Cursor provides enterprise-grade security, compliance, and administrative controls for organizations deploying AI-assisted development at scale.

If you are rolling out multiple linked teams, start with Organizations.

Security and compliance resources

For security reviews and compliance assessments, start with these resources:

Our certifications include SOC2 Type II, and we maintain GDPR compliance. Visit the Trust Center for the latest certification documents and third-party assessment reports.

Enterprise documentation

Learn how to deploy, configure, and manage Cursor for your organization. This documentation covers:

Key features

Identity and access

  • SSO and SAML - Single sign-on for streamlined authentication
  • SCIM - Automated user provisioning and deprovisioning
  • MDM policies - Enforce allowed team IDs and extensions on user devices

Privacy and security

  • Privacy Mode - No training on your data by Cursor or other AI providers
  • Agent Security - Guardrails for agent tool execution
  • Hooks - Custom security and compliance workflows

Administrative controls

  • Dashboard - Team management, settings, and monitoring
  • Admin API - Programmatic access to admin features
  • Analytics - Usage metrics and insights
  • Conversation Insights - Understand the type of work being done with Cursor (Enterprise only)
  • AI Code Tracking API - Per-commit AI usage metrics (Enterprise only)
  • Cursor Blame - AI-aware git blame that shows AI vs human code attribution (Enterprise only)
  • Analytics API - Usage metrics and insights
  • Billing Groups - Manage spend across groups of users for reporting and chargebacks (Enterprise only)
  • Service Accounts - Non-human accounts for automated workflows (Enterprise only)

Models and integrations

  • Models - Available models and configuration
  • Cyber Safeguards - Anthropic Cyber Verification Program (CVP) access for security groups (Enterprise only)
  • MCP - Model Context Protocol server trust management
  • Slack - Cloud Agents in Slack
  • GitHub - Repository integration
  • Linear - Issue tracking integration
  • Bugbot - Automated bug detection and fixing

Monitoring and compliance

  • Audit logs - Track authentication, user management, and administrative actions (Enterprise only)
  • SIEM integration - Stream audit logs to your security tools
  • OpenTelemetry Export - Stream usage metrics and logs to your observability stack over OTLP (Enterprise only)
  • HIPAA Business Associate Agreements - BAA support for Enterprise customers

Getting started

Start with the Admin Setup Guide for a short rollout checklist. In short:

  1. Review the Trust Center and Security page for your security assessment
  2. Read through the enterprise documentation to understand deployment options
  3. Set up SSO and SCIM for user management
  4. Deploy Cursor and configure MDM policies to enforce team IDs and extensions
  5. Review the Dashboard to monitor team usage

Plan Comparison

Team Admin & Billing

Capability Individual Plans Teams Enterprise
Centralized Billing
Usage Spend Controls Personal limits Team limits Pooled usage + admin-only controls
Billing Groups
Team Usage Analytics Analytics Dashboard Analytics Dashboard,AI Code Tracking API,Conversation Insights
Cursor Blame
SSO (SAML/OIDC)
SCIM Provisioning
Audit Logs
Service Accounts

Marketplace

Capability Individual Plans Teams Enterprise
Team marketplaces 1 team marketplace Unlimited team marketplaces
Community plugin import On by default Off by default
Marketplace edits All teams can edit Only admin edits
SCIM distribution & access gating No SCIM access gating Scope distribution and gate access via SCIM (control who sees which marketplace based on identity provider groups)

Centralized Agent Controls

Capability Individual Plans Teams Enterprise
Privacy Mode User choice Enforce org-wide Enforce org-wide
Team Rules Enforceable + Optional Enforceable + Optional
Hooks for Logging,Auditing, and more MDM Distribution MDM & Server-side distribution
Agent Sandbox Mode Enforce org-wide
Repository Blocklist
Model Access Restrictions
Auto-run, Browser, and Network Controls

User Access Controls

Capability Individual & Teams Plans Enterprise
Cursor CLI Restrict which users can access agents via CLI
Cloud Agents Restrict which users can create Cloud Agents
Analytics Restrict analytics dashboard to admins only
BYOK Disable users from using their own API keys
Capability Individual Plans Teams Enterprise
Technical Support Community & Standard Support Community & Standard Support First human response times: 8 hours (critical), 24 hours (standard)
Terms Online Terms MSA & DPA MSA & DPA

For security vulnerabilities, see our responsible disclosure program.

Ready to deploy Cursor at scale?

Contact our team to discuss your organization’s needs.