This page describes the Observe by Snowflake AI data security measures and practices.

Zero data retention (ZDR)

Q: Zero Data Retention: Where does the ZDR policy apply?

A: The ZDR policy applies to all of Observe by Snowflake AI features.

Encryption

Q: Is data encrypted in transit to AI providers? What encryption standards?

A: All requests to external providers are encrypted in transit using TLS v1.2+.

Audit logs

Q: What audit capabilities exist for tracking AI queries and data access?

A: All AI queries and data access are done using the users context and are audited and tracked to the user as per our standard audit capabilities.

Opt-out

Q: Can AI features be disabled at workspace/organization level?

A: Yes.

MCP Server security

Q: What additional security controls exist for MCP Server given higher risk?

A: MCP Server uses OAuth authentication. Observe by Snowflake never sees the IdP password. The MCP server uses the user’s token. See OAuth authentication for the MCP Server​.

Prompt injection

Q: What protections exist against prompt injection attacks in AI SRE?

A: We use the prompt injection protection provided by the AI models we leverage for prompt processing. Observe by Snowflake also puts some additional protections in place to prevent misuse of the AI for non-AI SRE related tasks.

All customer queries against their data in Observe by Snowflake are done in the context of the user Role Based Access Controls (RBAC) of the user and thus will be limited to the scope and access that the user is provided.

Model updates

Q: How are changes to underlying AI models communicated and assessed?

A: Changes to AI models are driven through our standard development and testing lifecycle before release and may also include an early access period where user feedback is collected and used to assess the quality. Customer data is never used to update or train any of our AI models.




Did this page help you?