Cutshort logo

Security & compliance

Cutshort security

How we host and protect data on our sourcing platform — plus downloadable documents for enterprise due diligence.

Cloud security outline

This page summarizes how Cutshort is scoped and hosted for enterprise due diligence. Cutshort is a talent sourcing platform used by a small set of customer personnel — typically recruiting or talent-acquisition users — in a largely manually managed environment.

No system integration by default. Integrations are not turned on unless the customer enables them. When ATS sync is enabled, it is generally one-directional: candidate data flows from Cutshort into a job-specific pipeline in the customer’s ATS. Employee data and external candidate data from the customer do not flow into Cutshort.

Recruiters primarily use Cutshort in the browser over HTTPS. Candidate profiles live in Cutshort’s cloud until a customer chooses to export or sync them under their own process.

Production workloads run primarily on Amazon Web Services in Mumbai (ap-south-1), with limited supporting services on Google Cloud. Traffic passes through edge protection and an AWS load balancer with WAF into application services in private subnets. The primary database is not internet-reachable; admin access requires SSO and a certificate-based Client VPN.

Cutshort high-level cloud security architecture showing customer organization out of scope, HTTPS access for a few recruiting users, AWS private subnets, and Google Cloud supporting services
Cloud security architecture
High-level diagram of customer scope, AWS / Google Cloud zones, and access controls (PNG)
Download
Security policy outlines
Information security, incident response, risk management, and third-party risk policy outlines (ZIP)
Download