What it says
What this says
Current to 11 Oct 26BB-Demo's answers to a security questionnaire for Strandvig Energi on the Growth tier, dated 6 Oct 2026. It quotes a four-hour response for non-urgent queries, one hour for high-priority issues and a 07:00 nightly refresh. It states no availability percentage and no price.
What it is: a version 1 questionnaire marked Final, dated 6 Oct 2026, answered by BB-Demo for Strandvig Energi on the Growth tier. The stored author is Hannah Lowe, Solutions Engineer.
Commits: "Growth tier includes email support with a four-hour response time for non-urgent queries and one-hour response for high-priority issues." Nightly refresh is "completed by 07:00 your local time each business day".
Unusual: security incidents are acknowledged within four business hours, with a full report within one business day. SSO and query-level logging are Enterprise features, so this Growth answer excludes both.
Not settled: availability is only "our standard availability commitment", with no percentage. It is not a contract, states no price, and does not say whether Strandvig Energi has asked for SSO or deeper logging.
As found in this document
Current to 9 Oct 26- Non-urgent support responsefour-hour response time for non-urgent queriesfour-hour response time for non-urgent queries · Source: object_read:doc_057_001
- High-priority responseone-hour response for high-priority issuesone-hour response for high-priority issues · Source: object_read:doc_057_001
- Nightly data refreshcompleted by 07:00 your local time each business daycompleted by 07:00 your local time each business day · Source: object_read:doc_057_001
- AvailabilityGrowth tier guarantees our standard availability commitmentGrowth tier guarantees our standard availability commitment · Source: object_read:doc_057_001
- Security incident acknowledgementacknowledged within four business hoursacknowledged within four business hours · Source: object_read:doc_057_001
- Incident reportA full incident report is provided within one business dayA full incident report is provided within one business day · Source: object_read:doc_057_001
- Audit log retentionretained for twelve monthsSource: object_read:doc_057_001
- Encryption in transitTLS 1.2 or higherSource: object_read:doc_057_001
The document
Body
Strandvig Energi, Security Questionnaire
Version: 1 Date: 6 October 2026 Status: Final
Data Handling and Residency
| Question | Answer |
|---|---|
| Where is my data stored? | Your data remains in your own Snowflake account in your chosen AWS, Azure or Google Cloud region (typically Northern Europe for Danish customers). BB-Demo runs as an application inside your Snowflake instance. Your data does not leave Snowflake. |
| Is my data encrypted? | All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted per your Snowflake and cloud provider configuration. |
| Can I choose my data region? | Yes. You select your Snowflake region and cloud provider, and BB-Demo runs in the same region. |
Access and Permissions
Read the whole document (3,728 characters)
| Question | Answer |
|---|---|
| Who can access the data? | Only users you authorise can access BB-Demo. Your admins define which users see which data sources. Role-based access control is built in. |
| Can I restrict which teams see what data? | Yes. Admins can create data policies so that, for example, only your finance team sees financial data, and only sales sees opportunity pipeline. |
| How do I manage user access? | You invite users by email. Admins assign roles. Growth tier includes role-based access control and six-monthly access reviews. |
Authentication and Security
| Question | Answer |
|---|---|
| Is Single Sign-On available? | SSO (SAML 2.0) is included with Enterprise tier. For Growth tier, we recommend a standard email login with password policies enforced via your IT team. |
| Is multi-factor authentication (MFA) supported? | Yes. MFA can be enforced at the Snowflake account level and applies to all BB-Demo users. |
| How are passwords secured? | Passwords are hashed and salted. We enforce a minimum password complexity policy. |
Audit and Logging
| Question | Answer |
|---|---|
| Can I see who accessed what data? | Yes. A basic audit log shows login history and page views. Growth tier does not include detailed query-level logging (that's an Enterprise feature), but usage analytics are available via your dashboard. |
| How long are logs retained? | Audit logs are retained for twelve months and exported to your Snowflake audit schema for long-term retention under your control. |
Compliance and Support
| Question | Answer |
|---|---|
| Are you SOC 2 certified? | Yes. BB-Demo maintains SOC 2 Type II compliance. Certification details are available on request. |
| Is GDPR compliance included? | Yes. BB-Demo is GDPR compliant and a Data Processing Addendum is included with your contract. |
| What support will I receive? | Growth tier includes email support with a four-hour response time for non-urgent queries and one-hour response for high-priority issues. Quarterly business reviews are included to discuss usage and value. |
| What is your availability SLA? | Growth tier guarantees our standard availability commitment. Nightly data refresh is completed by 07:00 your local time each business day. |
Incident Response
| Question | Answer |
|---|---|
| How quickly do you respond to security incidents? | For Growth tier, security incidents are acknowledged within four business hours. A full incident report is provided within one business day. |
| Who do I contact if there is an incident? | Your account contact will notify you immediately. You can also escalate to our security team via support. |
Next Steps
If you have further questions, please contact the BB-Demo team or raise them with your Solutions Engineer. We are happy to arrange a security discussion and provide additional documentation as needed.
Unusual terms
Current to 9 Oct 26- Security incident acknowledgement within four business hours
- Full incident report within one business day
- Audit logs retained for twelve months
- SOC 2 Type II compliance stated