Snowflake Cortex
low riskAI Infrastructure / Managed LLM Servicessnowflake.comverified 2024-05-22profile 85% complete
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Customer data is processed ephemerally; Snowflake does not retain customer prompts or completions for service improvement or model training.
- Data region
- Customer-defined (Multi-region support in AWS, Azure, GCP)
- Certifications
- SOC 1 Type IISOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018FedRAMP Authorized (High)HIPAAPCI DSS
- DPA available
- Yes
- Breach history
- Snowflake experienced a high-profile incident in May 2024 involving unauthorized access to individual customer environments due to compromised credentials; however, this was an identity-based access issue rather than a compromise of the Snowflake Cortex AI model infrastructure itself.
- EU AI Act
- Snowflake aligns with GDPR and provides transparency documentation for AI features; classification under EU AI Act is managed via internal AI governance frameworks for enterprise providers.
Sources
- https://www.snowflake.com/privacy-policy
- https://www.snowflake.com/trust-center/link no longer resolves
- https://docs.snowflake.com/en/user-guide/snowflake-cortex/llm-functions
- https://www.snowflake.com/blog/snowflake-cortex-ai-trust-security/link no longer resolves
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes. 2 of these 4 links no longer resolve. We record what we relied on rather than deleting it, so the trail stays auditable — but a struck-through source cannot be re-checked today.
Control mapping
Obligations this vendor triggers, each attributable to the fact it rests on — for your supplier register, not a compliance determination.
- EU AI Act Art. 50 — Transparency obligations for AI systemsok
trains_on_input = no. Vendor states inputs are not used for training.
- EU AI Act Art. 26 — Obligations of deployers of high-risk AI systemsapplies
Applies to your organisation as deployer, independent of vendor. Assign human oversight, keep logs, and monitor operation where this tool is used in a high-risk context (Annex III duties apply from 2 Dec 2027).
- ISO/IEC 27001 A.5.19 — Information security in supplier relationshipsapplies
Snowflake Cortex processes organisational data as a supplier. Include this vendor in the supplier register and risk assessment.
- ISO/IEC 27001 A.5.20 — Addressing information security within supplier agreementsok
dpa_available = true. A data processing agreement is available and should be executed.
- ISO/IEC 27001 A.5.22 — Monitoring, review and change management of supplier servicesattention
breach_history: Snowflake experienced a high-profile incident in May 2024 involving unauthorized access to individual customer environments due to compromised credentials; however, this was an identity-based access issue rather than a compromise of the Snowflake Cortex AI model infrastructure itself. Prior incident on record — justify continued use and monitor.
- ISO/IEC 27001 A.5.23 — Information security for use of cloud servicesapplies
Cloud AI service; trains_on_input = no. Define acceptable-use and configuration rules for this cloud service.
- ISO/IEC 42001 A.10.3 — Suppliers of AI systems and servicesapplies
certifications: SOC 1 Type II, SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, FedRAMP Authorized (High), HIPAA, PCI DSS No AI-management certification identified; assurance must come from your own supplier assessment.
- GDPR Art. 44–49 — International transfers of personal dataattention
data_region = Customer-defined (Multi-region support in AWS, Azure, GCP). Processing occurs outside the EU/EEA — a transfer mechanism (SCCs or adequacy) must be in place.
- NIS2 Art. 21(2)(d) — Supply chain securityapplies
AI vendor forms part of your ICT supply chain. In scope for entities covered by NIS2; include in supply-chain risk measures.
- DORA Art. 28 — General principles for ICT third-party riskapplies
AI vendor is an ICT third-party service provider. For financial entities: register of information and contractual requirements apply.
Change history
No material changes recorded since monitoring began.