A 0–3 score across the 8 moats, anchored to comparable companies. It surfaces where Snowflake's defensibility is real, where it's thin, and where the story outruns the structure.
Five of eight moats clear the real-moat threshold, anchored by a Workflow lock-in on par with Salesforce and an Ecosystem that partners are building real revenue on top of. But the fortress isn’t where the marketing points — the “AI Data Cloud” story leans on a Data moat that the company’s own privacy commitments cap at a 1, while the two moats actually doing the work (Workflow, Ecosystem) barely feature in the pitch.
Snowflake markets itself as “the AI Data Cloud” — Cortex, agentic AI, and the implication that data compounding across the platform is what makes it powerful. But the scoring says the opposite: Data caps at 1 because Snowflake’s own privacy commitment (no training on customer data, strict per-tenant isolation) forecloses the cross-customer compounding a real Data moat requires, and Cortex’s AI features get matched within a quarter or two by Databricks, BigQuery, and Microsoft Fabric. What’s actually load-bearing is unglamorous: the multi-quarter pain of ripping a system-of-record warehouse out of thousands of downstream pipelines, and a Marketplace where partners have built real revenue. This is the same trap Gong and Salesforce fall into — the AI layer gets the headline, the boring plumbing underneath does the work.
Each moat is scored 0–3 for structural durability — not for how useful or popular it is. The tier is set by how many moats reach 2+, not by the total.
| Moat | Meter | Score | One-line take | |
|---|---|---|---|---|
| 01 | Data | 1 | Per-tenant by design — and by promise; not a compounding asset. | |
| 02 | Workflow | 3 | Rip out the system of record and you take the downstream stack with it. | |
| 03 | Regulatory | 1 | FedRAMP High and HIPAA are real, but the hyperscalers clear the same bar. | |
| 04 | Distribution | 2 | A privileged seat on all three cloud marketplaces — contested, not owned. | |
| 05 | Ecosystem | 3 | The Marketplace and Native Apps framework is a platform partners build revenue on. | |
| 06 | Network Effects | 2 | Data-sharing edges compound value, but most usage is still single-player. | |
| 07 | Physical / Infra. | 0 | Runs entirely on rented AWS, Azure, and GCP compute. | |
| 08 | Scale | 2 | Consumption-model efficiency, capped by hyperscalers who can subsidize. | |
| Total | 14 / 24 |
The tier is set by counting how many moats score 2 or higher — not by the total out of 24. One strong moat isn't a stack.
| Exposed | 0 moats at 2+ | No defenses; open to attack from every direction. |
| Partial | 1–2 moats at 2+ | Some defense, but below the stack threshold. |
| Stacked | 3 moats at 2+ | Stack threshold met; defensibility begins here. |
| Fortified← This company | 4+ moats at 2+ | Multiple moats compound; the strongest state. |
Snowflake has 5 moats at 2+ (Workflow, Distribution, Ecosystem, Network Effects, Scale), which lands it in Fortified.
Scores are anchored against comparable companies in the same category — not isolated opinion.
Snowflake’s core asset is customer data sitting inside each account’s own storage — isolated by design, and Snowflake makes a public commitment not to train shared models on it. That’s the textbook data-moat illusion: rich, valuable data that never aggregates into a cross-customer product improvement. Databricks’ lakehouse sits on the identical structural pattern for the same reason. For this to move to a 2, Snowflake would need an opt-in, cross-tenant data product — aggregate benchmarking, anomaly detection trained on de-identified patterns — something it has so far avoided building because it would cut against the privacy commitment that wins enterprise trust in the first place.
Snowflake is the system of record for structured analytics at thousands of enterprises — Time Travel history, dialect-specific SQL and stored procedures, RBAC and masking policies, and years of downstream BI dashboards, ETL jobs, and Snowpark pipelines all built against it. Pulling it out is the same multi-quarter, high-operational-risk migration that anchors Salesforce and Stripe at a 3 in their categories, and 126% net revenue retention for five straight quarters is the retention evidence Attio and Day.ai don’t have yet. The one real erosion pressure is the rise of open table formats like Iceberg, which loosen the storage layer even as the compute and orchestration layer stays sticky — worth watching, not yet enough to move the score.
FedRAMP High authorization on both AWS GovCloud and Azure Government, plus HIPAA and PCI DSS coverage, is real compliance infrastructure that opens government and healthcare accounts other vendors can’t touch without the same paperwork. But Databricks, Redshift, and BigQuery have all cleared the identical bar — this is table stakes for a major cloud data platform, not a structural barrier unique to Snowflake, the same gap that keeps Rox and Gong at a 1 despite real compliance footprints.
Snowflake reaches customers through direct enterprise sales, a large systems-integrator channel (Accenture, Deloitte, and similar), and a privileged position on all three hyperscaler marketplaces, where deals draw down customers’ committed cloud spend. That’s owned reach with real pull — 41% penetration into the Forbes Global 2000 is the evidence — but every one of those channels is shared with Databricks, which sits on the same three marketplaces. It lands with HubSpot and Salesforce: real, but contested, not a self-propagating loop.
The Marketplace and Native Apps framework let third parties build and monetize inside a customer’s own Snowflake account without moving data — partners booked over $100M in gross transactions in H1 2026 alone, up 277% year over year, and companies like dbt Labs, Sigma, and FactSet have built real distribution on top of the platform rather than just integrating with it. That’s the Salesforce AppExchange / Stripe Connect pattern: a canonical platform others structure their own businesses around, not just an API to consume.
Each new data provider or app on the Marketplace makes the platform more valuable to every consumer already there, and Snowflake reports 42% of customers now maintain ongoing provider-consumer relationships rather than one-off purchases. That’s a genuine contributory network effect, but it still sits on top of a customer base whose primary use — single-tenant analytics — has zero cross-customer value transfer. It’s the same shape as Apollo’s Community Edition: real, but a minority-of-usage effect, not a marketplace-grade G2/LinkedIn 3.
Snowflake owns no data centers or hardware — every workload runs on rented AWS, Azure, or GCP compute and storage. That’s the near-universal 0 for software in this category, and it’s a deliberate model choice (multi-cloud portability is part of the pitch), not a gap to close.
$1.49B in quarterly product revenue growing 37% year over year, 75% non-GAAP product gross margin, and a 23% full-year free cash flow margin target give Snowflake real consumption-pricing efficiency and negotiating leverage on the cloud capacity it resells. But it competes against Databricks at comparable scale and against Microsoft, Google, and Amazon’s own native warehouses, all of which can subsidize a competing product from a much larger balance sheet — the same ceiling that caps Salesforce and ZoomInfo at 2.
Not every moat fits every business. Three buckets narrow the field — they don't name which available moat to pursue. That's what the Stress Test is for.
You've seen where Snowflake stands. Two ways forward: run this same free diagnostic on your own company, or commission the rigorous version.
Thanks — your scorecard and a short email series are on the way, and I'll be in touch within one business day. If you want the rigorous version, the Stress Test on the right is the next step.
The same eight moats, run with the full methodology visible. Where the Diagnostic names the state, the Stress Test names the move: