Compliance frameworks, security audits, and quality certifications this company maintains.
All data transmitted to and from Shortcut is encrypted in transit using TLS 1.2 or higher, protecting story, sprint, and team data from interception across all API and web application connections.
Shortcut maintains SOC 2 Type II certification, demonstrating that its platform meets rigorous security, availability, and confidentiality controls required by engineering teams at regulated enterprises storing sprint and product data in the cloud.
Shortcut is GDPR compliant, providing EU customers with data processing agreements, data subject rights workflows, and configurable data residency options to meet European privacy requirements for project and team data.
Shortcut complies with the California Consumer Privacy Act, giving California-based users and organizations the right to access, delete, and opt out of the sale of their personal information stored on the platform.
Shortcut is pursuing ISO 27001 certification to formalize its information security management system, addressing demand from enterprise customers in financial services and healthcare who require it as a vendor qualification criterion.
Shortcut supports SAML 2.0 single sign-on integration with identity providers including Okta, Azure AD, and Google Workspace, enabling enterprise IT teams to enforce centralized access controls for Shortcut workspaces.
Shortcut supports SCIM 2.0 for automated user provisioning and deprovisioning, allowing enterprise customers to sync Shortcut workspace membership directly from their identity provider without manual administration.
Shortcut encrypts all customer data at rest using AES-256 encryption, ensuring that workspace data including stories, epics, comments, and attachments is protected in Shortcut cloud storage infrastructure.
Shortcut is working toward WCAG 2.1 AA accessibility conformance, improving keyboard navigation, screen reader compatibility, and color contrast across its project management interface for users with disabilities.
Shortcut is pursuing CSA STAR Level 1 self-assessment to publish its cloud security controls inventory, supporting procurement teams at enterprise customers evaluating Shortcut as a compliant SaaS vendor.