Source
Security / trust page — found from the homepage — Shortcut
Checked for Shortcut on 30 Sep 2026
- Page
- https://www.shortcut.com/security/
- Checked
- 30 Sep 2026, 12:54 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:154f4d9890390fe0d243ee3ae38693c82d35e5c969fe04493378ed98acb8df29
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
SOC 2 Report an error
“Shortcut has successfully completed its SOC 2 Type 2 audits for controls relevant to security, availability, and confidentiality with no exceptions in entity-level testing.”
-
HIPAA baa Report an error
“For HIPAA compliance, we offer a Business Associate Agreement (BAA) to customers on our Business and Enterprise Plans.”
-
Provider Report an error
“Shortcut runs on Amazon Web Services.”
-
Storage Report an error
“Live Shortcut data is stored on AWS in DynamoDB”
-
Backups Report an error
“We also do incremental, encrypted backups of the DynamoDB datastore every 10 minutes to Amazon S3 which is designed to offer 99.999999999% durability”
-
Https Report an error
“All data exchanged with Shortcut is done via the HTTPS protocol.”
-
Employee access Report an error
“No Shortcut employee will ever see your customer data unless required to do so for support reasons. If you reach out with a support issue which requires us to access your customer data, we will request and wait for your written permission before doing so.”
-
Password security Report an error
“All passwords are filtered from all our logs and are one-way encrypted in the database using bcrypt.”
-
2FA Report an error
“We also allow you to use two-factor authentication, or 2FA, as an additional security measure when accessing your Shortcut account.”
-
Stripe payments Report an error
“your credit card information is handed off to Stripe, a company dedicated to storing your sensitive data on PCI-Compliant servers. Our servers do not store or even see your credit card information.”
-
Documents Report an error
“Terms of Service Security Privacy Policy GDPR & Data Privacy Framework Notice GDPR & Subprocessors Responsible Disclosure AI Info”
-
Ssh disabled Report an error
“all machines with access to Shortcut data have SSH disabled to prevent any unauthorized access to customer data.”
Scores citing this record
- The Bootstrapper Pricing transparency
- The Bootstrapper European sovereignty
- The Data Protection Officer European sovereignty
- The Enterprise Architect Pricing transparency
- The Enterprise Architect European sovereignty
- The Integrator Pricing transparency
- The Integrator European sovereignty
- The Skeptic Pricing transparency
- The Skeptic European sovereignty
- The UX Purist Pricing transparency
- The UX Purist European sovereignty