01Trust Score

Cursor

Conditional Proceed

Week 2026-W22 May 25, 2026 Vendor-Neutral
40 /100 Notable Concerns
4.1/5 (5707)
↓ PDF Report
Key risks include unverified compliance certifications (SOC 2 Type II, GDPR DPA) due to inaccessible documentation, potential for AI model errors as explicitly stated in the Terms of Service, and community-reported issues regarding UI changes, model configuration transparency, and AI code quality. While the company demonstrates strong financial health and a commitment to data privacy with an opt-out for model training, the lack of verifiable compliance reports poses a significant procurement hurdle.
Trust Score 40/100 CONDITIONAL
Est. Annual Cost 58000 100 users / yr
Top Risk HIGH Reliability Overall: Medium
Priority Action Obtain verifiable SOC 2 Type II and GDPR DPA reports. ↓ PDF  · TCO  · Hardening
Enterprise: DPA: Unknown · Residency: Unknown · Lock-in: Medium (50/100)

Verified Compliance Facts

Cited and timestamped — every claim traceable to an official vendor source.

Base price
$20 / mo (lowest paid tier)
Source ↗ Checked: May 17, 2026 ~ Evidence found
Data residency
United States
Source ↗ Checked: May 17, 2026 ~ Evidence found
GDPR
Not yet verified
No citation Checked: May 25, 2026 ⏳ Claimed
HIPAA
Not yet verified
No citation Checked: May 25, 2026 ⏳ Claimed
ISO/IEC 27001
Not yet verified
No citation Checked: May 25, 2026 ⏳ Claimed
SOC 2
Not yet verified
No citation Checked: May 25, 2026 ⏳ Claimed
Sub-processors
Not yet verified
Source ↗ Checked: May 17, 2026 ~ Evidence found
Trains on customer data
✗ Not offered
Source ↗ Checked: May 17, 2026 ~ Evidence found

Enterprise Verdict

! Conditional Approval
Risk: Medium Confidence: medium 50 sources

Conditional Proceed

Cursor offers advanced AI coding capabilities and strong financial backing, but critical compliance documentation (SOC 2, GDPR DPA) remains unverified due to broken links. An extended evaluation is necessary to address these legal and security transparency gaps before full adoption.
Key Strength

Advanced AI coding capabilities and multi-model support.

Top Risk

Unverified critical compliance documentation (SOC 2, GDPR DPA).

Priority Action

Obtain verifiable SOC 2 Type II and GDPR DPA reports.

This report updates every week. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
02Top Risks

Risk Assessment

Seven-category enterprise risk analysis derived from community and vendor signals. Each card shows the evidence tier and the underlying finding.

High Reliability Community Data

Public documentation buyers may want to verify availability of specific uptime commitments or reliability history.

Medium Cost Predictability Community Data

Enterprises should negotiate fixed-rate contracts and monitor pricing changes for overage risks.

High Vendor Lock-in Community Data

Data export status unclear. Integration score: 85/100. Webhooks available, reducing lock-in risk.

Medium Support Quality Community Data

Insufficient public community reviews to verify support quality. Standard support channels (email/documentation) are assumed.

Medium Data Privacy Community Data

Compliance score: 93/100. GDPR status: dpa_available. Encryption at rest: yes.

Low Compliance Posture Community Data

SOC 2: type_ii. ISO 27001: none. Overall compliance score: 93/100.

High AI Transparency Verified

Vendor may train on user data. Users retain code/output ownership. Legal/ToS risk score: 40/100.

Verified — Confirmed by vendor documentation Community — Derived from community reports

Due Diligence Alerts

Priority reviews, recommended inquiries, and verified strengths — based on 106+ community data points

Recommended Inquiry Unverified SOC 2 Type II Attestation

Cursor claims a SOC 2 Type II attestation report is available upon request via its trust portal, but the provided URL (https://cursor.sh/trust) is a broken link, preventing direct verification of this critical security control.

Sources: Web
Recommended Inquiry Unverified GDPR Data Processing Addendum (DPA)

A Data Processing Addendum (DPA) is claimed to be available, but the provided URL for the DPA (https://www.cursor.com/dpa) results in a 'page couldn't load' error, making it impossible to review the terms for processing personal data, particularly for EU/UK users.

Sources: Web
Recommended Inquiry Extremely Low Liability Cap in Terms of Service

The Terms of Service limit Anysphere's aggregate liability to the greater of fees paid in the preceding six months or $100. This cap is exceptionally low and poses a severe unmitigated risk for any enterprise adopting the service, particularly concerning data breaches or service failures.

Sources: Web
03Security & Compliance

Security & Compliance

ISO 27001 ✓ Active
PEN_TEST ⏳ Claimed Unverified
SOC 2 ~ Active (unverified link) ⚠ Dead link
GDPR ~ DPA (unverified link) ⚠ Dead link

External Registry Verification

Data Security

Encryption (At Rest): AES-256
Encryption (In Transit): TLS 1.2+

Security Features

SSO SAML, OIDC
MFA TOTP
Audit Logs
Vulnerability Disclosure

Enterprise Contract Intelligence

DPA availability, data residency, and contract risk signals for procurement teams

DPA: Unknown Residency: Unknown Lock-in: Medium (50/100)
📄 Data Processing Agreement Unknown

A DPA is claimed to be available at the provided URL, but the page is inaccessible. This prevents verification of critical data processing terms, including Standard Contractual Clauses (SCCs) or subprocessor lists, which are essential for GDPR compliance.

🌐 Data Residency Unknown

Anysphere processes personal data on servers located in various jurisdictions, including the United States. For users in the EEA/UK, personal data may be transferred to US servers. EU hosting is not available, which may impact organizations with strict EU data residency requirements.

⚠️ Contract Risk Medium Lock-in (50/100)
Notice: 30 days
⚠ 1 contract risk flag — click to review
⚠ Auto-renewal terms and data export rights not publicly documented — verify before signing.

Full contract terms for Cursor require direct vendor engagement. Ensure data portability on exit, notice period, and pricing lock clauses are negotiated before execution.

Compliance & Document Matrix

🛡️ Security Certifications

Certification Status Auditor Valid Until Source
ISO 27001 ✅ Active View
3rd Party Penetration Test 📄 Claimed View
SOC 2 Type II ✅ Active View

🔒 Data Privacy Documents

Document Status URL AI Assessment
Sub-processors ❌ Not Found ❌ Not found
AI/Model Training Policy ❌ Not Found — Unclear
Data Retention Policy ❌ Not Found ❌ Not found
Data Flow Diagram ❌ Not Found
GDPR Compliance Statement ❌ Not Found ❌ Not found
KVKK Compliance Statement ❌ Not Found ❌ Not found
CCPA Compliance Statement ❌ Not Found ❌ Not found

⚖️ Legal Contracts

See Legal & IP Assessment section above for full analysis of ToS, DPA, MSA, SLA, EULA, and AUP.

🔧 Operational Readiness

Document Status URL AI Assessment
Business Continuity Plan (BCP) ❌ Not Found ❌ Not found
Disaster Recovery Plan (DRP) ❌ Not Found ❌ Not found
Incident Response Plan ❌ Not Found ❌ Not found
3rd Party Penetration Test 📄 Claimed View ❌ Not found

📋 Technical Transparency

Document Status URL AI Assessment
SBOM ❌ Not Found ❌ Not found
OSS License Inventory ❌ Not Found ❌ Not found
Vulnerability Management Policy ✅ Active Link ❌ Not found
Patch Management Policy ❌ Not Found ❌ Not found
Offboarding / Data Export Guide ❌ Not Found ❌ Not found
SIG Questionnaire ❌ Not Found
CAIQ ❌ Not Found

💰 Financial Resilience

Item Status Details
Cyber Liability Insurance ❌ Not Found ❌ Not mentioned
TCO Disclosed ✅ Available Annual: 58000
New risk signals detected weekly. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
04Community Signals

Community Intelligence

Recurring issues and curated signals from GitHub, Hacker News, Reddit, Stack Overflow, web sources, and enterprise review platforms.

Intelligence Synthesis

Cursor, an AI coding assistant by Anysphere, demonstrates strong AI capabilities and significant financial backing, including a reported $3 billion ARR by early 2026. However, critical compliance documentation, such as SOC 2 Type II and GDPR DPA, remains unverified due to broken links, raising significant legal and security concerns. Community feedback highlights issues with recent UI changes, agent experience, and transparency around model usage, while also praising its productivity benefits.

Recurring Issues

Buggy and confusing agent experience / UI issues 🟠 Community 4 mentions medium → Stable

Enterprise Impact: Reduced developer efficiency, increased frustration, and potential for errors in AI-assisted workflows due to a non-intuitive or buggy interface. This can hinder adoption and ROI.

As of 2026-05, community reports indicate a need for UI/UX improvements, particularly regarding multi-window management and agent interaction flows, to ensure a smooth and efficient developer experience.

Lack of transparency in model selection and usage limits 🟠 Community 1 mentions medium → Stable

Enterprise Impact: Unpredictable costs and difficulty in budgeting for AI model consumption. Lack of clear usage statistics hinders cost optimization and accountability within enterprise teams.

As of 2026-05, users are requesting clearer documentation on how 'Auto' model selection works, explicit quota limits, and detailed usage dashboards to better manage costs and model behavior.

Sources: Reddit
AI code quality concerns and context loss 🟠 Community 2 mentions medium → Stable

Enterprise Impact: Increased effort for human developers to review and correct AI-generated code, especially for complex languages like Rust or large codebases where context is lost. This can negate productivity gains and introduce technical debt.

As of 2026-05, community feedback suggests improvements are needed in AI model's understanding of specific language idioms (e.g., Rust) and its ability to maintain context across large codebases to ensure high-quality code generation.

Sources: HN HN

Source Signals

05Financial Impact

Financial Impact Panel

Cost intelligence and pricing signals for enterprise procurement decisions

Switching Cost Estimate High
Subscription-based with usage-based add-ons for model consumption. Free tier available

Hobby

Individual

Teams

Enterprise

Base price sourced from: official pricing page ↗ — "Individual $20 / mo."

Pricing data from public sources — enterprise rates differ. Verify with vendor.

TCO Calculator

Calculate the real monthly cost for your team. Adjust seats, usage, and pricing tier below.

Estimated Monthly Cost

Base Subscription $0
AI Credits / Tokens $0
Hidden Costs (onboarding, overages, support) $0
Total Monthly TCO $0
Per User / Month $0
Annual Projection $0

Estimated Annual TCO — 100 Users ±20% confidence band

SMB / Pay-as-you-go
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.
Mid-market / Per-seat
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.
Enterprise / Provisioned
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.

Pricing data not available — all estimates undisclosed.

Don't evaluate blind next quarter. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.

Synthesized from 20+ independent public sources: developer forums & repositories, security databases, vendor disclosures, regulatory filings, and community review platforms. Not affiliated with any vendor. Corrections?

Download PDF Report

Create a free account to download the full enterprise audit PDF.

Sign up — it's free →

Already have an account? Log in