We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
All AI tools
Cursor

Cursor

Anysphere, Inc.

Medium riskCodeHow we rate

Short answer

Short answer: Cursor is reasonable for code with Privacy Mode on (no training, no plaintext storage) — enforce it via Business/Enterprise. Remember it routes your code to external model providers, so keep secrets and regulated code out unless your policy covers that egress.

At a glance

Vendor / legal entity
Anysphere, Inc.
Headquarters
🇺🇸 San Francisco, US
Category
Code
Ownership / jurisdiction
US company (Anysphere, Inc.), founded 2022, San Francisco.
Trains on your data?
No
Data hosting & residency
Primary infrastructure is AWS (US). No verified EU-region residency option; Cursor states it maintains no infrastructure in China.
Sub-processors
Sub-processors are published at trust.cursor.com and include the model providers OpenAI, Anthropic, Google and xAI (under zero-retention agreements), plus AWS and a vector store.
Enterprise tier
Business/Enterprise force Privacy Mode on (code never trained on, not stored in plaintext) with SSO/admin controls; Free/Pro can enable Privacy Mode themselves.
Certifications
SOC 2 Type II

Why this rating

Medium risk

Cursor doesn't train on your code by default, and 'Privacy Mode' (a no-storage guarantee) is forced-on for Business/Enterprise and available to individuals. But it sends your code context to third-party model providers (OpenAI, Anthropic, Google, xAI) as sub-processors to generate responses, its only verified certification is SOC 2 Type II, and no EU data-residency option could be confirmed. Medium: reasonable defaults, but code egress to multiple external models is inherent to how it works.

How we rate

What it is

Cursor (by Anysphere) is an AI-first code editor. It does not train on your inputs by default, and Privacy Mode gives a no-storage guarantee — forced on for Business/Enterprise and available to individuals. The inherent consideration is that Cursor sends your code context to third-party model providers (OpenAI, Anthropic, Google, xAI) as sub-processors to generate responses. Its verified certification is SOC 2 Type II; no EU-residency option could be confirmed.

Frequently asked questions

Does Cursor train on your code?

Not by default, and with Privacy Mode enabled your code is never trained on or stored in plaintext. Privacy Mode is forced on for Business/Enterprise and optional for Free/Pro.

Where does my code go?

Cursor sends the relevant code context to third-party model providers (OpenAI, Anthropic, Google, xAI) under zero-retention agreements to generate responses. They're listed as sub-processors on its trust portal.

How do I govern Cursor at work?

Enforce Privacy Mode via the Business tier, and use Qadar AI Shield to discover usage and keep secrets and regulated code out of prompts.

Sources

Every fact and the risk rating on this page trace to a primary source — the vendor's own trust center, privacy policy, DPA, or a regulator. Verify current terms before relying on them.

  • •Privacy Mode, SOC 2 Type II, no China infra
  • •No training by default; Anysphere as processor
  • •Sub-processors (model providers)

Govern this tool

Qadar AI Shield turns these risk facts into enforcement — discover who uses the tool, redact personal data before it reaches it, and allow-list or block it per team.

Book a demoSee how Shield Web governs AI

Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·