Hannah Lowe

Fenmoor Specialty Underwriting / BB-Demo – Security Review

Callcompleted

Fenmoor Specialty Underwriting: documents logo Fenmoor Specialty Underwriting: documents · 2025-11-07 15:45

Hannah Lowe took Fenmoor's IT Security Lead Nadia Osei through encryption, keys and data location. Six written answers are owed by BB-Demo. Nadia will not sign off or set a date until her capacity providers see the full pack.

What was said

What this says

Current to 10 Oct 26

Hannah Lowe took Fenmoor's IT Security Lead Nadia Osei through encryption, keys and data location. Six written answers are owed by BB-Demo. Nadia will not sign off or set a date until her capacity providers see the full pack.

What happened: Hannah Lowe ran a security review session with Nadia Osei on 7 Nov 2025. They covered where data sits, encryption at rest and in transit, key custody and deletion.

Customer view: Nadia wants evidence she can attach, not statements on a call. She welcomed answers that were held back until checked.

Commercial: Residency matters to Fenmoor more than boilerplate, so the two remaining sessions on access control and residency decide the pack. Hannah also advised deciding early on a customer-managed key.

Watch: Six items are owed in writing, and Nadia will check the Snowflake edition and the retention setting. No sign-off date exists.

AI · claude-sonnet-5-5 · 10 Oct 2026

Themes

Current to 9 Oct 26
Theme
Encryption and key custody
Importance
neutral
Sentiment
positive
Voice
decision-maker

Who was there

BB-Demo

Them

Follow-up

Next steps

Current to 9 Oct 26
  • Hannah Lowe sends the written answers, marking confirmed and unconfirmed items, to Nadia and copies Daniel.
  • Nadia Osei checks the Snowflake edition and the retention setting and says which way Fenmoor leans on keys.
  • Hannah aligns the diagram legend with the questionnaire and prepares access control and residency for the next session.

Risks

Current to 9 Oct 26
  • Several answers are still unconfirmed, including key-withdrawal behaviour and connector credential storage, so a slip in the written replies could stall the review.
  • Whether a customer-managed key is possible depends on a Snowflake edition that neither side has confirmed.
  • Residency matters more to Fenmoor than usual and is still open for the next session.

Opportunities

Current to 9 Oct 26
  • A clear, evidenced pack gives Fenmoor's capacity providers what they need and moves the review towards sign-off.
  • Early advice on the customer-managed key option positions BB-Demo as the careful supplier in a regulated buyer's review.

Transcript

  1. Hannah Lowe
    Hannah Lowe None
    Hello Nadia, can you hear me alright? I've got you on my side but the audio's a touch tinny.
  2. Nadia Osei
    Nadia Osei None
    I can hear you, yes. Good afternoon, Hannah. Is it better if I switch my camera off?
  3. Hannah Lowe
    Hannah Lowe None
    No, it's cleared up now, you're fine. Afternoon. Right, before we start, what do you most need to come away with today? I've got the encryption and key management material ready, but I'd rather aim it at what you actually need.
  4. Nadia Osei
    Nadia Osei None
    Thank you, that's helpful. If you don't mind, I'll go through the open items from last time first, for the audit trail. First, you owed me the architecture diagram showing where data sits at rest. Second, the written answer on who at BB-Demo can reach customer data. Third, whether keys can be customer-managed. And fourth, I'd like to understand what is encrypted, where, and who holds the keys.
  5. Hannah Lowe
    Hannah Lowe None
    Good, that's a clean list, and it maps almost exactly onto today. The diagram went to you on Wednesday by email, so you should have it. The access question is session four, along with data residency, so I'll park that one. Today is the third and fourth of your list, really.
  6. Nadia Osei
    Nadia Osei None
    I did receive the diagram, thank you. I have it open. I'll come back to it, because I have a couple of questions on the arrows. Can we start with the foundation, though? Where does the data physically live?
  7. Hannah Lowe
    Hannah Lowe None
    So the short answer is, in your own Snowflake account. The longer answer is that the brain is built and run inside your account, not ours. BB-Demo doesn't keep a separate copy of your submissions, bordereaux or claims data in some environment of our own. The tables, the indexes, the embeddings, all of it sits in Snowflake under your account, under your controls.
  8. Nadia Osei
    Nadia Osei None
    Mm. And the embeddings, to be precise, are they derived data in the same account, or are they somewhere else?
  9. Hannah Lowe
    Hannah Lowe None
    Same account. To be precise, nothing derived leaves it. I'll put that in writing so it's on the record, because it's the sort of thing a capacity provider will ask.
  10. Nadia Osei
    Nadia Osei None
    They will. Can you evidence that? I need something I can attach, not just a statement on a call.
  11. Hannah Lowe
    Hannah Lowe None
    Yes. The diagram you've got is the starting point, and I'll add a short written statement that sits beside it and says exactly that. You can also verify it yourself, because it's your account. Your own administrators can see every object the brain creates. That's probably the strongest evidence you can have.
  12. Nadia Osei
    Nadia Osei None
    That's a fair point, and I'd like that in the pack. Moving on to encryption at rest. What is actually doing the encrypting?
  13. Hannah Lowe
    Hannah Lowe None
    Snowflake. Data at rest in your account is encrypted by the platform, and that applies to the objects the brain creates just as it does to anything else you store there. We don't add our own layer of storage encryption on top, and I wouldn't want to suggest we do. What BB-Demo contributes is how it's configured and what it's allowed to touch.
  14. Nadia Osei
    Nadia Osei None
    Understood. So the strength and the algorithm are Snowflake's attestation, not yours.
  15. Hannah Lowe
    Hannah Lowe None
    Correct. And I'd rather you rely on their published documentation and their audit reports for that than on anything I say. I can point you to the sections, and I'll list them in the follow-up. If your supplier review needs the reports themselves, you'd normally obtain those through your own relationship with the platform.
  16. Nadia Osei
    Nadia Osei None
    Yes, we do hold that relationship. I'll pull the reports myself. That's actually cleaner for the audit trail. Now, keys. Who holds them?
  17. Hannah Lowe
    Hannah Lowe None
    By default the platform manages a hierarchy of keys, and rotation happens on a schedule without anyone at your end or ours doing anything. Nobody at BB-Demo has the keys to your data. That's the default position.
  18. Nadia Osei
    Nadia Osei None
    And the non-default position? You'll have seen from my list that my capacity providers like to see that the firm itself controls its keys, or at least can revoke them.
  19. Hannah Lowe
    Hannah Lowe None
    Right, this is where I want to be careful. There's an option for the customer to bring a key of their own that works together with the platform's, so that you can effectively cut off access by withdrawing it. Whether that's available to you depends on the edition of Snowflake you hold, and on how it's been set up. I don't know which edition Fenmoor is on, and I'm not going to guess.
  20. Nadia Osei
    Nadia Osei None
    That is an answer I can use. I'll find out the edition on my side. Would the brain continue to work if we withdrew a key?
  21. Hannah Lowe
    Hannah Lowe None
    The honest answer is no, and that's the point of it. If the key were withdrawn, the data would be unreadable and the brain would have nothing to answer from. It would fail closed. What I'd like to do is confirm exactly how it behaves, what the user sees, and how it recovers when the key comes back, before I describe it to you in detail. I'll check that with a colleague in security and put it in writing.
  22. Nadia Osei
    Nadia Osei None
    Thank you. Please include recovery time, if it's known. Not a promise, just what has been observed.
  23. Hannah Lowe
    Hannah Lowe None
    I'll say what's observed and what's expected, and keep the two separate. That seems the right way to do it.
  24. Nadia Osei
    Nadia Osei None
    Good. Next, data in transit. Between your connectors and Snowflake, and between the browser and the brain.
  25. Hannah Lowe
    Hannah Lowe None
    Everything goes over encrypted connections, using current versions of TLS, and unencrypted connections aren't accepted. The connectors pull from your sources, so Salesforce, Zendesk, Microsoft 365 and the rest, over the sources' own encrypted interfaces, and then write into Snowflake. Between the user's browser and the brain it's the same.
  26. Nadia Osei
    Nadia Osei None
    I noticed on the diagram that the connectors have a box of their own. What do they hold? Specifically credentials.
  27. Hannah Lowe
    Hannah Lowe None
    Good, I was hoping you'd ask, because it's the part I'd rather not answer from memory. Each connector needs some form of credential for the source system. How those are stored, who can read them, and how they rotate are exactly the sort of detail that has to be right first time. Let me take it as an action, check with our security colleague, and give you a written answer instead of a half-remembered one.
  28. Nadia Osei
    Nadia Osei None
    That is entirely acceptable. I'd rather wait for the right answer. I'll note it as item five. And I'll need that in the questionnaire, not in an email on its own.
  29. Hannah Lowe
    Hannah Lowe None
    Understood, it goes straight into the questionnaire, with the email as a cover note. Do you want to give me the reference for the question so I put it in the right place?
  30. Nadia Osei
    Nadia Osei None
    It's the section headed key custody. Give me a moment, I'm just scrolling. Yes, key custody and rotation. There are three sub-questions underneath.
  31. Hannah Lowe
    Hannah Lowe None
    Right, I've got it. While you're there, can I read back what I think the three are, so we're not talking at cross purposes? Who generates the keys, who can rotate or revoke them, and what evidence exists that rotation actually happens.
  32. Nadia Osei
    Nadia Osei None
    Almost. The third one is worded slightly differently. It asks what evidence can be produced to a third party on request. That's the audit angle. The capacity providers don't want to take our word for it.
  33. Hannah Lowe
    Hannah Lowe None
    That's a better question than the one I read back. So evidence that can be handed to a third party. The platform's own reporting would be the main route there, and I'll say so plainly rather than inventing something of ours.
  34. Nadia Osei
    Nadia Osei None
    Thank you. Now, a related point on backups and deletion. If we ask for the brain to be removed, what happens to the data and the keys?
  35. Hannah Lowe
    Hannah Lowe None
    Because it all sits in your account, removal is largely something you control. We'd decommission the brain's objects and connectors, and you'd retain or delete your data under your own policy. I should be careful about retention windows, though, because the platform has its own recovery features and those apply to your account's settings, not to anything BB-Demo decides.
  36. Nadia Osei
    Nadia Osei None
    So the retention is governed by our configuration.
  37. Hannah Lowe
    Hannah Lowe None
    Yes. And I'd suggest your team looks at what that's currently set to, because I haven't seen it and wouldn't want to claim a number.
  38. Nadia Osei
    Nadia Osei None
    Noted. I'll check it. Let me ask about something slightly different, and tell me if it's session four. Logging. If somebody queried the brain and retrieved something they shouldn't, would we see the key being used?
  39. Hannah Lowe
    Hannah Lowe None
    That's partly session four, and I don't want to blur it, so let me answer the key part only. Access to data is recorded by the platform in your account, and your administrators can see it. Whether that is granular enough to show key usage specifically, I'd want to check. I'll add it to the list.
  40. Nadia Osei
    Nadia Osei None
    Please do. Again, evidence. I appreciate that you're not stretching to answer.
  41. Hannah Lowe
    Hannah Lowe None
    It's not worth anyone's time otherwise. If I overstated a control and your auditors found it, that would be worse for both of us than a slower answer.
  42. Nadia Osei
    Nadia Osei None
    Quite. Now, one more on the architecture. Does the embedding step ever send content outside the account, to be processed?
  43. Hannah Lowe
    Hannah Lowe None
    Another one to be precise about. The design intent is that processing happens inside your Snowflake account. I want the written answer to name exactly which steps run where, so rather than say a flat no now, I'll confirm it against the design and return it with the diagram annotated. If there is any step that doesn't, you'll see it flagged.
  44. Nadia Osei
    Nadia Osei None
    That is how I'd want it handled. Annotated, step by step. I'll list it as item six.
  45. Hannah Lowe
    Hannah Lowe None
    Fine. That's six now. Can I just play the list back so we agree it? One, the written statement on where derived data sits. Two, the customer-managed key option, subject to your edition. Three, the behaviour when a key is withdrawn, and recovery. Four, how connector credentials are stored and rotated. Five, whether key usage is visible in the logs. Six, the annotated diagram showing where processing runs.
  46. Nadia Osei
    Nadia Osei None
    That's right, though I'd renumber, because the access question from last time is still open, and I want the audit trail to keep the original numbers intact. I'll keep the old ones and number yours continuing from where mine finish.
  47. Hannah Lowe
    Hannah Lowe None
    Sensible. Then you own the numbering and I'll follow yours. It stops us creating two versions of the list.
  48. Nadia Osei
    Nadia Osei None
    Thank you. Let me also be clear about timing, so there's no misunderstanding. I can't sign anything off today, and I wouldn't set a date for sign-off until the capacity providers have seen the full pack. They'll want to review this in one go.
  49. Hannah Lowe
    Hannah Lowe None
    That's absolutely fine, and it's what we'd planned for. There are two more sessions. The next one is access control and data residency, and the last one is the wrap-up, where we pull everything into the pack. Nobody's asking for a sign-off on a verbal answer.
  50. Nadia Osei
    Nadia Osei None
    Good. On residency, can I flag now that it matters to us more than the usual boilerplate suggests? The capacity providers ask where data is held, and the honest answer for us depends on which region the account sits in.
  51. Hannah Lowe
    Hannah Lowe None
    Understood, and thank you for flagging it. It's the region of your Snowflake account, which you control, so I'd come to the next session with that spelled out. I'll also be clear about what BB-Demo staff can see when they support the brain, because that's the other half of the residency question.
  52. Nadia Osei
    Nadia Osei None
    Yes, that's the half I care about. Right. I think I have what I need from my side on encryption, at least for the questions I came with. Is there anything you'd flag that I haven't asked?
  53. Hannah Lowe
    Hannah Lowe None
    One thing, and it's more of a suggestion. Decide early whether you want the customer-managed key option, because it's much easier to design in than to retrofit once the brain has been running a while. If you can tell me which way you're leaning once you've checked the edition, I can make sure the written answers cover both cases.
  54. Nadia Osei
    Nadia Osei None
    That's useful. I'll take that to our own people and revert. I'd expect to know the edition quickly, within a few days, and the decision may take longer.
  55. Hannah Lowe
    Hannah Lowe None
    That's fine. I'll aim to get the written answers to you next week, so you have them before the next session, and I'll say clearly in the email which items are confirmed and which are still being checked.
  56. Nadia Osei
    Nadia Osei None
    Thank you, Hannah. And would you copy Daniel on it? He's been very good at keeping the thread together on our side and I'd like him to have the paper trail too.
  57. Hannah Lowe
    Hannah Lowe None
    Of course. I'll copy Daniel and keep everything on the one thread, so it can be found later.
  58. Nadia Osei
    Nadia Osei None
    Lovely. I think that's everything. Oh, one small thing. The diagram's legend uses a different symbol for external sources than the one in the questionnaire. Would you align them? Auditors do notice.
  59. Hannah Lowe
    Hannah Lowe None
    Yes, I'll make them match. Fair point, and exactly the kind of thing that costs a reviewer ten minutes of confusion. Thanks for catching it.
  60. Nadia Osei
    Nadia Osei None
    Not at all. Then let me close the loop on my list. Items one and two from last time are answered or parked to session four. Three and four are open pending your written answers and the edition check. Five and six are yours. Does that match your notes?
  61. Hannah Lowe
    Hannah Lowe None
    It matches. I'll send the written answers and the annotated diagram, and I'll say which ones I've checked with our security colleague. You'll check the edition and the retention setting. Next session, access control and residency.
  62. Nadia Osei
    Nadia Osei None
    Agreed. Thank you for not rushing the answers. It makes my side easier.
  63. Hannah Lowe
    Hannah Lowe None
    Thank you, it's a proper review and it should feel like one. Same time for the next session, I think, but I'll confirm by email.
  64. Nadia Osei
    Nadia Osei None
    Kind regards, Hannah. Speak soon.

BB-Demo is a fictional company; every organisation and person here is invented. B-Brain is the tool. Built by site/build_site.py from the site tree, data as of Fri 9 Oct 2026. Help & Support

Help & Support

Open as a page

Help & Support

B-Brain is one place to read everything the company knows about its customers: the CRM, calls, emails, support tickets, product usage, invoices, documents, news and HR. Every page is built from those systems and the data is current to Fri 9 Oct 2026.

How to use the site

How to ask

Press Ask Brain in the header. Type a question, or pick one of the examples.

The site itself does not call an AI model; answers in Claude come from the same figures you see here.

What the data covers

DataRecords
Organisations75
People at customers290
BB-Demo staff40
Calls784
Email threads1,169
Support tickets449
Documents477
Deals117
Invoices101
Events49
News items56

Data as of Fri 9 Oct 2026. Text marked AI was written by the brain from the records listed in its made-from link; an AI output that cannot cite its evidence is refused and the previous text kept. Where two systems disagree (for example a contract and the CRM), the key facts show both values and mark the difference.

BB-Demo is a fictional company: every organisation, person and figure here is invented for this demonstration. B-Brain is the tool that reads its data.

Who to contact

Email support@b-brain.example or talk to your B-Brain account team. Tell us the page address and what looked wrong; a screenshot helps.

Ask B

Ask B

B-Brain · read-only