Security
Last updated: 29 September 2026
HolySN runs inside your browser, on the page you already have open, with the session you are already signed in with. This page is what a security reviewer asks for before an extension is allowed near an instance: what it can reach, what it stores, what leaves the machine, and what is still open.
It acts as you
Every read and write goes through your own ServiceNow session. The extension has no account on your instance, no service user and no elevated path: it can do what your roles already allow and nothing beyond them. A background script still needs the role ServiceNow requires for it, and an ACL that stops you stops the extension.
Where the privileged code lives
The parts that can fetch, read cookies or open tabs live in the extension's
service worker, which the ServiceNow page cannot call directly. The widget you
see runs in the page and asks the worker to act, so a script on the page cannot
borrow a privileged handle: nothing is published on window for it to take.
One allowlist, checked twice
The hosts the extension may reach are declared once, in its configuration, and
the manifest is generated from that list. The worker rebuilds the same list at
runtime and re-checks every request against it, so a page cannot talk it into
fetching somewhere else. Suffix-confusion hosts, scheme downgrades and
javascript: URLs are covered by tests that run on every build.
What it asks the browser for
| Permission | Why |
|---|---|
| Your ServiceNow instances | The panel, the palette and every other tool run on those pages and nowhere else |
cookies | To use the ServiceNow session you are already signed in with |
scripting, activeTab | To attach the panel to a ServiceNow page |
storage | Your settings, and the vault as ciphertext |
contextMenus | The right-click entries on a ServiceNow page |
offscreen | The microphone for dictation, only while you are dictating |
identity | Signing in with Google, Microsoft or GitHub |
alarms | Noticing when your HolySN sign-in has expired |
There is no tabs or history permission: the extension cannot see which sites you visit.
Where the code comes from
The editor, the formatter, the type definitions and the speech models ship inside the extension and load from disk. They are downloaded once when the package is built, not when you use it, which is also why the package is large: the alternative is code that can change after review.
Two things are still fetched while you work, both from public package CDNs and both optional. The extra editor colour themes are pulled the first time you pick one, and if a bundled file is ever missing the editor falls back to fetching that library rather than losing the feature. Neither call carries account data or anything from your instance; the CDN sees the file name and your IP address. The privacy policy lists them by name.
The credential vault
Credentials are encrypted in the browser, with AES-GCM under a key derived from your passphrase with PBKDF2 at 600,000 iterations. Only the ciphertext and its labels ever sync. The passphrase is never stored and never sent, so a copy of the server data is a copy of unreadable blobs. Vault operations are not relayed to the page, so a script running on the ServiceNow page cannot ask for a secret or aim one at an instance of its choice.
The assistant
Off until you use it, and bounded by four permissions that all start off: you grant each one, and each takes effect immediately. A question leaves your browser with names and identifiers stripped, reaches HolySN's server, and from there Vercel's AI Gateway, which passes it to the model that answers. Vercel is a US company serving from an EU edge, and the transfer rests on the European Commission's Standard Contractual Clauses. The privacy policy names every recipient.
What leaves your browser
| What | When | Form |
|---|---|---|
| Your question to the assistant, the conversation so far, and the record fields it needed to answer | Only when you ask one | Text, with names and identifiers stripped |
| A file you attach to a question | Only when you attach one | Text is stripped like the message. An image or a PDF cannot be, and is sent as it is |
| Dictated audio | Only while you dictate | Audio, for transcription |
| Stored credentials | Only if you use the vault and turn on sync | Ciphertext, with labels |
| Your scripts, snippets, themes, custom commands and recorded tests | Only while you are signed in on a plan that syncs them | As you wrote them |
| Your conversations with the assistant | Only while you are signed in | As you wrote them |
| How often each command is used | Only while you are signed in | A count per command, no arguments |
| The records you open, the update sets you browse, your ServiceNow session | Never | — |
An attachment is the one place where personal data leaves your machine unfiltered and by design: a screenshot of an incident carries every name the scrubber strips out of the message beside it. The interface says so next to the button, and the privacy policy says it again.
Browser and platform
Chrome and Edge, version 128 or newer. The floor comes from script injection into the page's own world, which the extension needs on every instance page.
Reporting something
If you find a flaw, tell us before you tell anyone else and give us time to fix it. Write to support@holysn.com.
