Is this your company?Buyers are checking Snowflake Computing LLC here. Claim snowflake.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Snowflake’s Compliance Center is an online portal that affords customers the ability to self-request and download Snowflake’s security compliance certifications, reports and attestations. Should you require any support please reach out to your Snowflake Account Team or go to https://www.snowflake.com/en/contact/ Compliance Center instructions and FAQ are included within the "Resources Tab".
Snowflake's Secure by Design Pledge Commitment OverviewJul 2025
Read full Security by Design Overview here: https://www.snowflake.com/en/resources/white-paper/snowflakes-secure-by-design-pledge-commitment-overview/ We’re pleased to announce the launch of Snowflake’s Secure by Design Overview, a single, comprehensive document that outlines our progress and future commitments under the Cybersecurity and Infrastructure Security Agency (CISA) Secure by Design Pledge, which we signed in 2024. Since signing the pledge, Snowflake has introduced new security features, announced additional upcoming capabilities, and remained actively engaged in the Secure by Design community. This document summarizes our progress to date and details our roadmap across the seven key commitment areas outlined in the pledge.
SOC2C shows the verified essentials. 7 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Snowflake Computing LLC SOC 2 compliant?
Snowflake Computing LLC is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Snowflake Computing LLC ISO 27001 certified?
According to Snowflake Computing LLC's public trust center, Snowflake Computing LLC is ISO 27001 certified. On SOC2C this listing is Listed.
Is Snowflake Computing LLC ISO 42001 certified?
According to Snowflake Computing LLC's public trust center, Snowflake Computing LLC is ISO 42001 certified. On SOC2C this listing is Listed.
Is Snowflake Computing LLC PCI DSS compliant?
According to Snowflake Computing LLC's public trust center, Snowflake Computing LLC is PCI DSS compliant. On SOC2C this listing is Listed.
Is Snowflake Computing LLC FedRAMP compliant?
According to Snowflake Computing LLC's public trust center, Snowflake Computing LLC is FedRAMP compliant. On SOC2C this listing is Listed.
Is Snowflake Computing LLC HITRUST certified?
According to Snowflake Computing LLC's public trust center, Snowflake Computing LLC is HITRUST certified. On SOC2C this listing is Listed.
Is Snowflake Computing LLC SOC 2 Type I or Type II?
Snowflake Computing LLC is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Snowflake Computing LLC's SOC 2 for a vendor risk assessment?
Yes. Snowflake Computing LLC's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Snowflake Computing LLC penetration tested?
Snowflake Computing LLC hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Snowflake Computing LLC secure?
Security isn't a single yes/no, but Snowflake Computing LLC is SOC 2 Type II compliant and holds ISO 27001, ISO 42001, SOC 2 Type II, PCI DSS, FedRAMP, HITRUST. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Snowflake Computing LLC have a bug bounty or vulnerability disclosure program?
Snowflake Computing LLC hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@snowflake.com or via a /security page.
Who are Snowflake Computing LLC's subprocessors?
Snowflake Computing LLC's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Snowflake Computing LLC host or store data?
Snowflake Computing LLC's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Snowflake Computing LLC's trust center or security page?
Snowflake Computing LLC's trust center is at https://trust.snowflake.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How to contact Snowflake
Please reach out to your Account Team for any additional assistance around security and compliance concerns or specific information regarding certifications and attestations. For general contact purposes please refer to the following link- https://www.snowflake.com/en/contact/
K-FSI (Korean Financial Security Institute) with RSEFT
The Korean Financial Security Institute (K-FSI) performs the CSP Safety Evaluation in order to evaluate cloud service provider compliance with the Regulation on Supervision of Electronic Financial Transactions (RSEFT) regulation. They support the financial services industry in security assessments and assist in various areas that help create a secure environment for financial institutions. Snowflake’s CSP Safety Evaluation is scoped to SaaS service controls. If customers will store or process unique private information (UPI) or protected credit information (PCI) on Snowflake or safety/reliability of electronic financial transactions are materially impacted by using Snowflake, then customers must review the CSP Safety Evaluation results and perform an analysis of vendor risk and submit documentation to the Financial Supervisory Service prior to utilizing Snowflake for these types of data.
TISAX (Assessment Level) AL 3
Developed by the ENX Association and published by the German Association of the Automotive Industry or VDA, Trusted Information Security Assessment Exchange or TISAX is a certification specifically designed to address the automotive industry’s cybersecurity requirements. TISAX focuses on the secure processing of information from business partners, the protection of prototypes and data protection in accordance with the General Data Protection Regulation (GDPR) for potential business transactions between automobile manufacturers and their service providers or suppliers. TISAX was established in 2017 by VDA and the ENX Association. All organizations involved in business with major German automotive industry partners must obtain a TISAX certification. Assessment Level 3 is required for data with a very high need for protection, such as data classified as confidential or secret. Snowflake’s TISAX is scoped to Information Security and Assessment Level 3. For more information, please visit the Official TISAX website.
Is Snowflake GxP Compatible?
GxP data integrity requirements (e.g.; 21 CFR 11) apply to life sciences organizations that produce regulated medical products including pharmaceuticals, medical devices, and mobile medical applications. Snowflake is GxP compatible, allowing life sciences customers to ensure data integrity and build GxP compliant solutions with the help of a secure, validated cloud data platform.
Is Snowflake FedRAMP authorized?
Yes, Snowflake is FedRAMP authorized in the SnowGov regions. It can be confirmed through the FedRAMP marketplace: https://marketplace.fedramp.gov/products. Snowflake Regions: https://docs.snowflake.com/en/user-guide/intro-regions#u-s-regions-supporting-public-sector-workloads
Is Snowflake GovRAMP authorized?
Yes. GovRAMP is a 501(c)6 nonprofit that standardizes security requirements for cloud offerings and verifies those cloud offerings for use by state and local governments and public education institutions through independent audits and continuous monitoring. The Snowflake offerings that are working towards or have achieved GovRAMP authorizations are included on the Authorized Product List. Snowflake maintains 3 deployments that are currently authorized or under review by the GovRAMP PMO for authorization: - Snowflake The Data Cloud on Azure Government - GovRAMP Moderate Authorized - Snowflake The Data Cloud on AWS - GovRAMP Moderate Authorized - Snowflake The Data Cloud on AWS GovCloud - GovRAMP High Authorized
Is Snowflake TX-RAMP authorized?
Yes. TX-RAMP provides a standardized approach for security assessment, authorization, and continuous monitoring of cloud computing services used by Texas state agencies. Texas state agencies can use Snowflake to comply with TX-RAMP. Snowflake currently maintains 4 deployments that are TX-RAMP Authorized: - Snowflake The Data Cloud on Azure - Level 2 Authorized - Snowflake The Data Cloud on AWS - Level 2 Authorized - Snowflake The Data Cloud on Azure Government - Level 2 Authorized - Snowflake The Data Cloud on AWS GovCloud - Level 2 Authorized You can find an up-to-date list of authorized products on the TX-RAMP website.
Is Snowflake DOD Impact Level 5 (IL5) authorized?
The U.S. military creates, stores, and operationalizes massive amounts of sensitive data. Protecting that data is a strategic priority and is the focus of the Department of Defense Impact Levels framework. This framework is used to categorize information systems and data and to indicate the security requirements that data is subject to. Snowflake has received Provisional Authorization (PA) by the Defense Information Systems Agency (DISA) at the U.S. Department of Defense (DoD) to operate at Impact Level 5 (IL5) on AWS GovCloud. Agencies may download Snowflake’s DoD package from eMASS. Snowflake has received Provisional Authorization (PA) by the Defense Information Systems Agency (DISA) at the U.S. Department of Defense (DoD) to operate at Impact Level 5 (IL5) on AWS GovCloud. Agencies may download Snowflake’s DoD package from eMASS
Is Snowflake CJIS compliant?
Snowflake’s SnowGov Regions are ready and able to support customer compliance with the FBI’s Criminal Justice Information Services (CJIS) Security Policy. The CJIS Security Policy provides federal and state agencies with a unified set of standards for the protection and safeguarding of Criminal Justice Information (CJI) in the cloud. Snowflake recognizes the importance of protecting CJI and works collaboratively with customers to satisfy CJIS requirements.
Does Snowflake follow IRS Publication 1075 standards?
Internal Revenue Service (IRS) Publication 1075 (IRS 1075) outlines the policies, practices, controls and safeguards to be employed by federal, state, and local agencies and contractors handling Federal Tax Information (FTI). Snowflake supports customer compliance with IRS 1075 in our FedRAMP-authorized SnowGov Regions. While there is no official certification for IRS 1075, Snowflake follows IRS Publication 1075 standards and works closely with our customers to meet the IRS’s stringent regulatory requirements for the protection and safeguarding of FTI. For more information, please visit the IRS Safeguards Program webpage on Cloud Computing.
Is Snowflake ITAR compliant?
International Traffic in Arms Regulations (ITAR) state that non-US persons are prohibited from physically or logically accessing the ITAR environment. A Third-Party Assessment Organization (3PAO) performed an audit to confirm that Snowflake’s Microsoft Azure Government (MAG) and AWS GovCloud deployments provide an environment compliant with ITAR.