Legal » UPDATE_2026 » Security
January 20, 2026

Security

1. Vendor’s Security Whitepaper / Documentation / Policies

1.1 Overview

ChromaChecker is a cloud-based Software-as-a-Service (SaaS) platform designed to manage print quality data, measurement workflows, and related production assets across customer organizations and locations.

This Security Overview consolidates ChromaChecker’s security, privacy, and data-handling practices into a single reference document intended to support customer security, IT, and compliance reviews. It complements ChromaChecker’s published legal and technical documentation and defines the scope of ChromaChecker’s security governance at the application, infrastructure, and operational levels.

ChromaChecker delivers its services using a centralized SaaS model, with optional local client software for data acquisition. Security controls are implemented across hosting infrastructure, cloud services, application logic, and operational processes.

1.2 Security Ownership and Contact

The internal owner of security architecture, platform security design, and technical controls is the System Architect at ChromaChecker Corp.

The official external contact point for all security-related inquiries, incident reports, vulnerability disclosures, and documentation requests is:

security@chromachecker.com

This mailbox is monitored by ChromaChecker’s engineering and support teams and serves as the centralized intake for operational and security-related communications, including incident response coordination.

1.3 Scope of Security Documentation

This Security Overview addresses the following areas:

Subsequent sections of this document expand on architecture, data flows, authentication, hosting, and operational controls in detail.

1.4 Reference Documentation

1.4.1 Platform & SaaS Documentation

1.4.2 Privacy & Regulatory Documentation

1.4.3 AI Assistant (Third-Party Component)

The ChromaChecker AI assistant provides contextual assistance within the SaaS platform:

1.5 Hosting & Infrastructure Compliance (Provider Level)

ChromaChecker’s SaaS platform is hosted on OVHcloud infrastructure. The following certifications apply to the underlying hosting environment operated by OVHcloud and provide context for the physical and infrastructural security of the platform:

These certifications apply to OVHcloud’s data centers, physical security, environmental controls, and infrastructure operations supporting ChromaChecker services.

1.6 Incident Handling and Security Communications

Incident Response Scope

ChromaChecker maintains a documented incident response process covering security incidents that may affect the confidentiality, integrity, or availability of the SaaS platform or customer data.

Covered incidents include:

Operational or functional support requests that do not involve security or data protection are handled through standard support channels and are not classified as security incidents.

Incident Reporting and Handling

All suspected security incidents or vulnerabilities must be reported to:

security@chromachecker.com

Reported incidents are triaged by authorized engineering personnel, assessed for impact, and handled according to internal response procedures. Where required by contract or applicable law, affected customers are notified within defined timelines.

1.7 Backup and Data Protection Practices

ChromaChecker maintains regular backups of production data to support service continuity, operational recovery, and data integrity.

Backup execution, access controls, and retention practices are documented and centrally governed. Backup integrity is verified through routine operational checks.

Backup retention and purge timelines are aligned with ChromaChecker’s data retention and deletion policies described in Section 10.

 

2. Vendor’s SOC 2 Report (or Other Security Certification Documentation)

2.1 Overview

ChromaChecker operates as a cloud-based Software-as-a-Service (SaaS) platform, delivering centralized quality control, measurement analysis, and reporting services to customers across multiple locations.

At this time, ChromaChecker does not provide a SOC 2 Type II audit report. Instead, our security and compliance posture is currently supported through a combination of infrastructure-level certifications, documented operational practices, and customer-facing security documentation consolidated in this Security Overview.

All security and compliance-related inquiries are handled through the official contact:

security@chromachecker.com

2.2 Infrastructure-Level Certifications

ChromaChecker’s SaaS platform is hosted on OVHcloud, whose infrastructure maintains internationally recognized security and privacy certifications. These certifications apply to the physical data centers, cloud services, and underlying hosting environment used by ChromaChecker.

Relevant OVHcloud certifications include:

These certifications provide assurance regarding the physical security, environmental controls, access controls, and operational safeguards of the hosting environment supporting the ChromaChecker SaaS platform.

2.3 ChromaChecker Security Controls (SaaS Layer)

At the application and service layer, ChromaChecker implements security controls appropriate to a multi-tenant SaaS environment, including:

These controls are described in detail across this Security Overview and supporting documentation.

2.4 Future Certification Path

ChromaChecker continuously evaluates customer security requirements and industry expectations. Formal third-party security attestations (such as SOC 2) are part of ongoing strategic planning and will be considered as customer demand and operational scope evolve.

 

3. Vendor’s Implementation Guidance

3.1 Overview

ChromaChecker is delivered as a Software-as-a-Service (SaaS) platform, combined with optional locally installed client applications used for data acquisition and device interaction. This hybrid model allows centralized cloud processing and storage while supporting on-premise measurement workflows.

Implementation guidance is designed to support secure deployment across single or multiple customer locations, including optional dedicated environments when required.

3.2 Platform Components

ChromaChecker deployments typically include the following components:

3.3 Supported Operating Systems

Local client applications are supported on the following platforms:

No Linux client is required for standard use cases.

3.4 Software Updates and Maintenance

This approach allows security updates and functional improvements to be deployed efficiently while maintaining operational continuity.

3.5 Deployment Models

ChromaChecker supports multiple deployment models depending on customer security and operational requirements:

Standard SaaS Deployment

Dedicated Deployment (Optional)

Optional dedicated deployments are provisioned on request and are intended to support customers with enhanced security, compliance, or contractual requirements.

3.6 Technical Reference Documentation

 

4. Data Flow Diagram – Data Elements Processed, Stored, and Transmitted

4.1 Overview

ChromaChecker operates as a cloud-based SaaS platform with both local components and cloud components, designed to securely collect, process, store, and distribute print quality and production-related data.

Data flows are configurable based on customer needs and may include local capture, cloud storage, and controlled external system integrations via APIs or connectors.

4.2 Core System Components

ChromaChecker data flows involve three primary components:

  1. Local Installed Software
    • CC Capture / Uploader (Windows / macOS)
    • Installed at customer sites
    • Interfaces directly with measurement devices, presses, and local workflows

  2. ChromaChecker Cloud Compute Layer (SaaS)
    • Application services
    • APIs and connectors
    • Business logic and validation

  3. ChromaChecker Cloud Database
    • Centralized data storage
    • Measurement data, metadata, assets, and logs
    • Can be deployed as a dedicated database per customer if required

4.3 Primary Data Flows

Local → Cloud (Ingestion)

Cloud Processing & Storage

Cloud → External Systems (Optional, Controlled)

4.4 External System Integrations

Read-Only Upload Integrations

Bidirectional / Read Access APIs

All external integrations are authenticated and governed by customer-defined permissions.

4.5 Configurable Deployment Models

ChromaChecker supports flexible deployment models:

This allows customers to align deployment with internal security, compliance, or data-residency requirements.

Illustrative diagrams are provided to explain typical deployment and data flow scenarios. Actual configurations may vary based on customer deployment model, integrations, and regional hosting requirements.

 

 

5. Solution / Application Physical and Hosted Location

5.1 SaaS Hosting Model

ChromaChecker is delivered as a cloud-based Software-as-a-Service (SaaS) platform.

All customer data is processed and stored within ChromaChecker’s cloud environment and accessed securely via web interfaces, APIs, and local client software (CC Capture / Uploader).

5.2 Hosting Provider

ChromaChecker’s cloud infrastructure is hosted on OVHcloud, a global cloud service provider operating data centers across multiple geographic regions.

Relevant OVHcloud compliance and infrastructure references:

These certifications apply to the infrastructure layer supporting ChromaChecker services.

5.3 Current Deployment Regions

At the time of writing, ChromaChecker production instances are hosted in Canada.

This includes cloud compute services, databases, and supporting infrastructure.

5.4 Regional Flexibility & Dedicated Deployments

ChromaChecker supports regional hosting flexibility based on customer requirements:

This option is typically used to address regulatory, data residency, or enterprise security requirements.

5.5 Data Residency

Customer data remains within the selected hosting region and is not moved across regions unless explicitly agreed upon as part of a migration or infrastructure change.

 

6. Architecture Documentation

6.1 Architecture Overview

ChromaChecker is a cloud-based SaaS platform designed to collect, process, store, and analyze print quality and process-control data across distributed customer environments. The system follows a centralized cloud architecture with local data-capture components deployed on customer workstations.

The platform is composed of three primary layers:

  1. Local Client Layer (Customer Environment)
  2. Cloud Application Layer (ChromaChecker SaaS)
  3. Cloud Data Layer

These layers communicate exclusively over secure network channels.

6.2 Local Client Layer (Customer Environment)

The local layer consists of installed software running within the customer’s environment:

The local software is responsible for:

No cloud database or server components are deployed within the customer’s local network.

6.3 Cloud Application Layer (ChromaChecker SaaS)

The cloud application layer is hosted on OVHcloud infrastructure and includes:

This layer processes incoming data, enforces access control, applies validation logic, and coordinates data storage and retrieval.

6.4 Cloud Data Layer

The cloud data layer is responsible for persistent storage and includes:

All production instances are hosted in Canada by default.

6.5 External Systems and Integrations

ChromaChecker supports controlled integration with external systems:

All integrations are governed by authentication, authorization, and access-scope controls. 

6.6 Dedicated Instance Option

ChromaChecker offers optional dedicated cloud deployments as a paid upgrade, which may include:

Dedicated deployments are isolated from the shared SaaS environment and are provisioned on request.

Additional diagrams covering common enterprise deployment scenarios and external integrations may be provided upon request.

6.7 Security Boundaries

The architecture enforces clear security boundaries:

7. Authorization & Authentication Details

7.1 Overview

ChromaChecker is a cloud-based SaaS platform that enforces authentication and authorization controls to ensure that access to data and functionality is limited to authorized users and systems. Access controls apply consistently across the web application, APIs, and local client software (CC Capture / Uploader).

7.2 User Authentication

7.3 Password Policy and Account Security

7.4 Multi-Factor Authentication (2FA)

ChromaChecker has implemented two-factor authentication (2FA) as an additional security control beyond username and password authentication.

When enabled, users are required to verify their identity using a secondary authentication factor during login.

2FA is available within the ChromaChecker platform and applies consistently across supported interfaces. Authentication events related to 2FA are logged for security monitoring and audit purposes.

7.5 Authorization Model (Role-Based Access Control)

7.6 API Authentication and Access

Examples of API consumers include:

7.7 Local Client Authorization (CC Capture / Uploader)

7.8 Security Contact

All authentication, authorization, or security-related questions and incident reports should be directed to:

security@chromachecker.com

This address is monitored by ChromaChecker’s support and engineering teams and serves as the primary escalation channel for access control and security matters.

 

8. If Migration from One Data Centre / Location to Another – Source and Destination Details

8.1 Overview

ChromaChecker supports region-based hosting and can migrate customer environments between data-centre locations when required. Such migrations are customer-initiated, planned, and executed under a formal agreement to ensure data integrity, continuity of service, and compliance with regional requirements.

8.2 Supported Hosting Regions

Regional availability is based on supported OVHcloud infrastructure locations:

https://us.ovhcloud.com/about/global-infrastructure/locations/

8.3 Migration Conditions

8.4 Migration Process (High Level)

When a migration is requested, the process includes:

8.5 Data Protection During Migration

 

9. Data Centre Migration (If Applicable)

ChromaChecker supports controlled data-centre migrations when required by customer agreements or regulatory constraints.

9.1 Migration Policy

9.2 Supported Migration Scenarios

9.3 Migration Controls

 

10. Description of the Data Elements / Types Housed or Used by the System

ChromaChecker processes and stores data strictly required to operate the platform, support quality analysis workflows, and provide reporting, validation, and integrations. Data is logically separated by customer account and protected through access control, authentication, and audit mechanisms described elsewhere in this document.

10.1 Data Categories Overview

The system processes the following high-level categories of data:

10.2 Data Classification Table

Data Category

Data Elements

Source

Purpose

Storage Location

Retention / Deletion

User Identity

Username, role, access level

User input

Authentication and authorization

ChromaChecker cloud database

Deleted upon account termination

Personal Contact

Business email, phone number (optional)

User input

Account communication and notifications

ChromaChecker cloud database

Deleted upon account termination

Account Metadata

Company name, country, address

User input

Account configuration and identification

ChromaChecker cloud database

Deleted upon account termination

User Profile Data

First name, last name, role, advancement level

User input

User management and access control

ChromaChecker cloud database

Deleted upon account termination

Operational Roles

Quality manager, production manager, IT manager, etc.

User input

Permission scoping and workflow control

ChromaChecker cloud database

Deleted upon account termination

Measurement Data

Spectral data, colorimetric data, targets, curves

Measurement devices

Print quality analysis and reporting

ChromaChecker cloud database

Customer-controlled; deleted on account termination

Device Metadata

Printer model, serial number, instrument identifiers

User input / device

Device tracking and performance analysis

ChromaChecker cloud database

Deleted upon account termination

Environmental Data

Temperature, humidity records

Data loggers

Environmental monitoring and correlation

ChromaChecker cloud database

Deleted upon account termination

Integration Data

MIS identifiers, Pub/Sub messages, API payloads

External systems

System integration and automation

ChromaChecker cloud database

Retained per integration configuration

Audit & Security Logs

Login timestamps, IP addresses, access events

System generated

Security auditing and troubleshooting

Secure audit logs

Retained per operational policy

10.3 Audit Logs and IP Addresses

10.4 External Systems and Data Access

10.5 Data Sharing Options

10.6 Data Retention and Deletion

 

Contact ChromaChecker Support

Additional information and Support Form is available for logged users.

Peter · AI Assistant
Need help choosing the right path into ChromaChecker? I can guide you based on your role and workflow.