1. Vendor’s Security Whitepaper / Documentation / Policies
1.1 Overview
ChromaChecker is a cloud-based Software-as-a-Service (SaaS) platform designed to manage print quality data, measurement workflows, and related production assets across customer organizations and locations.
This Security Overview consolidates ChromaChecker’s security, privacy, and data-handling practices into a single reference document intended to support customer security, IT, and compliance reviews. It complements ChromaChecker’s published legal and technical documentation and defines the scope of ChromaChecker’s security governance at the application, infrastructure, and operational levels.
ChromaChecker delivers its services using a centralized SaaS model, with optional local client software for data acquisition. Security controls are implemented across hosting infrastructure, cloud services, application logic, and operational processes.
1.2 Security Ownership and Contact
The internal owner of security architecture, platform security design, and technical controls is the System Architect at ChromaChecker Corp.
The official external contact point for all security-related inquiries, incident reports, vulnerability disclosures, and documentation requests is:
security@chromachecker.com
This mailbox is monitored by ChromaChecker’s engineering and support teams and serves as the centralized intake for operational and security-related communications, including incident response coordination.
1.3 Scope of Security Documentation
This Security Overview addresses the following areas:
- SaaS delivery and hosting model
- Data handling, classification, retention, and deletion practices
- Authentication, authorization, and access control principles
- Infrastructure and application security controls
- Use of third-party services and subprocessors
- Operational handling of security-related inquiries and incidents
Subsequent sections of this document expand on architecture, data flows, authentication, hosting, and operational controls in detail.
1.4 Reference Documentation
1.4.1 Platform & SaaS Documentation
- ChromaChecker Platform Manual:
https://chromachecker.com/page/en/show/manual
- CC Capture / Uploader – Technical Requirements:
https://chromachecker.com/manuals/en/show/hardware_requirements
1.4.2 Privacy & Regulatory Documentation
- Privacy Policy:
https://chromachecker.com/other_tools/en/manual/privacy_policy
- GDPR Compliance & Data Subject Rights:
https://chromachecker.com/other_tools/en/manual/gdpr
1.4.3 AI Assistant (Third-Party Component)
- Peter — ChromaChecker AI Assistant:
https://chromachecker.com/page/en/show/peter_chromachecker_ai_assistant
The ChromaChecker AI assistant provides contextual assistance within the SaaS platform:
- Access is limited to operational, aggregated, and statistical account-level data
- The assistant does not access personal data fields, credentials, billing data, or individual measurement records
- When used without authentication, the assistant is restricted to general, non-account-specific information
- AI service providers are contractually bound to data protection obligations and configured, where supported, to avoid retention or training on customer personal data
1.5 Hosting & Infrastructure Compliance (Provider Level)
ChromaChecker’s SaaS platform is hosted on OVHcloud infrastructure. The following certifications apply to the underlying hosting environment operated by OVHcloud and provide context for the physical and infrastructural security of the platform:
- ISO/IEC 27001, 27017, 27018:
https://us.ovhcloud.com/compliance/iso-27001-27017-27018/
- ISO/IEC 27701 (Privacy Information Management):
https://us.ovhcloud.com/compliance/iso-27701/
These certifications apply to OVHcloud’s data centers, physical security, environmental controls, and infrastructure operations supporting ChromaChecker services.
1.6 Incident Handling and Security Communications
Incident Response Scope
ChromaChecker maintains a documented incident response process covering security incidents that may affect the confidentiality, integrity, or availability of the SaaS platform or customer data.
Covered incidents include:
- Unauthorized access or suspected data breach
- Security vulnerabilities impacting the production environment
- Service disruptions caused by security events
- Loss, corruption, or unintended disclosure of customer data
Operational or functional support requests that do not involve security or data protection are handled through standard support channels and are not classified as security incidents.
Incident Reporting and Handling
All suspected security incidents or vulnerabilities must be reported to:
security@chromachecker.com
Reported incidents are triaged by authorized engineering personnel, assessed for impact, and handled according to internal response procedures. Where required by contract or applicable law, affected customers are notified within defined timelines.
1.7 Backup and Data Protection Practices
ChromaChecker maintains regular backups of production data to support service continuity, operational recovery, and data integrity.
- Production databases are backed up on a recurring schedule using infrastructure-level mechanisms provided by the hosting environment.
- Backup data is stored separately from live production systems to reduce the risk of data loss or compromise.
- Access to backup data is restricted to authorized engineering personnel only.
Backup execution, access controls, and retention practices are documented and centrally governed. Backup integrity is verified through routine operational checks.
Backup retention and purge timelines are aligned with ChromaChecker’s data retention and deletion policies described in Section 10.
2. Vendor’s SOC 2 Report (or Other Security Certification Documentation)
2.1 Overview
ChromaChecker operates as a cloud-based Software-as-a-Service (SaaS) platform, delivering centralized quality control, measurement analysis, and reporting services to customers across multiple locations.
At this time, ChromaChecker does not provide a SOC 2 Type II audit report. Instead, our security and compliance posture is currently supported through a combination of infrastructure-level certifications, documented operational practices, and customer-facing security documentation consolidated in this Security Overview.
All security and compliance-related inquiries are handled through the official contact:
security@chromachecker.com
2.2 Infrastructure-Level Certifications
ChromaChecker’s SaaS platform is hosted on OVHcloud, whose infrastructure maintains internationally recognized security and privacy certifications. These certifications apply to the physical data centers, cloud services, and underlying hosting environment used by ChromaChecker.
Relevant OVHcloud certifications include:
- ISO/IEC 27001 – Information Security Management
https://us.ovhcloud.com/compliance/iso-27001-27017-27018/
- ISO/IEC 27017 – Cloud Security Controls
https://us.ovhcloud.com/compliance/iso-27001-27017-27018/
- ISO/IEC 27018 – Protection of Personal Data in Cloud Environments
https://us.ovhcloud.com/compliance/iso-27001-27017-27018/
- ISO/IEC 27701 – Privacy Information Management System (PIMS)
https://us.ovhcloud.com/compliance/iso-27701/
These certifications provide assurance regarding the physical security, environmental controls, access controls, and operational safeguards of the hosting environment supporting the ChromaChecker SaaS platform.
2.3 ChromaChecker Security Controls (SaaS Layer)
At the application and service layer, ChromaChecker implements security controls appropriate to a multi-tenant SaaS environment, including:
- Logical separation of customer data within shared infrastructure
- Encrypted communications between local software components (e.g., CC Capture) and cloud services
- Role-based access control within the platform
- Centralized logging and operational monitoring
- Controlled access to third-party services (including the ChromaChecker AI assistant)
These controls are described in detail across this Security Overview and supporting documentation.
2.4 Future Certification Path
ChromaChecker continuously evaluates customer security requirements and industry expectations. Formal third-party security attestations (such as SOC 2) are part of ongoing strategic planning and will be considered as customer demand and operational scope evolve.
3. Vendor’s Implementation Guidance
3.1 Overview
ChromaChecker is delivered as a Software-as-a-Service (SaaS) platform, combined with optional locally installed client applications used for data acquisition and device interaction. This hybrid model allows centralized cloud processing and storage while supporting on-premise measurement workflows.
Implementation guidance is designed to support secure deployment across single or multiple customer locations, including optional dedicated environments when required.
3.2 Platform Components
ChromaChecker deployments typically include the following components:
- Cloud Platform (SaaS)
Centralized ChromaChecker application, APIs, and databases hosted on managed cloud infrastructure.
- Local Client Software
Installed applications such as ChromaChecker Capture / Uploader, used to collect measurement data and interact with local devices before securely transmitting data to the cloud.
3.3 Supported Operating Systems
Local client applications are supported on the following platforms:
- Microsoft Windows
- Apple macOS
No Linux client is required for standard use cases.
3.4 Software Updates and Maintenance
- ChromaChecker client applications include a “Check for Updates” mechanism available directly within the application.
- Updates may require administrator credentials on the workstation to complete installation, depending on system policies.
- Cloud-side updates (SaaS components) are managed centrally by ChromaChecker and do not require customer intervention.
This approach allows security updates and functional improvements to be deployed efficiently while maintaining operational continuity.
3.5 Deployment Models
ChromaChecker supports multiple deployment models depending on customer security and operational requirements:
Standard SaaS Deployment
- Shared cloud environment with logical tenant isolation.
- Centralized database with tenant-level access controls.
- Suitable for most customers and standard security reviews.
Dedicated Deployment (Optional)
- Dedicated cloud instance deployed exclusively for a specific customer.
- Separate database isolated from other tenants.
- Customizable application stack, allowing adjustments to configuration, scaling, and operational parameters.
- Region selection available, for example deployment on a US-based cloud environment when required by customer policy or data residency requirements.
Optional dedicated deployments are provisioned on request and are intended to support customers with enhanced security, compliance, or contractual requirements.
3.6 Technical Reference Documentation
- CC Capture technical requirements and system prerequisites:
https://chromachecker.com/manuals/en/show/hardware_requirements
- General platform documentation:
https://chromachecker.com/page/en/show/manual
4. Data Flow Diagram – Data Elements Processed, Stored, and Transmitted
4.1 Overview
ChromaChecker operates as a cloud-based SaaS platform with both local components and cloud components, designed to securely collect, process, store, and distribute print quality and production-related data.
Data flows are configurable based on customer needs and may include local capture, cloud storage, and controlled external system integrations via APIs or connectors.
4.2 Core System Components
ChromaChecker data flows involve three primary components:
- Local Installed Software
- CC Capture / Uploader (Windows / macOS)
- Installed at customer sites
- Interfaces directly with measurement devices, presses, and local workflows
- ChromaChecker Cloud Compute Layer (SaaS)
- Application services
- APIs and connectors
- Business logic and validation
- ChromaChecker Cloud Database
- Centralized data storage
- Measurement data, metadata, assets, and logs
- Can be deployed as a dedicated database per customer if required
4.3 Primary Data Flows
Local → Cloud (Ingestion)
- Measurement data is generated locally (spectral, colorimetric, environmental, etc.)
- CC Capture / Uploader securely transmits data to the ChromaChecker cloud
- Communication uses HTTPS/TLS
Cloud Processing & Storage
- Uploaded data is validated and processed by the cloud application
- Data is stored in the cloud database (shared or dedicated instance, depending on configuration)
- Access is controlled via role-based permissions
Cloud → External Systems (Optional, Controlled)
- External systems may access data only through APIs or approved connectors
- Examples include MIS systems, analytics pipelines, and event-based integrations (e.g., Google Pub/Sub)
- Access scope is limited to authorized datasets
4.4 External System Integrations
Read-Only Upload Integrations
- Press management systems such as HP Indigo ColorBeat
- ColorBeat can upload measurement data into ChromaChecker
- ColorBeat cannot retrieve data back from ChromaChecker
Bidirectional / Read Access APIs
- Customer MIS systems
- Analytics platforms
- Third-party applications (e.g., Rutherford Graphics)
- APIs allow authorized retrieval of data for reporting, automation, or monitoring
All external integrations are authenticated and governed by customer-defined permissions.
4.5 Configurable Deployment Models
ChromaChecker supports flexible deployment models:
- Shared SaaS environment
- Dedicated cloud instance for a customer
- Dedicated database per customer
- Region selection available (for example, US-based deployment)
This allows customers to align deployment with internal security, compliance, or data-residency requirements.
Illustrative diagrams are provided to explain typical deployment and data flow scenarios. Actual configurations may vary based on customer deployment model, integrations, and regional hosting requirements.

- ColorBeat: Upload-only into ChromaChecker
- APls: Controlled read access for authorized systems
- Dedicated instance/database optional per customer
5. Solution / Application Physical and Hosted Location
5.1 SaaS Hosting Model
ChromaChecker is delivered as a cloud-based Software-as-a-Service (SaaS) platform.
All customer data is processed and stored within ChromaChecker’s cloud environment and accessed securely via web interfaces, APIs, and local client software (CC Capture / Uploader).
5.2 Hosting Provider
ChromaChecker’s cloud infrastructure is hosted on OVHcloud, a global cloud service provider operating data centers across multiple geographic regions.
Relevant OVHcloud compliance and infrastructure references:
- OVHcloud global data center locations:
https://us.ovhcloud.com/about/global-infrastructure/locations/
- OVHcloud ISO/IEC 27001, 27017, 27018 certifications:
https://us.ovhcloud.com/compliance/iso-27001-27017-27018/
- OVHcloud ISO/IEC 27701 (privacy information management):
https://us.ovhcloud.com/compliance/iso-27701/
These certifications apply to the infrastructure layer supporting ChromaChecker services.
5.3 Current Deployment Regions
At the time of writing, ChromaChecker production instances are hosted in Canada.
This includes cloud compute services, databases, and supporting infrastructure.
5.4 Regional Flexibility & Dedicated Deployments
ChromaChecker supports regional hosting flexibility based on customer requirements:
- Customer environments can be deployed in alternative OVHcloud regions (for example, United States or Europe), subject to project scope and contractual agreement.
- Optional dedicated cloud instances may be provisioned for individual customers, including:
- Dedicated compute resources
- Dedicated database
- Customizable application stack
- Region selection (for example, US-based deployment)
This option is typically used to address regulatory, data residency, or enterprise security requirements.
5.5 Data Residency
Customer data remains within the selected hosting region and is not moved across regions unless explicitly agreed upon as part of a migration or infrastructure change.
6. Architecture Documentation
6.1 Architecture Overview
ChromaChecker is a cloud-based SaaS platform designed to collect, process, store, and analyze print quality and process-control data across distributed customer environments. The system follows a centralized cloud architecture with local data-capture components deployed on customer workstations.
The platform is composed of three primary layers:
- Local Client Layer (Customer Environment)
- Cloud Application Layer (ChromaChecker SaaS)
- Cloud Data Layer
These layers communicate exclusively over secure network channels.
6.2 Local Client Layer (Customer Environment)
The local layer consists of installed software running within the customer’s environment:
- CC Capture / Uploader (Windows and macOS)
- Connected devices, including:
- Spectrophotometers
- Environmental data loggers
- Barcode readers
The local software is responsible for:
- Collecting measurement and device data
- Validating and packaging data locally
- Transmitting data to the ChromaChecker cloud over HTTPS/TLS
No cloud database or server components are deployed within the customer’s local network.
6.3 Cloud Application Layer (ChromaChecker SaaS)
The cloud application layer is hosted on OVHcloud infrastructure and includes:
- Application services and business logic
- Authentication and authorization services
- API endpoints for data ingestion and retrieval
- Connectors for approved external systems
This layer processes incoming data, enforces access control, applies validation logic, and coordinates data storage and retrieval.
6.4 Cloud Data Layer
The cloud data layer is responsible for persistent storage and includes:
- Centralized databases for customer data
- Logical tenant separation between customer accounts
- Storage of structured and unstructured data (see Section 10)
All production instances are hosted in Canada by default.
6.5 External Systems and Integrations
ChromaChecker supports controlled integration with external systems:
- Upload-only integrations
- Example: press management systems such as ColorBeat (data can be uploaded into ChromaChecker but not retrieved)
- API-based integrations
- Authorized read access for MIS systems
- Connectivity with event-driven systems (e.g., Google Pub/Sub)
- Third-party applications
- Integration through documented APIs (e.g., Rutherford Graphics)
All integrations are governed by authentication, authorization, and access-scope controls.
6.6 Dedicated Instance Option
ChromaChecker offers optional dedicated cloud deployments as a paid upgrade, which may include:
- Dedicated cloud compute resources
- Dedicated database instance
- Customizable application stack
- Region selection (for example, a US-based deployment instead of the default Canada region)
Dedicated deployments are isolated from the shared SaaS environment and are provisioned on request.
Additional diagrams covering common enterprise deployment scenarios and external integrations may be provided upon request.
6.7 Security Boundaries
The architecture enforces clear security boundaries:
- Customer local environments are isolated from the cloud
- All communications use encrypted channels (HTTPS/TLS)
- External systems access data only through controlled APIs
- Internal cloud services are not directly exposed to the public internet
7. Authorization & Authentication Details
7.1 Overview
ChromaChecker is a cloud-based SaaS platform that enforces authentication and authorization controls to ensure that access to data and functionality is limited to authorized users and systems. Access controls apply consistently across the web application, APIs, and local client software (CC Capture / Uploader).
7.2 User Authentication
- All user access to the ChromaChecker platform requires authenticated login credentials.
- Authentication is performed centrally by ChromaChecker cloud services.
- Communication between client applications (web browser, CC Capture / Uploader) and cloud services is secured using HTTPS/TLS.
7.3 Password Policy and Account Security
- Users authenticate using username and password credentials.
- Password strength requirements are enforced at the application level. Users with passwords that do not meet current security requirements are prompted to update their password upon login and cannot continue until a compliant password is set.
- Users are prompted to update passwords that do not meet current security requirements.
- Authentication events are logged for audit, security monitoring, and troubleshooting purposes.
7.4 Multi-Factor Authentication (2FA)
ChromaChecker has implemented two-factor authentication (2FA) as an additional security control beyond username and password authentication.
When enabled, users are required to verify their identity using a secondary authentication factor during login.
2FA is available within the ChromaChecker platform and applies consistently across supported interfaces. Authentication events related to 2FA are logged for security monitoring and audit purposes.
7.5 Authorization Model (Role-Based Access Control)
- ChromaChecker implements role-based access control (RBAC).
- User roles determine access to:
- Customer accounts and organizations
- Devices (presses, instruments, barcode readers, data loggers)
- Measurement data, reports, and assets
- Configuration settings and administrative features
- Users can only access data and perform actions explicitly permitted by their assigned role(s).
7.6 API Authentication and Access
- External systems and third-party applications may access ChromaChecker data via authenticated APIs.
- API access is controlled using platform-issued credentials or tokens.
- API permissions are scoped and limited to explicitly authorized datasets and operations.
- API access and usage are logged and monitored.
Examples of API consumers include:
- MIS systems
- Analytics platforms
- Google Pub/Sub integrations
- Third-party applications (for example, Rutherford Graphics, Barbieri Electronic, etc.)
7.7 Local Client Authorization (CC Capture / Uploader)
- CC Capture / Uploader is installed locally on Windows or macOS systems.
- The application authenticates against ChromaChecker cloud services using the user’s credentials.
- Updates to CC Capture may require local administrative privileges on the workstation.
- Access to connected devices (measurement instruments, barcode readers, data loggers) is governed by operating system and local device permissions.
7.8 Security Contact
All authentication, authorization, or security-related questions and incident reports should be directed to:
security@chromachecker.com
This address is monitored by ChromaChecker’s support and engineering teams and serves as the primary escalation channel for access control and security matters.
8. If Migration from One Data Centre / Location to Another – Source and Destination Details
8.1 Overview
ChromaChecker supports region-based hosting and can migrate customer environments between data-centre locations when required. Such migrations are customer-initiated, planned, and executed under a formal agreement to ensure data integrity, continuity of service, and compliance with regional requirements.
8.2 Supported Hosting Regions
- Default region: Canada
- Optional regions: Deployment in alternative regions (including but not limited to the United States, Europe, and China) is supported upon customer request.
- Hosting regions are selected to meet customer requirements related to data residency, latency, and regulatory constraints.
Regional availability is based on supported OVHcloud infrastructure locations:
https://us.ovhcloud.com/about/global-infrastructure/locations/
8.3 Migration Conditions
- Data-centre or region migration is not performed automatically.
- Migration is executed only upon explicit customer request and requires a signed commercial agreement covering scope, timeline, and responsibilities.
- Dedicated instances and region changes are treated as paid upgrades when applicable.
8.4 Migration Process (High Level)
When a migration is requested, the process includes:
- Source environment identification: Current hosting region and instance (default Canada or existing dedicated deployment).
- Destination environment definition: Target region and infrastructure (shared or dedicated instance).
- Planned data transfer: Secure migration of customer data, including measurement records, metadata, and configuration data.
- Validation phase: Post-migration checks to confirm data completeness, integrity, and application functionality.
- Customer confirmation: Migration is considered complete only after customer validation.
8.5 Data Protection During Migration
- Data transfers are performed using secure channels (HTTPS/TLS).
- Access to migration operations is restricted to authorized ChromaChecker engineering personnel.
- No data is migrated without customer approval and documented scope.
9. Data Centre Migration (If Applicable)
ChromaChecker supports controlled data-centre migrations when required by customer agreements or regulatory constraints.
9.1 Migration Policy
- Data-centre migration is not performed by default and only occurs upon explicit customer request.
- Any migration requires a signed commercial agreement (contractual amendment or new deal).
- Migration scope, timing, and region are defined per customer.
9.2 Supported Migration Scenarios
- Region-based migration (for example, Canada → United States, Canada → China).
- Migration to a dedicated instance and dedicated database when required.
- Separation from shared infrastructure as part of an enterprise deployment.
9.3 Migration Controls
- Source and destination regions are clearly identified and documented.
- Data is transferred using secure, encrypted channels.
- Post-migration validation is performed to confirm data integrity and system availability.
10. Description of the Data Elements / Types Housed or Used by the System
ChromaChecker processes and stores data strictly required to operate the platform, support quality analysis workflows, and provide reporting, validation, and integrations. Data is logically separated by customer account and protected through access control, authentication, and audit mechanisms described elsewhere in this document.
10.1 Data Categories Overview
The system processes the following high-level categories of data:
- User and Account Metadata
- Organization and Company Metadata
- Device and Asset Metadata
- Measurement and Quality Data
- Integration and API Data
- Audit, Logging, and Operational Data
10.2 Data Classification Table
|
Data Category
|
Data Elements
|
Source
|
Purpose
|
Storage Location
|
Retention / Deletion
|
|
User Identity
|
Username, role, access level
|
User input
|
Authentication and authorization
|
ChromaChecker cloud database
|
Deleted upon account termination
|
|
Personal Contact
|
Business email, phone number (optional)
|
User input
|
Account communication and notifications
|
ChromaChecker cloud database
|
Deleted upon account termination
|
|
Account Metadata
|
Company name, country, address
|
User input
|
Account configuration and identification
|
ChromaChecker cloud database
|
Deleted upon account termination
|
|
User Profile Data
|
First name, last name, role, advancement level
|
User input
|
User management and access control
|
ChromaChecker cloud database
|
Deleted upon account termination
|
|
Operational Roles
|
Quality manager, production manager, IT manager, etc.
|
User input
|
Permission scoping and workflow control
|
ChromaChecker cloud database
|
Deleted upon account termination
|
|
Measurement Data
|
Spectral data, colorimetric data, targets, curves
|
Measurement devices
|
Print quality analysis and reporting
|
ChromaChecker cloud database
|
Customer-controlled; deleted on account termination
|
|
Device Metadata
|
Printer model, serial number, instrument identifiers
|
User input / device
|
Device tracking and performance analysis
|
ChromaChecker cloud database
|
Deleted upon account termination
|
|
Environmental Data
|
Temperature, humidity records
|
Data loggers
|
Environmental monitoring and correlation
|
ChromaChecker cloud database
|
Deleted upon account termination
|
|
Integration Data
|
MIS identifiers, Pub/Sub messages, API payloads
|
External systems
|
System integration and automation
|
ChromaChecker cloud database
|
Retained per integration configuration
|
|
Audit & Security Logs
|
Login timestamps, IP addresses, access events
|
System generated
|
Security auditing and troubleshooting
|
Secure audit logs
|
Retained per operational policy
|
10.3 Audit Logs and IP Addresses
- IP addresses are stored as part of audit logs.
- Audit logs are used exclusively for security monitoring, troubleshooting, and traceability.
- Audit data is accessible only to authorized internal personnel and is not exposed to other customers.
10.4 External Systems and Data Access
- External systems may interact with ChromaChecker through APIs or dedicated connectors.
- Upload-only integrations (for example, ColorBeat) may push data into ChromaChecker but cannot retrieve data.
- Read access via API may be granted to authorized customer systems (for example, MIS platforms, analytics tools, Google Pub/Sub).
- All API access is authenticated and subject to permission controls.
10.5 Data Sharing Options
- Customers may optionally enable anonymous data sharing for benchmarking and comparison against aggregated industry data.
- This option is explicitly opt-in and configurable at the account level.
10.6 Data Retention and Deletion
- Customers may terminate their account at any time using the self-service controls within the ChromaChecker platform. Account termination constitutes a Customer deletion request for Customer Data.
- Upon termination, ChromaChecker deletes Customer Data from active production systems in accordance with internal operational procedures and, where applicable, within contractually defined timeframes. Backup data is retained for a limited period for operational recovery purposes and is purged on a rolling basis. Security and access logs (including IP addresses) are retained for a limited period for security monitoring, troubleshooting, and traceability, then purged.
- ChromaChecker may retain specific records to the extent required to comply with applicable law, enforce agreements, or resolve disputes. Where retention is required, access remains restricted to authorized personnel only.