Skip to main content

Security & Trust

Enterprise data, governed and secure.

Viewnear builds in the client's Snowflake account, on Snowflake's independently audited platform (SOC 2 Type II and ISO 27001 across editions), and applies least-privilege access, PII classification, and Horizon Catalog lineage from the first table.

Compliance posture

Built on a certified foundation

We build on Snowflake's independently audited platform and extend it with our own governed delivery practices. The certifications below are Snowflake's, not Viewnear's. SOC 2 Type II and ISO 27001 apply across Snowflake editions; PHI and cardholder data need Business Critical or VPS, and PHI additionally needs a signed BAA with Snowflake before it is loaded.

SOC 2 Type II

Inherited from Snowflake

ISO 27001

Inherited from Snowflake

HIPAA

Snowflake Business Critical or VPS, with a BAA in place

PCI DSS

Snowflake Business Critical or VPS

FedRAMP

Snowflake Government regions

GDPR-ready

Regional deployment, access controls, and PII classification

Snowflake’s audited controls

  • SOC 2 Type II
  • ISO 27001
  • HIPAA (Business Critical or VPS)
  • PCI DSS (Business Critical or VPS)

Viewnear delivery practices

  • Least-privilege access
  • Lineage & auditability
  • PII classification
  • Secure delivery practices

Our practices

How we keep data safe

The controls we apply on every engagement by default, never as optional add-ons.

AccessCTRL-01

Least-privilege access

Role-based access control modeled to the organization, so people see only the data they need, enforced in Snowflake, not bolted on after.
LineageCTRL-02

Lineage & auditability

Horizon Catalog lineage and access history mean every figure is traceable to its source and every access is logged for audit.
PIICTRL-03

PII classification

Sensitive data is classified, masked, and protected with tagging and row/column policies from the first table we build.
ResidencyCTRL-04

Data residency by region

We deploy in the Snowflake region required across the Americas, so data stays where policy and regulators need it.
SecretsCTRL-05

Secrets & key management

Credentials and keys are managed through the cloud's secrets and KMS services: never hard-coded, never shared in the clear.
DeliveryCTRL-06

Secure delivery practices

Code review, least-privilege delivery accounts, and environment separation are standard on every engagement.

Governance

One governed foundation, not scattered copies

Most data risk comes from sprawl: exports, shadow copies, and ungoverned spreadsheets. We consolidate onto a single governed Snowflake platform so access, lineage, and policy live in one place that can actually be audited.

  • A single governed source of truth, not data spread across tools
  • Access, masking, and retention policy enforced centrally
  • Full access history and lineage for audit and incident response
  • Open table formats (Apache Iceberg), queryable by any engine, no re-platforming
Talk to our team
Data center server racks with fiber-optic cabling

By industry

Compliance where it counts

Regulated sectors carry specific obligations. We configure governance to the rules each industry answers to.

Financial services

FINRA, SEC, and SOX-aligned reporting with auditable lineage and segregation of duties built in by design.

Healthcare

HIPAA-aligned handling of clinical and patient data, with masking, access policies, and audit trails designed in.

Retail & payments

PCI-aware handling of payment and customer data, isolated and governed end to end.

Have a specific compliance or security requirement? Talk to our team and we'll walk through how we'd meet it.

Security questions before a build starts?

Tell us the requirements (data residency, certifications, audit, or vendor review) and we'll show exactly how we deliver against them.