Chroma
Security Posture
Baseline security
As of July 20, 2026, Chroma's security: SOC 2 Type II is confirmed, and the 7 controls include encryption at rest, encryption in transit, and SSO. That clears the baseline procurement bar for most mid-market buyers; enterprise buyers with stricter requirements should ask about controls beyond those seven.
Medium confidence · 8 dated facts
Grounded in a smaller fact set; directionally reliable.
Grounded in a smaller fact set; directionally reliable.
Certifications
SOC 2 Type II
Controls
Encryption At RESTEncryption In TransitSSORBACMFAPen TestingAudit Logs
Security Change Historydated events · values unlock with a key
Security signal added: Encryption In Transit · high significance
Security signal added: Pen Testing · high significance
Security signal added: Encryption At REST · high significance
Security signal added: SOC 2 Type II · high significance
Security signal added: SSO · high significance
Security signal added: MFA · high significance
Security signal added: RBAC · high significance
Security signal added: Single Tenant · high significance
Every security fact on this pagekey · value · provenance · dated · sourced
| Fact | Value | Provenance | As of | Source |
|---|---|---|---|---|
| security.audit-logs | Audit Logs | company stated | 2026-07-20 | www.trychroma.com/security |
| security.cert.soc2-type-ii | SOC 2 Type II | company stated | 2026-07-20 | www.trychroma.com/security |
| security.encryption-at-rest | Encryption At REST | company stated | 2026-07-20 | www.trychroma.com/security |
| security.encryption-in-transit | Encryption In Transit | company stated | 2026-07-20 | www.trychroma.com/security |
| security.mfa | MFA | company stated | 2026-07-20 | www.trychroma.com/security |
| security.pen-testing | Pen Testing | company stated | 2026-07-20 | www.trychroma.com/security |
| security.rbac | RBAC | company stated | 2026-07-20 | www.trychroma.com/security |
| security.sso | SSO | company stated | 2026-07-20 | www.trychroma.com/security |
Security across Vector DatabasesChroma ranked in place · tap through for each read
No observed security facts yet for Chroma, KDB.AI, LanceDB, Marqo, Milvus, MyScale, Vespa and Weaviate.
Get security for trychroma.com via API / MCPevery field dated and sourced
RESTopen tier
GET https://api.bixel.com/v1/companies/trychroma.com/facts?dimension=security
{
"data": {
"facts": [
{
"key": "security.cert.soc2-type-ii",
"value": true,
"provenance": "company_stated",
"as_of": "2026-07-20",
"source_url": "www.trychroma.com/security"
},
{
"key": "security.encryption-at-rest",
"value": true,
"provenance": "company_stated",
"as_of": "2026-07-20",
"source_url": "www.trychroma.com/security"
},
{
"key": "security.encryption-in-transit",
"value": true,
"provenance": "company_stated",
"as_of": "2026-07-20",
"source_url": "www.trychroma.com/security"
},
{
"key": "security.sso",
"value": true,
"provenance": "company_stated",
"as_of": "2026-07-20",
"source_url": "www.trychroma.com/security"
},
"…"
]
}
}MCPfor agents
# any MCP client (Claude, agents)
const record = await bixel.get_company_facts({ domain: "trychroma.com", dimension: "security" })
# returns the security record above,
# each value with its source_url + as_of,
# ready to reason overBuild on the company record. One key, REST + MCP, every signal dated and sourced back to the page it came from.
Public record, read from companies' own pages and boards. Every fact dated and sourced; provenance (observed vs company stated) shown inline.