跳到主内容
@wquguru
精选70Cursor 博客(web_list)行业动态

Cursor 获 AIUC-1 认证,通过代理安全与可靠性独立审计

Aug 13, 2026·companyCursor earns AIUC-1 certification for agent security and reliabilityKenneth Moras4mKenneth Moras·4m

原文
发到 X

Blog / company

Following an extensive independent review of our controls and the behavior of our agents, we're happy to share that Cursor is now AIUC-1 certified.

AIUC-1 is a new standard for AI agent security, safety, and reliability that combines an audit of organizational controls with adversarial testing of the product itself.

Today, 70% of the Fortune 500 use Cursor, and agents are taking on increasingly consequential work inside those companies. As that autonomy grows, enterprises need stronger evidence about how agents behave when their safeguards are put under pressure.

Existing security certifications can tell an enterprise a lot about how its data is stored, protected, and governed. They do less to evaluate how an agent itself behaves in practice. What happens when an agent is asked to write insecure code, expose a secret, or take an action it should refuse?

For Cursor, AIUC-1 provides an independent test of the safeguards we have built around our agents, and evidence for customers that those safeguards continue to hold when the product is pushed into difficult or adversarial situations.

#Independent audit and adversarial testing

AIUC-1 was developed with input from more than 100 Fortune 500 CISOs and risk leaders, with technical contributions from MITRE, the Cloud Security Alliance, and Stanford researchers.

It translates established frameworks such as the NIST AI Risk Management Framework, MITRE ATLAS, and the OWASP agentic threat taxonomy into requirements that can be tested against live AI systems. For coding agents, those requirements extend to areas such as secrets protection, secure code generation, MCP security, and agent identity and permissions.

To assess how Cursor performs against those requirements, we underwent an independent audit by Schellman, the world's first ANAB-accredited ISO 42001 certification body and the first authorized auditor for AIUC-1. Schellman reviewed our documented controls and validated the AI governance practices and implementations behind them.

We also put our agents through adversarial testing across thousands of scenarios designed to probe the limits of Cursor's safeguards.

The testing covered our key agent surfaces, including the IDE and cloud agents, using a representative enterprise configuration. Evaluators exercised the safeguards we have built into Cursor, including rules, hooks, and Auto-review, across scenarios involving the risks coding agents are most likely to encounter.

Across two rounds of testing and several thousand scenarios, Cursor passed the AIUC-1 requirements, with its safeguards holding across both benign and adversarial conditions.

#Agent safeguards built into Cursor

Passing those evaluations reflects the safeguards we have built into Cursor over time. Organizations can use rules and hooks to shape agent behavior and enforce checks around agent actions, while Auto-review evaluates risky commands before they run. These application-level controls sit alongside safeguards that influence how the agent responds to insecure requests and whether it generates secure code by default.

AIUC-1 evaluated those protections together, alongside the model-level safeguards that shape how the agent responds to insecure requests. It also tested how the agent handles potentially destructive actions, from generating vulnerable code to running unsafe commands or deleting data.

#Ongoing evaluation as agents improve

One advantage of AIUC-1 over many traditional certifications is that the evaluation recurs. Maintaining certification requires Cursor to be tested at least quarterly, with a full audit each year.

That ongoing scrutiny is important as our agents become more capable and the risks around them change. AIUC-1 itself is updated quarterly, including requirements specific to coding agents, so each new evaluation holds Cursor to a higher bar as the standard evolves.

AIUC-1 is one part of a broader security program that includes our SOC 2 Type II attestation, third-party penetration testing, bug bounty program, and our work toward ISO 27001 and ISO 42001 certification.

Our AIUC-1 report, including the scope of the certification and detailed testing results, is available through our trust portal at trust.cursor.com.

Read more about Cursor's enterprise security, compliance, and administrative controls in our docs, or visit cursor.com/security.

Related posts

Aug 14, 2026·Company

Cursor is now a part of SpaceX

Cursor Team · 2 min read

Jul 6, 2026·Company

CFOs and the new economics of AI

Jordan Topoleski · 4 min read

Mar 3, 2026·Company

How technical support at Cursor uses Cursor

Kody & Zach · 5 min read

View more posts →

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近