We take security seriously, plainly explained.
What we do, what we don't, and how to reach us if you find something wrong.
TLS everywhere
All The Color Tools traffic is HTTPS-only with HSTS enabled. We support TLS 1.3 and disable insecure cipher suites.
Encryption at rest
All data — palettes, brand kits, exports — is encrypted at rest with AES-256 (Supabase-managed).
Authentication
Email + Google + Apple SSO out of the box. Enterprise SSO via SAML 2.0 and OIDC. SCIM 2.0 for automated provisioning.
Two-factor auth
Optional TOTP-based 2FA for every account. Recovery codes generated on enable.
Access control
Role-based permissions inside workspaces (Owner, Admin, Editor, Commenter, Viewer). Audit log on Team and Enterprise.
Backups
Continuous backups with point-in-time recovery up to 7 days. Daily snapshots retained for 30 days.
Hosting
Hosted on Vercel (US + EU) and Supabase (US, EU). Enterprise plans can pin data residency to a specific region.
Vulnerability disclosure
Responsible disclosure encouraged at security@thecolortools.com. We respond within 48 hours and credit reporters in our security advisories.
Compliance roadmap
- SOC 2 Type IIIn progress — observation period starts Q3 2026.
- GDPRCompliant — data subject access via /account/data-export, deletion via /account/danger-zone.
- CCPACompliant — data subject rights honored.
- HIPAANot covered — The Color Tools is not for PHI.
- ISO 27001Planned for 2027.
Found a vulnerability?
Email security@thecolortools.com. We respond within 48 hours and credit responsible reporters.
See sub-processors →