Hannah Lowe

Quillmark Health / BB-Demo – Security Review

Callcompleted

Quillmark Health: documents logo Quillmark Health: documents · 2026-06-15 15:00

Megan Alvarez reviewed eight security findings with Hannah Lowe on the Enterprise scope: one closed subject to contract, six open, one demonstrated, a ninth added. Content-level redaction is recorded as a limitation.

What was said

What this says

Current to 10 Oct 26

Megan Alvarez reviewed eight security findings with Hannah Lowe on the Enterprise scope: one closed subject to contract, six open, one demonstrated, a ninth added. Content-level redaction is recorded as a limitation.

What happened: On 15 Jun 2026 Megan went through BB-Demo's written answers in order. She closed third parties subject to the contract and held most others open pending documents.

Customer view: The most significant item is customer approval of BB-Demo staff access, which she called difficult to accept for a HIPAA environment. She also wants a time commitment for incident notification written into the contract.

Commercial: The call recorder connector cannot redact inside a transcript, which she will report to her risk committee as a limitation. Premium support ends at 20:00 UK time, which she called a gap for incidents.

Watch: Hannah named 30 Jun 2026 as the date in the commercial plan, and Megan said it would not influence her review. The evidence does not show the third session or any signature.

AI · claude-sonnet-5-5 · 10 Oct 2026

Themes

Current to 9 Oct 26
Theme
Enterprise security review findings
Importance
neutral
Sentiment
mixed
Voice
decision-maker

Who was there

BB-Demo

Them

Follow-up

Next steps

Current to 9 Oct 26
  • Hannah Lowe to send the answer on customer approval of staff access first, on its own, before the third session.
  • Hannah Lowe to send the credentials section, limitation paragraph, deletion evidence, schema-change gate and out-of-hours handling.
  • Hannah Lowe to give the commercial owner Megan's wording on a contractual incident-notification time.

Risks

Current to 9 Oct 26
  • Customer approval of BB-Demo staff access is unresolved and could change how the deployment is run.
  • Transcripts cannot be redacted at content level, which the risk committee will see as a limitation.
  • Premium support hours of 07:00 to 20:00 UK time leave a gap for security incidents in Boston.

Opportunities

Current to 9 Oct 26
  • Clear written answers on the open findings could let the review close and unblock the Enterprise order.
  • Metadata-only or team-scoped sources give the customer a way to start within the limits.

Transcript

  1. Hannah Lowe
    Hannah Lowe None
    Hi Megan, good afternoon. Can you hear me?
  2. Megan Alvarez
    Megan Alvarez None
    Good afternoon, Hannah. Yes, I can. Jordan is not joining?
  3. Hannah Lowe
    Hannah Lowe None
    Not for this one. It's a technical session, so I suggested he leave it to us. He's on the thread for anything contractual. What would you most like to get through today?
  4. Megan Alvarez
    Megan Alvarez None
    I will restate where we are, so it is in the record. This is the second of three sessions. Scope is unchanged: BB-Demo Enterprise for client-services teams, with our CRM, helpdesk, call recorder and mailboxes as sources. At the first session I opened eight findings. I have received your written answers and the diagram. I will go through them in order and tell you which I consider closed, which remain open, and what I need.
  5. Hannah Lowe
    Hannah Lowe None
    That's exactly what I was hoping for. I've got the same eight in front of me, and the document, so I can point to the line you're reading.
  6. Megan Alvarez
    Megan Alvarez None
    Finding one, location of processing and storage. The list of components outside our account is shorter than I expected. I have a question on the metadata you describe as leaving the account. What exactly is in it?
  7. Hannah Lowe
    Hannah Lowe None
    To be precise, it's operational information about the deployment, which is what lets us support it. It isn't the content of your tickets or calls. The section lists the categories. If you want, I can go through each category and say whether a patient identifier could ever appear in it.
  8. Megan Alvarez
    Megan Alvarez None
    Please do. That is the question.
  9. Hannah Lowe
    Hannah Lowe None
    Okay. I'll read from the document so I don't paraphrase. The categories are deployment health, refresh status and counts of records processed. A count isn't content. There's nothing in those that carries free text from a ticket or a transcript. If you read anything else in there that looks like it could carry free text, tell me, because then the document is wrong and I'd want to fix it.
  10. Megan Alvarez
    Megan Alvarez None
    I will review it with that in mind. Finding one remains open pending that review. I may close it by the third session.
  11. Hannah Lowe
    Hannah Lowe None
    Fine.
  12. Megan Alvarez
    Megan Alvarez None
    Finding two, access. Your description separates customer users from BB-Demo staff. For staff it describes a request, an approval and a record. My question is whether the approval is by someone on our side.
  13. Hannah Lowe
    Hannah Lowe None
    That's the point I'd want you to push on, and the answer in the document is that the approval is internal to BB-Demo, with the access recorded. It's not customer-approved by default. Whether we can make customer approval a condition for your deployment is a fair request, and I don't want to promise it from a call. I'll take it back as a specific requirement.
  14. Megan Alvarez
    Megan Alvarez None
    Then I will make it a requirement. For a HIPAA environment, access to content by a vendor without our approval is difficult for me to accept.
  15. Hannah Lowe
    Hannah Lowe None
    Understood. I'll write it as a requirement from you and give you an answer from our security lead, and not a maybe.
  16. Megan Alvarez
    Megan Alvarez None
    Finding three, incident history. I have read the statement. I will record it as received and not closed. I have two observations. The definition of an incident you provided is reasonable. The notification commitment is expressed in terms of your process. I need it expressed in terms of a time, in the contract.
  17. Hannah Lowe
    Hannah Lowe None
    Right. That's a contractual point rather than a technical one, so I'm not going to answer it for Jordan. What I'll do is make sure he has your wording exactly, a time commitment in the order form or the agreement and not a reference to our internal process. I'd rather you got it from the person who can actually sign it.
  18. Megan Alvarez
    Megan Alvarez None
    Good. Please also confirm that the ninety days I asked about were counted back from the date of the first session, not from the date the statement was written.
  19. Hannah Lowe
    Hannah Lowe None
    I'll check that and confirm it in writing. I don't want to tell you the answer from memory and be a few days out.
  20. Megan Alvarez
    Megan Alvarez None
    Finding four, third parties. The list is clear. I have no further question on that one, other than the confirmation I requested on whether any of them see content.
  21. Hannah Lowe
    Hannah Lowe None
    That's in the second column. Content is seen by none of them, apart from the platform on which your account itself runs. If you read it differently, I'll reword it.
  22. Megan Alvarez
    Megan Alvarez None
    I read it the same way. Finding four is closed, subject to the contract matching the document.
  23. Hannah Lowe
    Hannah Lowe None
    Noted. And thank you.
  24. Megan Alvarez
    Megan Alvarez None
    Finding five, retention and deletion. The explanation is sensible. I want evidence of deletion at the end of a contract. A statement that it was done is not enough.
  25. Hannah Lowe
    Hannah Lowe None
    That's reasonable. What I can offer is a written confirmation of what was removed and when, and you'd verify the tables in your own account yourselves, since you hold them. I'll describe the sequence and the evidence you'd receive, as a short section you can attach to the contract.
  26. Megan Alvarez
    Megan Alvarez None
    Please do. Finding five remains open until I see that section.
  27. Megan Alvarez
    Megan Alvarez None
    Finding six, single sign-on and provisioning. The configuration notes are adequate. I would like confirmation that a user removed in our identity provider loses access to the brain, not at the next sync, but promptly.
  28. Hannah Lowe
    Hannah Lowe None
    With SCIM, a deprovision flows from your identity provider. How quickly it takes effect depends on how your provider sends it, and I can show you that on a test configuration shortly. I'd rather demonstrate it than say 'immediately' and have you find a gap.
  29. Megan Alvarez
    Megan Alvarez None
    Acceptable. I will hold six open until that demonstration.
  30. Megan Alvarez
    Megan Alvarez None
    Findings seven and eight. Credentials, and change control for source schemas.
  31. Hannah Lowe
    Hannah Lowe None
    Yes. Credentials first. I confirmed with our security lead and I've written the answer on where connector credentials are held and how they are rotated, and what happens to them when a connector is removed. Is the wording clear to you?
  32. Megan Alvarez
    Megan Alvarez None
    It is clear. Rotation is described as something that is possible. I need to know whether it is scheduled, and who owns it.
  33. Hannah Lowe
    Hannah Lowe None
    That's a good catch, and you're right: the document says it can be rotated, which isn't the same as saying it is, on a schedule, by a named owner. I'll tighten it to say who owns it. If the honest answer is that it's a joint responsibility, the document should say that.
  34. Megan Alvarez
    Megan Alvarez None
    Please do. I prefer a document that states a shared responsibility to one that implies a guarantee.
  35. Hannah Lowe
    Hannah Lowe None
    Same. That's how I'd want to be read by you.
  36. Megan Alvarez
    Megan Alvarez None
    Change control for schemas. You proposed a review step at implementation, in our change process. I need that as a defined step, not a recommendation.
  37. Hannah Lowe
    Hannah Lowe None
    Understood. I'd propose it appears in the implementation plan as a named gate, with you as the approver for any new field in a source that could hold clinical content. Then a new field can't start flowing without someone on your side having said yes.
  38. Megan Alvarez
    Megan Alvarez None
    That would meet the requirement. Seven and eight remain open until I see them in the plan.
  39. Hannah Lowe
    Hannah Lowe None
    Right. Shall I show you the source scoping now, the thing I promised last time?
  40. Megan Alvarez
    Megan Alvarez None
    Yes. I will interrupt.
  41. Hannah Lowe
    Hannah Lowe None
    Please do. I'm sharing a test configuration, with no real data in it. This is the connector list. Nothing is on until someone switches it on. Here's the call recorder connector. You can see it has the source-level toggle, and below that, the options for what comes through.
  42. Megan Alvarez
    Megan Alvarez None
    Stop. What are the options exactly? Please read them out.
  43. Hannah Lowe
    Hannah Lowe None
    Sure. For calls you can include or exclude by team, and by who hosted the call. You can choose whether transcripts come through or only the call metadata and summary. I'll be clear about the limit: I can't select inside a transcript for particular sentences. It's the whole transcript or not at all.
  44. Megan Alvarez
    Megan Alvarez None
    That is the answer I was concerned about. A transcript of a client call may well contain protected health information. The control exists at team level. It does not exist at content level.
  45. Hannah Lowe
    Hannah Lowe None
    Correct, and I'd rather say it plainly than dress it. The mitigation is at the source: you decide which teams' calls are included, and you could start with metadata and summaries only. But I understand that doesn't give you content-level redaction, and I won't say it does.
  46. Megan Alvarez
    Megan Alvarez None
    Thank you for saying it plainly. I will record it as a limitation, not a finding to be closed. The risk committee will want to see it described that way.
  47. Hannah Lowe
    Hannah Lowe None
    That's fair. If it helps, I can write the limitation up in a short paragraph, in terms the committee can read, with the options available and what each one leaves exposed.
  48. Megan Alvarez
    Megan Alvarez None
    That would help. Please include the helpdesk and mailbox connectors as well. I suspect the same pattern.
  49. Hannah Lowe
    Hannah Lowe None
    Let me show you the helpdesk one, so you can judge for yourself.
  50. Hannah Lowe
    Hannah Lowe None
    Same layout. You can include or exclude by queue and by ticket category. Comments and attachments are separate switches. So, for example, you could take ticket subjects and status and leave the comment thread out, if the comments are where clinical detail tends to appear.
  51. Megan Alvarez
    Megan Alvarez None
    That is more granular than the call recorder. Better. Not yet sufficient, but better.
  52. Hannah Lowe
    Hannah Lowe None
    Agreed on both. And the mailbox connector is closer to the call recorder in granularity than to the helpdesk. I'll set that out in the paragraph rather than guess at it live.
  53. Megan Alvarez
    Megan Alvarez None
    Now the deprovisioning demonstration, please.
  54. Hannah Lowe
    Hannah Lowe None
    Yes. I'll switch to the identity settings. In this test tenant I have a user, provisioned through SCIM from a test identity provider. I'll remove the user there, and we'll watch the brain.
  55. Hannah Lowe
    Hannah Lowe None
    Okay, so the removal's been sent. Refreshing the user list now. And the user shows as deactivated. Their session is rejected when I try to use it.
  56. Megan Alvarez
    Megan Alvarez None
    How long did that take, measured from your removal?
  57. Hannah Lowe
    Hannah Lowe None
    From where I sat, it took a couple of minutes. I don't want to turn a single test run into a service commitment, so I'll note it as an observation. The commitment, if you need one, would be a separate question.
  58. Megan Alvarez
    Megan Alvarez None
    Understood. That is acceptable for my purposes. I will annotate finding six as demonstrated, and hold it open until the written commitment question is settled.
  59. Hannah Lowe
    Hannah Lowe None
    Good. Anything else you want me to show while we have the screen?
  60. Megan Alvarez
    Megan Alvarez None
    One more topic, which is support coverage. Your documentation describes Premium support with a named engineer. What are the hours?
  61. Hannah Lowe
    Hannah Lowe None
    Seven in the morning to eight in the evening, UK time, so 07:00 to 20:00. And I'll be direct about the consequence for you: that ends in the mid-afternoon in Boston.
  62. Megan Alvarez
    Megan Alvarez None
    That is a gap for a security incident at our end of the day.
  63. Hannah Lowe
    Hannah Lowe None
    It is a gap, and I don't think I should argue otherwise. Enterprise has a thirty-minute first response on a priority one, but that's a response commitment, not the same as a named engineer's hours. I'll set out how out-of-hours priority one handling works, so you see the actual process, and Jordan can speak to whether anything contractual changes it.
  64. Megan Alvarez
    Megan Alvarez None
    Please do. Add it as a ninth item: out-of-hours handling of security incidents.
  65. Hannah Lowe
    Hannah Lowe None
    Ninth item, out-of-hours incident handling. Noted.
  66. Megan Alvarez
    Megan Alvarez None
    Let me summarise the position. Closed: finding four, subject to the contract. Open: one, two, three, five, seven and eight, and the ninth. Six demonstrated, awaiting a commitment. Content-level redaction recorded as a limitation. Is that your understanding?
  67. Hannah Lowe
    Hannah Lowe None
    That's mine as well. And I'd add that the customer-approval requirement for staff access is the item I most want a firm answer on, because it could change the shape of how we'd run your deployment.
  68. Megan Alvarez
    Megan Alvarez None
    Agreed. I regard that as the most significant one.
  69. Hannah Lowe
    Hannah Lowe None
    On timing, I know Jordan is working towards 30 Jun 2026 for the commercial side. I'm not raising it to pressure you. I mention it only so you know that's the date he has in his plan, and your review decides the pace, not that.
  70. Megan Alvarez
    Megan Alvarez None
    I appreciate it being stated that way. The date will not influence my review.
  71. Hannah Lowe
    Hannah Lowe None
    Understood. So from me: the revised credentials section, the plain-language limitation paragraph covering all three connectors, the deletion evidence section, the schema-change gate in the implementation plan, the out-of-hours handling, and the answer on customer approval of staff access. I'll send them ahead of the third session, early enough to read properly.
  72. Megan Alvarez
    Megan Alvarez None
    I would like the answer on staff access first, as it determines whether the rest is worth my time.
  73. Hannah Lowe
    Hannah Lowe None
    Then that goes first, on its own, and I'll say so in the subject line.
  74. Megan Alvarez
    Megan Alvarez None
    Good. For the record, nothing in this session constitutes approval, and I will send my remaining questions in writing.
  75. Hannah Lowe
    Hannah Lowe None
    Understood, and thanks, Megan. This was the sort of session I'd hoped for. I'll put it all in writing.
  76. Megan Alvarez
    Megan Alvarez None
    Thank you, Hannah. Goodbye.

BB-Demo is a fictional company; every organisation and person here is invented. B-Brain is the tool. Built by site/build_site.py from the site tree, data as of Fri 9 Oct 2026. Help & Support

Help & Support

Open as a page

Help & Support

B-Brain is one place to read everything the company knows about its customers: the CRM, calls, emails, support tickets, product usage, invoices, documents, news and HR. Every page is built from those systems and the data is current to Fri 9 Oct 2026.

How to use the site

How to ask

Press Ask Brain in the header. Type a question, or pick one of the examples.

The site itself does not call an AI model; answers in Claude come from the same figures you see here.

What the data covers

DataRecords
Organisations75
People at customers290
BB-Demo staff40
Calls784
Email threads1,169
Support tickets449
Documents477
Deals117
Invoices101
Events49
News items56

Data as of Fri 9 Oct 2026. Text marked AI was written by the brain from the records listed in its made-from link; an AI output that cannot cite its evidence is refused and the previous text kept. Where two systems disagree (for example a contract and the CRM), the key facts show both values and mark the difference.

BB-Demo is a fictional company: every organisation, person and figure here is invented for this demonstration. B-Brain is the tool that reads its data.

Who to contact

Email support@b-brain.example or talk to your B-Brain account team. Tell us the page address and what looked wrong; a screenshot helps.

Ask B

Ask B

B-Brain · read-only