What was said
What this says
Current to 10 Oct 26After the 17 Apr 2026 demo, Quillmark's CISO Megan Alvarez set four written security questions and stated that nothing discussed was an approval. Jordan Pike replied on 21 Apr 2026 that Hannah Lowe would answer in writing.
Ask: Megan wants written answers on which systems connect, whether patient data leaves Snowflake, incidents in the last ninety days, named accountable owners, and which controls are contractual rather than practice. She wants all of it before the review moves forward.
Customer view: She is formal and guarded, and asked that the demo not be described internally as an approval. Ben Kowalski and Dana Whitcombe have no role in the review for now.
Next: Hannah owes written answers to all four questions. Jordan has put the working session for Dana's client-services leads on hold, and the 30 Jun 2026 close date is only a forecast placeholder.
The thread
Updated 9 Oct 26Messages
- Jordan Pike 17 Apr 2026 15:14Hi all, Thanks for the time today. Here's where we are after the demo, and what I think happens next. What we showed: the brain running on your own data, giving a client-services lead one view of each hospital client. Dana, I know your leads asked what that looks like on a Monday morning. I'm happy to set up a short working session just for them, with real examples from their accounts. What's open: the security review. Megan, Hannah runs every Enterprise review on our side, so she's copied here. To be transparent, the fastest way through is for you to send me your questions in one list, and Hannah will answer each one in writing rather than on a call. Our working plan has the deal expected to close on 30 Jun 2026, but that date depends entirely on your review, so please treat it as a placeholder for our forecast and nothing more. What would make this a yes? I'd rather ask than guess. Thanks, Jordan
- Megan Alvarez 17 Apr 2026 18:04Jordan, For the record, nothing discussed today constitutes an approval, and I would ask that it not be described as one internally or on your side. Our review remains open. Please respond in writing to the following: Question one: Please confirm which of our systems would be connected, and whether any data containing patient information would leave our Snowflake account at any point, including for logging or support. Question two: Please describe any incidents in the last ninety days, including anything affecting availability, data handling or access control, whether or not a customer was affected. Question three: Please provide your written security documentation and name the person at B-Brain accountable for each answer. Question four: Please state which of these controls are contractual commitments and which are practice. "Best effort" is not an answer we can accept. Our risk posture requires that I have all of this before the review moves forward. Megan Alvarez, CISO
- Jordan Pike 21 Apr 2026 09:31Megan, Thank you for the list, and understood on the approval point. Nothing from our demo should be read as a decision. That sits with you. Here's where we are on your four questions. On question one, B-Brain is built and run inside your own Snowflake account, so your data stays in your environment. I don't want to paraphrase the detail on logging and support access, though. Hannah will set it out precisely in writing. On question two, I'm not going to answer the incident question from memory. Hannah is pulling the history together and will confirm it in writing, including anything we'd rather not have to say. On questions three and four, Hannah will send the documentation and mark each control as contractual or not. If something is practice rather than a commitment, she'll say so. Ben, Dana, nothing needed from you on this for now. Dana, I'll keep the working session for your leads on hold until Megan's review is further along, so we don't get ahead of it. Thanks, Jordan