Trust Center
Security & trust, built for platform teams.
ISO 27001 certified. Enterprise-grade security for ServiceNow platform teams — your data, your instance, your control.
✓ ISO 27001 CertifiedSOC 2 Type II — In progress✓ AES-256 at rest✓ OAuth 2.0 · no stored credentials
How we protect you
Security you can hand to your auditor.
Architecture
Phyllis connects only through the official REST API and OAuth 2.0 — never your database, no VPN, and your credentials are never stored. Every call respects your existing ACLs, business rules and data policies.
Data handling
Phyllis reads configuration and metadata to do its work — never your business data, PII or attachments. Session context is encrypted at rest and you can delete it at any time.
Encryption
TLS 1.2 or higher in transit, AES-256 at rest. Backups are encrypted and stored in geographically isolated locations.
Certifications & compliance
ISO/IEC 27001 certified, with SOC 2 Type II in progress against the AICPA Trust Services Criteria. Phyllis is a ServiceNow Technology Partner, built to its security-review requirements.
Infrastructure
Isolated cloud with network segmentation, automated patching, a web application firewall and continuous monitoring. Production access is role-based and requires MFA.
Incident response
A documented incident-response plan with defined severities and 24-hour customer notification. Report a vulnerability to security@phyllis.app — acknowledged within 48 hours.



























