Cursor
medium riskAI Coding Assistantcursor.comverified 2026-06-27
Data-handling profile
- Trains on input
- Yes, on the consumer tier (enterprise tier excluded)
- Retention
- Zero data retention (ZDR) agreements held with all underlying model providers. With Privacy Mode ON (default and enforced for Business/enterprise plans), code is not stored or trained on and is discarded after each request. With Privacy Mode OFF (possible on individual/free tiers), prompts/code may be retained up to 30 days for safety monitoring and may contribute to product improvement.
- Data region
- US
- Certifications
- SOC 2 Type II
- DPA available
- Yes
- Breach history
- Multiple 2025 CVEs disclosed (e.g., CVE-2025-54135 'CurXecute', CVE-2025-54136 'MCPoison', CVE-2025-64110, CVE-2025-59944) — prompt-injection/RCE-class vulnerabilities in the editor's agent and MCP handling, patched by vendor; not a data-training/retention breach but relevant application-security history.
- EU AI Act
- Enterprise privacy-mode-by-default and ZDR contracts with model providers reduce EU AI Act training-data exposure, but numerous 2025 agentic-tool CVEs indicate elevated application-security risk to weigh alongside data-handling posture.
Sources
- https://cursor.com/data-use
- https://cursor.com/privacy
- https://cursor.com/security
- https://thehackernews.com/2025/08/cursor-ai-code-editor-vulnerability.html
- https://www.lakera.ai/blog/cursor-vulnerability-cve-2025-59944
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.