Quillmark Health: documents logo

Security review session - scheduling

Email thread

Quillmark Health: documents logo Quillmark Health: documents · sales

Hannah Lowe offered a working session on open security findings. CISO Megan Alvarez accepted Tuesday at 10:00 Eastern but set strict terms: written incident disclosure beforehand, no product walkthrough, and no approval implied.

What was said

What this says

Current to 10 Oct 26

Hannah Lowe offered a working session on open security findings. CISO Megan Alvarez accepted Tuesday at 10:00 Eastern but set strict terms: written incident disclosure beforehand, no product walkthrough, and no approval implied.

Ask: Hannah proposed a session covering the architecture diagram, the access model and each open finding. Megan accepted Tuesday at 10:00 Eastern with two team members, limited to the open findings.

Customer view: Megan will not treat anything said on the call as confirmation and wants incidents in writing before the session. She rejects "best effort" for controls touching patient data and will not share her review scoring.

Next: BB-Demo owes written incident disclosure and the architecture diagram ahead of the session, with customer-side dependencies stated explicitly.

AI · claude-sonnet-5-5 · 10 Oct 2026

The thread

Updated 9 Oct 26
Typesales
Messages2
First message2026-07-01
Last message2026-07-02

Messages

  1. Hannah Lowe
    Hannah Lowe 1 Jul 2026 15:07
    to Megan Alvarez
    Hi Megan, Following our last call, I'd like to find a time for a working session on the security review. You asked what we could put in writing and what we could only show live, so I thought it best to ask what you most need to know before I plan the agenda. To be precise, here is what I can cover: - the architecture diagram, showing that BB-Demo runs inside your Snowflake account, so the data does not leave your environment - the access model, including who at BB-Demo can see what, and how that is logged - each of the findings you've left open, one at a time, with the written answer beside it The short answer on incidents is that I'll give you our disclosure in writing, not on the call. The longer answer is that I'd like to walk through it with you so you can ask follow-ups, then send the written version straight after. I'll put that in writing either way. I can do Monday or Tuesday next week at 10:00 or 15:00 Eastern. Please bring whoever on your team should be in the room. If any of your questions go beyond what I can answer with confidence, I'll check with a colleague on our security side and come back to you, rather than guess. Thanks, Hannah Hannah Lowe Solutions Engineer, BB-Demo
  2. Megan Alvarez
    Megan Alvarez 2 Jul 2026 16:37
    to Hannah Lowe
    Hannah, Thank you for your note of 1 Jul 2026. Responses below, numbered for ease of reference. 1. Timing: Tuesday at 10:00 Eastern works. Two members of my team will attend. 2. Scope: for the record, the session should be limited to the open findings from our review. Please do not plan a general product walkthrough. 3. Incidents: please describe any incidents in the last ninety days in writing, before the session, so my team can read it in advance. A verbal summary will not be sufficient for our risk posture, and I will not be able to treat anything said on the call as confirmation. 4. Controls: where an answer depends on a customer-side configuration, please say so explicitly. "Best effort" is not an answer we can accept for a control that touches patient data. 5. Follow-up: please send the architecture diagram with the written answers, not after the session. Please note that I do not share the scoring of our review with vendors, and this session does not change that. It also does not constitute an approval. Megan Alvarez, CISO

BB-Demo is a fictional company; every organisation and person here is invented. B-Brain is the tool. Built by site/build_site.py from the site tree, data as of Fri 9 Oct 2026. Help & Support

Help & Support

Open as a page

Help & Support

B-Brain is one place to read everything the company knows about its customers: the CRM, calls, emails, support tickets, product usage, invoices, documents, news and HR. Every page is built from those systems and the data is current to Fri 9 Oct 2026.

How to use the site

How to ask

Press Ask Brain in the header. Type a question, or pick one of the examples.

The site itself does not call an AI model; answers in Claude come from the same figures you see here.

What the data covers

DataRecords
Organisations75
People at customers290
BB-Demo staff40
Calls784
Email threads1,169
Support tickets449
Documents477
Deals117
Invoices101
Events49
News items56

Data as of Fri 9 Oct 2026. Text marked AI was written by the brain from the records listed in its made-from link; an AI output that cannot cite its evidence is refused and the previous text kept. Where two systems disagree (for example a contract and the CRM), the key facts show both values and mark the difference.

BB-Demo is a fictional company: every organisation, person and figure here is invented for this demonstration. B-Brain is the tool that reads its data.

Who to contact

Email support@b-brain.example or talk to your B-Brain account team. Tell us the page address and what looked wrong; a screenshot helps.

Ask B

Ask B

B-Brain · read-only