequence — A phased roadmap from Baseline and Audit through Configure, Validate and Scale, and Operationalize, with distinct paths for the MID Server, Kafka Connector, and Direct Kafka connectivity methods. Each phase carries success measures covering volume and licensing baselines, prerequisite validation, end-to-end connectivity, failover testing, and compliance evidence.
|
Bookmark These Resources!
ServiceNow Customer Success Center — The CSC is a one-stop shop that gives you instant access to proven methodologies, leading practices, and expert insights and advice.
NowSupport — You can get technical issues resolved quickly by contacting our team comprised of ServiceNow employees with deep product knowledge and real-world experience. Read more about how to use NowSupport.
Best Practices Library — ServiceNow’s library of more than 700 leading implementation practices.
ServiceNow Community — Get insights, troubleshooting tips, answers to your questions, and other useful information from ServiceNow experts and other community members.
Platform Privacy & Security Community — Stay up to date with the latest security features, best practices, and release announcements from the ServiceNow Platform Security team.
|
 |
|
Additional Vault resources:
Related Guides and Workshops:
If you need hands-on implementation support:
- NowSupport for technical issues or Platform questions during deployment.
- Contact your Impact Squad (if applicable) to discuss implementation options and potential Expert Services engagement.
- For complex or multi-capability deployments, a Certified Implementation Partner can be engaged. ServiceNow partners with firms that have built dedicated Vault practice areas and maturity frameworks.
|
|
Ready to get started? Contact your Impact Squad and/or Account Team to further discuss your implementation options.
|
|
© 2026 ServiceNow, Inc. All rights reserved. ServiceNow, the ServiceNow logo, Now, and other ServiceNow marks are trademarks and/or registered trademarks of ServiceNow, Inc. in the United States and/or other countries.
|