Certification & Security Review

Pass Security Review
The First Time.

Certification and security review preparation for ServiceNow applications.

Most first submissions come back. Not because the application is bad, but because it was written to work rather than written to pass review — and those are different standards. Ramisun reviews your application against the criteria reviewers actually apply, remediates what they will find, and prepares the documentation in the form they expect, so review becomes a confirmation rather than a rejection cycle.

Pre-Submission Review Vulnerability Remediation Documentation Prepared Submission Managed
15-Minute Quick Call
V
Vinnay Nigam, Founder & CEO
Ramisun

Got 15 minutes?
Let's see if we're a fit.

No deck. No pitch. Straight talk.
  • Tell us what you're trying to solve
  • We'll tell you honestly if ServiceNow can help
  • Walk away with clarity, zero commitment
Book a Free 15-Min Call
Free · 15 minutes · No sales pressure
Pre-flight
Review Before Submission
Findings fixed before reviewers see them
100%
Code Reviewed to Standard
Not sampled
4–8 wks
Typical Preparation
Depending on starting state
Managed
Submission & Responses
Your team stays on the product
Direct Answer

What Is ServiceNow App Certification & Security Review??

Certification and security review is ServiceNow's assessment process for applications being published to the Store or deployed into sensitive customer environments. Reviewers examine access control, injection protection, data handling, third-party dependencies, upgrade safety, and structural conformance against published standards. Ramisun runs the same assessment ahead of submission, remediates what would be found, and prepares the documentation set reviewers expect — converting an unpredictable rejection cycle into a planned piece of work.

"
"An application that works and an application that passes review are different standards. Most teams only discover the second one after their first rejection."
Vinnay Nigam, Founder & CEO, Ramisun
WHAT RAMISUN DELIVERS
01

Pre-Submission Code Review

The full application assessed against real review criteria before submitting.

02

Vulnerability Remediation

Access control, injection, and data exposure issues fixed, not just listed.

03

Documentation Preparation

The artefacts reviewers expect, produced in the form they expect them.

04

Submission & Response Management

Findings triaged and answered so your engineers stay on product.

Why It Matters

Why First Submissions Get Rejected

The findings are predictable, which is exactly why they are preventable.

Common
Access control gaps as a review finding
Review pattern
Common
Hardcoded credentials found in submitted code
Review pattern
Weeks
Added by each rejection and resubmission cycle
Certification benchmark
229%
3-year ROI on ServiceNow ITSM
Forrester TEI Study

Figures shown are industry benchmarks and illustrative placeholders — replace with sourced, dated statistics before publication.

How It Works

How We Prepare an App for Review

Find what reviewers would find, before they do.

1

Scan

Automated analysis and Instance Scan across the application

2

Review

Manual code review against real security review criteria

3

Triage

Findings ranked by likelihood of rejection and effort to fix

4

Remediate

Issues fixed and verified, not merely documented

5

Document

Submission artefacts prepared in the expected form

6

Submit

Package submitted and review responses managed through to outcome

The Ramisun Difference

Submit and Hope vs Prepared Submission

Same reviewer, very different experience.

Area❌ Typical Approach✅ Ramisun Approach
Code ReviewNone, or a quick internal skimFull manual review against real criteria
VulnerabilitiesDiscovered by the reviewerFound and fixed before submission
Access ControlAssumed adequateACL model verified record by record
CredentialsSometimes still in the codeVerified absent from code, update sets, and logs
DependenciesThird-party libraries unexaminedReviewed for licence and vulnerability exposure
DocumentationAssembled hurriedly at submissionPrepared to the expected structure in advance
OutcomeRejection cycles with unpredictable timingReview as confirmation, remaining findings minor
Capabilities

What Ramisun Delivers for Certification

Each capability maps to real delivery work — with outcomes and the Ramisun approach.

🔍 Pre-Submission Code Review

We read the whole application against the criteria reviewers apply, not a sample. Automated scanning catches the obvious; manual review catches the access-control and data-handling issues that scanners routinely miss.

  • Full manual review, not sampled
  • Instance Scan and automated analysis run alongside
  • Findings mapped to the specific review criteria they would breach
  • Effort estimate attached to every finding before work starts
Instance ScanSecurity ReviewCode ReviewScoped Apps
100%
Application reviewed
Mapped
To review criteria
Estimated
Remediation effort
Manual
Plus automated

🔐 Access Control & ACL Verification

Access control is the most common source of review findings and the least reliably caught by tooling. We verify the ACL model record by record against least-privilege expectations rather than trusting that it was designed correctly.

  • ACL coverage verified for every table in the application
  • Least-privilege enforced rather than assumed
  • Role model checked for privilege escalation paths
  • Cross-scope access reviewed and justified explicitly
ACLsRolesCross-Scope PrivilegesSecurity Review
Every
Table verified
Checked
Escalation paths
Justified
Cross-scope access
Least
Privilege enforced

🛠 Vulnerability Remediation

A findings report you have to act on yourself is half a service. We fix what we find, verify the fix, and re-review the affected area so remediation does not introduce its own problems.

  • Injection and input validation issues fixed at the boundary
  • Hardcoded credentials removed and moved to the credential store
  • Data exposure paths closed and verified
  • Fixes re-reviewed rather than assumed correct
Instance ScanCredential StoreACLsScoped Apps
Fixed
Not just reported
Verified
After remediation
0
Hardcoded credentials
Re-reviewed
Affected areas

📦 Third-Party Dependency Review

Bundled libraries carry both licence and vulnerability exposure, and both are reviewable. We check what your application ships with before a reviewer does.

  • Inventory of all bundled third-party code and libraries
  • Licence compatibility checked against distribution requirements
  • Known vulnerability exposure assessed per dependency
  • Unnecessary dependencies removed rather than justified
Scoped AppsSecurity ReviewDependency AnalysisDocumentation
Full
Dependency inventory
Checked
Licence compatibility
Assessed
Vulnerability exposure
Reduced
Where possible

📜 Submission Documentation

Reviewers work from documentation, and a package that is hard to review takes longer and attracts more questions. We prepare the artefacts in the structure reviewers expect.

  • Architecture and data-flow documentation prepared
  • Security model and access control documented explicitly
  • Data handling, storage, and retention described clearly
  • Installation, configuration, and upgrade notes written
DocumentationStore CertificationKnowledgePartner Portal
Expected
Structure and format
Explicit
Security model
Clear
Data handling
Complete
Install and upgrade notes

🏆 Submission & Response Management

Once submitted, the review generates questions and sometimes findings. We handle that exchange so your engineering team is not repeatedly pulled off the product to answer them.

  • Submission package assembled and lodged correctly
  • Reviewer questions answered promptly and accurately
  • Remaining findings triaged, fixed, and resubmitted
  • Status tracked transparently through to outcome
Store CertificationPartner PortalSecurity ReviewDocumentation
Managed
End to end
Prompt
Reviewer responses
Protected
Your engineering time
Transparent
Status tracking
Delivery & Governance

How Ramisun Approaches Certification

Predictable preparation instead of an unpredictable rejection cycle.

Review Before They Do

We apply the same criteria a reviewer will, ahead of submission. Findings are far cheaper to fix on your own schedule than under the pressure of a rejection.

Fix, Do Not Just Report

A findings list you have to act on alone is half the job. We remediate, verify the fix, and re-review the affected area so remediation does not introduce new issues.

Manual Review, Not Just Scanning

Automated tools miss most access-control and data-handling problems, which are exactly the findings that cause rejections. Full manual review is the core of the service.

Your Engineers Stay on Product

We manage the submission and the reviewer exchange. Certification should not consume the capacity you need for your roadmap.

Honest About Timelines

ServiceNow's review runs on their schedule. We scope our preparation work precisely and are explicit that the review period itself is outside any partner's control.

Criteria Verified Currently

Review requirements change between releases. We confirm current criteria with ServiceNow at the start of each engagement rather than working from last year's checklist.

Explore Integrations & Marketplace Publishing

Related Integration & Marketplace Services

Latest Insights

From the Ramisun Blog

ISV

5 Things That Break When an AI Product Goes to the ServiceNow Store

Jun 15, 2026 · 8 min
Free Consultation

Facing a ServiceNow Security Review?

Let us find what the reviewers would find, first. You will get a ranked findings list with effort estimates before committing to remediation.

  • Free certification readiness conversation
  • Full manual code review, not automated sampling
  • Findings fixed and verified, not just reported
  • Submission and reviewer exchange managed for you
  • Response within 1 business day
"
"An application that works and an application that passes review are different standards."
Vinnay Nigam, Founder & CEO, Ramisun
100%
Code reviewed
4–8 wks
Typical preparation
Managed
Submission process
Confidential. We never sell data or send spam.

Get Your Free Integration Strategy

Takes 60 seconds. No commitment required.
No commitment · Response within 1 business day · NDA on request
Frequently Asked Questions

App Certification & Security Review Support — Questions Answered

Broadly: access control and ACL coverage, injection and input validation, credential handling, data storage and exposure, third-party dependencies, upgrade safety, and structural conformance to scoped application requirements. The precise criteria evolve between releases, so we verify the current standard with ServiceNow at the start of every engagement.

Because applications are typically written to work rather than written to pass review, and those are different standards. The most common findings are access control gaps, hardcoded credentials, and insufficient input validation — all preventable, and all much cheaper to fix before submission than under the time pressure of a rejection.

Yes, and it is a common starting point. We work from the findings you received, address each one properly rather than minimally, and then review the rest of the application — because a rejection on three findings often means there are others the reviewer did not reach.

We fix them. A findings report you then have to act on yourself is half a service. We remediate, verify each fix, and re-review the affected area, because remediation done hastily is a common source of new problems.

Typically 4–8 weeks depending on application size and starting state, covering review, remediation, and documentation. ServiceNow's own review period follows and runs on their schedule, which we scope separately and do not promise dates for.

It is required for Store publishing, but the same standards are worth meeting for any application deployed into a regulated or security-conscious customer environment. Many enterprise customers apply comparable scrutiny to applications installed directly on their instance.

Enterprise-Grade Security & Compliance

Trusted by enterprise teams and software vendors worldwide
Security and compliance are embedded at the platform architecture level, not added post-deployment.
SOC 2Enterprise Security
GDPRData Privacy
ISO 27001Information Security
Build PartnerServiceNow Store