90 Days Gen AI Risk Trial -Start Now
Book a demo
Code Assistants·Hobby free; Pro $20/mo; Teams $40/user/mo; Enterprise custom·cursor.com

Cursor

Cursor is an AI-first code editor built on VS Code with agent, tab completion, and multi-model chat powered by frontier LLMs across a developer's codebase.

Risk Score
Low
3/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Cursor (Anysphere) is an AI-native code editor built on VS Code. It combines autocomplete, in-editor chat, and agentic edits across a codebase, routing requests to OpenAI, Anthropic, Google, and other frontier model providers. Teams and Enterprise tiers add Privacy Mode (zero data retention with model providers), SSO, usage analytics, audit logs, and SCIM. Cursor is SOC 2 Type II certified and runs on AWS, Azure, and GCP with US, EU, and Singapore regions.

Risk factors

3
  • Self-hosted option available for data privacy.
  • Local mode for data processing.
  • Minimal data access required for core functionality.

Recommendations

8
  • Enforce Privacy Mode org-wide via Teams/Enterprise admin controls
  • Deploy SSO (SAML/OIDC) and SCIM to centralize access on Enterprise plan
  • Use .cursorignore to exclude secrets, customer data, and regulated directories from indexing
  • Review SOC 2 Type II report at trust.cursor.com before procurement
  • Block personal Cursor accounts via identity provider; require managed workspace
  • Enable audit logs and AI code tracking API to monitor agentic edits
  • Train engineers on prompt hygiene; prohibit pasting production secrets into chat
  • Pilot with a single team before broad rollout; measure code-acceptance and security events

Data handling

Storage
AWS, Azure, GCP, and Cloudflare subprocessors with primary US region and latency services in EU/Singapore; no China infrastructure. Obfuscated embeddings stored in Turbopuffer.
Retention
Account deletion completed within 30 days (backups purged). Privacy Mode: zero retention at model providers. Share Data Mode: temporary provider access for inference.
Training on inputs
Privacy Mode (default on Teams) guarantees code is never used to train models. Share Data Mode allows limited provider telemetry but not training reuse.