---
sourceDocument: Xanadu Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/platform-security

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Code Signing

# Code Signing {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use Code Signing to create digital signatures that prevent unauthorized or tampered External Communication Channel (ECC) queue records from being processed by MID Servers. This cryptographic verification helps maintain the
integrity of integrations between ServiceNow and external systems.

## Code signing and Circle of Trust {#code-signing-landing__section_dnb_vfd_mzb}

The Circle of Trust (COT) is a prerequisite for Code Signing that creates secure communication between your trusted and production instances to ensure that only authorized users can access the Code Signing feature.

Multiple security measures help to prevent malicious actors from disabling or misusing code signing in the case a production instance is compromised. As part of the defense-in-depth strategy, the COT uses the following components:

* Controls that restrict even the most powerful administrator accounts are established in the production instance to help protect Code Signing processes and configuration.
* Trusted instances are required to work together with production instances to establish the Circle of Trust relationship. At least one trusted instance is required, but multiple trusted instances may be configured to collaborate with the production instance.  
  Figure 1. Circle of Trust overview

  The Circle of Trust uses jobs, scripts, and business rules along with a key pair to generate signatures to sign update sets to the production instance. When the job is called, the signature is verified along with
  the trusted certificate to execute production instance updates.  
  Figure 2. Trusted update sets process  
  Figure 3. Code Signing flow

{#code-signing-landing__ul_tsx_gvb_ppb}

The Circle of Trust requires an initial trust relationship between trusted and production instances that prevents any unauthorized user with any authorization level from accessing unapproved activities.

## Get started {#code-signing-landing__section_llx_cnb_mzb}

|-|-|-|
| [Explore](https://www.servicenow.com/docs/vtxfa2~XF8SQAEBwIgF1ZQ "Code Signing provides cryptographic verification to ensure that only authorized scripts can execute on MID Servers. Code Signing prevents unauthorized or tampered ECC queue records from being processed by MID Servers, maintaining the integrity of integrations between ServiceNow and external systems.") [Learn the key features and business value of Code Signing.](https://www.servicenow.com/docs/vtxfa2~XF8SQAEBwIgF1ZQ "Code Signing provides cryptographic verification to ensure that only authorized scripts can execute on MID Servers. Code Signing prevents unauthorized or tampered ECC queue records from being processed by MID Servers, maintaining the integrity of integrations between ServiceNow and external systems.") | [ConfigureActivate and configure Code Signing.](https://www.servicenow.com/docs/Wg~RLTTd_RBLeQujXXuu0g "Activate and configure Code Signing to verify the authenticity and integrity of your data.") | [ReferenceGet details about properties and troubleshooting](https://www.servicenow.com/docs/I4KO2nJW_01~WmHSzNkkCQ "Reference topics provide additional information to administer and troubleshoot Code Signing.") |
|   | [UseLearn how to use Code Signing to help verify the authenticity and integrity of your data.](https://www.servicenow.com/docs/7U~bFnsgi~7Ab3GQzvq6AQ "Learn how to sign records, messages, and attachments to help verify the authenticity and integrity of your data.") |   |
[ ]

{#code-signing-landing__table_mlx_cnb_mzb}

## Troubleshoot and get help {#code-signing-landing__section_rlx_cnb_mzb}

* <https://www.servicenow.com/community/secops/ct-p/security-operations>
* [Search the Known Error Portal for known error
  articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477)
* [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case)
{#code-signing-landing__ul_slx_cnb_mzb}
* **[Exploring Code Signing](https://www.servicenow.com/docs/vtxfa2~XF8SQAEBwIgF1ZQ)**   
  Code Signing provides cryptographic verification to ensure that only authorized scripts can execute on MID Servers. Code Signing prevents unauthorized or tampered ECC queue records from being processed by MID Servers, maintaining the integrity of integrations between ServiceNow and external systems.
* **[Configuring Code Signing](https://www.servicenow.com/docs/Wg~RLTTd_RBLeQujXXuu0g)**   
  Activate and configure Code Signing to verify the authenticity and integrity of your data.
* **[Using Code Signing](https://www.servicenow.com/docs/7U~bFnsgi~7Ab3GQzvq6AQ)**   
  Learn how to sign records, messages, and attachments to help verify the authenticity and integrity of your data.
* **[Code Signing reference](https://www.servicenow.com/docs/I4KO2nJW_01~WmHSzNkkCQ)**   
  Reference topics provide additional information to administer and troubleshoot Code Signing.

