What it says
What this says
Current to 11 Oct 26Security questionnaire answers for Vossberg Logistik, version 1, dated 2 Nov 2025 and marked Final. Data stays in the customer's own Snowflake account, and Enterprise adds SSO, SCIM and audit logging. No availability percentage, P1 response time or price is stated.
What it is: BB-Demo's answers to a customer security questionnaire, covering architecture, encryption, access, compliance, incident response, backup and vendors. Hannah Lowe, Solutions Engineer, is the resolved author.
Commits: it states that "nightly refresh must complete by 07:00 your local time on business days, with service credits for breaches". It also states Enterprise security incidents are "acknowledged within thirty minutes", with a full response plan within four business hours.
Unusual: the availability commitment is described as "our highest availability commitment" with no percentage. The P1 response time is called "the fastest" with no figure.
Not settled: it is not an order form and states no price, term or renewal. It does not say which tier Vossberg Logistik holds, and it promises a further dedicated security review session without a date.
As found in this document
Current to 9 Oct 26- Availability (Enterprise)Enterprise tier guarantees our highest availability commitment, with service credits for breaches.Enterprise tier guarantees our highest availability commitment, with service credits for breaches. · Source: object_read:doc_056_001
- Data freshness (Enterprise)nightly refresh must complete by 07:00 your local time on business days, with service credits for breaches.nightly refresh must complete by 07:00 your local time on business days, with service credits for breaches. · Source: object_read:doc_056_001
- Security incident acknowledgement (Enterprise)investigated and acknowledged within thirty minutesinvestigated and acknowledged within thirty minutes · Source: object_read:doc_056_001
- Security incident response planA full response plan is provided within four business hours.A full response plan is provided within four business hours. · Source: object_read:doc_056_001
- Incident updatesupdates every two hours until resolutionupdates every two hours until resolution · Source: object_read:doc_056_001
- Rebuild after total data losswe can rebuild your brain within one business daywe can rebuild your brain within one business day · Source: object_read:doc_056_001
- Encryption in transitTLS 1.2 or higherSource: object_read:doc_056_001
- Offboarding with SCIMautomatically revokes BB-Demo access within minutesautomatically revokes BB-Demo access within minutes · Source: object_read:doc_056_001
The document
Body
Vossberg Logistik, Security Questionnaire
Version: 1 Date: 2 November 2025 Status: Final
Architecture and Data Residency
| Question | Answer |
|---|---|
| Where does BB-Demo store our data? | Your data remains in your own Snowflake account, in your chosen AWS, Azure or Google Cloud region. BB-Demo runs as a managed application inside your Snowflake instance. We do not copy, cache or store your data outside Snowflake. |
| Can data residency be restricted to a specific region? | Yes. With Enterprise tier, dedicated EU data residency is available as an add-on, ensuring all compute and metadata remain within your chosen EU region. |
| How are data flows managed? | Your Snowflake account connects to your source systems (CRM, call recordings, emails, finance, HR) via connectors you authorise. All connectors run inside your Snowflake account or your secure network. BB-Demo queries your data; we do not pull raw data to external infrastructure. |
Encryption and Data Protection
Read the whole document (5,482 characters)
| Question | Answer |
|---|---|
| Is data encrypted in transit? | Yes. All communication between your systems and Snowflake is encrypted using TLS 1.2 or higher. |
| Is data encrypted at rest? | Data at rest is protected according to your Snowflake security configuration and your cloud provider's encryption. BB-Demo does not control this; it remains your responsibility and follows your standards. |
| Who has encryption key management? | You retain full control of encryption keys via your cloud provider and Snowflake configuration. BB-Demo has no access to or control over key material. |
Access Control and Identity
| Question | Answer |
|---|---|
| Do you support Single Sign-On (SSO)? | Yes. Enterprise tier includes SAML 2.0 SSO and SCIM for user provisioning and lifecycle management. |
| How are permissions enforced? | Role-based access control is built in. Your admins configure which users can see which data sources, pages and dashboards. Permissions sync with your identity provider via SCIM. |
| Can we audit user access? | Yes. Enterprise includes comprehensive audit logging: who logged in, when, what they accessed, what queries they ran. All audit logs are retained and queryable. |
| What happens if a team member leaves? | With SCIM enabled, offboarding in your identity provider automatically revokes BB-Demo access within minutes. Manual de-provisioning is also available. |
Compliance, Standards and Certifications
| Question | Answer |
|---|---|
| Are you SOC 2 Type II certified? | Yes. BB-Demo maintains SOC 2 Type II compliance. Detailed certification reports are available under our standard NDA. |
| Do you comply with GDPR? | Yes. BB-Demo is fully GDPR compliant. A Data Processing Addendum (DPA) is included with your contract to define data processing terms in line with GDPR requirements. |
| Is a DPA provided? | Yes. Our standard DPA covers data processing, sub-processors, international transfers and data subject rights. It can be customised for regulated customers. |
| Do you work with regulated industries? | Yes. We work with financial services, healthcare and other regulated sectors. Security review and compliance customisation are standard for Enterprise tier. |
Incident Response and Support
| Question | Answer |
|---|---|
| What is your incident response time? | Security incidents affecting Enterprise customers are investigated and acknowledged within thirty minutes. A full response plan is provided within four business hours. |
| How are we notified of incidents? | We notify your security contact and technical account manager immediately, with updates every two hours until resolution. |
| What is your uptime SLA? | Enterprise tier guarantees our highest availability commitment, with service credits for breaches. Data freshness SLA is also included: nightly refresh must complete by 07:00 your local time on business days, with service credits for breaches. |
| What is your support model? | Enterprise includes a dedicated executive sponsor, a named technical account manager, and the fastest P1 response time. Optional Premium support adds a dedicated named engineer available 07:00–20:00 UK time. |
Backup, Disaster Recovery and Data Loss Prevention
| Question | Answer |
|---|---|
| Is disaster recovery included? | Your data is protected by Snowflake's native backup and replication. BB-Demo's configuration is version-controlled and recoverable. In the event of total data loss, we can rebuild your brain within one business day. |
| Can we perform a backup audit? | Yes. You can audit your Snowflake backups at any time. We can walk you through recovery procedures. |
Vendor and Third-Party Risk
| Question | Answer |
|---|---|
| Who are your sub-processors and vendors? | BB-Demo runs inside your Snowflake account and uses only your authorised cloud provider (AWS, Azure or Google Cloud). We do not use additional third-party data processors. A full vendor list is provided in our security documentation. |
| Can we audit your vendors? | Yes. Vendor security assessments and certifications are available for review. |
Next Steps
Please review this questionnaire and raise any further questions with our security team. We will schedule a dedicated security review session to walk through controls in depth and address any concerns specific to your environment or regulatory requirements.
Unusual terms
Current to 9 Oct 26- Availability commitment without a stated percentage
- Premium support 07:00–20:00 UK time as optional add-on
- Encryption at rest left to the customer's responsibility