Research

Emil Lassen

Emil Lassen

3 min read

3 min read

Cursor achieves AIUC-1 certification

Cursor logo

Coding agents now do work that used to require a trusted engineer. Cursor’s AIUC-1 certification validates how its agents behave across real-world coding risks.

Coding agents now do work that used to require a trusted engineer. They read repositories, write and execute code, install dependencies, and open pull requests.

Close to 70% of the Fortune 500 use Cursor, and as coding agent autonomy grows, so does the blast radius of an agent that misbehaves: a secret surfaced in a commit, a package installed against policy, or an instruction obeyed because someone planted it in a README.

Traditional security certifications answer how data is stored, protected, and governed. They say little about how an agent behaves when it is asked to write insecure code, expose a credential, or take an action it should refuse.


Certifying an agent that writes and runs code

Coding agents pose a distinct certification challenge. A consumer service agent can be assessed largely on what it says. A coding agent must be assessed on what it does: the files it reads, the commands it runs, the dependencies it pulls in, and the code it leaves behind.

Cursor’s agents were subjected to thousands of evals across two rounds, covering 12 risk categories including secrets leakage, hidden prompt injection, and insecure code defaults.

Evals ran against Cursor’s key product surfaces — the agent in the IDE and cloud agents — using a representative enterprise configuration with rules, hooks, .cursorignore, and Auto-review enabled. This ensures the results reflect the collective defenses operating across the model and application layers rather than a single control in isolation.

Alongside the evals, Schellman reviewed Cursor’s operational, governance, and security controls, including Privacy Mode enforcement, data retention, subprocessor governance, access controls, incident response, and human oversight.

Setting the bar for coding agents

AIUC-1 is developed with input from 250+ Fortune 500 CISOs and risk leaders, and technical contributions from MITRE, the Cloud Security Alliance, and Stanford researchers. The standard is updated quarterly to evolve alongside AI capabilities, risks, and regulation.

The latest version introduced new coding-agent requirements for secrets management, secure defaults in generated code, and runtime containment. Cursor’s certification included these requirements, validating their real-world applicability.

The scope of Cursor’s certification and detailed evals are available upon request through Cursor’s trust portal at trust.cursor.com.

Move with confidence


Move with confidence


Move with confidence