Chroma

Chroma Inc.·Trychroma.com
Security Posture

Compliance-ready

As of September 3, 2026, Chroma's security: SOC 2 Type II is in hand alongside 6 controls including encryption at rest, encryption in transit, and MFA; that combination typically satisfies the baseline security review at mid-market and larger enterprise buyers.

Backed by 8 dated facts
Every value derives from a dated, sourced capture — open any fact for its source.
Certifications
SOC 2SOC 2 Type II
Controls
Encryption At RESTEncryption In TransitMFAPen TestingRBACSSO
Security Change Historydated events · values unlock with a key
Security signal added: SOC 2 · high significance
Security signal removed: Audit Logs · high significance
Security signal added: Pen Testing · high significance
Security signal added: Encryption At REST · high significance
Security signal added: SOC 2 Type II · high significance
Security signal added: SSO · high significance
Security signal added: MFA · high significance
Security signal added: RBAC · high significance
Every security fact on this pagekey · value · provenance · dated · sourced
FactValueProvenanceAs ofSource
security.cert.soc2SOC 2company stated2026-09-03www.trychroma.com/pricing
security.cert.soc2-type-iiSOC 2 Type IIcompany stated2026-09-03www.trychroma.com/security
security.encryption-at-restEncryption At RESTcompany stated2026-09-03www.trychroma.com/security
security.encryption-in-transitEncryption In Transitcompany stated2026-09-03www.trychroma.com/security
security.mfaMFAcompany stated2026-09-03www.trychroma.com/security
security.pen-testingPen Testingcompany stated2026-09-03www.trychroma.com/security
security.rbacRBACcompany stated2026-09-03www.trychroma.com/security
security.ssoSSOcompany stated2026-09-03www.trychroma.com/security
Security across Vector DatabasesChroma ranked in place · tap through for each read

No observed security facts yet for KDB.AI, LanceDB, Marqo, Milvus, MyScale and Vespa.

Get security for trychroma.com via API / MCPevery field dated and sourced
RESTopen tier
GET https://api.bixel.com/v1/companies/trychroma.com/facts?dimension=security

{
  "data": {
    "facts": [
      {
        "key": "security.cert.soc2",
        "value": true,
        "provenance": "company_stated",
        "as_of": "2026-09-03",
        "source_url": "www.trychroma.com/pricing"
      },
      {
        "key": "security.cert.soc2-type-ii",
        "value": true,
        "provenance": "company_stated",
        "as_of": "2026-09-03",
        "source_url": "www.trychroma.com/security"
      },
      {
        "key": "security.encryption-at-rest",
        "value": true,
        "provenance": "company_stated",
        "as_of": "2026-09-03",
        "source_url": "www.trychroma.com/security"
      },
      {
        "key": "security.encryption-in-transit",
        "value": true,
        "provenance": "company_stated",
        "as_of": "2026-09-03",
        "source_url": "www.trychroma.com/security"
      },
      "…"
    ]
  }
}
MCPfor agents
# any MCP client (Claude, agents)
const record = await bixel.get_company_facts({ domain: "trychroma.com", dimension: "security" })

# returns the security record above,
# each value with its source_url + as_of,
# ready to reason over
Build on the company record. One key, REST + MCP, every signal dated and sourced back to the page it came from.

Public record, read from companies' own pages and boards. Every fact dated and sourced; provenance (observed vs company stated) shown inline.