<h2>Encryption and Key Management</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2025" /><meta name="DC.rights.owner" content="(C) Copyright 2025" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="concept" /><meta name="DC.title" content="Encryption and Key Management" /><meta name="abstract" content="Encryption is a cryptographic procedure that converts plaintext into ciphertext to control the disclosure of information." /><meta name="description" content="Encryption is a cryptographic procedure that converts plaintext into ciphertext to control the disclosure of information." /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2023-02-02" /><meta name="DC.date.modified" content="2023-10-06" /><meta name="mini-toc" content="yes" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="encryption" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Encryption and Key Management</title></head><body id="encryption"> <h1 class="title topictitle1" id="ariaid-title1">Encryption and Key Management</h1> <div class="body conbody"><p class="shortdesc">Encryption is a cryptographic procedure that converts plaintext into ciphertext to control the disclosure of information.</p> <div class="section" id="encryption__section_tcy_yrq_dsb"><h2 class="title sectiontitle">Overview</h2> <p class="p"><span class="ph">ServiceNow</span> key management includes the activities involving the handling of cryptographic keys and related security parameters during the end-to-end key lifecycle, and is an effective control based on National Institute of Standards and Technology (NIST) 800-57 guidelines.</p> <p class="p">Encryption is used to convert plaintext strings of characters into ciphertext, which remains indecipherable without access to the correct key. The security benefits of encryption are derived from the combination of strong algorithms and quality key management.</p> <p class="p">Encrypting all information may not be necessary for all data and would greatly increase processing time due to the large number of data supported across all applications. When you determine encryption is needed for data, these <span class="ph">Now Platform</span> options are available:</p> </div> <div class="section" id="encryption__section_ucy_yrq_dsb"><h2 class="title sectiontitle">Get started</h2> <div class="p"> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="encryption__table_vcy_yrq_dsb" class="table nav-card" frame="void" border="1" rules="all"><colgroup><col style="width:33.33333333333333%" /><col style="width:33.33333333333333%" /><col style="width:33.33333333333333%" /></colgroup><tbody class="tbody"><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p"><a class="xref" href="../../key-management-framework/concept/understanding-kmf.html" title="The Key Management Framework (KMF) API/UX lets you fully customize and manage how cryptographic operations are performed on your ServiceNow instance. The ServiceNow Key Management Framework provides a secure and comprehensive interface for instance-side cryptographic key management services."><span class="ph nav-card-title"> Key Management Framework (KMF)</span> <img class="image icon" id="encryption__image_wcy_yrq_dsb" height="70" src="../image/kmf-icon.png" alt="KMF icon." /></a></p> <p class="p">The <span class="ph">Key Management Framework</span> (KMF) API/UX lets you fully customize and manage how cryptographic operations are performed on your <span class="ph">ServiceNow</span> instance.</p> </td><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p"><a class="xref" href="c_EncryptionSupport.html" title="Field Encryption, formerly Encryption Support, permits and denies access to encrypted data based on user role. Field Encryption has been enhanced to include basic key management using encryption modules at no additional charge."><span class="ph nav-card-title">Field Encryption</span> <img class="image icon" id="encryption__image_xcy_yrq_dsb" height="70" src="../image/encryption-icon-cle.png" alt="Lock icon for CLE." /></a></p> A built-in application that permits encryption of string, date, date/time, or attachment fields using AES-128 or AES-256 in encryption modules.</td><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p"><a class="xref" href="../../now-platform-encryption/concept/now-platform-encryption.html" title="Field Encryption Enterprise utilizes the Key Management Framework (KMF) to enable you to customize and manage how fields and attachments are encrypted and decrypted on your instance. A subscription is required to utilize Field Encryption Enterprise."><span class="ph nav-card-title"> <span class="ph">Column Level Encryption Enterprise</span> (<span class="ph">CLE_Ent</span>)</span> <img class="image icon" id="encryption__image_ycy_yrq_dsb" height="70" src="../image/cle-ent-icon3.png" alt="Column Level Encryption Enterprise with Key Management icon." /></a></p> <p class="p">Offers a more extensive encryption solution to Field Encryption, such as customer-supplied keys, script access via APIs, additional cryptographic modules and module access policies, and more.</p> </td></tr><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p"><a class="xref" href="../../encryption-dare/concept/dare-overview.html" title="ServiceNow Cloud Encryption offers encrypted storage for the database using block encryption, along with enhanced key management. Cloud Encryption is available with the ServiceNow Platform Encryption subscription bundle."><span class="ph nav-card-title">Cloud Encryption</span> <img class="image icon" id="encryption__image_zcy_yrq_dsb" height="70" src="../image/cloud-key-icon.png" alt="Cloud Encryption with Key Management icon." /></a></p> <p class="p">Cloud Encryption enables you to use a <span class="ph">ServiceNow</span> generated key or supply a key that you create and manage.</p> </td><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p"><a class="xref" href="../../encryption-database/concept/db-full-disk-encryption.html" title="ServiceNow offers database encryption (DBE) and full-disk encryption methods for customers with statutory obligations for data protection, which may require at-rest protection for all data."><span class="ph nav-card-title">Database Encryption</span> <img class="image icon" id="encryption__image_ady_yrq_dsb" height="65" src="../image/dbe-icon.png" alt="Database encryption icon." /></a></p> <p class="p">Enables all data to be protected with symmetric AES-256 encryption, whether the database is online or offline, and provides standard key management, such as key rotation. All data flows are decrypted during runtime.</p> </td><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p"><a class="xref" href="../reference/encryption-sku.html" title="With Key Management, Field Encryption is upgraded at no additional charge to include highly configurable encryption modules. You can also optionally upgrade to the unlimited-use license. Subscribe to the new encryption entitlement bundle, Platform Encryption, which includes Field Encryption Enterprise and Cloud Encryption."><span class="ph nav-card-title">Platform Encryption entitlement bundle</span> <img class="image icon" id="encryption__image_bdy_yrq_dsb" height="70" src="../image/encryption-bundle-icon.png" alt="Shopping cart containing Platform Encryption subscription bundle." /></a></p> <p class="p">Upgrade to unlimited-use Field Encryption Enterprise, Cloud Encryption, and Database Encryption.</p> </td></tr><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p"><a class="xref" href="../../encryption-database/concept/full-disk-encryption.html" title="Full disk encryption (FDE) applies encryption to the entire storage system within the database server only, because this is the only customer data-storing component. FDE protects only against physical loss or theft of storage devices. When encrypted disk servers are powered on and providing data, the encryption provides no additional protection."><span class="ph nav-card-title">Full Disk Encryption (FDE)</span> <img class="image icon" id="encryption__image_cdy_yrq_dsb" height="70" src="../image/fde-icon.png" alt="Full disk encryption" /></a></p> <p class="p">Full disk encryption applies encryption to the entire storage system within the database server only. Because this is the only customer data-storing component.</p> </td><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p"><a class="xref" href="../../edge-encryption/reference/edge-encryption.html" title="ServiceNow Edge Encryption encrypts sensitive data on your company premises before sending it over the Internet to your ServiceNow instance (encrypted in flight), where it remains encrypted at rest."><span class="ph nav-card-title">Edge Encryption</span> <img class="image icon" id="encryption__image_ddy_yrq_dsb" height="70" src="../image/edge-icon.png" alt="Edge encryption" /></a></p> <p class="p">Encrypts sensitive data on your company premises before sending data over the internet to your <span class="ph">ServiceNow</span> instance. Data remains encrypted at rest on the instance.</p> </td><td class="entry nocellnorowborder" style="vertical-align:top;"> </td></tr></tbody></table> </div> </div> </div> <div class="section" id="encryption__section_phy_rtz_fvb"><h2 class="title sectiontitle">Activation information</h2> <p class="p">The <span class="ph">ServiceNow</span> Platform Encryption subscription bundle is a group commercial entitlement that includes <span class="ph">Key Management Framework</span>, <span class="ph">Field Encryption Enterprise</span>, <span class="ph">Cloud Encryption</span>, and Database Encryption.</p> <p class="p"><span class="ph">Field Encryption Enterprise</span> is the unlimited license of <span class="ph">Field Encryption</span>. The <span class="ph">Field Encryption</span> Enterprise plugin is available with the activation of the com.glide.now.platform.encryption plugin. For details, see <a class="xref" href="../reference/encryption-sku.html" title="With Key Management, Field Encryption is upgraded at no additional charge to include highly configurable encryption modules. You can also optionally upgrade to the unlimited-use license. Subscribe to the new encryption entitlement bundle, Platform Encryption, which includes Field Encryption Enterprise and Cloud Encryption.">Encryption and Key Management subscription bundle</a>.</p> <div class="note"><span class="notetitle">Note:</span> KMF doesn’t support domain separation, but can be used with on-premise instances.</div> </div> </div> </body></html></div>