What was said
What this says
Current to 10 Oct 26Nadia Osei, IT Security Lead, accepts a Thursday security working session but wants residency, admin access and connector credentials answered in a questionnaire. She will not set a sign-off date until the capacity providers have reviewed.
Ask: Hannah Lowe proposed a working session and asked what Nadia most needs and who else should join. Nadia asked for evidence on data residency, administrator access and logging, and connector credential storage and rotation.
Customer view: Nadia needs answers in writing because her capacity providers audit the controls. She says the session is not a commitment on timing, and she replied several days after Hannah's note of 17 Oct 2025.
Next: Hannah should answer in the questionnaire with evidence, not verbally. The evidence does not show which tier Fenmoor is on or whether a deal depends on this review.
The thread
Updated 9 Oct 26Messages
- Hannah Lowe 17 Oct 2025 11:28Hi Nadia, Thanks for your time on the call. As promised, I'd like to get the security review on the diary so it doesn't drift. The short answer on architecture is that the brain is built and run inside Fenmoor's own Snowflake account, so your data stays where your controls already apply. The longer answer is that you will want the detail on access control, how connectors authenticate and what is stored where. I'll put all of that in writing and walk you through it. Could you tell me what you most need to know, and who else at Fenmoor should join? It would help me to have the questionnaire your capacity providers expect, so I can answer it right first time rather than send you a generic pack. I could do a working session next Thursday or Friday, whichever suits you. Please say which, and I'll hold the time. Thanks, Hannah
- Nadia Osei 22 Oct 2025 17:53Hello Hannah, Thank you for the note, and apologies for the delay in replying. Thursday works for me, in the morning if possible. Before then, these are the open items I listed after our call: First, data residency. Can you evidence where the data and any derived indexes sit, for the audit trail? Second, access control. I need to see how administrator access is granted and removed, and how it is logged. Third, connector credentials. How are they stored and rotated? I will need your answers in the questionnaire rather than in conversation, as our capacity providers audit this and I cannot sign off a control on a verbal answer. I will send the questionnaire separately. One caveat: I won't set a sign-off date until the capacity providers have seen the pack, so please don't read the session as a commitment on timing. Kind regards, Nadia