Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. Triggers on "cursor compliance", "cursor audit", "cursor security review", "cursor soc2", "cursor gdpr", "cursor data governance".
.claude/skills/jeremylongshore-cursor-compliance-audit/SKILL.md| Model | Eval pass | Runs |
|---|---|---|
| gemini-3.6-flash | 100% | 16 |
| gemini-3.1-pro-preview | 100% | 1 |
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 43% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 38% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 61% | 0% |
| case-09 | ✓→✗ | ▼ Worse | 12% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 90% | 0% |
Assess a Cursor deployment against approved privacy, identity, source-code, and audit controls. This is an evidence-backed configuration review, not legal certification.
.cursorignore settings to the approved baseline.Compliance and security auditing framework for Cursor IDE usage. Covers SOC 2, GDPR, and HIPAA assessment with audit checklists, evidence collection, and remediation guidance.
| Certification | Status | Notes | |--------------|--------|-------| | SOC 2 Type II | Certified | Annual audit, report available on request | | Penetration testing | Annual | Results shared under NDA (Enterprise) | | Encryption at rest | AES-256 | All stored data | | Encryption in transit | TLS 1.2+ | All API communications | | Zero data retention | Available | Via Privacy Mode | | GDPR compliance | Yes | EU data processing supported | | HIPAA BAA | Not available (as of early 2026) | See HIPAA section |
Developer Machine
│
├─► Cursor Client ──► Cursor API (US/EU) ──► Model Provider
│ (local) (routing + auth) (OpenAI/Anthropic)
│ │
│ └─► Zero retention agreement
│
├─► Codebase Index ──► Embedding API ──► Turbopuffer (vectors)
│ (no plaintext stored)
│
└─► Local Settings (API keys, preferences)
(never transmitted)[ ] SSO (SAML/OIDC) configured and enforced
[ ] MFA enabled at Identity Provider level
[ ] RBAC roles assigned: Owner, Admin, Member
[ ] Inactive users deprovisioned (SCIM or manual)
[ ] Access review completed (quarterly)
Evidence:
- SSO configuration screenshot from admin dashboard
- IdP MFA policy documentation
- User list export from Cursor admin
- SCIM sync logs (if applicable)[ ] Privacy Mode enforced at team level
[ ] .cursorignore configured for sensitive files
[ ] Data classification aligned with .cursorignore patterns
[ ] Model provider data retention agreements documented
[ ] BYOK configuration documented (if applicable)
Evidence:
- Privacy Mode enforcement screenshot
- .cursorignore file contents (committed to git)
- Cursor data use policy acceptance
- API key provider agreements[ ] All Cursor API calls use TLS 1.2+
[ ] Corporate proxy configured with valid certificates
[ ] No self-signed certificates or TLS bypasses
[ ] Network firewall rules documented
Evidence:
- Network architecture diagram showing Cursor data flows
- Firewall rules for cursor.com domains
- Proxy configuration settings[ ] Admin dashboard usage analytics reviewed monthly
[ ] Anomalous usage patterns investigated
[ ] Seat utilization tracked for access reviews
Evidence:
- Monthly usage report screenshots
- Incident response log for anomalies
- User activity summaryData Category: Source code snippets
Processing Purpose: AI-assisted code generation
Legal Basis: Legitimate interest (developer productivity)
Data Location: In-transit only (zero retention with Privacy Mode)
Sub-processors: OpenAI, Anthropic, Turbopuffer (embeddings)
Retention: None (Privacy Mode) or per provider policy (no Privacy Mode)| Right | Cursor Support | |-------|---------------| | Right to access | Account settings at cursor.com/settings | | Right to erasure | Account deletion removes all server-side data | | Right to portability | Settings export (settings.json) | | Right to restriction | Privacy Mode limits processing | | Right to object | Privacy Mode + .cursorignore |
[ ] Data Processing Agreement (DPA) signed with Cursor (Enterprise)
[ ] Privacy Mode enabled for all EU team members
[ ] Sub-processor list reviewed (cursor.com/privacy)
[ ] Data protection impact assessment (DPIA) completed
[ ] Team briefed on not pasting PII into Chat/Composer
Evidence:
- Signed DPA
- Privacy Mode enforcement confirmation
- DPIA document
- Team training recordsCurrent status: Cursor does not offer a Business Associate Agreement (BAA) as of early 2026.
If your organization handles PHI:
1. Enable Privacy Mode (mandatory)
2. Configure .cursorignore to exclude ALL PHI-containing files:
.cursorignore:
**/patient-data/
**/medical-records/
**/hl7/
**/fhir-resources/
**/*.hl7
**/*.ccda
3. Consider BYOK through Azure with BAA:
- Azure OpenAI has HIPAA BAA option
- Route Cursor AI requests through Azure
- Azure handles data governance
4. Train developers: NEVER paste PHI into Chat or Composer
5. Code review policy: verify no PHI in AI-generated code
6. CRITICAL: Consult your compliance team before any Cursor
usage with systems that process PHISeverity: High
Risk: Code may be retained by model providers for training
Remediation:
1. Admin Dashboard > Privacy > Enable enforcement (immediate)
2. Notify all team members (email)
3. Verify enforcement: check each member's status in dashboard
4. Document: date of enforcement, approval authoritySeverity: Medium
Risk: Sensitive files may be included in AI context
Remediation:
1. Create .cursorignore at project root
2. Add patterns for: .env*, secrets/, credentials/, PII directories
3. Commit to git (PR review required)
4. Verify: Cursor Settings > Codebase Indexing > View included files
5. Confirm sensitive files absent from indexed listSeverity: Medium
Risk: Shared or unrotated API keys
Remediation:
1. Audit which team members use BYOK keys
2. Verify keys are personal (not shared team keys)
3. Implement quarterly key rotation schedule
4. Document key management policy
5. Consider centralizing through Azure gateway (Enterprise)Severity: Medium
Risk: Former employees retaining Cursor access
Remediation:
1. Export current member list from admin dashboard
2. Cross-reference with HR active employee list
3. Deactivate accounts for departed employees
4. Enable SCIM for automatic deprovisioning
5. Schedule quarterly access reviews| Condition | Safe response | |---|---| | Admin evidence is incomplete | Mark the control unverified; do not infer compliance from plan level or screenshots alone. | | Sensitive code may have been exposed | Activate the incident process, restrict evidence distribution, and consult security/privacy owners. | | A policy conflicts with tenant configuration | Keep the restrictive policy in effect and escalate for a documented decision. |
For a privacy-mode control, capture the enforced tenant setting and a sampled member status, redact personal identifiers, and record the reviewer and date. If enforcement is absent, create a high-severity finding, assign the tenant admin, and verify again after the approved change.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 20,266 | 19,084 | -6% | 1 | 1 | 0% | 3,560 | 5,088 | +43% | 0 | 0 | — |
case-02 | fail→fail | 23,523 | 21,080 | -10% | 1 | 1 | 0% | 3,596 | 5,644 | +57% | 0 | 0 | — |
case-03 | fail→fail | 33,165 | 20,584 | -38% | 1 | 1 | 0% | 3,713 | 4,780 | +29% | 0 | 0 | — |
case-04 | pass→pass | 9,947 | 10,582 | +6% | 1 | 1 | 0% | 1,932 | 3,673 | +90% | 0 | 0 | — |
case-05 | fail→pass | 11,285 | 5,833 | -48% | 1 | 1 | 0% | 1,896 | 2,615 | +38% | 0 | 0 | — |
case-06 | fail→fail | 15,551 | 12,161 | -22% | 1 | 1 | 0% | 2,672 | 3,780 | +41% | 0 | 0 | — |
case-07 | pass→pass | 17,964 | 16,782 | -7% | 1 | 1 | 0% | 2,969 | 4,597 | +55% | 0 | 0 | — |
case-08 | fail→fail | 17,573 | 14,652 | -17% | 1 | 1 | 0% | 2,792 | 4,158 | +49% | 0 | 0 | — |
case-09 | pass→fail | 14,689 | 11,606 | -21% | 1 | 1 | 0% | 2,560 | 2,873 | +12% | 0 | 0 | — |
case-10 | fail→pass | 11,823 | 9,280 | -22% | 1 | 1 | 0% | 2,170 | 3,501 | +61% | 0 | 0 | — |
case-11 | pass→pass | 13,863 | 10,364 | -25% | 1 | 1 | 0% | 2,168 | 3,444 | +59% | 0 | 0 | — |
case-12 | pass→pass | 25,510 | 9,877 | -61% | 1 | 1 | 0% | 2,929 | 2,896 | -1% | 0 | 0 | — |
case-13 | pass→pass | 27,182 | 14,743 | -46% | 1 | 1 | 0% | 2,274 | 3,026 | +33% | 0 | 0 | — |
case-14 | pass→pass | 5,223 | 3,058 | -41% | 1 | 1 | 0% | 839 | 2,205 | +163% | 0 | 0 | — |
case-15 | fail→fail | 10,039 | 4,735 | -53% | 1 | 1 | 0% | 1,764 | 2,516 | +43% | 0 | 0 | — |
case-16 | pass→pass | 6,992 | 3,031 | -57% | 1 | 1 | 0% | 1,125 | 2,146 | +91% | 0 | 0 | — |
case-17 | pass→pass | 5,551 | 2,946 | -47% | 1 | 1 | 0% | 1,024 | 1,978 | +93% | 0 | 0 | — |
case-18 | pass→pass | 14,233 | 14,044 | -1% | 1 | 1 | 0% | 2,262 | 3,966 | +75% | 0 | 0 | — |
case-19 | pass→pass | 12,655 | 12,176 | -4% | 1 | 1 | 0% | 2,026 | 3,823 | +89% | 0 | 0 | — |
case-20 | pass→pass | 15,513 | 13,194 | -15% | 1 | 1 | 0% | 3,165 | 4,412 | +39% | 0 | 0 | — |
case-21 | pass→pass | 19,646 | 17,044 | -13% | 1 | 1 | 0% | 4,513 | 5,526 | +22% | 0 | 0 | — |
case-22 | pass→pass | 18,835 | 17,347 | -8% | 1 | 1 | 0% | 3,676 | 5,430 | +48% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +9 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.