Color · Trust Center

Color Trust Center

Trust center

Color maintains a public trust center documenting SOC 2, SOC 2 Type II, HIPAA, ISO 27001:2013, CSA STAR, CCPA, and FISMA Moderate compliance.

CompanyHealthHealthcareGenomicsOncologyCancer CarePreventive HealthEligibilityVirtual CareDiagnosticsLaboratoryEmployee Benefits
Trust center: https://security.color.com/

Certifications & Compliance

SOC 2SOC 2 Type IIHIPAAISO 27001:2013CSA STARCCPAFISMA Moderate

Source

Trust Center

Raw ↑
generated: '2026-08-15'
method: searched
probe: true
source: https://security.color.com/
url: https://security.color.com/
platform: SafeBase
certifications:
- SOC 2
- SOC 2 Type II
- HIPAA
- ISO 27001:2013
- CSA STAR
- CCPA
- FISMA Moderate
questionnaires:
- CAIQ
- HECVAT Full
- VSA Full
security_ratings:
- BitSight
- Black Kite
- CyberVadis
- SecurityScorecard
- UpGuard
- RiskRecon
- ImmuniWeb
- Qualys SSL Labs
- MDN Observatory
- CryptCheck
- CIS Score
requestable_documents:
- SOC 2 Type II Report
- HIPAA Report
- Pentest Report
- Network Diagram
- Security Whitepaper
- Privacy Policy
- Terms of Service
- Subprocessors
control_domains:
- Access Control
- Application Penetration Testing
- Audit Logging
- BC/DR
- Change Management
- Code Analysis
- Credential Management
- Data Backups
- Data Erasure
- Encryption-at-rest
- Encryption-in-transit
- Endpoint Detection & Response
- Incident Response
- Multi-Factor Authentication
- Physical Security
- Responsible Disclosure
- Risk Management
- Role-Based Access Control
- Separate Production Environment
- Software Development Lifecycle
- Threat Detection
- Vulnerability & Patch Management
hosting:
- Amazon Web Services
- Google Cloud Platform
notes: >-
  Certification, questionnaire and control names are read verbatim from the titles
  Color's SafeBase-hosted trust centre publishes. The underlying reports (SOC 2
  Type II, HIPAA, pentest) sit behind an NDA request form, so these are Color's
  own assertions rather than independently verified attestations. The Responsible
  Disclosure control is broken out into
  security/color-vulnerability-disclosure.yml.
evidence:
- source: https://security.color.com/
  status: 200
  keywords:
  - soc 2
  - soc 2 type ii report
  - hipaa
  - iso 27001:2013 stage 1 & stage 2
  - csa star
  - caiq
  - hecvat full
  - vsa full
  - ccpa
  - fisma moderate
  - responsible disclosure

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/color-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.