Skip to content

Security changed Cursor, Jun 3, 2026

Cursor · Jun 3, 2026 · 15 added, 57 removed · found in an Internet Archive capture

  1. Added: Please submit potential vulnerabilities via email to security-reports@cursor.com . For any other security-related questions, contact us at security@cursor.com .
  2. Added: A SOC 2 Type II attestation report is available on request at trust.cursor.com .
  3. Added: We commit to at-least-annual penetration testing by reputable third parties. An executive summary of the latest report is also available on request via our trust portal.
  4. Added: Our list of subprocessors is published on our trust portal . Each subprocessor is evaluated under our vendor risk management program and re-reviewed annually. Cursor respects model blocklists and will not send requests to models on a blocklist.
  5. Added: Cursor does not use or maintain any infrastructure in China. We do not use any companies headquartered in China as subprocessors, and to our knowledge none of our subprocessors do either.
  6. Added: Infrastructure access is granted according to the principle of least privilege. We enforce multi-factor authentication, deploy cybersecurity tools, and monitor system logs and activity.
  7. Added: We assess upstream security patches based on risk and impact and, where warranted, merge and release immediately.
  8. Added: Our app makes requests to Cursor backend domains to deliver API, indexing, update, and marketplace functionality. If you're behind a corporate proxy, please allowlist these domains .
  9. Added: Best practices for using Cursor agents securely are documented in our developer docs :
  10. Added: We use our own products to help secure our codebase, including BugBot and Cloud Agent automations . See our security agents blog post for more information.
  11. Added: Privacy Mode can be enabled in settings or by a team or enterprise admin. When enabled, we implement technical controls and contractual requirements - such as Zero Data Retention (ZDR) terms with our model providers - so that code data is not stored by our model providers or used for training. Privacy Mode is available to anyone (free or Pro) and is enabled by default for members of a team.
  12. Added: Learn more about how your data is used .
  13. Added: You can delete your account at any time from the Settings dashboard -- see our account deletion guide for instructions.
  14. Added: For additional assistance with account deletion, contact customer support at hi@cursor.com .
  15. Added: If you believe you have found a vulnerability in Cursor, please submit a report to security-reports@cursor.com . We acknowledge vulnerability reports within 5 business days and address them as soon as we are able. Critical incidents are communicated via email to affected users.
  16. Removed: Please submit potential vulnerabilities via email to security-reports@cursor.com .
  17. Removed: For any security-related questions, feel free to contact us at security@cursor.com .
  18. Removed: While we have several large organizations already trusting Cursor, please note that we are still in the journey of growing our product and improving our security posture. If you're working in a highly sensitive environment, you should be careful when using Cursor (or any other AI tool). We hope this page gives insight into our progress and helps you make a proper risk assessment.
  19. Removed: Cursor is SOC 2 Type II certified. Please visit trust.cursor.com to request a copy of the report.
  20. Removed: We commit to doing at-least-annual penetration testing by reputable third parties. Please visit trust.cursor.com to request an executive summary of the latest report.
  21. Removed: We depend on the following subprocessors, roughly organized from most critical to least. Note that code data is sent up to our servers to power all of Cursor's AI features (see AI Requests section ), and that code data for users on privacy mode (legacy) is never persisted (see Privacy Mode Guarantee section).
  22. Removed: Explore how each mode affects how data is sent and stored:
  23. Removed: Explore how each mode affects how data is sent and stored.
  24. Removed: AWS Sees and stores code data : Our infrastructure is primarily hosted on AWS. Our primary servers are in the US, with some latency critical services in Europe and Singapore.
  25. Removed: Cloudflare Sees code data : We use Cloudflare as a reverse proxy in front of parts of our API and website in order to improve performance and security.
  26. Removed: Microsoft Azure Sees code data : Some secondary infrastructure is hosted on Microsoft Azure. All of our Azure servers are in the US.
  27. Removed: Google Cloud Platform (GCP) Sees code data : Some secondary infrastructure is hosted on Google Cloud Platform (GCP). All of our GCP servers are in the US.
  28. Removed: Fireworks Sees code data : Our custom models are hosted with Fireworks, on servers in the US, Europe, or Japan. We have a zero data retention agreement with Fireworks for users in Privacy Mode and Privacy Mode (Legacy). For Share Data users, Fireworks may temporarily access and store model inputs and outputs to improve our inference performance, for the minimum duration required to perform such tasks, after which it is securely deleted. Fireworks does not reuse the data for any other purpose.
  29. Removed: Baseten Sees code data : Our custom models are hosted with Baseten, on servers in the US and Canada. We have a zero data retention agreement with Baseten for users in Privacy Mode and Privacy Mode (Legacy). For Share Data users, Baseten may temporarily access and store model inputs and outputs to improve our inference performance, for the minimum duration required to perform such tasks, after which it is securely deleted. Baseten does not reuse the data for any other purpose.
  30. Removed: Together Sees code data : Our custom models are hosted with Together, on servers in the US. We have a zero data retention agreement with Together for users in Privacy Mode and Privacy Mode (Legacy). For Share Data users, Together may temporarily access and store model inputs and outputs to improve our inference performance, for the minimum duration required to perform such tasks, after which it is securely deleted. Together does not reuse the data for any other purpose.
  31. Removed: OpenAI Sees code data : We rely on OpenAI's models to provide AI responses. In Privacy Mode and Privacy Mode (Legacy), we have a zero data retention agreement with OpenAI. Additionally, requests may be sent to OpenAI for certain background or summarization tasks with zero data retention, regardless of which model provider you have selected*. For users that created their account after October 15, 2025, in Share Data mode, prompts and limited telemetry may also be shared with OpenAI when directly using their models.
  32. Removed: Anthropic Sees code data : We rely on many of Anthropic's models to give AI responses. Additionally, requests may be sent to Anthropic for certain background or summarization tasks with zero data retention, regardless of which model provider you have selected*. We have a zero data retention agreement with Anthropic.
  33. Removed: Google Cloud Vertex API Sees code data : We rely on some Gemini models offered over Google Cloud's Vertex API to give AI responses. Requests may be sent to Google Cloud Vertex API for certain background or summarization tasks with zero data retention, regardless of which model provider you have selected*. We have a zero data retention agreement with Vertex.
  34. Removed: xAI Sees code data : We rely on some Grok models offered over the xAI API to give AI responses. We have a zero data retention agreement with xAI.
  35. Removed: Turbopuffer Stores obfuscated code data : Embeddings of indexed codebases, as well as metadata associated with the embeddings (obfuscated file names), are stored with Turbopuffer on Google Cloud's servers in the US. You can read more on the Turbopuffer security page. Users can disable codebase indexing; read more about it in the Codebase Indexing section of this document.
  36. Removed: Exa See search requests (potentially derived from code data) : Used for web search functionality. Search requests are potentially derived from code data (e.g., when using "@web" in the chat, a separate language model will look at your message, conversation history and current file to determine what to search for, and Exa/SerpApi will see the resulting search query).
  37. Removed: * Cursor respects model blocklists and will not send any requests to models on a blocklist.
  38. Removed: None of our infrastructure is in China. We do not directly use any Chinese company as a subprocessor, and to our knowledge none of our subprocessors do either.
  39. Removed: We assign infrastructure access to team members on a least-privilege basis. We enforce multi-factor authentication for AWS. We restrict access to resources using both network-level controls and secrets.
  40. Removed: Cursor is a fork of the open-source Visual Studio Code (VS Code), maintained by Microsoft. They publish security advisories on their GitHub security page . Every other mainline VS Code release, we merge the upstream 'microsoft/vscode' codebase into Cursor. You can check which version of VS Code that your Cursor version is based on by clicking "Cursor > About Cursor" in the app. If there is a high-severity security-related patch in the upstream VS Code, we will cherry-pick the fix before the next merge and release immediately.
  41. Removed: Our app will make requests to the following domains to communicate with our backend. If you're behind a corporate proxy, please whitelist these domains to ensure that Cursor works correctly.
  42. Removed: 'api2.cursor.sh' : Used for most API requests.
  43. Removed: 'api5.cursor.sh' : Used for Cursor's agent requests.
  44. Removed: 'api3.cursor.sh' : Used for Cursor Tab requests (HTTP/2 only).
  45. Removed: 'repo42.cursor.sh' : Used for codebase indexing (HTTP/2 only).
  46. Removed: 'api4.cursor.sh' , 'us-asia.gcpp.cursor.sh' , 'us-eu.gcpp.cursor.sh' , 'us-only.gcpp.cursor.sh' : Used for Cursor Tab requests depending on your location (HTTP/2 only).
  47. Removed: 'adminportal42.cursor.sh' : Used to configure SSO and domain verification.
  48. Removed: 'marketplace.cursorapi.com' , 'cursor-cdn.com' , 'downloads.cursor.com' , 'anysphere-binaries.s3.us-east-1.amazonaws.com' : Used for client updates and for downloading extensions from the extension marketplace.
  49. Removed: Two security-related differences to VS Code to note:
  50. Removed: Workspace Trust is disabled by default in Cursor. You can enable it by setting 'security.workspace.trust.enabled' to 'true' in your Cursor settings. It is disabled by default to prevent confusion between Workspace Trust's "Restricted Mode" and Cursor's "Privacy Mode", and because its trust properties are nuanced and hard to understand (for example, even with Workspace Trust enabled, you are not protected from malicious extensions, only from malicious folders). We are open to community feedback on whether we should enable it by default.
  51. Removed: Extension code signatures: Cursor does not verify signatures of extensions that are downloaded from the marketplace. VS Code recently started doing this. In particular, the 'extensions.verifySignature' setting defaults to 'false' in Cursor but to 'true' in VS Code. If you set it to 'true' in Cursor, you'll see a pop-up saying that signature verification failed, every time you try to download an extension. We hope to start supporting extension signature verification in the medium-term future.
  52. Removed: To provide its features, Cursor makes AI requests to our server. This happens for many different reasons. For example, we send AI requests when you ask questions in chat, we send AI requests on every keystroke so that Cursor Tab can make suggestions for you, and we may also send AI requests in the background for building up context or looking for bugs to show you.
  53. Removed: An AI request generally includes context such as your recently viewed files, your conversation history, and relevant pieces of code based on language server information. This code data is sent to our infrastructure on AWS, and then to the appropriate language model inference provider (Fireworks/OpenAI/Anthropic/Google). Note that the requests always hit our infrastructure on AWS even if you have configured your own API key for OpenAI in the settings.
  54. Removed: We currently do not have the ability to direct-route from the Cursor app to your enterprise deployment of OpenAI/Azure/Anthropic, as our prompt-building happens on our server, and our custom models on Fireworks are critical in providing a good user experience. We do not yet have a self-hosted server deployment option.
  55. Removed: Cursor allows you to semantically index your codebase, which allows it to answer questions with the context of all of your code as well as write better code by referencing existing implementations. Codebase indexing is enabled by default, but can be turned off in settings.
  56. Removed: Our codebase indexing feature works as follows: when enabled, it scans the folder that you open in Cursor and computes a Merkle tree of hashes of all files. Files and subdirectories specified by '.gitignore' or '.cursorignore' are ignored. The Merkle tree is then synced to the server. Every 10 minutes, we check for hash mismatches, and use the Merkle tree to figure out which files have changed and only upload those.
  57. Removed: At our server, we chunk and embed the files, and store the embeddings in Turbopuffer . To allow filtering vector search results by file path, we store with every vector an obfuscated relative file path, as well as the line range the chunk corresponds to. We also store the embedding in a cache in AWS, indexed by the hash of the chunk, to ensure that indexing the same codebase a second time is much faster (which is particularly useful for teams).
  58. Removed: At inference time, we compute an embedding, let Turbopuffer do the nearest neighbor search, send back the obfuscated file path and line range to the client, and read those file chunks on the client locally. We then send those chunks back up to the server to answer the user's question. This means that for privacy mode users, no plaintext code is stored on our servers or in Turbopuffer.
  59. Removed: To block specific files in your codebase from being sent to Cursor's servers and included in AI requests, add a '.cursorignore' file to your codebase that lists the files and directories that should be excluded. Cursor will make a best effort to prevent exposure of these files from being included in any request.
  60. Removed: File path obfuscation details: the path is split by '/' and '.' and each segment is encrypted with a secret key stored on the client and a deterministic short 6-byte nonce. This leaks information about directory hierarchy, and will have some nonce collisions, but hides most information.

12 more changed paragraphs are on the page itself.

About this change
Page
cursor.com/security
Kind
Documentation
Text hash
173d3ed032b5 to 8dddbccaa378
Dated by
the first Internet Archive capture sampled that shows the new text; the change happened on or before this date

Terms changes by email

Mondays, only in weeks when a watched page changed.

Double opt-in. Unsubscribe any time.