TRUST & LEGAL · PREVIEW STATUS
Cutloom Trust Center
A clear view of what exists today, what data the preview handles, and what is still required before private customer use.
Current infrastructure
Cutloom uses Cloudflare Pages for website delivery, Pages Functions for its API, and D1 for project metadata. Local, staging, and production environments use separate database configurations.
The important limitation
The foundation workspace and project API are public and are not protected by user accounts. Project records can be read by other visitors. Only use fictional project names. This is not a private workspace for customer data.
What is not claimed
Cutloom has no published SOC 2 report, ISO certification, independent penetration-test report, or compliance attestation. A provider’s certifications do not certify Cutloom.
There is no published uptime SLA, bug-bounty program, completed disaster-recovery assessment, or monitored security intake. Do not submit sensitive security material to the mock contact address.
Before customer onboarding
Private authentication and authorization, verified support/privacy contacts, retention and deletion procedures, incident response, and reviewed legal documents must be completed. No video uploads or payment processing are enabled today.