2 unchanged sentences
Risk Management and Strategy
−Removed: We have implemented and maintain a cybersecurity program designed to identify, assess, and manage material risks from cybersecurity threats to (i) our information systems and data, which include critical computer networks, third-party hosted services, communications systems, hardware and software, and (ii) critical data, including our intellectual property, confidential information that is proprietary, strategic or competitive in nature, and our customers’ data.
−Removed: Our cybersecurity program includes an information security policy, access management policies, an open-source policy, security incident response processes, and a supply chain policy, in addition to the secure design and vendor management programs described below.
−Removed: For a description of the risks from cybersecurity threats that may materially affect us, see the risk factor titled “ If we, our customers, or third-party service providers experience an actual or perceived security breach or unauthorized parties otherwise obtain access to our customers’ data, our data, or our platform, our platform may be perceived as not being secure, our reputation may be harmed, demand for our platform may be reduced, and we may incur significant liabilities.
+Added: We have implemented and maintain a cybersecurity program designed to identify, assess, and manage material risks from cybersecurity threats to (i) our information systems and data, which include critical computer networks, third-party hosted services, communications systems, hardware and software, and (ii) critical data, including our intellectual property, confidential information that is proprietary, strategic or competitive in nature, and our customers’, vendors’, and partners’ data.
+Added: Our cybersecurity program includes an information security policy, access management policies, supply chain policies (which include open-source security review procedures), and security incident response processes, in addition to the secure design and vendor management programs described below.
+Added: For a description of the risks from cybersecurity threats that may materially affect us, see the risk factor titled “ We, our customers, or third-party service providers have in the past and may in the future experience an actual or perceived security breach, unauthorized access to data, or unintended operation of our products.
+Added: If any such event occurs, our products may be perceived as not being secure, our reputation may be harmed, demand for our products may be reduced, and we may incur significant liabilities.
” in the section titled “Risk Factors” included elsewhere in this Annual Report on Form 10-K.
1 unchanged sentence
our platform and our corporate systems.
−Removed: Each category has dedicated teams and processes in place to address cybersecurity risk.
−Removed: Our product security team, which reports into our SVP, Engineering and Support, works alongside our product and engineering teams to address how security is designed into our platform.
−Removed: Our corporate security team, which reports to our Chief Information Security Officer, is responsible for the secure design of our corporate systems.
+Added: Each category has dedicated teams and processes in place to address cybersecurity risk, and both our product security team and our enterprise security team report into our Chief Security and Trust Officer as a single, integrated security organization within Snowflake.
+Added: Our product security team works alongside our product and engineering teams to address how security is designed into our platform.
+Added: Our enterprise security team, led by our Chief Information Security Officer, is responsible for the secure design of our corporate systems.
In addition, our Chief Information Security Officer manages a global security team that performs certain cybersecurity functions for both our platform and corporate systems, including certification management, incident response, threat detection, analytics, and offensive security (such as simulations and penetration tests).
4 unchanged sentences
Our assessment and management of material risks from cybersecurity threats is a key risk area within our enterprise risk management program.
−Removed: Our Chief Information Security Officer and SVP, Engineering and Support are responsible for management of cybersecurity risk under our enterprise risk management program, and senior management and the audit committee of our board of directors receive reports on the key risks and the effectiveness of our management of such enterprise risks.
+Added: Our Chief Security and Trust Officer, Chief Information Security Officer, and SVP, Engineering and Support are responsible for management of cybersecurity risk under our enterprise risk management program, and senior management and the audit committee of our board of directors receive reports on key risks and the effectiveness of our management of such enterprise risks.
In addition, key cybersecurity risks are assessed as part of our internal audit program.
1 unchanged sentence
We also employ a shared responsibility cybersecurity model where our customers are responsible for using and configuring our platform in a manner that meets applicable cybersecurity standards and requirements.
−Removed: As part of this shared responsibility cybersecurity model, customers have sole responsibility for creating and securing their access credentials for our platform.
+Added: As part of this shared responsibility cybersecurity model, customers have sole responsibility for creating and securing the access credentials in their possession for our platform.
Our platform and corporate systems involve the use of third-party technology or service providers, or vendors, such as hosting platforms, open-source software, and application providers.
We also use vendors to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats to our platform and corporate systems, including consulting firms, external legal counsel, incident response vendors, penetration test providers, auditors, monitoring technology, and cybersecurity data providers .
−Removed: We have a vendor management program under which our corporate security, product security, and legal teams evaluate cybersecurity risks presented by our use of vendors.
+Added: We have a vendor management program under which our enterprise security, product security, and legal teams evaluate cybersecurity risks presented by our use of vendors.
Depending on the nature of the technology or services provided, the sensitivity of the information systems and data at issue, and the identity of the vendor, our vendor management process may involve different levels of assessment designed to help identify cybersecurity risks.
For vendors that may pose higher risks, this process includes a vendor security questionnaire, an evaluation of the vendor’s security program and security documentation, and the imposition of contractual obligations related to cybersecurity on the vendor.
−Removed: All vendors are required to undergo this review, which is in addition to the applicable security reviews that may be conducted by our product security and corporate security teams described above.
−Removed: Our board of directors has formed a cybersecurity committee of the board to assist it in fulfilling its oversight responsibility with respect to the management of cybersecurity risks related to our products and services as well as our information technology and network systems.
+Added: All vendors are required to undergo this process, which is in addition to the applicable security reviews that may be conducted by our product security and enterprise security teams described above.
+Added: Our board of directors has formed a cybersecurity committee to assist it in fulfilling its oversight responsibility with respect to the management of cybersecurity risks related to our products and services as well as our information technology and network systems.
The responsibilities of the cybersecurity committee include overseeing our implementation and maintenance of cybersecurity measures, data governance, compliance with applicable information security laws, and overseeing disclosure controls relating to cybersecurity.
The cybersecurity committee receives reports from management concerning our significant cybersecurity threats and risk and the processes we have implemented to address them and has access to various reports, summaries or presentations related to cybersecurity threats, risk, and mitigation.
−Removed: In addition, our audit committee has oversight responsibility over our internal financial controls and our enterprise risk management program.
+Added: In addition, the audit committee of our board of directors has oversight responsibility over our internal financial controls and our enterprise risk management program.
Finally, management periodically provides cybersecurity briefings to the entire board of directors .
−Removed: The members of management who are primarily responsible for assessing and managing our material risks from cybersecurity threats are our Chief Information Security Officer and our SVP, Engineering and Support.
+Added: The members of management who are primarily responsible for assessing and managing our material risks from cybersecurity threats are our Chief Security and Trust Officer, Chief Information Security Officer, and our SVP, Engineering and Support.
Our Chief Information Security Officer joined Snowflake in 2023 and previously served in various cybersecurity roles for over 12 years across multiple technology sectors, including manufacturing, software, and services.
−Removed: Our SVP, Engineering and Support joined Snowflake as VP of AI Engineering in 2023 in connection with our acquisition of Neeva, where he served as the head of engineering and, prior to that, he served in various roles at Google, including as VP Engineering in various technical leadership roles.
−Removed: Each of our Chief Information Security Officer and SVP, Engineering and Support is responsible for hiring appropriate personnel, integrating cybersecurity risk considerations into our overall risk management strategy, communicating key priorities to relevant personnel, approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports.
+Added: Our Chief Information Security Officer reports to our Chief Security and Trust Officer, who joined Snowflake in 2026 from Google, where he spent 21 years and most recently served as VP of Engineering responsible for security across its cloud infrastructure and platform.
+Added: Our Chief Security and Trust Officer reports to our SVP, Engineering and Support, with a secondary reporting relationship to our Chief Information Officer.
+Added: Our SVP, Engineering and Support joined Snowflake as VP of AI Engineering in 2023 in connection with our acquisition of Neeva, where he served as the head of engineering and, prior to that, served in various roles at Google for over a decade, including as VP of Engineering in various technical leadership roles.
+Added: Our Chief Information Officer joined Snowflake in 2025 from J.P.
+Added: Morgan, where he served as Chief Information Officer of Payments, and has over 35 years of experience managing information systems in the technology industry.
+Added: Each of our Chief Security and Trust Officer, Chief Information Security Officer, and SVP, Engineering and Support is responsible for hiring appropriate personnel, integrating cybersecurity risk considerations into our overall risk management strategy, communicating key priorities to relevant personnel, approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other security-related reports.
Our cybersecurity incident response processes are designed to escalate certain cybersecurity incidents to management depending on the circumstances, including the individuals named above, who work with our incident response team to help us mitigate and remediate cybersecurity incidents of which they are notified .
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.