Compliance frameworks, security audits, and quality certifications this company maintains.
Snowflake is SOC 2 Type II certified across all three cloud providers, with independent audits verifying security, availability, and confidentiality controls for enterprise data stored in Snowflake.
Snowflake holds ISO 27001 certification for its information security management system covering cloud infrastructure, data access controls, and incident response processes.
Regulatory
FedRAMP Moderate
CertifiedSnowflake is FedRAMP Moderate authorized on AWS GovCloud, enabling US federal agencies to store and analyze government data in Snowflake in compliance with federal security requirements.
Snowflake supports HIPAA-compliant configurations for healthcare customers, with Business Associate Agreements and data isolation controls for protected health information workloads.
Snowflake is PCI DSS Level 1 certified, enabling financial services and e-commerce customers to store and process payment card data within the Snowflake Data Cloud.
Snowflake provides GDPR compliance with EU data residency options, data subject access workflows, and signed Data Processing Agreements for customers processing EU personal data.
Snowflake holds ISO 27017 cloud security certification, extending its ISO 27001 controls with cloud-specific guidance for multi-tenant data platform deployments.
Snowflake maintains ISO 27018 certification for cloud privacy, providing organizations using Snowflake Data Cloud with assurance that personally identifiable information processed in Snowflake is handled according to international cloud data protection standards.
Snowflake complies with the California Consumer Privacy Act for data processed through the Snowflake Data Cloud, providing California-based organizations with appropriate data processing agreements and enabling customers to meet their own CCPA obligations using Snowflake.
Snowflake participates in the Cloud Security Alliance STAR Level 2 program with third-party assessment of security controls for the Snowflake Data Cloud, offering customers independent validation of cloud security practices aligned to the CSA Cloud Controls Matrix.