For security architects, GRC analysts, and ServiceNow platform owners
ServiceNow secures the infrastructure. Everything you build on it — configurations, access, integrations, every line of custom code — is yours to secure and yours to evidence. Nowisor works on that layer alone.
The platform keeps closing configuration and access gaps natively. What it cannot close is the security of the code your team wrote: business rules, script includes, ACL scripts, integrations and agent definitions. Built on the ServiceNow platform surface itself, not a SaaS-posture connector.
Cloud and self-hosted instances · connected read-only, or upload from a scoped application you install through your own change process — the instance never has to be reachable.
Detection engine is open source — github.com/nowisor/instance-scan-pack · Apache-2.0
ServiceNow ships the hardening most organisations need: session and authentication controls, ACL defaults, scripted-REST and integration restrictions, encryption, anonymisation of cloned data, secrets management. The gap is rarely a missing product. It is a property left at its 2015 default, a plugin never activated, a Vault licence paid for and a fraction deployed.
Our findings say which control exists on your release, whether it is on, what turning it on changes, and where it is a one-way door. If we can't read it conclusively, the verdict says so — silence is never rendered as good news.
Hardening properties against your release baseline, authentication and session controls, and the ACL and role model as it stands today rather than as it was designed.
Custom script includes, business rules and ACL scripts, read as syntax rather than as settings — the surface a checklist framework cannot reach by construction.
Integrations, OAuth clients and their last token use, stored-credential records, MID Servers and scheduled jobs — the identities that never log in and never leave.
Encryption contexts, data anonymisation on clones, secrets-management adoption and code signing: what you licensed against what is actually deployed.
Which agents run in your tenant, what each one runs as, and what its role mask lets it reach.
Misconfigured ACLs, exposed endpoints, and sys_properties that create exploitation paths invisible to standard reviews.
NIS2, DORA, ISO 27001 and NCA ECC require instance-specific technical evidence — not generic policy documents.
Every integration, MID Server and OAuth client is a non-human identity (NHI): it never logs in, never leaves, and is a potential lateral movement path.
After ten years as Principal Security Advisor in ServiceNow's Office of the CISO, I saw every enterprise hit the same blind spots. Nowisor — a virtual subject-matter expert (SME) for ServiceNow security — makes that expertise accessible on demand.
Describe your concern in plain language — ACL gaps, integration risks, compliance requirements, attack paths.
Receive attack chains, detection scripts, and compliance mappings specific to your ServiceNow configuration.
Deploy scripts, close gaps, and generate auditor-ready compliance evidence.
Bring in a senior practitioner. Your full session context transfers automatically.
ServiceNow's Shared Responsibility Model draws the line: ServiceNow secures the platform, and you are responsible for how your instance is configured, who can reach what, and proving it to a regulator. Nowisor works entirely on your side of that line.
When you connect an instance, Nowisor reads your Security Center hardening score and the settings behind it, and treats them as the authoritative platform baseline. It does not recompute what ServiceNow already scores.
The detection engine installs as a scoped application and runs as a suite scan in ServiceNow's own Instance Scan framework. Findings land in your instance and remain there whether or not you ever connect the advisor.
A settings-comparison framework cannot read the syntax of your custom Script Includes, Business Rules, and UI Actions, and it has no concept of an out-of-the-box ACL that was edited last night. Those two gaps are structural — they are where the detection engine's static analysis and drift checks sit.
When ServiceNow sets a platform deadline — the Basic Auth API restriction (KB3025707 / KB3055080) is the current one — the pack ships readiness checks, so you can evidence where you stand before enforcement rather than after it.
Nowisor is built and run for organisations that answer to NIS2, DORA, ISO 27001 and NCA ECC. Where your data lives, where it is processed, and who controls the stack are design decisions — not afterthoughts.
Accounts, scan snapshots, and your ServiceNow configuration values are stored and scanned on EU infrastructure in Amsterdam. AI answer-generation uses a US provider by default; on Connected and above you can keep that in the EU too — see below.
On Connected and above, AI analysis runs on Claude served from EU data centres in Frankfurt, through an EU-hosted gateway governed by a signed GDPR Article 28 DPA. The gateway endpoint and the region-pinned model are what keep processing in the EEA — that part is enforced in code. Prompt and output logging is switched off on our gateway account, so under that DPA no copy is kept there. The model behind it is served by AWS Bedrock in Frankfurt under its own terms, which makes this EU-resident processing with no gateway-side logging rather than end-to-end zero retention. Retention and model-training terms come from that DPA rather than from a setting in this product.
When EU processing is selected, the system fails closed: if the EU route is ever unavailable, the request is refused — never quietly rerouted to a US endpoint. Jurisdiction is enforced in code, not just in a policy document.
The detection engine is open source under Apache-2.0, and the AI backend is swappable by design. You keep European control over the stack — inspect it, fork it, run the detection yourself without depending on nowisor.com at all.
Every property name, table reference, and detection script is verified against a release-pinned ServiceNow instance, not generated from training data. Current pin and verification methodology are on the how-verdicts page. If a configuration claim cannot be proven on a live instance, Nowisor does not ship it.
ServiceNow’s own security tooling scores your configuration against ServiceNow’s checklists. Nowisor audits the same substrate independently and frames it as cross-domain attack chains — empty ACLs combined with scoped-app cross-scope grants and AI agent role-mask gaps, not isolated checklist items. Independence is the point: a platform vendor’s own dashboard is a weak audit artifact when a regulator asks who verified it.
Findings are framed as attack paths an adversary would actually exploit, not as generic policy violations. Cross-scope privilege records, AI agent role-mask gaps, fabricated property recommendations from older guides — Nowisor surfaces what matters to an attacker.
Every finding maps to specific framework articles — NIS2 Article 21 sub-points, DORA Article 9, ISO 27001 Annex A controls, NCA ECC main controls. Coverage scope is declared honestly: comprehensive where it is, partial where it is, never overclaimed.
Every finding includes the exact ServiceNow Background Script that produced it. Copy, paste, run on your own instance — no black box, no vendor dependency. The methodology is the deliverable as much as the findings.
Reports include verified configuration values, framework citations, and verification scripts — auditable artifacts your assessor or regulator can validate independently. Built for the moment a CISO has to defend a finding under questioning.
Findings tell you what is misconfigured; log-export correlation tells you which misconfigurations are actually being exercised. A sustained brute-force against an unprotected admin endpoint is not the same risk class as a dormant un-audited table. The Active Risk Report correlates each finding against 7 days of runtime activity (sys_audit, sysevent, syslog_transaction) and marks every verdict EXERCISED, DORMANT, NOISE, or INVESTIGATE — qualified by log-export coverage at every step.
nowisor is built by Rachid Harrando — author of Securing ServiceNow, former Principal Security Advisor at ServiceNow's Office of the CISO, co-founder and Review Board member of Black Hat Arsenal. Twenty-five years in security — ten of them inside that office — encoded into a system that refuses to ship anything it cannot prove against a live ServiceNow instance.
The verification methodology is public: every property reference is checked against version-pinned ServiceNow schema dumps (Zurich Patch 6 and Zurich Patch 10 PDIs — 3,585 and 3,595 properties, captured and archived). Every detection script is tested against a live PDI before it ships. Every finding cites its evidence.
The detection engine is open source under Apache-2.0 at github.com/nowisor/instance-scan-pack. Every check the advisor reads from your instance was produced by code you can inspect, fork, or run on your own without depending on nowisor.com at all. The advisor is the value-add; the detection is the floor — and the floor is yours.
Generated code is bound to a release-pinned catalog — 143 ServiceNow table schemas and 90 system properties, drawn from the full sys_properties dumps of Zurich Patch 6 and Zurich Patch 10 PDIs (3,585 and 3,595 properties). Fabricated tables, fields, or API names are caught at the bind step, before any script is generated.
Every answer passes through nine automated detectors — uncited claims, unknown KB IDs, self-contradictions, prescriptions without diagnosis — before it reaches you.
Claims link back to specific knowledge-base articles with IDs validated post-response. If the source isn't there, the citation doesn't ship.
On Connected, your tenant's actual schema is extracted on connect so scripts target your customizations — not a generic template.
Fabricated property names and unsupported claims are stripped before display — not quietly flagged in a log you'll never read.
Every response carries a quality signature tracked in the admin console. Regressions are visible; drift is auditable.
Run a full security assessment in hours, not weeks. Pre-built attack paths and detection scripts across 15 domains.
Every engagement uses the same adversarial framework — repeatable, auditable, defensible.
Generate NIS2, DORA, ISO 27001 and NCA ECC evidence mapped to each client's configuration.
Access
Securing what you built on ServiceNow is a recurring load: an annual platform review, advisory fire drills, evidence for whoever audits you. Most organisations defer it and find the gap during an audit, a supervisory review or a client's due-diligence questionnaire. For NIS2, DORA, ISO 27001 or NCA ECC entities, the same work doubles as the evidence those regimes require. Three plans run inside your own tenant. Connected watches a live instance and keeps checking. You pay per instance you defend, not per question you ask.
Free
Recon
Find out in an afternoon whether your instance has a problem worth escalating.
No credit card required
25 queries · nothing to connect
Solo
Practitioner
For the person who owns the tenant and gets the call when something is wrong with it.
Billed monthly · 14-day trial · cancel anytime
Runs in your tenant or from pasted output — no connection to your instance
Multi-client
Practice
For a practice whose reputation rides on the same answer being right at every client.
Billed monthly · 14-day trial · cancel anytime
Runs in your tenant or from pasted output — no connection to your instance
Live instance
Connected
For a production instance where "we think it is fine" is not an answer you can give.
Billed annually — €34,800 invoiced
1 connected instance · unlimited scans
When the answer has to hold up in front of a regulator, a named security SME carries it with you. Scoped and signed offline, never bought from this page.
| Engagement | For | Access |
|---|---|---|
| Baseline Assessment | A first engagement on one production instance. Nine expert days over 30 calendar days, with 30 days of Connected included. Additional instances are priced per scope. Credited in full against an annual engagement signed within 90 days. | Read-only API, or results-file upload for self-hosted |
| Self-Hosted Assurance | Self-hosted or egress-locked instances that cannot be reached from outside. Advisory verdicts within 48 hours on your release, one upgrade security delta a year, two platform reviews, two signed evidence packs, and four hours a quarter with your auditor. Runs from a scoped application you install through your own change process, or our five standalone Background Scripts for a reduced review. | Upload only — nothing connects inward, no credentials leave your side |
| Assured | A single regulated organisation, up to three instances. Continuous posture, quarterly signed evidence packs, 48-hour advisory verdicts, eight hours a quarter of auditor support, and direct access to the named SME. | Connected |
| Programme | Multi-entity groups, MSPs and partners, or platforms mid-migration. Everything in Assured plus architecture review, programme design, delivery capacity and quarterly CISO governance. Local install available on request. | Any |
Vault Implementation Review
You own ServiceNow Vault. What is deployed, what is scoped wrong, and what the integrations still bypass. Five expert days and a written plan. Credited against Assured.
Delivered by Rachid Harrando — 25 years in cybersecurity, ten as Principal Security Advisor in ServiceNow's Office of the CISO for EMEA, co-founder of Black Hat Arsenal, author of Securing ServiceNow: A CISO's Field Guide. The person who reviews your instance is the person who presents the findings.
Book a 30-minute scoping call →A scope and a fixed price within five working days.
The instance never has to be reachable from outside. Same detection engine, the same rules and the same reports either way — what differs is how the reading reaches us and how often.
| Connected | Upload | |
|---|---|---|
| What we read | Your instance, over its own REST Table API, with a per-table field allow-list | A results file produced by our open-source bundle script, run by your team inside the instance: the reads a connected scan makes, and no others |
| What crosses the network | Read calls inbound to your instance. Our outbound calls are allow-listed by hostname before a socket is opened; source-IP allow-listing is not available today | One file, outbound, that you review before sending |
| Credentials we hold | Encrypted AES-256-GCM under a key kept separate from the session secret. They are deleted when you disconnect | None |
| Installed in your instance | Nothing | A scoped application you install through your own change process, or our five standalone Background Scripts for a reduced review. Both are open source |
| What it produces | Posture Map, Remediation Leverage, Evidence Table, scheduled scans and drift | The same Posture Map, Remediation Leverage, Evidence Table and reports, as of the capture date. Re-upload on your own cadence |
| Plan | Connected and above | Connected and above; the basis of Self-Hosted Assurance |
| Best for | Cloud instances that need posture to stay current | Self-hosted, egress-locked or sovereign instances |
All plans include the open-source detection engine. Monthly plans switch or cancel anytime. EU data hosting · EU-only AI processing (Connected and above) · DPA available.
No credit card.
Start free — 25 queries