The ServiceNow agent, on your terms
Run NovusAI's ServiceNow agent inside your own network, on your own model — with your data never leaving your walls or training anyone's AI, and the full capability of its skills and tools.
Your network · your model · no data egress · no training
Built for teams that can't send data out
The same agent your developers already love — deployed where your security policy requires.
Your own LLM model
Run the agent on your Azure OpenAI deployment, a model in Azure AI Foundry, or your own self-hosted vLLM endpoint. Inference bills to your cloud agreement — we never resell or mark up tokens.
Your data never leaves your network
Deploy inside your own VPC or on-prem. Your ServiceNow data, prompts, and outputs stay within your network boundary — and nothing you send is ever used to train a model. No egress, no training, no exceptions.
The full agent — every skill and tool
Not a stripped-down tier. The enterprise agent keeps the complete toolset (query, build, verify, server-side scripts), the curated ServiceNow best-practice skills, long-term memory, and — at your discretion — live web knowledge.
How it deploys
Everything that touches your data runs inside your tenant. We ship software; you run it.
Want the full architecture document — component inventory, data-flow diagrams, network requirements and the hardening guide? Your reviewers can have it.
Request the architecture documentBring your own model
The agent connects to an inference endpoint you already own and operate. Three supported shapes:
Azure OpenAI
Your existing deployment, in your subscription and region. Your quota, your content filters, your private endpoint.
Azure AI Foundry
Any model you have provisioned in Foundry, including open-weight models on managed compute.
Self-hosted vLLM
An OpenAI-compatible endpoint you run yourself — on your GPUs, in your network, on air-gapped infrastructure if required.
Inference runs on your cloud agreement. We never mark up tokens.
You pay Microsoft — or nobody, if you self-host — at the rate you have already negotiated, against commitments you may already have spent. Our licence is a fixed, predictable line item that does not move with usage, so scaling the agent across more teams does not reprice your contract with us.
Verified Skills — governed, not guessed
Everything your agent knows is a skill under lifecycle control. Every skill is tested, signed, and activated only when your admin approves it — with one-step rollback. Your team decides exactly what the agent can do, and can prove it.
- 01
Tested
Every skill is tested before it ships
Each ServiceNow skill is validated against real instances before release — no untested guidance ever reaches your agent. What the agent knows is curated, versioned expertise, not a model's best guess.
- 02
Signed
Signed, so provenance is verifiable
Skills ship inside cryptographically signed releases, pulled outbound from our registry. Your deployment verifies the signature before anything installs — you can prove what your agent runs came from us, unaltered.
- 03
Approved
Activated only when your admin approves
A new or updated skill does nothing until an administrator in your tenant approves it. Nothing changes what your agent knows or can do without an explicit sign-off — updates are outbound-only, never auto-applied.
- 04
Reversible
Roll back instantly
Every activation is versioned and reversible. Roll a skill back to a prior version in one step, and the agent's changes to your instance stay behind approval gates and your own ServiceNow change management.
Security your team can sign off on
Dedicated, isolated, auditable — and always with your approval on every change.
Runs in your network
Self-hosted or in your VPC — the agent and its execution run where your security team can see them.
No training on your data
Your prompts, instance data, and outputs are never used to train any model. Full stop.
Dedicated, isolated
A dedicated model and workspace for your org — no shared tenancy with other customers.
SSO / SAML & RBAC
Connect your identity provider; control who can use the agent and who can enable writes.
Full audit trail
Every run is traced — the tools it called, what it changed, and the sources it used — for compliance and review.
Admin controls & caps
Per-user run and cost limits, read-only by default, and approval gates on every change to the instance.
Questions your procurement team will ask
Answered here so the first call can be about whether this solves your problem.
Do we need a BAA with you?
Under the self-hosted deployment, no — because the architecture does not put us in the path of your data. The platform runs entirely inside your tenant. We have no inbound access, no standing credentials in your environment, and receive no telemetry. Patient data in your incidents never reaches us, so we are a software supplier rather than a business associate handling PHI on your behalf.
Two caveats we would rather state than have you discover. If you engage us for support in a way that would expose PHI — sharing raw logs or a database extract, for example — that changes the position, so our support process is built to work from a licence ID, an image digest and a run trace instead. And our hosted SaaS product is a different arrangement entirely; this answer covers self-hosted only.
We will sign a BAA where your counsel requires one. Many hospital legal teams prefer one on file regardless of the architecture, and we would rather sign than argue.
Do you have SOC 2?
Not today, and we would rather tell you that in the first call than in the third.
What exists now is specific and verifiable: images are signed with Sigstore and you verify the signature before you run them, each release ships an SBOM so a new CVE is a query rather than a rebuild, the deployment makes no outbound calls except to your own ServiceNow instance and your own model gateway, and every agent action is written to an audit trace inside your database.
If a certification is a hard gate for your procurement, tell us during evaluation. It is materially easier for us to commit to a timeline against a named customer than against a hypothetical one, and we will put that commitment in writing rather than in a slide.
What happens if NovusAI disappears?
Your deployment keeps running. The image is in your registry and the platform is in your cluster; nothing calls us to start, to stay running, or to authenticate. There is no licence server to go dark.
Licence expiry is designed for exactly this. An expired licence does not stop the software — existing agents keep serving, and only the creation of new agents is blocked. A hospital service desk losing its agent overnight because a company folded is not an acceptable failure mode, so it is not one we built.
Source escrow is available on enterprise agreements, with release conditions covering insolvency and sustained failure to support. Ask for it during contracting; it is far easier to add then than later.
What are your support SLAs?
Response targets by severity are below, and the figures that bind are the ones in your agreement — this page describes them, it does not replace them.
One practical consequence of the architecture is worth knowing up front: because we receive no telemetry, we cannot see your deployment. Raising an issue means sending us the licence ID, the image digest and the relevant part of the run trace from your admin portal — all of which the portal shows you. It is a little more work at the point of raising a ticket, and it is the direct cost of us not having a window into your network.
| Severity | Definition | Response target | Coverage |
|---|---|---|---|
| Sev 1 | Production down; no workaround. | 1 business hour | 24×7 |
| Sev 2 | Major function impaired; workaround exists. | 4 business hours | Business hours |
| Sev 3 | Minor issue or question. | 1 business day | Business hours |
Something not covered here? Ask us directly — we would rather answer it now than in a security review.
How buying works
Three steps, and the middle one is the point: you find out whether this works on your instance before there is an enterprise commitment to argue about.
- 01
Demo
A working session on a real ServiceNow instance — you bring the questions and the use cases you actually care about. No commitment, no procurement involvement.
- Start here02
Proving Ground — 90-day pilot
A scoped, paid pilot on your own instance, run by the read-only Business Agent. Ninety days is long enough to survive a real quarter — a release, an audit, a month-end — rather than a good week.
- A fixed fee, agreed up front — no hourly billing and no scope creep.
- Runs the read-only Business Agent: it answers and analyses, and cannot change a thing on your instance.
- Success criteria are written down before it starts, so the outcome is a verdict rather than an opinion.
- The fee is credited against your first year if you convert.
- 03
Enterprise subscription
Deployed inside your network, on your own model, with the agent tier each team needs — from read-only through to the full Developer Agent. Annual, with the pilot fee credited.
Most teams start with the Proving Ground pilot — ask for it by name in the form below.
Talk to our team
Tell us about your environment and we'll design an enterprise deployment that fits.