What it says
What this says
Current to 11 Oct 26Completed security questionnaire for Marrowby Foods, answered by Hannah Lowe on 20 Sep 2026. It states a P1 first response of one business hour for Growth, TLS 1.2 minimum, UK data in the customer's Snowflake account, and SAML 2.0 single sign-on for Growth at no extra cost.
What it is: a final, completed security questionnaire in the Marrowby Foods security folder, written by Hannah Lowe, Solutions Engineer at BB-Demo. It is a set of answers, not a contract, and states no price.
Commits: it states a first response to critical issues "within one business hour", escalation to engineering within two hours and a root cause summary within 24 hours. Logs are retained for 90 days and data stays in the customer's UK Snowflake account.
Unusual: it offers SAML 2.0 single sign-on for "Growth tier and above at no extra cost". The standard tier list places SSO and SCIM at Enterprise, so this needs checking against the order form. The provisioning answer says "SCML", which looks like a typo for SCIM.
Not settled: the document does not say which tier Marrowby Foods holds, whether answers are contractual, or who at the customer asked for it.
As found in this document
Current to 9 Oct 26- Critical incident first response (Growth tier)within one business hourSource: object_read:doc_049_001
- Escalation to engineeringwithin two hoursSource: object_read:doc_049_001
- Root cause analysis and summarywithin 24 hoursSource: object_read:doc_049_001
- Deprovisioningon request within one business dayon request within one business day · Source: object_read:doc_049_001
- Audit log retentionLogin and data access logs retained for 90 daysLogin and data access logs retained for 90 days · Source: object_read:doc_049_001
- Encryption in transitTLS 1.2 minimumSource: object_read:doc_049_001
- Data locationEntirely within your Snowflake account in your chosen geographic region (UK)Entirely within your Snowflake account in your chosen geographic region (UK) · Source: object_read:doc_049_001
The document
Body
Marrowby Foods - Security Questionnaire
Status: Final Completed: 20 Sep 2026
1. Access and Identity Management
| Question | Answer |
|---|---|
| What authentication methods do you support? | Multi-factor authentication is standard. We support SAML 2.0 single sign-on for Growth tier and above at no extra cost. |
| How are users provisioned and deprovisioned? | User provisioning via SCML or manual invite through our admin interface. Deprovisioning on request within one business day. We recommend a quarterly access review process. |
| What is your admin access model? | Role-based access control. Admins can manage users, configure connectors and view usage metrics. We recommend two named admins minimum for operational resilience. |
2. Data Protection and Encryption
Read the whole document (2,409 characters)
| Question | Answer |
|---|---|
| What encryption applies to data in transit and at rest? | Transport layer security: TLS 1.2 minimum. Data at rest: encrypted within your Snowflake account using Snowflake native encryption and your own encryption keys. We do not hold your keys. |
| How is backup data encrypted? | All Snowflake backups inherit the encryption of the source data. Encryption key management remains your responsibility. |
| Where is customer data stored? | Entirely within your Snowflake account in your chosen geographic region (UK). We maintain no separate data centres or copies. |
3. Incident and Risk Management
| Question | Answer |
|---|---|
| What is your incident response time for Growth tier? | First response to critical issues within one business hour. Escalation to engineering within two hours. Root cause analysis and summary within 24 hours. All incidents logged and reviewed monthly. |
| Do you carry professional indemnity insurance? | Yes. Our cyber liability and professional indemnity insurance covers data handling and service delivery. Details available on request. |
4. Compliance
| Question | Answer |
|---|---|
| Are you GDPR compliant? | Yes. Compliant as a data processor under GDPR Article 28. Standard Data Processing Agreement included in our MSA. |
| Do you provide audit logs? | Yes. Login and data access logs retained for 90 days, accessible through your Snowflake account. Extended retention available on request. |
Completed by: Hannah Lowe, Solutions Engineer, BB-Demo Date: 20 Sep 2026
Unusual terms
Current to 9 Oct 26- SAML 2.0 SSO for Growth tier at no extra cost
- Root cause summary within 24 hours
- Escalation to engineering within two hours