Cursor
Cursor reads codebases and completes multi-file tasks from its editor.
Overview
- Transparency
- 7 / 10
- Trust
- 92 / 100
Trains on your data
- Free
- No
- Paid
- No
- Opt-out
- Yes
Incidents
3- mediumCursor Desktop sandbox escape via symlink and failed path canonicalization
- mediumModification of MCP Server Definitions Bypasses Manual Re-approval
- highPersonal Data Breach in Cursor Dashboard Analytics Page
Assessed SEP 21, 2026 · Checked by hand SEP 21, 2026
Cursor confirms SOC 2, ISO 27001, a GDPR DPA and eligible Enterprise BAA, with training opt-out, provider ZDR, seventeen subprocessors and three supported incidents.
Trust breakdown
92 / 100
Overall trust score
Data and privacy
Trains on your data
No training on user data
Storage regions
Sub-processors
Data retention
Cursor maintains zero data retention (ZDR) agreements with all providers, and AI model providers will not store or train on your data.
Deletion: At Customer’s written direction, Vendor shall delete or return all Personal Data to Customer as requested at the end of the provision of the Service, within thirty (30) days of such request, unless retention of the Personal Data is required by law, and upon request shall provide written certification thereof.
Incidents
2026-06-05
Cursor Security Advisory
2025-08-01
GitHub Advisory
2026-03-04
Cursor Community Forum
Powered by
Cursor trains its own proprietary models like Composer, Fast Apply, and the Tab model. They also utilize third-party models such as GPT-4, Claude, Google Gemini 3 Pro, xAI Grok Code, and OpenAI's embedding models. They use various providers for training and fine-tuning their models, including Voltage Park, Databricks MosaicML, and Foundry. Inference is primarily done on Azure and AWS, with tens of thousands of NVIDIA H100 GPUs.
Integrations and access
Integrations
Available on
Pricing
Hobby
Free
Limited usage of other models
Pro
$20/mo
Included usage of Cursor Models and Other Models, unlimited tab completions, extended agent usage limits, Bugbot, Cloud Agents
Pro+
$60/mo
Higher included usage of Cursor Models and Other Models, unlimited tab completions, extended agent usage limits, Bugbot, Cloud Agents
Ultra
$200/mo
Highest included usage of Cursor Models and Other Models, unlimited tab completions, extended agent usage limits, Bugbot, Cloud Agents
Start (India only)
₹649/mo
Included usage of Cursor Models, Cloud Agents. Does not include Other Models pool, on-demand usage, Bugbot, Auto, Automations, or Cursor SDK.
Teams Standard
$40/user/mo
Standard team allowance, additional team features
Teams Premium
$120/user/mo
5x Standard team allowance, additional team features
Enterprise
Custom
Custom pricing, pooled usage, SCIM provisioning, audit logs, advanced admin controls, invoice billing. Contact sales.
Prices as listed on SEP 21, 2026; check the vendor's page.
Moat and openness
Moat
- Proprietary Model
- Proprietary Data
- Network Effects
- Switching Costmoderate
- Unique UX
- Distributionmoderate
Cursor exhibits some defensibility through its proprietary models (Composer, Fast Apply, Tab model) and a unique, agent-driven UX that integrates multiple frontier models. While it has a significant user base and notable enterprise customers, its reliance on third-party models for complex reasoning and the competitive landscape with GitHub Copilot and Claude Code suggest a moderate switching cost and distribution, preventing a stronger moat.
Openness
- Open model weights
- Published research
- Open source contributions
- Transparency reports
- Public safety evals
Anysphere, the company behind Cursor, demonstrates moderate openness. They have a significant presence on GitHub with numerous public repositories, including some related to prompt design and GPT-4 for code, indicating contributions to open-source. They also have a whitepaper describing their threat model and security measures. However, the product itself (Cursor) is closed-source, and there are concerns regarding the transparency of their data handling practices, particularly concerning the scope of code context transmission and the lack of a published formal threat model for their agent mode. While they offer SOC 2 Type II certification and DPAs, they do not publicly disclose a full list of sub-processors for GDPR compliance, and their training data composition for proprietary models is not public.
Timeline
- 2024-06Claude 3.5 Sonnet Integration.
- 2024-05Composer Feature Released.
- 2023-10Cursor raises an $8M seed round led by OpenAI Startup Fund.
- 2023-03Cursor 1.0 launches as an AI code editor.
Company
Anysphere
- Founded
- 2022
- HQ
- San Francisco, California, United States
- Site
- anysphere.inc
Popularity
16.8M
monthly visits
Notable customers
Cursor leads in enterprise revenue among pure-play AI coding vendors, but trails GitHub Copilot in user base and Claude Code in developer satisfaction.
Value and ROI
What it should move: It shortens the path from an issue to a reviewable change.
Best fit
It fits teams with tests, disciplined reviews, and written repository instructions.
The catch
Cursor sends code context to model services and can change many files. Teams must control data settings, diffs, and commands.
- Box: Uses Cursor for code guardrails, tests and large codebase migrations.[1]
- Vercel: Uses Cursor to build and test event-streaming infrastructure against cloud environments.[2]
In our stacks for
References
- 01Box: how it uses CursorCursorVendor-published
- 02Vercel: how it uses CursorCursorVendor-published
- 03Privacy policyAnysphereVendor-published
- 04TermsAnysphereVendor-published
- 05Trust centerAnysphereVendor-published
- 06Pricing pageAnysphereVendor-published
- 07Company siteAnysphereVendor-published
- 08SOC 2AnysphereVendor-published
- 09GDPRAnysphereVendor-published
- 10HIPAAAnysphereVendor-published
- 11Cursor Desktop sandbox escape via symlink and failed path canonicalizationCursor Security AdvisoryIndependent
- 12Modification of MCP Server Definitions Bypasses Manual Re-approvalGitHub AdvisoryIndependent
- 13Personal Data Breach in Cursor Dashboard Analytics PageCursor Community ForumIndependent