---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Data protection

# Data protection {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Data protection

The Data protection features in ServiceNow Brazil release provide comprehensive security controls to safeguard your data throughout the AI lifecycle.
These tools include the Key Management Framework, Field Encryption, Data Classification, and Now Assist privacy configurations.
They enable you to manage personally identifiable information (PII), control data sharing, and discover and protect sensitive data in your instance.
Show full answer Show less  

## Data Transit, Storage, and Privacy Controls

* **Now Assist User Data Usage Policy:** Understand how user data is transmitted, processed, and protected, with options to mask sensitive data and control sharing for AI model improvement.
* **Data Privacy Configuration:** Configure how PII is anonymized before reaching large language models, specifying data types and anonymization rules.
* **Privacy Policies Setup:** Define policies to anonymize sensitive information during AI processing effectively.
* **Data Steward Role:** Assign a data steward responsible for making informed data sharing decisions related to Now Assist.
* **Data Sharing Opt-Out:** Optionally disable data sharing with ServiceNow for AI model improvements directly from the Admin console.

## Sensitive Data Discovery and Classification

* **Key Management Framework:** Create and manage encryption keys that regulate access to sensitive data, including keys used by AI agents and workflows.
* **Field Encryption:** Encrypt individual fields to protect sensitive data at rest, ensuring AI agents access only with appropriate permissions.
* **Data Classification:** Apply classification labels to identify sensitive content, helping you understand AI agents' data access and where additional protection is required.
* **ServiceNow Otto for Vault:** Utilize generative AI skills to generate custom data patterns, verify role access to encrypted columns, and schedule data discovery jobs.
* **Data Discovery Scheduling:** Run one-time or recurring jobs to detect sensitive data such as PII or PHI in inputs to large language models.
* **Role Access Checks:** Identify which user roles can access encryption keys to monitor and maintain your encryption posture.
* **Custom Data Patterns:** Create and activate custom regular expression patterns for sensitive data detection from plain-language descriptions.
* **AI Data Kit:** Scan and cleanse datasets from sensitive data before using them in AI evaluations, ensuring compliance and privacy.

## Key Outcomes

By leveraging these data protection capabilities, ServiceNow customers can confidently manage sensitive information, enforce privacy policies, and control AI data usage. These measures help maintain data security and compliance while enabling effective AI functionality in your ServiceNow instance.  
Learn how ServiceNow security tools such as the Key Management Framework, Field Encryption, and Data Classification work to keep your data secure.

Now Assist keeps your data secure throughout the AI lifecycle. Additional controls let you manage how personally identifiable information (PII) is handled, who can make data sharing decisions, and how
sensitive data is discovered and protected across your instance.

## Data transit, storage, and privacy controls {#naai-data-protection__section_data_handling}

The following topics, all in AI Admin Hub, describe how Now Assist handles your data and how to configure privacy controls for your instance.

[User data usage policy for Now Assist](https://www.servicenow.com/docs/access?context=user-data-usage-policy-now-assist&version=brazil&pubname=brazil-intelligent-experiences&ft:locale=en-US)
:   Understand how Now Assist transmits, processes, and protects your data, including options to mask sensitive data and control data sharing for model improvements.

[Configuring Data Privacy for ServiceNow Otto](https://www.servicenow.com/docs/ay~XzCatAl085zLBYZxOEQ "Configure a data privacy advanced configuration to de-identify personally identifiable information (PII) in generative AI applications.")
:   Configure how PII is de-identified before it reaches the large language model, including which data types are caught and how anonymization rules are applied.

[Configure Now Assist privacy policies](https://www.servicenow.com/docs/access?context=configure-privacy-policies&version=brazil&pubname=brazil-intelligent-experiences&ft:locale=en-US)
:   Set up privacy policies to control how sensitive information is anonymized during AI processing.

[Assign the data steward role](https://www.servicenow.com/docs/access?context=assign-data-steward-role&version=brazil&pubname=brazil-intelligent-experiences&ft:locale=en-US)
:   Assign a data steward, the role responsible for making data sharing decisions for Now Assist on your instance.

[Opt out of data sharing for Now Assist](https://www.servicenow.com/docs/access?context=opt-out-of-data-sharing-for-now-assist&version=brazil&pubname=brazil-intelligent-experiences&ft:locale=en-US)
:   Opt your instance out of data sharing with ServiceNow for AI model improvements from the Admin console Settings page.

## Sensitive data discovery and classification {#naai-data-protection__section_data_discovery}

The following topics describe how to use ServiceNow Otto for Vault and Now Assist Data Kit to discover, classify, and protect sensitive data on your instance.

[Key Management Framework](https://www.servicenow.com/docs/gWG0Ws7Cy5kJLRsRHn~IdA "Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.")
:   Use the Key Management Framework to create and manage encryption keys that control access to sensitive data on your instance, including keys used by AI agents and agentic workflows.

[Field Encryption](https://www.servicenow.com/docs/usl_5DKKkEMqsFljFcfflQ "Protect encrypted data on your instance from unauthorized users, scripts, or system processes using Field Encryption.")
:   Encrypt individual fields on your instance to protect sensitive data at rest, ensuring that AI agents can only access encrypted fields when they have the appropriate permissions.

[Data classification](https://www.servicenow.com/docs/lCbkq9xOt0FCQoj8YK1yvw "Group data by type, using pre-defined or user-defined data classifications. If you have an assigned data classification administrator or auditor role, you can administer different data classes or visually analyze the current state of different types of data within the instance.")
:   Define and apply data classification labels to identify sensitive content across your instance, helping you understand what data your AI agents can access and where protection controls are needed.

[ServiceNow Otto for Vault](https://www.servicenow.com/docs/PEdj3~ZZPvn_1tG_kY77cg "With ServiceNow Otto for Vault, you can generate custom data patterns, check role access for an encrypted column, and schedule data discovery jobs. ServiceNow Otto for Vault can make it easier for you to perform common tasks without going to multiple systems.")
:   Learn about the generative AI skills available in ServiceNow Otto for Vault for generating custom data patterns, checking role access for encrypted columns, and scheduling data discovery jobs.

[Schedule a Data Discovery job with ServiceNow Otto for Vault](https://www.servicenow.com/docs/eN3JjNBdQoZGRYoXU5lFrQ "Use the schedule data discovery job skill to schedule one-time or recurring Data Discovery jobs with ServiceNow Otto for Vault. Data Discovery jobs can detect sensitive data such as PII or PHI provided as input to the Azure OpenAI model.")
:   Schedule one-time or recurring Data Discovery jobs to detect sensitive data such as PII or PHI that may be present in inputs to the LLM.

[Check role access for an encrypted column with ServiceNow Otto for Vault](https://www.servicenow.com/docs/WLVl5QWO4ug__XQse0tKiQ "Use the check role access for encrypted column skill to identify user roles that have access to encryption and decryption keys in your instance.")
:   Identify which user roles have access to encryption and decryption keys in your instance to monitor your encryption access posture.

[Generate a custom data pattern by using ServiceNow Otto for Vault](https://www.servicenow.com/docs/UkKSPmMNhJDe33~BxZInpA "Use the generate custom data pattern skill to create a custom regular expression data pattern from your description and add it as an active data pattern to your instance.")
:   Create a custom regular expression data pattern from a plain-language description and add it as an active data pattern on your instance.

[Find and cleanse sensitive data](https://www.servicenow.com/docs/access?context=sensitive-data&version=brazil&pubname=brazil-intelligent-experiences&ft:locale=en-US)
:   AI Data Kit: Scan your datasets for sensitive data including PII, and cleanse identified data before it is used in AI evaluations.

