SECURITY & TRUST
Built to pass your security review
Theom deploys inside your own account through a scoped read-only identity, analyzes data in place, and never extracts your record data. The evidence a review asks for is on this page.
Customer-controlled by design
Theom integrates with your environment through a customer-controlled deployment inside your account. Customer record data is analyzed in place using your own compute and is not copied into a secondary Theom repository. Connectivity is encrypted, access is limited by role and network policy, and processing is isolated on dedicated compute.
What a review needs to see
Least privilege
A single scoped service identity with USAGE and SELECT only on the approved scope. No write, delete, alter, ownership, or grant on your business data, and no ACCOUNTADMIN or SYSADMIN. Objects outside the granted boundary stay invisible.
In-place classification
Classification runs on your own compute, through a read-only identity, on a schedule. Findings and aggregated metadata are written to a customer-owned database inside your account.
No record-data extraction
Customer record data remains inside your account and is not copied into a secondary Theom raw-data repository.
Encrypted, network-scoped connectivity
Snowflake drivers over TLS 1.3, a network policy permitting only Theom’s fixed source addresses, RSA key-pair authentication preferred, and optional same-cloud PrivateLink.
Dedicated, isolated compute
Processing runs on a dedicated warehouse so discovery and classification are isolated from production workloads, with auto-suspend and resizing under your control.
Reversible
Rollback can suspend the task, disable the identity, remove the network route, revoke grants, and remove Theom-owned objects under your change procedures.
Reference architecture
The full deployment and boundary architecture is public, not sent on request.
See how Theom runs and what crosses the boundaryAssurance and testing
The reference architecture and the deployment detail on this page are public. The SOC 2 Type II report, penetration-test results, and customer references are shared under NDA.
SOC 2 — Theom holds a SOC 2 Type II report, available under NDA.
Independent penetration testing — the most recent assessment was completed within the last twelve months; the report or executive summary is available under NDA.
Customer references — Theom supports regulated financial-services, healthcare, insurance, and other enterprise customers; references can be coordinated on request.
Holds & supports
Holds & supports
SOC 2
Certified. Type II, audited annually.
GDPR
Supported. EU data protection.
EU AI Act
Supported. Conformity aligned.
Coverage you can evaluate
Theom maps its detections to industry frameworks, so you can judge breadth at review time instead of reading through a full rule list. See coverage at the framework level, plus a handful of distinctive detections that show where Theom goes further.
MITRE ATT&CKMITRE ATT&CK — 64 detections across Snowflake and Databricks, mapped to the enterprise matrix, with named tactic coverage across Initial Access, Reconnaissance, Collection, Defense Evasion, and Exfiltration.
CIS BenchmarksCIS Benchmarks — 101 controls: 65 against Databricks, 36 against Snowflake.
Distinctive detectionsSix detections that come from watching inside the store, where the query, the identity, and the data are all visible at once:
- Shadow AI activity, told apart from the person whose credentials it uses
- Which tables, views, and columns reach AI services, each tagged by sensitivity
- Platform-weakening configuration changes, such as a network policy edited, an external stage created, or a provisioning token issued, each tied to the identity behind it
- The concrete signals of exfiltration, from bulk exports and copy-outs to oversized interactive downloads and secrets left in query text
- Masking-policy conflicts, where an identity can still read what a policy was meant to mask
- Production-to-non-production data flows, traced through lineage rather than inferred from configuration
Common questions
Where does Theom run, and does our data leave?
Theom runs inside your own account on your own compute. Customer record data is analyzed in place and never copied to a secondary Theom repository. Findings and object metadata are resolved for display and not retained outside your environment.
What access does Theom have?
A single scoped, read-only service identity with USAGE and SELECT only on the scope you approve. No write, delete, alter, ownership, or grant on your data, and no account-admin privileges. Objects outside the granted boundary remain invisible.
Does Theom hold a SOC 2 report?
Yes. Theom holds a SOC 2 Type II report, available under NDA. Theom also runs independent penetration tests, with the most recent assessment completed within the last twelve months and the report available under NDA.
How long does deployment take, and can we roll back?
Once approvals are complete, deployment takes about an hour: objects created, the identity granted, and the first classification running. Rollback can suspend the task, disable the identity, remove the network route, revoke grants, and remove Theom-owned objects under your change procedures.
Deploy with confidence
We will walk your reviewers through the deployment on your own environment.
Book a Demo