Shortcut

United States · shortcut.com · 35 vendors

Shortcut is a project management software company that provides an intuitive platform for software development teams. It helps engineering teams plan, build, and deploy products by offering features like issue tracking, sprint planning, and documentation to streamline workflows and collaboration.

Resilience scores

Disruption prediction

Shortcut has an estimated 11% probability of disruption in the next 6 months.

18 of Shortcut's 35 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 35 sub-vendors.

Insights

Last updated 2026-08-16 · revision 6

35 direct vendors, 267 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Shortcut exhibits a high level of migration readiness, scoring 72 out of 100. The company's tech stack is highly cloud-native, leveraging Amazon Web Services (AWS) extensively for core services like DynamoDB and S3, alongside a wide array of modern cloud-based tools. The use of Clojure for backend engineering, coupled with a REST API, Model Context Protocol (MCP), and AI/LLMs, suggests a modular and flexible architecture that would facilitate migration efforts. The absence of specified data residency requirements provides significant flexibility in choosing new infrastructure locations or cloud providers. Financially, Shortcut's history of successful funding rounds (Seed, Series A, Series B) indicates a strong capacity to invest in and fund complex migration projects. Despite these strengths, several factors present challenges to migration. The company's reliance on 40 distinct third-party services introduces a high degree of integration complexity and potential vendor-specific dependencies, which could complicate a large-scale migration. While vendor geographic diversity is present, the sheer number of integrations could lead to moderate vendor lock-in, even if individual vendors are diverse. The 'Unknown' vendor lock-in risk further highlights this potential challenge. Furthermore, Shortcut's adherence to stringent regulatory compliance standards (SOC 2 Type 2, GDPR, HIPAA) means that any migration must be meticulously planned and executed to ensure continuous compliance, adding significant overhead and complexity to the process.

Compliance

7 in-scope frameworks identified; showing 3.

PCI DSS (source) — Compliant

Shortcut explicitly delegates all payment card processing to Stripe, a PCI-compliant payment processor. Shortcut's own servers do not store, process, or transmit cardholder data, which means Shortcut operates at the lowest PCI DSS scope (SAQ A or equivalent). By using Stripe as a compliant third-party processor, Shortcut effectively eliminates its own PCI DSS compliance burden for cardholder data. Risk is low because the architecture is designed to minimize PCI scope.

Evidence: https://shortcut.com/security

SOC 2 (source) — Compliant

Shortcut has successfully completed SOC 2 Type 2 audits with no exceptions in entity-level testing, covering the Trust Services Criteria of Security, Availability, and Confidentiality. SOC 2 Type 2 is the gold standard for cloud service providers and represents the highest level of SOC 2 assurance (ongoing operational effectiveness over a period, not just point-in-time design). The 'no exceptions' result indicates strong control performance. Risk is low given the confirmed Type 2 certification with clean results.

Evidence: https://shortcut.com/security

CPRA — Compliant

Shortcut is headquartered in New York but operates as a US-wide SaaS platform serving California residents, making CCPA/CPRA applicable. The privacy policy provides data subject rights (access, deletion, opt-out of direct marketing) consistent with CCPA requirements. The company provides a clear contact mechanism (support@shortcut.com and privacy@shortcut.com) for data requests. Risk is low given the published privacy policy with CCPA-aligned rights and the company's demonstrated commitment to privacy compliance across multiple frameworks.

Evidence: https://shortcut.com/privacy, https://shortcut.com/security

Financials

Three-year financials

Financial Resilience Score: 6/10

Shortcut is a mid-stage, venture-backed private SaaS company that does not publicly disclose revenue, EBIT, or equity, making a precise financial resilience assessment impossible from public sources. However, qualitative indicators support a moderate resilience score. The company benefits from a recurring subscription SaaS revenue model with per-seat pricing (typically producing 70-85% gross margins in the peer group), a broad and non-concentrated customer base of 50,000+ organizations across multiple verticals, and backing from top-tier VCs including Greylock Partners and Battery Ventures. Total disclosed funding of approximately $47.5M provides some capital cushion, though the last major round (Series B, $25M) was in January 2020, and no subsequent large raise has been prominently announced, making current cash runway unclear. On the risk side, Shortcut operates in an intensely competitive category against well-capitalized incumbents (Atlassian/Jira, Monday.com, Asana, ClickUp) and rapidly growing AI-native challengers (Linear, Notion, GitHub Projects). The 2021 rebrand from Clubhouse likely cost SEO and brand equity. Category disruption from AI-native tools poses execution risk, though Shortcut's September 2025 launch of the Korey AI agent and MCP server shows active reinvestment. Overall, the company appears to have solid product-market fit and enterprise-ready compliance (SOC 2, GDPR, HIPAA-ready), but lack of financial transparency and competitive intensity temper the resilience score.

Key strengths: Recurring subscription SaaS revenue model with high typical gross margins, Blue-chip VC backing from Greylock Partners and Battery Ventures, Broad customer base of 50,000+ organizations across multiple verticals, Total disclosed funding of ~$47.5M across Seed/Series A/B/C, Enterprise compliance posture (SOC 2, GDPR, HIPAA-ready, SSO/SCIM), Active product reinvestment including AI agent Korey (Sep 2025), 21M+ stories completed on platform indicating strong usage scale

Risk factors: Intense competition from Atlassian, Linear, Monday.com, ClickUp, Asana, Notion, No IPO track and limited financial transparency, Category disruption from AI-native project management tools, Last major funding round was Series B in January 2020; runway unclear, Rebrand from Clubhouse in 2021 likely cost SEO/brand equity, Execution risk on AI product roadmap (Korey)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report