For security architects, GRC analysts, and ServiceNow platform owners
An independent, attacker's-eye audit of your ServiceNow configuration. Every finding ships with the detection script that proves it — instance-specific technical evidence, not a generic policy PDF.
Empty ACLs, scoped-app cross-scope grants, AI agent role-mask gaps, audit forensic blind spots — mapped to NIS2, DORA, and ISO 27001 at the article level.
No signup · no instance access · pick your release and get an instant CVE verdict.
Detection engine is open source — github.com/nowisor/instance-scan-pack · Apache-2.0
Misconfigured ACLs, exposed endpoints, and sys_properties that create exploitation paths invisible to standard reviews.
NIS2, DORA, and ISO 27001 require instance-specific technical evidence — not generic policy documents.
Every integration, MID Server, and OAuth token is a potential lateral movement path.
After ten years as Principal Security Advisor in ServiceNow's Office of the CISO, I saw every enterprise hit the same blind spots. Nowisor — a virtual subject-matter expert (SME) for ServiceNow security — makes that expertise accessible on demand.
Describe your concern in plain language — ACL gaps, integration risks, compliance requirements, attack paths.
Receive attack chains, detection scripts, and compliance mappings specific to your ServiceNow configuration.
Deploy scripts, close gaps, and generate auditor-ready compliance evidence.
Bring in a senior practitioner. Your full session context transfers automatically.
ServiceNow's Shared Responsibility Model draws the line: ServiceNow secures the platform, and you are responsible for how your instance is configured, who can reach what, and proving it to a regulator. Nowisor works entirely on your side of that line.
When you connect an instance, Nowisor reads your Security Center hardening score and the settings behind it, and treats them as the authoritative platform baseline. It does not recompute what ServiceNow already scores.
The detection engine installs as a scoped application and runs as a suite scan in ServiceNow's own Instance Scan framework. Findings land in your instance and remain there whether or not you ever connect the advisor.
A settings-comparison framework cannot read the syntax of your custom Script Includes, Business Rules, and UI Actions, and it has no concept of an out-of-the-box ACL that was edited last night. Those two gaps are structural — they are where the detection engine's static analysis and drift checks sit.
When ServiceNow sets a platform deadline — the Basic Auth API restriction (KB3025707 / KB3055080) is the current one — the pack ships readiness checks, so you can evidence where you stand before enforcement rather than after it.
Nowisor is built and run for organisations that answer to NIS2, DORA, and GDPR. Where your data lives, where it is processed, and who controls the stack are design decisions — not afterthoughts.
Accounts, scan snapshots, and your ServiceNow configuration values are stored and scanned on EU infrastructure in Amsterdam. AI answer-generation uses a US provider by default; on Enterprise you can keep that in the EU too — see below.
On Enterprise, AI analysis runs on Claude served from EU data centres in Frankfurt, through an EU-hosted gateway governed by a signed GDPR Article 28 DPA. The gateway endpoint and the region-pinned model are what keep processing in the EEA — that part is enforced in code. Prompt and output logging is switched off on our gateway account, so under that DPA no copy is kept there. The model behind it is served by AWS Bedrock in Frankfurt under its own terms, which makes this EU-resident processing with no gateway-side logging rather than end-to-end zero retention. Retention and model-training terms come from that DPA rather than from a setting in this product.
When EU processing is selected, the system fails closed: if the EU route is ever unavailable, the request is refused — never quietly rerouted to a US endpoint. Jurisdiction is enforced in code, not just in a policy document.
The detection engine is open source under Apache-2.0, and the AI backend is swappable by design. You keep European control over the stack — inspect it, fork it, run the detection yourself without depending on nowisor.com at all.
Every property name, table reference, and detection script is verified against a real ServiceNow instance — a Zurich Patch 6 PDI — not generated from training data. Australia has been GA since May 2026 and our baseline has not moved to it yet, so we name the release we actually tested rather than the newest one. If a configuration claim cannot be proven on a live PDI, Nowisor does not ship it.
ServiceNow’s own security tooling scores your configuration against ServiceNow’s checklists. Nowisor audits the same substrate independently and frames it as cross-domain attack chains — empty ACLs combined with scoped-app cross-scope grants and AI agent role-mask gaps, not isolated checklist items. Independence is the point: a platform vendor’s own dashboard is a weak audit artifact when a regulator asks who verified it.
Findings are framed as attack paths an adversary would actually exploit, not as generic policy violations. Cross-scope privilege records, AI agent role-mask gaps, fabricated property recommendations from older guides — Nowisor surfaces what matters to an attacker.
Every finding maps to specific framework articles — NIS2 Article 21 sub-points, DORA Article 9, ISO 27001 Annex A controls. Coverage scope is declared honestly: comprehensive where it is, partial where it is, never overclaimed.
Every finding includes the exact ServiceNow Background Script that produced it. Copy, paste, run on your own instance — no black box, no vendor dependency. The methodology is the deliverable as much as the findings.
Reports include verified configuration values, framework citations, and verification scripts — auditable artifacts your assessor or regulator can validate independently. Built for the moment a CISO has to defend a finding under questioning.
Findings tell you what is misconfigured; the twin-sensor log-export tells you which misconfigurations are actually being exercised. A sustained brute-force against an unprotected admin endpoint is not the same risk class as a dormant un-audited table. The Active Risk Report correlates each finding against 7 days of runtime activity (sys_audit, sysevent, syslog_transaction) and marks every verdict EXERCISED, DORMANT, NOISE, or INVESTIGATE — qualified by log-export coverage at every step.
nowisor is built by Rachid Harrando — author of Securing ServiceNow, former Principal Security Advisor at ServiceNow's Office of the CISO, co-founder and Review Board member of Black Hat Arsenal. Twenty-five years in security — ten of them inside that office — encoded into a system that refuses to ship anything it cannot prove against a live ServiceNow instance.
The verification methodology is public: every property reference is checked against a version-pinned ServiceNow schema dump (Zurich Patch 6, 3,585 properties, captured and archived). Every detection script is tested against a live PDI before it ships. Every finding cites its evidence.
The detection engine is open source under Apache-2.0 at github.com/nowisor/instance-scan-pack. Every check the advisor reads from your instance was produced by code you can inspect, fork, or run on your own without depending on nowisor.com at all. The advisor is the value-add; the detection is the floor — and the floor is yours.
Generated code is bound to a release-pinned catalog — 143 ServiceNow table schemas and 90 system properties, drawn from the full 3,585-property Zurich Patch 6 dump. Fabricated tables, fields, or API names are caught at the bind step, before any script is generated.
Every answer passes through nine automated detectors — uncited claims, unknown KB IDs, self-contradictions, prescriptions without diagnosis — before it reaches you.
Claims link back to specific knowledge-base articles with IDs validated post-response. If the source isn't there, the citation doesn't ship.
On Enterprise, your tenant's actual schema is extracted on connect so scripts target your customizations — not a generic template.
Fabricated property names and unsupported claims are stripped before display — not quietly flagged in a log you'll never read.
Every response carries a quality signature tracked in the admin console. Regressions are visible; drift is auditable.
Run a full security assessment in hours, not weeks. Pre-built attack paths and detection scripts across 14 domains.
Every engagement uses the same adversarial framework — repeatable, auditable, defensible.
Generate NIS2, DORA, and ISO 27001 evidence mapped to each client's configuration.
Access
One ServiceNow security assessment by hand is three to five days of senior consultant time. Nowisor delivers it in hours — connect an instance, get attack-chain findings and auditor-ready NIS2/DORA/ISO 27001 evidence. Pay for the instances you audit, not the keystrokes.
Free
Recon
For practitioners and evaluators who want to see a real finding first.
No credit card required
25 queries · no instance connection
Solo
Practitioner
For platform owners and solo security architects hardening one instance.
or €1,490/year — two months free
1 connected instance · unlimited scans
Multi-client
Practice
For boutiques and independents scaling a ServiceNow security practice across client engagements. Pays for itself on the first one.
or €4,990/year — two months free
Up to 3 client instances · white-label
Managed · Regulated
Enterprise
For regulated enterprises that need their ServiceNow posture managed and evidenced continuously — not another tool to run.
Scoped to your instances, regulatory cycle, and Vault footprint
Managed posture assurance — we operate it, you get the evidence
Human expertise on top of any paid plan. Both are included in Enterprise.
Written responses from a senior practitioner within 48 hours.
Monthly 60-minute live session plus unlimited async Q&A.
Added to an existing subscription — ask in chat or talk to the founder.
Engagements scoped on a short discovery call. Annual terms; complementary to ServiceNow native security and your implementation partner.
Anchored on published EU rates: senior ServiceNow security consulting runs €1,500–2,500/day, and a meaningful audit takes 5–15 days.
One instance
A manual security review: €5,000–7,500 in senior consultant time. Once.
Practitioner — €1,490/year, unlimited scans.
3–5× return on the first assessment. Every re-scan after it is included.
A consulting practice
One enterprise config-review engagement: €15,000–40,000 of billable senior days.
Practice — €4,990/year across 3 client instances, white-label deliverables.
A year of tooling for less than one engagement — each client instance becomes repeatable margin.
A regulated enterprise
The annual point-in-time review is stale by Q2 — and audit evidence is still weeks of screenshot-collection.
Enterprise — from €4,500/mo, operated for you.
Findings close only when a re-scan proves the fix; evidence per reporting cycle is a generated report, and "were we exploited?" (NIS2 Art. 23 / DORA Art. 19) has a same-day answer.
What goes away: 5–15 consultant days per audit cycle · Weeks of GRC screenshot-collection per reporting cycle · The fire-drill hours after a ServiceNow CVE drops
All plans include the open-source detection engine. Annual billing available on every paid tier. Switch or cancel anytime. EU data hosting · EU-only AI processing (Enterprise) · DPA available.
25 free queries. No credit card.
ASK YOUR FIRST QUESTION