What was said
What this says
Current to 10 Oct 26Ben Kowalski sent security's follow-ups on HIPAA scope, data residency and nightly refresh logging. Jordan Pike answered the Snowflake-native point and promised written security answers. Ben gave no timeline.
Ask: Ben needs plain facts to hand to his security team on HIPAA scope, where data lives and who can reach it, and how refresh and logs work. He says these decisions are not his.
Customer view: He valued the straight answer and the Snowflake-native point, which he has been repeating internally. Security holds a standard questionnaire he will share once cleared.
Next: Jordan owes a written security response. Ben cannot give a timeline because security and procurement decide.
The thread
Updated 9 Oct 26Messages
- Ben Kowalski 23 Feb 2026 17:20Jordan, Quick one, and it's a bit of a list. Our security team came back after the last session with follow-ups, and I need to be able to answer them cleanly. First, HIPAA scope. Which parts of BB-Demo would actually touch protected health information in our setup? Is it just the connectors we point at the brain, or does anything else in your side of things see it? Second, data residency. Everything sits in our Snowflake today. Can you confirm in plain terms where the data lives and who can reach it, including your own staff? Third, they want to know how the nightly refresh and the logs work from a compliance point of view. I know these aren't mine to decide, I just need the facts to hand them. Thanks. Ben
- Jordan Pike 23 Feb 2026 19:32Hi Ben, Thanks for sending these. To be transparent, I'll answer what I can and flag what I can't. What I can say plainly: BB-Demo is built and run inside your own Snowflake account. The data stays in your account, and the sources you connect are the only things the brain reads. That's the architecture, and it's why a lot of regulated buyers like it. Where the data physically sits is whatever region your Snowflake account is in. If you need a dedicated US data residency arrangement on top of that, that's an add-on we can scope with you. What I'm not going to guess at: the exact HIPAA scoping language, who on our side could reach your environment and under what controls, and the detail on logging. Those answers need to come in writing from our security people, and I don't want to paraphrase them from memory to your security team. That's the wrong way to do it. Here's what I'll do: send your three questions to our security team tonight and ask for a written response. I'll forward it to you as soon as I have it, and I'll tell you if any part is thin. If your security team has a standard questionnaire, send it over and I'll route that too. What would make this easier for them? Thanks, Jordan On 23 Feb 2026, at 17:20, Ben Kowalski wrote: > Which parts of BB-Demo would actually touch protected health information in our setup?
- Ben Kowalski 24 Feb 2026 14:58Jordan, Appreciate the straight answer, and the Snowflake-native point helps. That's the story I've been telling internally. Security does have a standard questionnaire. I'll send it over once they've signed off on me sharing it. Written answers are what they'll want, so thanks for not winging it. One thing to be upfront about: I can't give you a timeline on this. It goes through security and procurement, and I don't override either of them. I'll let you know the moment I hear something. Ben