What was said
What this says
Current to 10 Oct 26Megan Alvarez, CISO, asks Jordan Pike for a written statement of incidents in the last ninety days, covering availability, freshness, integrity and unauthorised access. She wants a reply by end of day tomorrow.
Ask: four numbered points covering events, access, root cause and fixes, and customer notification. Every item must be answered explicitly, even if there is nothing to report.
Customer view: Megan will not accept a general assurance and needs a statement to file with the review. The thread, dated 23 Jul 2026, shows the vendor review still being worked.
Next: Jordan must coordinate a written, itemised answer quickly.
The thread
Updated 9 Oct 26Messages
- Megan Alvarez 23 Jul 2026 13:00Jordan, For the record, I am working through the open findings on BB-Demo's vendor review and need to close out the incident section before it goes further within Quillmark Health. Please describe any incidents in the last ninety days, in writing, covering the following: 1. Any event affecting availability, data freshness or data integrity for any customer environment, whether or not it was classified as a security incident. 2. Any event that involved unauthorised access, or suspected unauthorised access, to customer data or to the Snowflake accounts the brain runs in. 3. For each item above, the date it began, the date it was resolved, the root cause, and what was changed to prevent a repeat. 4. Whether any customer was notified, and how. If there is nothing to report under a given number, please say so explicitly rather than leaving it blank. I cannot accept "best effort" or a general assurance as a response. Our risk posture requires a statement I can file with the review. I would appreciate a reply by end of day tomorrow if that is feasible. If you need Hannah or anyone else on your side to contribute, please include them. Megan Alvarez, CISO