Security

We take security seriously, plainly explained.

What we do, what we don't, and how to reach us if you find something wrong.

TLS everywhere

All The Color Tools traffic is HTTPS-only with HSTS enabled. We support TLS 1.3 and disable insecure cipher suites.

Encryption at rest

All data — palettes, brand kits, exports — is encrypted at rest with AES-256 (Supabase-managed).

Authentication

Email + Google + Apple SSO out of the box. Enterprise SSO via SAML 2.0 and OIDC. SCIM 2.0 for automated provisioning.

Two-factor auth

Optional TOTP-based 2FA for every account. Recovery codes generated on enable.

Access control

Role-based permissions inside workspaces (Owner, Admin, Editor, Commenter, Viewer). Audit log on Team and Enterprise.

Backups

Continuous backups with point-in-time recovery up to 7 days. Daily snapshots retained for 30 days.

Hosting

Hosted on Vercel (US + EU) and Supabase (US, EU). Enterprise plans can pin data residency to a specific region.

Vulnerability disclosure

Responsible disclosure encouraged at security@thecolortools.com. We respond within 48 hours and credit reporters in our security advisories.

Compliance roadmap

Found a vulnerability?

Email security@thecolortools.com. We respond within 48 hours and credit responsible reporters.

See sub-processors →