Anavsan
  • APEX
  • Engine
    APEXWorkload Governance Agent How Anavsan WorksTrace → Assign → Enforce → Prove TerminologyWorkload governance glossary Compare vs UnravelGovernance vs autonomous operator
    Snowflake
    Snowflake overviewWorkload governance hub Cost & credit governanceWaste, queries, warehouses Storage IntelligenceTime Travel & unused tables AI & CortexToken spend governance Native AppIn-account monitoring
    Tools
    Accountability Gap Assessment Governance Assessment Cortex Cost Simulator
    BigQuery
    BigQuery overviewSame loop: jobs, slots, owners Cost GovernanceSlots, reservations, scan Storage IntelligenceLogical vs physical, time travel Dataset LineageJobs, owners, unreferenced tables
    Start Free Trial
  • About AnavsanMission, team & values PartnersResellers & integrations AnavPro ProgramCertified partner program WorkshopsQuery optimization training Community MeetupsData Cloud · Snowflake Edition
  • Pricing
  • Blog
  • Docs
Start Free Trial Free Assessment
  • APEX
  • Engine
    APEX How Anavsan Works Terminology Compare vs Unravel
  • Snowflake
    Snowflake overview Cost & credit Storage Intelligence AI & Cortex Native App Accountability Assessment Governance Assessment Cortex Simulator
  • BigQuery
    BigQuery overview Cost Governance Storage Intelligence Dataset Lineage
  • Company
    About Partners AnavPro Program Workshops Community Meetups
  • Pricing
  • Blog
  • Docs ↗
Start Free Trial Free Assessment

Security

Architecture and permissions

Public. No sign-in. Sources: the privacy policy, how APEX works, and docs.anavsan.com.

Contents

What stays put What APEX reads Where it goes Retention Hosted APEX vs Native App Permissions Query path Docs without an account

This page is the technical boundary for a buyer who needs to judge deployment risk. It states what is already published. It does not add a new data right.

What stays in your account

Table contents stay where they are. Anavsan does not read, copy, or transmit the rows in your Snowflake tables or BigQuery datasets. Customer records, proprietary datasets, and financial records are not the input.

Snowflake stays in Snowflake. BigQuery stays in BigQuery.

What operational metadata includes

Hosted APEX reads operational metadata through a read-only service user you configure. For Snowflake, the privacy policy lists that metadata as:

  • Query history, including SQL query text, execution time, warehouse, user, and credits consumed
  • Warehouse usage and configuration
  • Storage metadata: table sizes, Time Travel settings, clone metadata
  • Account usage and cost signals from SNOWFLAKE.ACCOUNT_USAGE
  • AI Services and Cortex usage metadata

SQL text is included. It is query text from history, not the contents of the tables that query touched.

Access is read-only on SNOWFLAKE.ACCOUNT_USAGE and INFORMATION_SCHEMA. There is no write access to Snowflake objects, and no access to business-data tables, views, or procedures.

On BigQuery, APEX reads the same class of operational metadata: jobs, slots, reservations, and scans, including INFORMATION_SCHEMA-class signals. It does not read your datasets. The privacy policy's itemized metadata list is written for Snowflake. This page does not invent a second list.

Where hosted metadata goes

On hosted APEX, Snowflake metadata processed for the service is stored in Anavsan infrastructure. The privacy policy states that. It is encrypted in transit (TLS 1.2+) and at rest (AES-256).

That metadata is not sold, and it is not used for advertising. The Native App is a different deployment: processing stays inside the Snowflake account, and that metadata is not sent out. See the comparison below.

Retention

The privacy policy states:

  • Snowflake metadata: retained for up to 13 months, for trend analysis and historical comparison
  • Account data: kept for the life of the account, plus 30 days after closure
  • Usage logs: 90 days, for security and debugging

You can request deletion at contactus@anavsan.com. The policy says deletion is within 30 days, except where the law requires longer.

The 13-month clause names Snowflake metadata. It does not, in that section, state a separate BigQuery retention number. Do not read this page as creating one.

Hosted APEX and the Native App

Hosted APEXSnowflake Native App
Where it runsAnavsan's service, connected to your accountInside the Snowflake account
What leaves the accountOperational metadata, including SQL text, stored for the serviceNothing. Processing stays in Snowflake.
Table contentsNot readNot read
What it doesRecommends an action. Your team approves and deploys production changes.Monitors credits and usage. Advisory. It does not rewrite queries or change warehouses.

They are two products. You do not have to install the Native App to use hosted APEX, and you do not have to send metadata to Anavsan to use the Native App. The longer choice is on Native App vs full platform.

Permissions

  • You create the Snowflake service user. Anavsan does not take a password to your tables.
  • That user is read-only on metadata schemas.
  • APEX does not grant itself rights to apply a warehouse, reservation, or query change.
  • A production change leaves as a recommendation — and, on the full platform, can leave as a pull request in your repository. Your approvals and your deployment still apply. Anavsan does not reach into production and change a setting because it preferred that path.

Nothing sits in the production query path

APEX reads a workload after it has run. Before you deploy a recommended change, a simulation can estimate runtime and cost. That simulation is change-safety. It is not a gate in front of Snowflake or BigQuery.

There is no agent in the query path. Redirect recommends a different warehouse or reservation. It does not route the workload. Run means no change. Review means a person decides.

Readable without an account

You do not need an Anavsan login to read this page, the privacy policy, or the product documentation at docs.anavsan.com. The docs homepage is public.

Questions about a specific connection or a contract term: contactus@anavsan.com.

Anavsan

Trace the waste. Assign the owner. Enforce the decision. Prove it from the data. Workload Governance for Snowflake and BigQuery, powered by APEX.

Anavsan HQ
# 1553, 867 Boylston Street, 5th Floor
Boston, MA 02116, United States

Engine
  • APEX
  • How Anavsan Works
  • Terminology
  • Compare vs Unravel
Snowflake
  • Overview
  • Cost & credit governance
  • Storage Intelligence
  • AI & Cortex
  • Native App
  • Accountability Assessment
  • Governance Assessment
  • Cortex Simulator
BigQuery
  • Overview
  • Cost Governance
  • Storage Intelligence
  • Dataset Lineage
Company
  • About
  • Partners
  • AnavPro Program
  • Workshops
  • Community Meetups
  • Pricing
  • Blog
  • Contact Sales
Resources
  • Documentation
  • Start Free Trial
  • Book a Demo
  • Privacy Policy
  • Terms

Deploy Anavsan

Snowflake Native App · Full Version

© 2026 Anavsan, Inc. All rights reserved. Anavsan HQ · Boston, MA.

Privacy Terms Contact