Snowflake Cortex
low riskAI Infrastructure / Managed LLM Servicessnowflake.comverified 2024-05-22
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Customer data is processed ephemerally; Snowflake does not retain customer prompts or completions for service improvement or model training.
- Data region
- Customer-defined (Multi-region support in AWS, Azure, GCP)
- Certifications
- SOC 1 Type IISOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018FedRAMP Authorized (High)HIPAAPCI DSS
- DPA available
- Yes
- Breach history
- Snowflake experienced a high-profile incident in May 2024 involving unauthorized access to individual customer environments due to compromised credentials; however, this was an identity-based access issue rather than a compromise of the Snowflake Cortex AI model infrastructure itself.
- EU AI Act
- Snowflake aligns with GDPR and provides transparency documentation for AI features; classification under EU AI Act is managed via internal AI governance frameworks for enterprise providers.
Sources
- https://www.snowflake.com/legal/privacy-policy/
- https://www.snowflake.com/trust-center/
- https://docs.snowflake.com/en/user-guide/snowflake-cortex/llm-functions
- https://www.snowflake.com/blog/snowflake-cortex-ai-trust-security/
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.