ServiceNow Now Assist procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | medium | “1.1. Centralized ServiceNow Environment. Customer Data may be transferred outside of Customer’s ServiceNow instance to a centralized ServiceNow environment, which may be hosted in a different Data Center Region from Customer’s originating ServiceNow instance (“Centralized ServiceNow Environment”). The relevant terms set forth in the Agreement pertaining to ServiceNow’s security and data protection program will apply to the Centralized ServiceNow Environment, except for any terms relating to certifications, attestations, and penetration testing conducted by Customer. Notwithstanding the foregoing, ServiceNow will make available a SOC 2 Type 2 attestation and a penetration test summary report applicable to Customer Data processing by Advanced AI and Data Products in the Centralized ServiceNow Environment.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “2.3. EU Hosting. Customer Data Processed by ServiceNow and its Sub-processors as part of the provision of an Advanced AI and Data Product to the Customer which originate from Customer instances located within the European Union will remain hosted within the European Union except to the extent: (1) authorized by Customer in advance; (2) necessary to prevent or remediate a material issue involving security, data loss prevention, disaster recovery, or critical maintenance or service availability; (3) required by Law or to prevent fraud or abuse; or (4) documented in a Support Portal interaction (by or on behalf of Customer). The foregoing commitment does not supersede or modify those contractual terms applicable to certain ServiceNow products or services that require transfers of Customer Data to outside of the EU to use such products or services, nor will it apply to any third-party integrations or services utilized or configured by Customer that may transfer Customer Data to outside of the EU. Customer also acknowledges and agrees that the foregoing commitment does not apply to information provided to ServiceNow in respect of which ServiceNow is a data controller (e.g., marketing, billing, and account management data). 2.4. Ownership. Customer retains all ownership of Customer Data that is processed by the Advanced AI and Data Products. To the extent permitted by law and excluding any ServiceNow Core Technology, Customer owns the Generated Outputs. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “2.5.2. Certifications. ServiceNow will establish and maintain an ISO27001 certification for the AI Security Program. In addition, ServiceNow may establish additional certifications in the future, which may include an ISO 27018 certification. 2.5.3. Data Separation & Encryption at Rest. ServiceNow may, but is not obligated to, apply a logical separation of Filtered AI Content, except that ServiceNow will deploy standard technologies to encrypt data at rest. 2.5.4. Penetration Testing. ServiceNow will conduct penetration testing in accordance with ServiceNow’s standard security procedures. However, because Filtered AI Content will be used within a ServiceNow controlled environment, Customer will not be permitted to perform penetration testing on the environment and no reporting will be provided. 2.6. Necessary Rights and Privacy Obligations. Customer agrees that it has all rights necessary to use the Advanced AI and Data Products, including rights to the data Customer submits to any Advanced AI and Data Products. Customer is solely responsible for providing any legally adequate notices to and obtaining any consents from individuals and all third parties for ServiceNow to perform its rights and obligations under these Product-Specific Terms. 2.7. Acceptable Use. Customer's use of Advanced AI and Data Products is subject to ServiceNow’s AI Acceptable Use Policy, currently available at [https://www.servicenow.com/ai-acceptable-use-policy.html](https://www.servicenow.com/ai-acceptable-use-policy.html) (the "AUP"), as updated by ServiceNow from time to time. ” | Captured 2026-06-07Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.