What each block reads, and where it runs
We would rather you read this page than trust a badge. It says where each block runs, what it touches, and what we do not claim.
Block by block
- Assess
- Where it runsIn private preview. Shown on your account in a walkthrough.
- What it readsAccount metadata, not your business data.
- Plan
- Where it runsThe same web application as Estimate.
- What it readsThe estimate you approved, and the progress your team records.
- Deliver
- Where it runsAgents: on your engineer's machine, inside the project's repository. Migration accelerator: two containers or a desktop application, on your network.
- What it readsAgents: only what their policy allows, and never a credentials file. Migration accelerator: the source and target databases you connect.
- Observe
- Where it runsInside your Snowflake account, as a Native App.
- What it readsWarehouse and query activity, with the privileges of the person using it.
- Optimize
- Where it runsIn development, as a hosted control plane.
- What it readsMetadata across your accounts.
What we do not claim
We do not claim SOC 2, ISO 27001 or any other certification today.
If an audit is completed, we will publish its scope and its period. We will not show a badge before it is valid.
Where AI is used
Deliver runs on Snowflake's Cortex Code, on your own Snowflake connection.
Observe has an experimental profiler that sends query execution evidence to Snowflake Cortex. It is off until you turn it on.
We do not use customer data to train public or shared AI models unless you agree in writing.
Your part
You choose the roles, you read the privileges before granting them, and you approve changes before they reach production.
For an agent, a read-only role is the only real guarantee. Our checks read the statement. They cannot see what a view or a policy does inside Snowflake.
Reporting a problem
Write to contact@crithink.io. Tell us what you saw and how to reproduce it, and leave out any secret.
Please do not test against data that belongs to someone else.
A question for your security review? Ask it here
It goes straight to the founders. We reply within 24 hours.