What was said
What this says
Current to 10 Oct 26Megan Alvarez held the third and final security review for the Enterprise deployment. Hannah Lowe declined to give verbal answers on incidents, subprocessors and model retention. Written responses were promised by 31 Jul 2026, and approval stays open.
What happened: Megan Alvarez restated five numbered findings and added further questions on data location, model inference, encryption, change control and vulnerability management. Hannah Lowe answered the architecture and access control points and deferred the rest to written answers.
Customer view: Megan said she will give no verbal approval and will assess the written responses against her risk posture and report to the board risk committee. She said she does not penalise declining to guess, but does penalise guessing.
Commercial: Segmentation by client is a design obligation on the customer side, supported by BB-Demo in the implementation, not a built-in guarantee. This touches Enterprise features: single sign-on, SCIM and security review support.
Watch: Incident statement, subprocessor list and model retention commitment all need the security lead's signature. The 31 Jul 2026 date has passed, and the call does not show whether the set was delivered.
Themes
Current to 9 Oct 26Who was there
BB-Demo
Them
Follow-up
Next steps
Current to 9 Oct 26- Hannah Lowe to send the full written set with a cover note showing each item's status by 31 Jul 2026.
- Hannah to correct the questionnaire answer on segmentation by client.
- Confirm with Hannah whether the written set was delivered and what Megan concluded.
Risks
Current to 9 Oct 26- Several answers were deferred to written responses that need the security lead's signature, and the open findings remain open.
- Megan said vendors who disclose a slip before she finds out are treated differently, so any missed item must be flagged early.
- Client-level segmentation depends on roles the customer designs, which may be read as a gap against the questionnaire answer.
Opportunities
Current to 9 Oct 26- A complete, accurate written set could clear the security review for the Enterprise deployment.
- Security review support during implementation can help design client-level access restrictions.
Transcript
- Hannah Lowe NoneHello Megan, can you hear me all right? I'm sharing nothing yet, I'll do that in a minute.
- Megan Alvarez NoneI can hear you. Good afternoon, Hannah.
- Hannah Lowe NoneGood afternoon. Thanks for making the time. Before I touch anything, what do you most need to know from this session? I'd rather answer what you need than walk you through slides you've already seen.
- Megan Alvarez NoneFor the record, this is the third and final session in the agreed set. I will restate scope and the open findings. The scope is the Enterprise deployment as proposed, within our own Snowflake environment, handling data subject to HIPAA. The open findings are numbered. One, incident history. Please describe any incidents in the last ninety days. Two, audit log retention and who can read the logs. Three, the subprocessor list. Four, breach notification obligations and how they would map into our agreement. Five, access control, specifically single sign-on and provisioning.
- Hannah Lowe NoneGood, thank you. That's the list I have as well. Can I suggest an order? I'd like to start with the architecture, because several of those answers follow from it, and then take your numbered items one at a time. If you prefer your order, we do your order.
- Megan Alvarez NoneArchitecture first is acceptable, provided each numbered item is answered explicitly afterwards.
- Hannah Lowe NoneIt will be. I'm putting the diagram up now. Can you see it?
- Megan Alvarez NoneI can see it. It is legible.
- Hannah Lowe NoneSo the short answer to how it's built is: the brain runs inside your Snowflake account. The longer answer is that this matters for you in a few specific ways. The data we index from your systems lands in your account, under your roles and your policies. It doesn't get copied out to a store that we operate. So when you ask who can see what, the first answer is, the people your own administrators allow.
- Megan Alvarez NoneTo be precise, I need to understand what BB-Demo staff can access, if anything, and under what conditions.
- Hannah Lowe NoneThat's the right question, and I want to be careful with it. To be precise, BB-Demo's access is whatever your administrators grant to us in your account. We don't hold standing access by default. What I'm not going to do is describe the exact grant mechanics from memory and risk getting a detail wrong. I'll put the access model in writing, with the roles named, and you can check it against your own Snowflake configuration.
- Megan Alvarez NonePlease do. I would also want that document to state what happens when a BB-Demo employee leaves.
- Hannah Lowe NoneYes. I'll add that. Off-boarding for anyone with a grant in a customer account, and how it's evidenced.
- Megan Alvarez NoneThank you. Proceed to item one. Please describe any incidents in the last ninety days.
- Hannah Lowe NoneOkay. This is the one I want to be straight about. The short answer is that I am not going to give you a verbal statement on incident history that I can't stand behind. The longer answer is that incident disclosure is something our security lead signs, not me. I can describe how we classify and notify, but the statement of whether anything has occurred in the window needs to come in writing from him, and I'll make sure it's addressed to you.
- Megan Alvarez NoneUnderstood. And I will say, for the record, that an unsupported verbal assurance would not have been acceptable either. A written statement with a named signatory is what I require.
- Hannah Lowe NoneThat's what you'll get. Can I give you the process in the meantime? Not the content of the statement, just how an incident is handled.
- Megan Alvarez NonePlease.
- Hannah Lowe NoneAn incident that touches a customer's data is classified, the customer's named contact is told, and a written account follows. What I won't do is quote you a notification window off the top of my head, because it's the kind of figure that has to match the agreement. I'll include whatever we can commit to, and I'll flag clearly anything we can't commit to.
- Megan Alvarez NoneThat is preferable to a number you cannot support. Please be aware that I will compare the stated window against our business associate obligations, which are not flexible.
- Hannah Lowe NoneUnderstood. Which takes us into item four, if you're happy to jump.
- Megan Alvarez NoneProceed.
- Hannah Lowe NoneSo breach notification. The honest position is that the technical side is mine and the contractual side isn't. I can tell you what we'd detect and surface from the platform side, sorry, from the brain's side, and what logs exist. The notification commitment itself would sit in the order form and the data processing terms, and I'd want your counsel and ours reading the same paragraph.
- Megan Alvarez NoneYou said platform and corrected yourself. Is there a distinction?
- Hannah Lowe NoneOnly a habit, honestly. We call it the brain. It's the same thing. I just don't want to describe it as more than it is, which is a layer that runs in your account.
- Megan Alvarez NoneNoted. Continue with the logs.
- Hannah Lowe NoneRight, item two. Audit logs. There are two layers and I want to keep them apart. The first is your own Snowflake account's logging, which is yours, under your retention settings. Because the brain runs in your account, query activity from the brain shows up there. You control how long it's kept and who reads it.
- Megan Alvarez NoneAnd the second layer?
- Hannah Lowe NoneThe second layer is the brain's own activity record: who asked what, which connectors loaded, which admin changed which setting. That's where I need to be careful. I know what it records. I'm not certain of the retention period as configured for Enterprise, and I don't want to guess in front of you. I'll confirm and give it to you in writing, with the setting named.
- Megan Alvarez NoneI would also want to know whether that record can be exported to our own security tooling.
- Hannah Lowe NoneGood question. My understanding is that, since it sits in your Snowflake account, you can read it with your own tooling, but I'll verify that rather than state it as settled. I'll write it as a question I've answered, not an assumption.
- Megan Alvarez NoneThat is the correct way to treat it.
- Hannah Lowe NoneWhile we're there, can I show you the part of the diagram on connectors? Because it bears on item five too.
- Megan Alvarez NoneGo ahead.
- Hannah Lowe NoneSo each connector, Salesforce, Zendesk, Microsoft 365 and so on, authenticates to the source with a credential that your administrators issue. We recommend a service account with read-only scope where the source allows it. The brain doesn't write back to those systems. Where a source doesn't offer a read-only scope, I'll say so in the written answer and name which ones.
- Megan Alvarez NoneThat last sentence is useful. Which of the systems in scope for us do not offer read-only scope?
- Hannah Lowe NoneI'd have to check each against what you've told us you'd connect. Let me not name one from memory. I'll go through your connector list and mark each one, read-only available or not. You'll have it as a table.
- Megan Alvarez NoneA table is acceptable.
- Hannah Lowe NoneItem five, then. Access control. Enterprise includes single sign-on and SCIM provisioning. So users arrive and leave through your identity provider, and when someone is deprovisioned on your side, they lose access to the brain. That one I'm confident of, because it's the design, not a configuration choice.
- Megan Alvarez NonePlease clarify whether access can be restricted by data domain. For example, a client-services user seeing one hospital client's records and not another's.
- Hannah Lowe NoneOkay, so that's a real distinction and I want to answer it accurately. The brain inherits the permissions in your Snowflake account. So if your roles restrict a table or a view, the brain can only answer from what the role can reach. What the brain doesn't do on its own is invent a restriction you haven't set up. The restriction is yours to design. I can help with the design in the implementation, that's part of the security review support.
- Megan Alvarez NoneSo the segmentation by client is a design obligation on our side, supported by you, not a built-in guarantee.
- Hannah Lowe NoneYes. That's exactly right. I'd rather you hear that from me now than discover it in the build. The short answer is it's supported. The longer answer is that it's configured with you, and it's only as strong as the roles you set.
- Megan Alvarez NoneThank you. That is a clearer answer than the questionnaire gave.
- Hannah Lowe NoneI'll update the questionnaire answer so it says the same thing. It should have been in there.
- Megan Alvarez NonePlease do. Item three. The subprocessor list.
- Hannah Lowe NoneRight. Now, this is the one where I'm going to be least helpful verbally and most helpful in writing, so I'll say that up front. The list of subprocessors, if any, that touch customer data is a controlled document. I don't want to read it out from memory and drop one. What I can say structurally is that, because the data stays in your Snowflake account, the question becomes which of our suppliers could ever touch it there, and the answer is whoever you grant access to.
- Megan Alvarez NoneThat does not answer the question. I need the list, or a statement that there are none, signed.
- Hannah Lowe NoneAgreed, it doesn't, and I'm not claiming it does. It's a separate item and it's going to you as a document with a named owner. I'd rather give you nothing verbal than something I have to correct later.
- Megan Alvarez NoneI accept that position. I will record it as pending.
- Hannah Lowe NonePending is fair.
- Megan Alvarez NoneI have several additional questions that are not on the numbered list, as they arose from the architecture. Question six. Where is data processed, and can you confirm it remains in the United States?
- Hannah Lowe NoneBecause it runs in your Snowflake account, it's processed wherever your account is deployed. We don't move it elsewhere. If you have a particular region in your account, that's the region. There's also a dedicated US data residency add-on in our catalogue, but for a Snowflake-in-your-account design, I'd say the residency follows your account. I'll state it in those terms in writing.
- Megan Alvarez NoneI would like the model processing step addressed explicitly. Where does the language model inference occur, and is any customer content retained by whoever runs it?
- Hannah Lowe NoneThat's a very good question and I want to be careful, because it's the part of the diagram that people ask about most and the part where I most want a precise answer. I know the design intent, which is that content is not retained for training. But I'm not going to state it to you as a verified control until I've confirmed the exact wording of what we can commit to. I'll take it to our security lead as a specific question and the answer will be in writing.
- Megan Alvarez NoneDesign intent is not a control. Please make sure the written answer distinguishes the two.
- Hannah Lowe NoneIt will. Design intent, contractual commitment, and verified control, three separate lines, so you can see which is which.
- Megan Alvarez NoneThank you. That structure is helpful.
- Hannah Lowe NoneCan I ask something back? You said retained by whoever runs it. Is it the retention you're worried about, or the transit? Because I can answer those separately and they have different owners.
- Megan Alvarez NoneBoth. Retention is the primary concern. Transit is the secondary. I want the encryption position in transit and at rest stated for each hop.
- Hannah Lowe NoneEach hop. Okay. I'll do it as a table against the diagram, so every arrow on this picture has a line. And where I can't evidence a hop, I'll mark it as not yet evidenced, not leave it blank.
- Megan Alvarez NoneNot yet evidenced is an honest label. I would rather see that than an omission.
- Hannah Lowe NoneGood. Let me also ask, because it might save a round: is there anything in the earlier two sessions you felt was answered thinly? I'd rather fix it now.
- Megan Alvarez NoneTwo things. The answer on vulnerability management was general. And the description of change control for the brain's own releases was not specific about customer notice.
- Hannah Lowe NoneRight. On change control, what I can tell you is that releases are communicated to customers, but I don't have the notice period in front of me and I'm not going to improvise one. Vulnerability management I'd put in the same category: it's owned by our security lead and it deserves a proper written answer rather than my paraphrase.
- Megan Alvarez NoneThen those become items seven and eight.
- Hannah Lowe NoneSeven and eight. I've got them.
- Megan Alvarez NoneI want to be clear about how this will be handled on our side. I will not provide a verbal approval, today or at any point. When the written responses arrive, I will assess them against our risk posture and report to the board risk committee. I do not share the scoring with vendors.
- Hannah Lowe NoneUnderstood, and that's completely reasonable. I wouldn't expect it any other way. What I can do is make sure what you're assessing is complete and accurate, which is my job.
- Megan Alvarez NoneThen let us confirm the deliverables. Please read them back.
- Hannah Lowe NoneOkay. One, a written statement on incidents in the ninety-day window, signed by our security lead, addressed to you. Two, the access model in writing, with roles named and the off-boarding process. Three, audit log retention for the brain's own activity record, and whether it can be exported. Four, the subprocessor list or a signed statement that there are none. Five, the connector table with read-only scope marked per source. Six, the processing and retention statement for model inference, with design intent, commitment and control separated. Seven, the encryption table by hop. Eight, change control and customer notice, and vulnerability management. And the corrected questionnaire answer on segmentation by client.
- Megan Alvarez NoneThat is complete. You also have the notification window under item four.
- Hannah Lowe NoneYes, thank you. That goes with the incident statement, with whatever we can commit to, and whatever we can't flagged as such.
- Megan Alvarez NoneDates. I require these before I convene the committee. What is your commitment?
- Hannah Lowe NoneI want to give you a date I can keep, not an optimistic one. Several of these need our security lead to sign. If I say all of it by 31 Jul 2026, I'm confident that I can deliver that. Some items will come sooner and I'll send them as they're ready, rather than hold them back to arrive together.
- Megan Alvarez NoneBy 31 Jul 2026 for the complete set, with earlier items as available. Please also state in your cover note which items are not yet complete, so I'm not left to find that out.
- Hannah Lowe NoneYes. A cover note with each item and its status, and if something slips I'll tell you before the date, not after.
- Megan Alvarez NoneVendors who disclose before I find out are treated differently from those who do not. I mention it for the record.
- Hannah Lowe NoneThat's understood, and it's how I'd want to work anyway.
- Megan Alvarez NoneOne further matter, for completeness. Has anything in the deployment design changed since the first session that I should be aware of?
- Hannah Lowe NoneNothing that I'm aware of in the design for your deployment. The scope is the same Enterprise configuration we described: single sign-on, provisioning, your own account. If anything did change, it would be in the cover note and I'd call you.
- Megan Alvarez NoneVery well. Is there anything you wish to raise before we close?
- Hannah Lowe NoneJust one thing. Some of the answers today were that I'd confirm rather than answer. I know that's not what a security team wants on a final session. I'd rather be in that position than give you an answer I might have to retract. If that costs us in the outcome, I accept that.
- Megan Alvarez NoneI will assess what is provided. I do not penalise a vendor for declining to guess. I do penalise guessing.
- Hannah Lowe NoneThen we're aligned. Anything else from you?
- Megan Alvarez NoneNo. This concludes the third session. The open findings remain open pending your written responses. I will be in touch through Jordan if I have further questions.
- Hannah Lowe NoneUnderstood. I'll copy Jordan on everything so the deal record matches the security record. Thanks for your patience today, Megan, and for being so specific. It makes the written answers better.
- Megan Alvarez NoneThank you, Hannah. Goodbye.
- Hannah Lowe NoneBye for now.