Vault Suite delivers the complete ServiceNow Vault offering as a single paid subscription, installing every plugin included with your ServiceNow Vault subscription automatically on entitled instances.
With Vault Suite, you can secure your most sensitive data, enforce zero trust access policies, encrypt fields and attachments, classify and anonymize data, forward instance logs to your enterprise analytics tools, and protect your data at rest at the platform level. Vault Suite also empowers organizations to efficiently auto-classify sensitive data within workflows, such as Financial Services Operations (FSO) and Customer Service Management (CSM).
Administrators manage and monitor all included capabilities from a unified Vault Console dashboard, with several capabilities arriving preconfigured with default policies to help you strengthen your security posture from day one.
- Vault Console dashboard: Manage and monitor every capability in the Vault bundle from one administration experience, with posture visibility, guided configuration, and per-service status in a single place. Administrators see where sensitive data is exposed and what to do about it without moving between separate applications.
- Sensitive data discovery and classification: Locate sensitive data across tables, fields, and attachments on your instance, and classify it against categories such as personal, financial, and health information. Discovery results give you the inventory you need before applying encryption, access, or retention controls, so protection is targeted rather than guesswork.
- Data anonymization: Replace or obscure sensitive values so records stay usable for reporting, testing, and support workflows without exposing the underlying data. Anonymization can be applied to discovered fields, reducing exposure in non-production and downstream analytics use.
- Data privacy policies and monitoring: Define privacy policies over classified data and monitor for conditions that need attention, with alerting on policy-relevant activity. Privacy controls operate on the same classification results used by encryption and access policies, keeping one view of what is sensitive and how it is governed.
- Field Encryption Enterprise: Protect sensitive data at rest with unlimited field and attachment encryption, including customer-managed key support. Encryption is applied at the field level so it follows the data through forms, lists, and workflows without redesigning your application.
- ServiceNow Cloud Encryption: Encrypt your instance data at rest at the cloud platform level, covering the full data store rather than selected fields. This provides a baseline layer beneath field-level encryption for organisations with platform-wide encryption-at-rest requirements.
- Zero Trust Access: Apply continuous authentication, location-based access controls, and session-level restrictions to sensitive data and operations. Access decisions account for context at the point of use, not only at login, so elevated actions can be gated even within an authenticated session.
- Log Export Service: Forward instance system and application logs to your external analytics and SIEM platforms for monitoring, threat detection, and compliance retention. Export is configured per log source, so security teams can bring ServiceNow activity into the tooling they already operate.
- Code Signing Enterprise: Verify the integrity of code artifacts on your instance before they are used, confirming that what runs is what was signed. This closes a supply-chain gap for organisations that must prove custom and third-party code has not been altered.
- Guided setup for auto-classification: Use prebuilt templates to auto-classify sensitive data across workflows, with out-of-the-box support for Financial Services Operations (FSO) and Customer Service Management (CSM). Templates shorten the path from install to a working classification model on the data your teams already handle.
- Default security configurations: Activate preconfigured defaults for anonymization and Log Export Service so protection is in place without manual setup. Defaults give entitled instances a working security baseline from day one, which you can then tighten to your own policy.
Changed:
- Vault Suite now installs Log Export Service 3.5.0.
Min supported: Australia