What was said
What this says
Current to 10 Oct 26Jordan Pike followed up the Enterprise proposal with written security responses. Megan Alvarez, CISO, listed three open items and rejected best-effort wording. One support-staff logging control was still being rolled out.
Ask: Megan Alvarez wants confirmation that the incident disclosure is complete, the specific controls with implementation dates, and a named list of subprocessors with locations.
Customer view: she will not accept "best effort" language and gives no indication of the review outcome. Findings will come through procurement.
Next: Jordan Pike answered all three items on 28 May 2026, admitting one access-logging control was not yet complete, and proposed a short call. The deal was open and unsigned at that point.
The thread
Updated 9 Oct 26Messages
- Jordan Pike 20 May 2026 18:50Ben, Megan, Thanks for the time on the call today. Here's where we are, so we're all working from the same page. The Enterprise proposal is with you. It covers the first subscription term and the one-off implementation, built around giving your client-services teams one view of each hospital client, inside your own Snowflake account. To be transparent, the deal is still open and nothing is signed. Our working target for a decision is Tuesday 30 June 2026, but that depends entirely on your security review, and I'm not going to push on that. Megan, I've pulled together our written responses on the open findings from your review, plus the incident disclosure you asked for covering the last ninety days. I'd rather you hear about anything from us than find it yourself. If a finding isn't fully closed, I've said so plainly in the document. Two things I need from you both: - Megan, please tell me which findings are still open on your side, so I can get the right engineers to answer them directly. - Ben, who else at Quillmark needs to see the proposal before it goes to procurement? What would make this a yes? I'd like to hear it in your words, not mine. Thanks, Jordan
- Megan Alvarez 22 May 2026 09:50Jordan, Thank you for the written responses. For the record, I have read them against the scope we restated on the call. Our open items are as follows. First, the incident disclosure is received. Please confirm in writing that it is complete for the period requested, and that no incident has been omitted because it was judged immaterial. Second, the responses on encryption key management and on access logging for support staff describe intent in several places. Please provide the specific controls in place today, with the date each was implemented. Third, the response on subprocessors and data residency needs a named list and the location of each. I will not accept "best effort" language on items one to three. Our risk posture requires specific commitments that can be written into the contract and audited. I am not in a position to give any indication of the outcome of the review at this time. Findings will be communicated through procurement per our process. Megan Alvarez, CISO
- Jordan Pike 28 May 2026 09:38Megan, Ben, Here's where we are on Megan's three items. On the incident disclosure: our security lead has confirmed it is complete for the ninety-day period, and nothing was left out on materiality grounds. That confirmation is attached. On controls: I've replaced the intent language with the controls as they run today, with implementation dates. For the support-staff access logging, to be transparent, one control is still being rolled out. I've marked it as not yet complete rather than describing it as done, and the document gives the date it will be finished. On subprocessors and residency: the named list and locations are in the second attachment. Megan, if any of this still reads as best effort to you, tell me which line and I'll get it rewritten as a commitment or tell you straight that we can't give one. Ben, nothing needed from you this week, but a short call with the three of us would help if Megan is open to it. Thanks, Jordan