Skip to main content

Help us improve the Digital Marketplace - send your feedback

UP3 SERVICES LTD

ServiceNow Licensing

ServiceNow offers a portfolio of robust cloud-based applications that automate and manage enterprise services. Our applications have the advantage of being built on a single service automation platform with one user interface, one code base, and one data model, delivering easy, automated upgrades.

Features

  • Digital workflows for IT, employees and customers
  • Ability to build your own applications on the platform
  • Native platform intelligence - predict, prioritise and proactively manage work
  • Access from anywhere - mobile applications
  • Collaboration - agent workspace/chat/visual taskboards
  • Easy to use GUI with drag-and-drop graphical workflow
  • Granular access control and certified multi-layered security
  • Integration hub - multiple out-of-the-box integrations
  • Real-time reporting, dashboards and analytics
  • Automation of business process across the enterprise

Benefits

  • One API
  • One web service interface
  • One data-store, one data-model
  • One job scheduler
  • One development approach
  • One architecture

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@up3.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 4 1 3 7 8 8 2 8 5 8 7 6 6 6

Contact

UP3 SERVICES LTD Matthew Shears
Telephone: 0203 432 1432
Email: hello@up3.co.uk

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
  • Advanced and predictive analytics
  • Location and geospatial data management and analytics
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No
System requirements
  • ServiceNow is a Saas-based solution
  • ServiceNow implement and maintains the required infrastructure

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Standard response varies by ticket type and priority, and may vary based on customer's requirements at
weekends. Typical target response for a P3 Incident would be two hours.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
EN 301 549
Web chat accessibility testing
ServiceNow has a User Experience (UX) team that has based much of their analysis on customer feedback and best practices. To help ensure usability, ServiceNow has asked customers to perform external audits, and ServiceNow staff have personally gone onsite to view some customers' operations. The ServiceNow UX team conducted eight separate site visits in the past year to watch how customers use the ServiceNow system and incorporated this information into work requests and SCRUM stories. One recent trip included a visit to an accessibility lab at a public educational institution. Our development team worked specifically with a blind user to help accessibility design.
Onsite support
Yes
Support levels
Varying degrees based on impact package. See pricing and packging presentation on the link below.
Product details - https://partnersuccess.servicenow.com/products/impact.html
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
UP3 is able to provide access to ServiceNow accredited training courses.

Our implementation services also include training to ensure that customers receive training on how to use their specific instance of ServiceNow.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
The process for the return of data follows: 1) ServiceNow exports the entire database in a MySQL format. 2) ServiceNow provides the customer a set of instructions on how to import the data on the customer's side. 3) The customer can FTP the files from ServiceNow to their site. Customers are permitted to store data hosted within ServiceNow for the duration of their service subscription with ServiceNow. Under this model, the customer can purge or retain data according to their own retention policy. ServiceNow retains customer data for up to 45 days from the end of a contract. Within the 45 days, the customer can request their data to be sent to them in a standard database export format. After 45 days, all data from the customer instances is removed from ServiceNow servers
End-of-contract process
On termination of an Order Form or expiration of a Subscription Term, Customer will stop accessing and using the Subscription Service and all related rights granted to Customer in this Agreement terminate. At any time during the applicable Subscription Term, Customer may export Customer Data using the functionality of the Subscription Service. After termination of an Order Form or expiration of a Subscription Term, ServiceNow may delete all Customer Data unless legally prohibited. ServiceNow will, within 30 days after the effective date of Customer’s termination for ServiceNow’s uncured breach, refund to Customer any prepaid fees received by ServiceNow covering the remainder of the Subscription Term for the affected Subscription Service. Within 30 days after the effective date of ServiceNow’s termination for Customer’s breach, Customer will pay all remaining amounts, if any, payable under this Agreement for the Subscription Term applicable to the terminated Order Form, regardless of the due dates in the Order Form.
Documentation accessibility standard
EN 301 549

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The ServiceNow mobile experiance is similar to the desktop experiances allowing users to perform the same functions as they would from the desktop. The mobile experiance does not however provide a mechanism to perform administration of the ServiceNow platform.
Service interface
Yes
User support accessibility
EN 301 549
Description of service interface
Customers' access is provided via the web portal, this includes the management interface for the instance. The ServiceNow platform is based on service-oriented architecture (SOA), in which all data objects can use web services to access bi-directional data-level integration. The interface is also direct and dynamic because all modifications to existing objects and all new objects are automatically published as a Direct Web Service. A more indirect web service creation and usage can be achieved through Mapped Web Service where a transform map is used to gather incoming web service data into the final targeted tables.
Accessibility standards
EN 301 549
Accessibility testing
ServiceNow has a User Experience (UX) team that has based much of their analysis on customer feedback and best practices. To help ensure usability, ServiceNow has asked customers to perform external audits, and ServiceNow staff have personally gone onsite to view some customers' operations. The ServiceNow UX team conducted eight separate site visits in the past year to watch how customers use the ServiceNow system and incorporated this information into work requests and SCRUM stories. One recent trip included a visit to an accessibility lab at a public educational institution. Our development team worked specifically with a blind user to help accessibility design.
API
Yes
What users can and can't do using the API
Inbound web services, such as the REST API, allow you to interact with ServiceNow instance data using web service requests. ServiceNow outbound REST functionality allows you to retrieve, create, update, or delete data on a web services server that supports the REST architecture. ServiceNow integrates with many third-party applications and data sources. A variety of techniques can be used, most notably Web Services, JDBC, LDAP, Excel, CSV, and Email, as well as any industry-standard technologies that use REST, SOAP or WSDL. With the correct permissions users can use these API's to bring data in and out of ServiceNow. Users who create these tend to be power users or Admin users.
API documentation
Yes
API documentation formats
  • HTML
  • ODF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users with the appropriate roles can configure various aspects of lists or forms. Configuration changes apply to all users.
With list configuration, you can add, remove, and reorder list columns. You can configure calculations to appear under columns. You can also hide controls and define access conditions by role for existing list controls. Users can also personalise lists which will not effect what other see.
Users can create their own reports and dashboards also with the correct permissions.
Forms can be configured as well, this includes the ability to configure a form to show or hide fields from a view. You can even create new fields on the table that is associated with the form, and put business rules, UI policies around them as well as define the data dictionary for the fields. With a runtime license you also have the ability to create new business applications in ServiceNow

Scaling

Independence of resources
ServiceNow’s data centers and cloud-based infrastructure have been designed to be highly available. All servers and network devices have redundant components and multiple network paths to avoid single points

Analytics

Service usage metrics
Yes
Metrics types
Users can configure SLA reports to consolidate data by any field or combination of fields. ServiceNow offers predefined reports that pertain to applications and features like incident management and service catalog requests. Reports can be scheduled for email delivery at specific times of the day, week, or month, internally and externally. These powerful features, combined with nearly 200 customizable, commonly used reports that are delivered with ServiceNow, provide the most robust native reporting tool available in any service management application on the market today. If out-of-box reports do not meet your needs, new reports can be created at any time.
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
ServiceNow

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
Never
Protecting data at rest
Other
Other data at rest protection approach
ServiceNow can provide two types of encryption for data at rest upon customer request.
-Column encryption of customer added fields and attachments: Provides data encryption using AES128/256 or 3DES symmetric key encryption. Customer provides the keys for this encryption. Data stored in these fields cannot be searched or reported on.

-Full disk encryption: Provided via self-encrypting hard drives with AES256 bit encryption. This encryption capability is only available by purchasing dedicated ServiceNow hardware at additional cost. This delivers “at-rest” protection only and is focused solely on preventing data exposure through the loss or theft of hard disks holding customer data.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Export individual records via PDF or XML directly from a form.
-Export multiple records via CSV, Excel, PDF or XML directly from a list.
-Automatically Export multiple records from a table on a set schedule. -Create a scheduled job to regularly Export data as a report.
-Export multiple records from a table using CSV, Excel, PDF or XML. specifying the table form or list you want to Export in the URL.
-Web services/SOAP: Export multiple records from a table when an external client makes a Web services request
Data export formats
  • CSV
  • Other
Other data export formats
  • .xlxs
  • JSON
  • XML
  • PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
ServiceNow provides 99.8% availability (calculated monthly) for production instances. This design includes redundancy and fault tolerance of the entire ServiceNow application and platform stack, including electrical, cooling, network, security, and server infrastructure. Over the last 3 years (2014-2016), we have averaged 99.995% availability and have not fallen below 99.8% (contract SLA) in any quarter. In 2016 we averaged 99.996% and did not fall below 99.8% in any quarter.
Approach to resilience
ServiceNow’s data centers are arranged in pairs. All customer production data is stored in both data centers and kept in sync using asynchronous database replication. Both data centers are active at all times, each with the ability to support the combined production load of the pair. A production instance from one customer may be operating out of one data center in the pair and a production instance of another customer from the other.
More details available on request
ServiceNow maintains continuous, asynchronous replication from the database in the current primary data center (read-write) to the secondary data center (read-only). To transfer a customer instance from a primary data center to a secondary, ServiceNow designates the secondary to be the primary and the primary to be the secondary if it still exists.
ServiceNow’s data centers and cloud-based infrastructure have been designed to be highly available. All servers and network devices have redundant components and multiple diverse network paths to avoid single points of failure.
Outage reporting
ServiceNow have a customer portal where all requests, changes and incidents can be logged. Customers also now have complete transparency into the real availability of their production and non-production instances. Users can view the impact severity of issues and even drill into incident records to view details for problems. It is this level of transparency that further sets ServiceNow apart.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
By User Access control lists and Groups and user roles
All ServiceNow staff are placed into Groups and have a user role, these groups and roles have access rights attached to them. Any personal that try to access an interface will have their group membership and user role checked and if they do not belong to the user role and group that is required to access that particular interface then access will be denied
Access restriction testing frequency
At least every 6 months
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO27001
• SSAE 18 SOC 1 Type 1
• SSAE 18 SOC 1 Type 2
• SSAE 18 SOC 2 Type 1
• SSAE 18 SOC 2 Type 2
• BSI Cloud Computing Compliance Controls Catalogue (C5) Standard
• APEC Privacy Recognition for Processors (PRP)
• FedRAMP JAB High P-ATO (for US government entities)
• DoD Impact Level 4 Authorisation (for US DoD/IC entities)
• Multi-Tier Cloud Security Standard for Singapore (MTCS) Level 3
• ASD IRAP assessed for OFFICIAL and PROTECTED cloud services
• Government of Canada GC Cloud Provider
• SOC 2 + HITRUST Report
• Cyber Essentials Plus Certification
• More details available on request
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
ServiceNow has a formally documented change management process that uses an internal ServiceNow instance to track change requests and approvals. All changes to production environments must go through the change management process. Change requests must include the change procedure, risk, and back out plans. Change requests are reviewed and approved by the Change Advisory Board (CAB). All assets are tagged and tracked though the ServiceNow CMDB.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
ServiceNow's Infrastructure stack is customized at each layer to specifically support the only application residing in the ServiceNow cloud. With the small footprint and limited ports/services enabled, many system and patches published do not apply to the private cloud's systems. ServiceNow follows an approach to determine if the patch is to be deployed. When confirmed that a patch needs be deployed, this then follows the Change process the testing process as well as the timeline for deployment. ServiceNow leverages the Advanced-High-Availability architecture to transfer customers' production instances to the other datacenter. Remediation timeframes are subject to ServiceNow's Vulnerability Management SOP.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
ServiceNow has an implementation of Sourefire for IDS and Splunk for SIEM. The IDS system monitors inbound traffic in the DMZ. Splunk does log collection on network devices, IDS and servers used to support customer information. These systems are monitored with both proactive alerting and regular log files reviews. Events are responded to within 24 hours.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
ServiceNow's documented Security Incident Response policy, process and workflow aligns with NIST 800-61. ServiceNow Incident Response process includes event discovery, triage, escalation, notification (including customer notification) remediation, and post-mortem review.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Saturday 1 August 2026
What the ISO/IEC 27001 doesn’t cover
Nothing
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Saturday 1 August 2026
What the ISO 9001 doesn’t cover
Nothing
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
9002854e-438c-4925-8b47-3cc5df99852b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
7a4c588f-8626-4e4b-b7c3-69bbfbb3f179
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@up3.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.