Trust & Data Handling
Last updated: June 2026
We ask security teams to point Nowisor at their ServiceNow estate, so we owe you a precise account of what touches your data and what does not. This page is that account. Where it matters, we lead with the option that keeps your data in your hands.
The paste-driven option: your logs never leave your tenant
Our forensic checks — such as the CVE exposure check — run from a read-only Background Script you run yourself on your instance. You paste its output into the page. For our free checks the verdict is computed in your browser: the pasted log text is never transmitted to us. The detection scripts only read log tables and print a result — they cannot write to, change, or call out from your instance. If you need to generate a dated PDF, only the computed verdict (the conclusion) is sent to render it — never the underlying log lines — and the anonymous path stores nothing.
When you connect an instance (OAuth): read-only by default
- Read-only scope. The connected scanner reads configuration and posture via the ServiceNow Table API. It does not modify your instance as part of scanning.
- The one write path is explicit and opt-in. Creating a remediation ticket (a change request or incident) is the only action that writes to your instance, and it happens only when you click to confirm a server-built request you can see first. Nothing is written silently.
- Tokens are encrypted at rest. OAuth tokens are encrypted with AES-256-GCM before storage. We do not store your ServiceNow username or password — the OAuth flow means we never receive them.
- Account passwords are hashed with scrypt; we never store plaintext passwords.
- You can disconnect at any time, which removes the stored connection and its tokens.
What we deliberately do not do
- We do not require admin credentials or a password to run a forensic self-check — paste-driven is the default.
- We do not write to your instance except the explicit, confirmed remediation-ticket path above.
- We do not run model-generated logic in the verdict path — exposure verdicts are deterministic from your log signals, not an LLM guess.
- We do not turn an incident determination into a legal conclusion. Regulatory output (NIS2, DORA, GDPR) is decision support, not a “you must report” call.
Hosting & data residency
The application and database are hosted on EU infrastructure (an EU region on Railway, with the database on a persistent volume). AI answer generation is the one exception: it is processed by our US-hosted AI provider. Enterprise accounts can enable Enhanced data protection — a zero-data-retention AI workspace with no model training (US-processed); EU-region inference is on our roadmap. If your organisation has a specific data-residency requirement (for example, EU-only processing for NIS2 or DORA), contact us before connecting an instance so we can confirm the current options — we would rather tell you plainly than imply a guarantee we have not verified for your case.
Trust artifacts
We are a small, focused vendor. Formal attestations (SOC 2, an independent penetration-test letter for the app and OAuth flow) are on our roadmap and prioritised by real enterprise demand. If your procurement process needs one of these to proceed, tell us — and in the meantime, the paste-driven path above lets you get value without connecting anything at all.
Contact
Questions about data handling, a security questionnaire, or a residency requirement? Reach us via the main site and we will respond directly.