What it says
What this says
Current to 11 Oct 26Final, version one security questionnaire issued on 9 May 2026 by Theo Gallagher for Ardcarne's information security and procurement teams. It covers the Enterprise tier, with a 30 minutes P1 first response and a 07:00 nightly refresh. It states no price.
What it is: a DORA-oriented security and resilience questionnaire answered for the Enterprise tier. It says "Nothing here describes a control that is not in place" and that the executed order form prevails.
Commits: "Thirty minutes on the Enterprise tier" for a priority one first response, and a refresh that "completes by 07:00 customer local time on business days". Credits cover availability and data freshness. The exit runbook is "delivered before go-live".
Unusual: the availability figure is not stated; it is left to the executed order form. Sign-off is incomplete: Matteo Ricci is "Not yet signed" and the Ardcarne security contact is "Awaiting receipt".
Not settled: price, contract dates and whether the optional EU residency, Premium support and Sandbox add-ons were taken. The document states no contract value.
As found in this document
Current to 9 Oct 26- P1 first responseThirty minutes on the Enterprise tier.Thirty minutes on the Enterprise tier. · Source: object_read:doc_008_003
- Nightly data refreshThe refresh completes by 07:00 customer local time on business days.The refresh completes by 07:00 customer local time on business days. · Source: object_read:doc_008_003
- Service creditsEnterprise service credits cover availability and data freshness.Enterprise service credits cover availability and data freshness. · Source: object_read:doc_008_003
- AvailabilityThe exact figure is stated in the executed order form.The exact figure is stated in the executed order form. · Source: object_read:doc_008_003
- Exit runbookthe runbook is delivered before go-live.the runbook is delivered before go-live. · Source: object_read:doc_008_003
The document
Body
Ardcarne Life Assurance - Security Questionnaire
Status: Final, version one Date: 9 May 2026 Prepared by: Theo Gallagher, Solutions Engineer, BB-Demo Prepared for: Ardcarne Life Assurance, information security and procurement Tier under review: Enterprise Account owner: Matteo Ricci Customer success manager: Elena Novak
Purpose and scope
This document answers the security and operational resilience questions raised by Ardcarne Life Assurance during its review of BB-Demo. Ardcarne is supervised by the Central Bank of Ireland and is subject to DORA, so answers are written to support Ardcarne's own third-party risk register and its exit planning.
Each answer states what the control is, where we can evidence it, and, where a control is a commitment rather than a feature, the dated commitment. Nothing here describes a control that is not in place. Where an answer depends on contract wording, the executed order form decides.
How the platform is deployed
Read the whole document (6,897 characters)
BB-Demo is built and run inside the customer's own Snowflake account. Ardcarne data is therefore not copied into a BB-Demo-owned data store. Connected systems are read into Ardcarne's own Snowflake environment, and the brain queries that data in place.
Questionnaire
Section A: Governance and ownership
| Ref | Question | Answer | Evidence |
|---|---|---|---|
| GOV-A | Who owns the customer data processed by the brain? | Ardcarne remains the owner and controller. BB-Demo acts as a processor under the MSA and data processing agreement. | MSA and DPA, supplied with the order form |
| GOV-B | Is there a named security contact at BB-Demo? | Yes. Theo Gallagher is the security review contact for Ardcarne during evaluation and implementation. | This document |
| GOV-C | Are subprocessors used? | The customer's Snowflake account is the processing environment. Any further subprocessor would be listed in the DPA and notified in advance. | DPA schedule |
Section B: Data location and residency
| Ref | Question | Answer | Evidence |
|---|---|---|---|
| LOC-A | Where is Ardcarne data stored? | In Ardcarne's own Snowflake account, in the region Ardcarne selects. | Snowflake account configuration, held by Ardcarne |
| LOC-B | Is dedicated EU data residency available? | Yes, as an add-on offered with the Enterprise tier. Because the brain runs in the customer's account, residency follows the region Ardcarne chooses. | Order form line, if taken |
| LOC-C | Does BB-Demo staff access leave the customer account? | Access is exercised within the customer's Snowflake account under roles Ardcarne grants and can revoke. | Role grants visible to Ardcarne |
Section C: Access control and identity
| Ref | Question | Answer | Evidence |
|---|---|---|---|
| IAM-A | Is single sign-on supported? | Yes. SSO is included in the Enterprise tier. | Tier definition |
| IAM-B | Is automated user provisioning and removal supported? | Yes. SCIM is included in the Enterprise tier, so leavers can be removed from the brain by the identity provider. | Tier definition |
| IAM-C | Can access be limited by role? | Yes. Access to connected sources and pages follows the roles Ardcarne defines. We can evidence that by walking through the role set-up in the implementation. | Implementation sign-off |
Section D: Availability, support and incident response
| Ref | Question | Answer | Evidence |
|---|---|---|---|
| SLA-A | What availability is committed? | The Enterprise availability commitment, which is the highest of our tiers. The exact figure is stated in the executed order form. | Order form |
| SLA-B | What is the first response time for a priority one incident? | Thirty minutes on the Enterprise tier. | Service level schedule |
| SLA-C | Is the nightly data refresh committed? | Yes. The refresh completes by 07:00 customer local time on business days. | Service level schedule |
| SLA-D | What remedy applies to a miss? | Enterprise service credits cover availability and data freshness. Freshness is credited on Enterprise only. | Service level schedule |
| SLA-E | Is enhanced support available? | Premium support is available from version two of the Enterprise tier, with a named engineer from 07:00 to 20:00 UK time. | Add-on description |
Section E: Change and testing
| Ref | Question | Answer | Evidence |
|---|---|---|---|
| CHG-A | Can changes be tested before production? | A Sandbox is available as an Enterprise add-on, so Ardcarne can test connector and configuration changes away from live data. | Add-on description |
| CHG-B | Are customers told about changes that affect them? | Yes. Changes that affect configured connectors or service levels are notified through the customer success manager. | Account communication log |
Section F: Resilience and exit (DORA)
| Ref | Question | Answer | Evidence |
|---|---|---|---|
| EXT-A | Can Ardcarne exit without losing its data? | Yes. The indexed data and the underlying source extracts sit in Ardcarne's own Snowflake account, so they stay with Ardcarne at termination. | Architecture description |
| EXT-B | What does Ardcarne lose on exit? | The brain's query layer and configuration managed by BB-Demo. These can be exported on request before termination. | Exit schedule in the MSA |
| EXT-C | Is there a documented exit plan? | The exit steps are set out in the contract. We will agree a dated exit runbook with Ardcarne during implementation. Here is the dated commitment: the runbook is delivered before go-live. | Implementation plan |
Security review support during implementation
The Enterprise implementation includes security review support over the implementation period. In practice that means:
- Theo Gallagher walks Ardcarne's security team through any answer above that needs further evidence.
- Open findings are listed with an owner on every review call, and closed only when the evidence is accepted by Ardcarne.
- Questions that depend on platform engineering are put to the platform team and answered in writing, not from assumption.
Limits of this document
- This questionnaire reflects the Enterprise tier and the standard service levels. An executed order form can change any of them, and the executed order form prevails.
- Controls that Ardcarne operates inside its own Snowflake account, such as network policy and key management, remain Ardcarne's responsibility. We can advise on configuration but do not claim them as BB-Demo controls.
- No contract value is assumed in this document. Commercial terms are set out separately.
Sign-off
| Role | Name | Date |
|---|---|---|
| Prepared and issued by, Solutions Engineer, BB-Demo | Theo Gallagher | 9 May 2026 |
| Account owner, BB-Demo | Matteo Ricci | Not yet signed |
| Security contact, Ardcarne Life Assurance | Job title only: Head of Information Security | Awaiting receipt |
Thanks, Theo
Unusual terms
Current to 9 Oct 26- availability figure deferred to order form
- dated exit runbook before go-live
- DORA exit planning