What it says
What this says
Current to 11 Oct 26Security questionnaire for the Growth tier implementation, dated 2 Oct 2026, answered by BB-Demo. It states TLS 1.2 or higher, a 24-hour recovery point objective and incident reporting within 4 business hours. It carries no price and no contractual commitment.
What it is: a BB-Demo response to Ravensholt Capital's security assessment for a Growth tier implementation, version 1, stored as final. Hannah Lowe, Solutions Engineer, is the resolved BB-Demo author.
States: "Security incidents reported to your nominated contact within 4 business hours with root-cause analysis and remediation tracking." Recovery is "24-hour recovery point objective", and the platform is described as "SOC 2 Type II certified and GDPR-compliant".
Unusual: "We do not maintain separate audit logs" relies on Snowflake's audit system. Customer-managed keys are available only on request.
Not settled: it is a questionnaire answer, not an order form or DPA, so it sets no price, term or service level. The text does not show a customer signatory, a customer reviewer or whether Ravensholt accepted the answers.
As found in this document
Current to 9 Oct 26- Data in transitTLS 1.2 or higher for all data to and from Snowflake. API authentication via OAuth 2.0.TLS 1.2 or higher for all data to and from Snowflake. API authentication via OAuth 2.0. · Source: object_read:doc_037_001
- Backup and recoveryRecovery environment maintained with 24-hour recovery point objective.Recovery environment maintained with 24-hour recovery point objective. · Source: object_read:doc_037_001
- Incident responseSecurity incidents reported to your nominated contact within 4 business hours with root-cause analysis and remediation tracking.Security incidents reported to your nominated contact within 4 business hours with root-cause analysis and remediation tracking. · Source: object_read:doc_037_001
The document
Body
Ravensholt Capital, Security Questionnaire
Version 1 · 2 October 2026
Assessment of security and compliance controls for Growth tier implementation.
Control assessment
| Question | Answer |
|---|---|
| Data in transit | TLS 1.2 or higher for all data to and from Snowflake. API authentication via OAuth 2.0. |
| Data at rest | Encrypted within your Snowflake account using Snowflake's native encryption. Customer-managed keys available on request. BB-Demo retains no copies outside Snowflake. |
| Access control | BB-Demo runs inside your Snowflake account. Access governed by your Snowflake roles and permissions. Support staff have no standing data access; access granted only for debugging with customer consent. |
| Audit logging | All queries and access logged in Snowflake's audit system. We do not maintain separate audit logs. |
| Authentication | Growth tier supports username/password and SSO via your identity provider. Passwords are salted and hashed; plaintext never stored. |
| Segregation of duties | Admins manage users and connectors. Query results restricted to authorised users. Data pipelines run under restricted Snowflake roles with no human |
Read the whole document (1,778 characters)
read access. | | Backup and recovery | Handled by Snowflake. Recovery environment maintained with 24-hour recovery point objective. | | Compliance | SOC 2 Type II certified and GDPR-compliant. Data Protection Addendum available. | | Incident response | Security incidents reported to your nominated contact within 4 business hours with root-cause analysis and remediation tracking. |
Summary
BB-Demo meets the security and compliance standards expected for a Growth tier platform. We welcome discussion of any aspect of this assessment with your security team.
Unusual terms
Current to 9 Oct 26- No separate audit logs beyond Snowflake
- Customer-managed keys on request only
- Support access only with customer consent