---
sourceDocument: Australia Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Tools and metrics

# Vault tools and metrics {#ariaid-title1}

Release version: Australia  
Updated May 26, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Vault tools and metrics

ServiceNow Vault provides an integrated set of tools and metrics designed to help customers discover, classify, protect, and monitor sensitive data across their ServiceNow instances.
These capabilities enable comprehensive data security management by combining data discovery, protection technologies, and AI-driven insights, ensuring sensitive data is identified, secured, and monitored against potential risks.
Show full answer Show less  

## Know your data

Vault uses **Data Discovery** to scan your instance for sensitive data patterns, reporting occurrences in tables and attachments with the ability to track discovery status such as new findings, classified data, or ignored results. **Data Classification** organizes discovered data into classes for better management and protection, highlighting which tables or columns are classifiable or already classified.

## Protect your data

To secure sensitive data, ServiceNow Vault offers multiple protection tools:

* **Anonymization:** Removes sensitive data while preserving data patterns, useful for instance sanitization or compliance with data removal requests. It includes real-time and existing data anonymization metrics and default protection policies.
* **Cloud Encryption with Key Management:** Provides block encryption with managed cryptographic keys, tracking active keys and key rotation intervals. Key management roles are required to view these metrics.
* **Field Encryption:** Protects classified data fields while allowing authorized access, reporting on encryption status per classification and number of active encryption keys. Requires specific admin roles to manage.
* **Log Export Service (LES):** Allows forwarding of instance logs to external analytics for monitoring sensitive data patterns, supporting activation of default configurations.
* **Zero Trust Access (ZTA):** Enforces continuous authentication for accessing classified data, protecting data classes with step-up authentication policies to reduce unauthorized access risk.

## Monitor your data

The **AI Insights** section aggregates activity data from sources like ServiceNow Otto, Virtual Agent, and real-time discovery-enabled tables to identify potential threats or data leaks. Metrics include user entries of sensitive data by channel and table, enabling prioritization of data protection efforts.

## Additional Vault Tools

* **Encryption Key Management and Field Encryption:** Configurable encryption modules to secure data at granular levels.
* **Code Signing:** Validates sensitive application configuration data and scripts before use, enhancing security.
* **Data Privacy Plugin:** Removes personally identifiable information (PII) when migrating data to non-production instances.
* **Data Discovery Plugin:** Identifies PII for classification and further protection.
* **Log Export Service:** Enhances security and analytics by exporting log data.
* **Zero Trust Access Service:** Dynamically reduces user privileges during sessions to minimize risk.

Overall, ServiceNow Vault equips customers with actionable insights and robust controls to effectively manage sensitive data discovery, classification, protection, and continuous monitoring within their ServiceNow environments.  
Learn about the tools and metrics ServiceNow Vault uses to protect and discover sensitive data.

ServiceNow Vault integrates with several tools to provide you with a cohesive overview of your sensitive data security. You can hover over a widget to get further insight on the reported data. Select the Go to button on any tool to go to its respective page.

## Know your data {#vault-tools__section_eds_1nx_rfc}

ServiceNow Vault uses Data Discovery and Data Classification help you understand and know your data.{#vault-tools__table_ltz_vcb_1gc__entry__3}

| Tool | Metric | Description |
|-|-|-|
| [Discovery](https://www.servicenow.com/docs/X23C57LKJeoyaAkL4r3FMQ "Use Data Discovery to identify sensitive data within an instance, such as credit card information, emails, or social security numbers.") Use Data Discovery to run a discovery scan to look for data patterns that might be sensitive data. Once discovered, data can then be reviewed or classified for further protection and management. | Discovered data | Occurrences of sensitive data across tables in your instance, categorized by sensitive data pattern type. |
| [Discovery](https://www.servicenow.com/docs/X23C57LKJeoyaAkL4r3FMQ "Use Data Discovery to identify sensitive data within an instance, such as credit card information, emails, or social security numbers.") Use Data Discovery to run a discovery scan to look for data patterns that might be sensitive data. Once discovered, data can then be reviewed or classified for further protection and management. | Discovery status | Current state of all discovered sensitive data patterns, including new findings pending review, classified, or marked as ignored. |
| [Discovery](https://www.servicenow.com/docs/X23C57LKJeoyaAkL4r3FMQ "Use Data Discovery to identify sensitive data within an instance, such as credit card information, emails, or social security numbers.") Use Data Discovery to run a discovery scan to look for data patterns that might be sensitive data. Once discovered, data can then be reviewed or classified for further protection and management. | Discovered attachments | Total sensitive data occurrences in attachments across tables in your instance. |
| [Classification](https://www.servicenow.com/docs/ESFtpH44O_WqID4cyAAEMw "Group data by type, using pre-defined or user-defined data classifications. If you have an assigned data classification administrator or auditor role, you can administer different data classes or visually analyze the current state of different types of data within the instance.") Data Classification creates data classes and helps organize your data into data classes for better management. Classified data can be protected at the class level. | Classifiable data | Tables or columns that can be classified. |
| [Classification](https://www.servicenow.com/docs/ESFtpH44O_WqID4cyAAEMw "Group data by type, using pre-defined or user-defined data classifications. If you have an assigned data classification administrator or auditor role, you can administer different data classes or visually analyze the current state of different types of data within the instance.") Data Classification creates data classes and helps organize your data into data classes for better management. Classified data can be protected at the class level. | Classified data | Dictionary entries, tables, or columns that are classified. |
[Table 1. Tools and metrics]

{#vault-tools__table_ltz_vcb_1gc}

## Protect your data {#vault-tools__vault-protect-your-data}

ServiceNow Vault uses data anonymization, cloud encryption, field encryption, log export, and zero trust access to help secure and protect your data.{#vault-tools__table_vdj_n2b_1gc__entry__3}

| Tool | Metric | Description |
|-|-|-|
| [Anonymization](https://www.servicenow.com/docs/zw4nkOkoTPTsW3MGAQ8exA "Anonymization provides a way to easily transform data so that it is unidentifiable and more compliant with data privacy regulations.") Anonymize data by data class with different anonymization techniques to preserve data patterns but remove sensitive data. Useful for sanitizing instances for development or removing specific user data because of rights to be forgotten. Default real-time protection policies are available from this card and are applied in addition to any existing policies. For more information, see [Default policies and configurations in ServiceNow Vault](https://www.servicenow.com/docs/UGpBkrRf7SaZ3A_FE6lZbg "ServiceNow Vault has a set of ready-to-use policies and configurations for selected tools to help you get started quickly."). | Existing data | All classified data per workflow that is anonymized or not. |
| [Anonymization](https://www.servicenow.com/docs/zw4nkOkoTPTsW3MGAQ8exA "Anonymization provides a way to easily transform data so that it is unidentifiable and more compliant with data privacy regulations.") Anonymize data by data class with different anonymization techniques to preserve data patterns but remove sensitive data. Useful for sanitizing instances for development or removing specific user data because of rights to be forgotten. Default real-time protection policies are available from this card and are applied in addition to any existing policies. For more information, see [Default policies and configurations in ServiceNow Vault](https://www.servicenow.com/docs/UGpBkrRf7SaZ3A_FE6lZbg "ServiceNow Vault has a set of ready-to-use policies and configurations for selected tools to help you get started quickly."). | Real time data | Number of successful real-time calls to anonymize sensitive data as it enters the platform, by channel. |
| [Anonymization](https://www.servicenow.com/docs/zw4nkOkoTPTsW3MGAQ8exA "Anonymization provides a way to easily transform data so that it is unidentifiable and more compliant with data privacy regulations.") Anonymize data by data class with different anonymization techniques to preserve data patterns but remove sensitive data. Useful for sanitizing instances for development or removing specific user data because of rights to be forgotten. Default real-time protection policies are available from this card and are applied in addition to any existing policies. For more information, see [Default policies and configurations in ServiceNow Vault](https://www.servicenow.com/docs/UGpBkrRf7SaZ3A_FE6lZbg "ServiceNow Vault has a set of ready-to-use policies and configurations for selected tools to help you get started quickly."). | Anonymization run times | How long scheduled user- or data-based jobs ran in hours for existing data. |
| [Cloud Encryption with Key Management](https://www.servicenow.com/docs/Sn~ZSQuEMVyrZq5fH1FKDw "ServiceNow Cloud Encryption offers encrypted storage for the database using block encryption, along with enhanced key management. Cloud Encryption is available with the ServiceNow Platform Encryption subscription bundle.") Securely protect sensitive data in encrypted storage for your data using block encryption, along with enhanced key management. | Active cloud key | Total rotations of the active cloud key. Note: To view this data, you need the [Key Management Framework](https://www.servicenow.com/docs/MHiryPH57IQmrXZUhh6nrA "Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.") admin role (sn_kmf.admin or sn_kmf.cryptographic_manager). |
|   | Key rotation | Time elapsed between each rotation of active keys on your instance. Bar height measures how long a key was used before rotation. Note: To view this data, you need the [Key Management Framework](https://www.servicenow.com/docs/MHiryPH57IQmrXZUhh6nrA "Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.") admin role (sn_kmf.admin or sn_kmf.cryptographic_manager). |
| [Field Encryption](https://www.servicenow.com/docs/PFznU_xdGqqLxsb6B~UdIA "Protect encrypted data on your instance from unauthorized users, scripts, or system processes using Field Encryption.") Securely protect sensitive data while providing access for authorized users. Useful for increasing protections from bad actors. | Encrypted fields classification status | Classification status of all data protected with Field Encryption. |
| [Field Encryption](https://www.servicenow.com/docs/PFznU_xdGqqLxsb6B~UdIA "Protect encrypted data on your instance from unauthorized users, scripts, or system processes using Field Encryption.") Securely protect sensitive data while providing access for authorized users. Useful for increasing protections from bad actors. | Classes protected with Field Encryption | The proportion of classified data protected withField Encryption. |
| [Field Encryption](https://www.servicenow.com/docs/PFznU_xdGqqLxsb6B~UdIA "Protect encrypted data on your instance from unauthorized users, scripts, or system processes using Field Encryption.") Securely protect sensitive data while providing access for authorized users. Useful for increasing protections from bad actors. | Active encryption keys | Number of active Field Encryption keys in your instance. Ideally, the number of active keys matches the number of classifications. Note: To view this data, you need the [Key Management Framework](https://www.servicenow.com/docs/MHiryPH57IQmrXZUhh6nrA "Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.") admin role (sn_kmf.admin or sn_kmf.cryptographic_manager) and the security_admin role. |
| [Exploring Log Export Service (LES)](https://www.servicenow.com/docs/kg94VslBIeGsUK_3_MNg3Q "The LES service provides a highly scalable and near real-time integration with your analytic tools that is easy to set up and maintain. If you're new to LES, read this overview section to learn what the tool can do.") Forward your instance's logs to external analytics tools to monitor data patterns. New users can activate default configurations from this card. For more information, see [Default policies and configurations in ServiceNow Vault](https://www.servicenow.com/docs/UGpBkrRf7SaZ3A_FE6lZbg "ServiceNow Vault has a set of ready-to-use policies and configurations for selected tools to help you get started quickly."). |   |   |
| [Zero Trust Access (ZTA)](https://www.servicenow.com/docs/MTVUKmrBoun6Hdhn~i3kpg "Zero Trust Access (ZTA) is a security model that assumes no user or device is trusted by default.") Continuous authentication while accessing classified sensitive data in real time. Default step-up authentication policies are available for Vault customers. For more information, see [Default policies and configurations in ServiceNow Vault](https://www.servicenow.com/docs/UGpBkrRf7SaZ3A_FE6lZbg "ServiceNow Vault has a set of ready-to-use policies and configurations for selected tools to help you get started quickly."). | Continuous authentication classification status | Number of classifications that are protected due to the Continuous Authentication policies. |
| [Zero Trust Access (ZTA)](https://www.servicenow.com/docs/MTVUKmrBoun6Hdhn~i3kpg "Zero Trust Access (ZTA) is a security model that assumes no user or device is trusted by default.") Continuous authentication while accessing classified sensitive data in real time. Default step-up authentication policies are available for Vault customers. For more information, see [Default policies and configurations in ServiceNow Vault](https://www.servicenow.com/docs/UGpBkrRf7SaZ3A_FE6lZbg "ServiceNow Vault has a set of ready-to-use policies and configurations for selected tools to help you get started quickly."). | Classes protected with continuous authentication | Number of classes protected with continuous authentication, categorized by class. |
[Table 2. Tools and metrics]

{#vault-tools__table_vdj_n2b_1gc}

## Monitor your data {#vault-tools__vault-monitor-your-data}

The AI Insights section within ServiceNow Vault helps you keep track of activities that may indicate potential threats or data leaks.These activities are generated from channels such as ServiceNow Otto and Virtual Agent, as well as database tables configured with real-time discovery. This insight can help you prioritize your data protection strategies more effectively. Select View tool metrics
to see the underlying metrics.
{#vault-tools__table_zhl_wfn_23c__entry__3}

| Metric | Chart Component | Description |
|-|-|-|
| User entering sensitive data | In tables with real-time discovery | The number of users whose sensitive data entries were detected in database tables configured with real-time discovery. |
| User entering sensitive data | In channels | The number of users whose sensitive data entries were detected within channels such as Now Assist or Virtual Agent. |
| Channels with sensitive data | Channel bars (x-axis) | Stacked bars representing each channel where sensitive data was detected, broken down by data patterns. The data pattern legend displays the color code for each pattern. They may include driver license numbers, financial information, and personal identifiers. |
| Channels with sensitive data | Occurrences of sensitive data (y-axis) | The count of sensitive data instances detected per channel. |
| Tables with sensitive data found through real-time discovery | Table bars (x-axis) | Stacked bars representing each database table where sensitive data was detected, broken down by data patterns. |
| Tables with sensitive data found through real-time discovery | Occurrences of sensitive data | The count of sensitive data instances detected per table. |
[Table 3. AI Insights charts]

{#vault-tools__table_zhl_wfn_23c}

## All ServiceNow Vault tools {#vault-tools__section_scx_qkd_55b}

|-|-|
| [Encryption](https://www.servicenow.com/docs/MHiryPH57IQmrXZUhh6nrA "Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.") [Key Management and Field Encryption is a suite of highly configurable encryption modules](https://www.servicenow.com/docs/MHiryPH57IQmrXZUhh6nrA "Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.") | [Code Signing](https://www.servicenow.com/docs/R6i3OEQ6nk_lsU3GnD5VSA "Use Code Signing to create digital signatures that prevent unauthorized or tampered External Communication Channel (ECC) queue records from being processed by MID Servers. This cryptographic verification helps maintain the integrity of integrations between ServiceNow and external systems.") [Help improve security by validating sensitive application configuration data and scripts before they are used.](https://www.servicenow.com/docs/R6i3OEQ6nk_lsU3GnD5VSA "Use Code Signing to create digital signatures that prevent unauthorized or tampered External Communication Channel (ECC) queue records from being processed by MID Servers. This cryptographic verification helps maintain the integrity of integrations between ServiceNow and external systems.") |
| [Data Privacy](https://www.servicenow.com/docs/vVpQY6EBT1JVN5t4n9T7~A "Use Data Privacy to classify sensitive data and to remove personally identifiable information (PII) from user data in a production instance and anonymize data in non-production instances. Once anonymized, the user data is no longer considered regulated private information.") [Use the Data Privacy plugin to remove personally identifiable information (PII) from user data when it is migrated from a production instance to a non-production instance.](https://www.servicenow.com/docs/vVpQY6EBT1JVN5t4n9T7~A "Use Data Privacy to classify sensitive data and to remove personally identifiable information (PII) from user data in a production instance and anonymize data in non-production instances. Once anonymized, the user data is no longer considered regulated private information.") | [Data Discovery](https://www.servicenow.com/docs/X23C57LKJeoyaAkL4r3FMQ "Use Data Discovery to identify sensitive data within an instance, such as credit card information, emails, or social security numbers.") [The Data Discovery plugin enables you to find personally identifiable information (PII) from user data. The data can then be classified for further security measures.](https://www.servicenow.com/docs/X23C57LKJeoyaAkL4r3FMQ "Use Data Discovery to identify sensitive data within an instance, such as credit card information, emails, or social security numbers.") |
| [Log Export Service](https://www.servicenow.com/docs/kg94VslBIeGsUK_3_MNg3Q "The LES service provides a highly scalable and near real-time integration with your analytic tools that is easy to set up and maintain. If you're new to LES, read this overview section to learn what the tool can do.") [Improve security, performance, and user experience by importing ServiceNow log data into enterprise log analytics using the log export service.](https://www.servicenow.com/docs/kg94VslBIeGsUK_3_MNg3Q "The LES service provides a highly scalable and near real-time integration with your analytic tools that is easy to set up and maintain. If you're new to LES, read this overview section to learn what the tool can do.") | [Zero Trust Access](https://www.servicenow.com/docs/MTVUKmrBoun6Hdhn~i3kpg "Zero Trust Access (ZTA) is a security model that assumes no user or device is trusted by default.") [ServiceNow Session Access enables organizations to dynamically reduce user privilege in a web session](https://www.servicenow.com/docs/MTVUKmrBoun6Hdhn~i3kpg "Zero Trust Access (ZTA) is a security model that assumes no user or device is trusted by default.") |
[ ]

{#vault-tools__table_ysx_slf_kfc}

