Customer Snowflake account
- Native App runtime on Snowpark Container Services
- Application state in Snowflake Hybrid Tables
- Customer-owned source tables, views, and policies
- Optional Cortex calls from the consumer environment
Security architecture
This page is a public reviewer URL for Snowflake Marketplace security review. It shows where EntryLayer runs, where application state lives, how source data is read, and which limited metadata can leave the consumer account.
Diagram
EntryLayer is installed as a Snowflake Native App. The reviewed application package supplies the containers; runtime behavior, application state, source reads, and administrator operations happen inside the customer Snowflake environment.
Authenticated operators, builders, reviewers, and admins.
EntryLayer UI served from the Native App service.
Project, workflow, access, source, and billing logic.
Projects, forms, submissions, memberships, audit history, and access logs.
Caller-rights reads preserve supported Snowflake grants, masking policies, and row access policies.
Used for form generation through Snowflake when enabled.
Boundaries
The provider boundary supplies the reviewed package and support process. The customer boundary is where runtime, state, source access, and operational work occur.
Data flow matrix
These are the normal product flows to evaluate for Marketplace approval. Source data and application state are not copied to a provider-hosted SaaS database.
Components
Does not flow
Questionnaire answer
Provide this page as the architecture diagram link in the Native Apps Security Questionnaire.
https://entrylayer.ai/security/architecture