[{"data":1,"prerenderedAt":808},["ShallowReactive",2],{"blog-en-is-cursor-ai-safe":3,"blog-index-en":565},{"id":4,"title":5,"body":6,"category":516,"cover":517,"coverAlt":518,"description":519,"draft":520,"extension":521,"faq":522,"image":541,"keywords":542,"meta":553,"navigation":554,"ogTitle":5,"path":555,"published":556,"seo":557,"stem":558,"tldr":559,"updated":563,"__hash__":564},"blog_en\u002Fblog\u002Fis-cursor-ai-safe.md","Is Cursor AI safe? The editor, the code, and the app you shipped",{"type":7,"value":8,"toc":502},"minimark",[9,13,21,24,29,32,54,57,63,67,70,73,84,93,102,111,116,120,123,132,135,157,176,180,183,192,195,198,206,211,215,218,221,244,247,251,254,262,265,370,382,393,397,400,439,443,446,458,462,491],[10,11,12],"p",{},"You built something in Cursor, it works, and you are about to put real people\non it. Somewhere in that week you typed \"is cursor ai safe\" into a search box,\nand what came back was a page about Cursor's privacy settings, a page about\nwhether AI-written code is any good, and a page about a custom mouse-pointer\ndownload. None of them said a word about the app you are about to publish.",[10,14,15,16,20],{},"Here is the part most of those answers get wrong: ",[17,18,19],"strong",{},"\"is Cursor AI safe\" is\nthree questions wearing one sentence",", and they have three different answers.\nTwo of them are about Cursor and the models behind it. The third is about what\nyou shipped, and it is the one that decides whether a stranger can read your\nusers' data.",[10,22,23],{},"Think of Cursor as a contractor you hired to build a house. Whether it keeps a\ncopy of your plans is one question. Whether what it builds is up to code is a\nsecond. Whether the doors lock once you have moved in is the third, and it stays\nyour question for as long as you live there.",[25,26,28],"h2",{"id":27},"is-cursor-ai-safe","Is Cursor AI safe?",[10,30,31],{},"As an editor, it is an ordinary cloud tool: a privacy switch, a published\nsecurity page and a SOC 2 Type II attestation. That answers one of the three\nquestions, and not the one that decides whether strangers can read your users'\ndata.",[33,34,35,42,48],"ol",{},[36,37,38,41],"li",{},[17,39,40],{},"The editor."," Does Cursor keep your code, train on it, or hand it to\nsomebody else. This is the contractor's copy of the plans.",[36,43,44,47],{},[17,45,46],{},"The code."," Is what the AI writes secure. This is whether the house is up\nto code, and nobody inspects it on the way in.",[36,49,50,53],{},[17,51,52],{},"The app you published."," What a stranger can reach from the street: a key\nin the code a browser downloads, a database that answers with no login, a\nfile that should never have had a URL. These are the doors.",[10,55,56],{},"Nothing on Cursor's side can answer the third. Nothing on ours can answer the\nfirst two.",[58,59],"diagram",{"alt":60,"caption":61,"src":62},"Three panels side by side. The first holds the Cursor logo with a cloud and a padlock beside it. The second holds a code glyph with a sparkle over it. The third holds a browser page with three visitors reaching toward it and a magnifying glass drawn over that panel alone.","Three questions inside one search. A scan from outside reads the third panel and nothing in the other two.","\u002Fblog\u002Fis-cursor-ai-safe\u002Fthree-questions-1600x700.png",[25,64,66],{"id":65},"does-cursor-keep-my-code","Does Cursor keep my code?",[10,68,69],{},"For as long as it takes to answer you, yes. After that it depends on one\nswitch.",[10,71,72],{},"Cursor is a cloud tool. When you ask it anything, the relevant parts of your\nproject leave your computer, go to Cursor's servers, and are passed on to a\nmodel provider (OpenAI, Anthropic, Google, whichever model you picked) to be\nanswered. That is how the product works. The plans have to reach the\ncontractor.",[10,74,75,76,83],{},"What happens afterwards is the switch, and Cursor's\n",[77,78,82],"a",{"href":79,"rel":80},"https:\u002F\u002Fcursor.com\u002Fdata-use",[81],"nofollow","data-use page"," puts both positions in one\nparagraph. With Privacy Mode on, \"Customer Data will not be used for training\nby Cursor\" and Cursor \"maintains zero data retention (ZDR) agreements with all\nproviders\", meaning the companies running the models agree to keep nothing\neither. With it off, Cursor \"may use and store codebase data, prompts, editor\nactions, code snippets, and other code data and actions to improve our AI\nfeatures and train our models.\"",[10,85,86,87,92],{},"The switch is available on every plan, the free one included, and a team or\nenterprise admin can turn it on for everyone and stop members turning it off.\nCursor's own ",[77,88,91],{"href":89,"rel":90},"https:\u002F\u002Fcursor.com\u002Fdocs\u002Fenterprise\u002Fsecurity-hardening",[81],"hardening guide","\nsays it is on by default for Enterprise accounts. On an individual plan it is a\nsetting, and the setting is worth finding today.",[10,94,95,96,101],{},"One more thing about it, because it has already caught somebody out. Since\nmid-2025 there have been two versions: \"Privacy Mode\", which lets Cursor store\nsome data for features such as its cloud agents and memories, and \"Privacy Mode\n(Legacy)\", which stores nothing. In July 2026 a\n",[77,97,100],{"href":98,"rel":99},"https:\u002F\u002Fnews.ycombinator.com\u002Fitem?id=48737226",[81],"Hacker News poster"," described\nsigning in to the iOS app and finding their account moved from the legacy\nsetting to the current one. A Cursor employee replied that the prompt to turn\non cloud agents had done it \"without making clear what that meant or that it's\nhard to undo\", and that moving back was not available in the app. If you chose\nthe stricter one, check it is still selected.",[10,103,104,105,110],{},"The certificates answer a narrower question than they look. Cursor's\n",[77,106,109],{"href":107,"rel":108},"https:\u002F\u002Fcursor.com\u002Fsecurity",[81],"security page"," lists a SOC 2 Type II attestation,\nISO\u002FIEC 27001 and ISO\u002FIEC 42001. Those mean an outside auditor checked that\nCursor has controls over how it handles the data it holds, the way a\ncontractor's insurance certificate says the contractor is insured. They say\nnothing about the code it writes and nothing about the app you deploy with it.",[58,112],{"alt":113,"caption":114,"src":115},"An editor window on the left with a document leaving it along an arrow, through a cloud, to a server on the right. Under the cloud sits a toggle switch. Beside the switch in its on position is a storage cylinder drawn as a dashed outline, and beside it in its off position a solid cylinder with a sparkle over it.","Your code leaves your machine on every request. The switch decides whether anything is kept afterwards, and whether it is trained on.","\u002Fblog\u002Fis-cursor-ai-safe\u002Fwhere-your-code-goes-1600x680.png",[25,117,119],{"id":118},"what-does-codebase-indexing-upload","What does codebase indexing upload?",[10,121,122],{},"An index of your project, kept on Cursor's servers, with the file paths\nencrypted and the code itself never stored as readable text.",[10,124,125,126,131],{},"Indexing is how Cursor answers a question about your whole project rather than\nthe file you have open. It splits your files into pieces, sends them to Cursor's\nservers to be turned into embeddings (a numeric summary of what each piece is\nabout), and keeps those embeddings so that when you ask \"where do we handle\nrefunds\" it can find the right pieces. Cursor's\n",[77,127,130],{"href":128,"rel":129},"https:\u002F\u002Fcursor.com\u002Fdocs\u002Fcontext\u002Fcodebase-indexing",[81],"documentation"," says:\n\"File paths are encrypted before being sent to Cursor's servers. Code content is\nnever stored in plaintext.\" What stays on their side is a map of your code, and\nthat is a different thing from a copy of it.",[10,133,134],{},"Two things are worth knowing about the map.",[10,136,137,140,141,145,146,149,150,153,154,156],{},[17,138,139],{},"Some files are left out by default, and you can add more."," Cursor skips\nanything in your ",[142,143,144],"code",{},".gitignore"," and a default list that includes ",[142,147,148],{},".env*",", the\nfile where your secret keys usually live. A ",[142,151,152],{},".cursorignore"," file in the project\nroot, written in the same syntax as ",[142,155,144],{},", keeps anything else you name\nout of the index and out of what the AI is shown.",[10,158,159,162,163,168,169,171,172,175],{},[17,160,161],{},"The agent's terminal does not read that list."," This is the caveat that\nmatters for keys. Cursor's ",[77,164,167],{"href":165,"rel":166},"https:\u002F\u002Fcursor.com\u002Fdocs\u002Fcontext\u002Fignore-files",[81],"ignore-files page","\nsays that \"the terminal and MCP server tools used by Agent cannot block access\nto code governed by ",[142,170,152],{},"\", and that \"complete protection isn't\nguaranteed due to LLM unpredictability\". When the agent runs a command on your\nmachine, it can read ",[142,173,174],{},".env"," the way any command can. The file is out of the\nindex and still within reach. If a key is in the project folder you have open\nin Cursor, treat it as a key the agent can see.",[25,177,179],{"id":178},"is-the-code-cursor-writes-secure","Is the code Cursor writes secure?",[10,181,182],{},"Not by default, and that is measured, though the measurement is of the models\nCursor uses and not of Cursor itself.",[10,184,185,186,191],{},"Veracode, a company that sells code-security testing, has put over 150 models\nthrough the same 80 programming tasks, in four languages, each task offering a\nsecure and an insecure way to do the job. Its\n",[77,187,190],{"href":188,"rel":189},"https:\u002F\u002Fwww.veracode.com\u002Fblog\u002Fspring-2026-genai-code-security\u002F",[81],"spring 2026 update",",\npublished on 24 March 2026, found that only 55% of the results were secure, a\nfigure Veracode calls \"virtually identical to where they stood two years ago\",\nwhile the share that compiled had passed 95%. On two of the four flaw types the\nmodels almost never chose the safe version: cross-site scripting, which lets one\nvisitor's text run as code in another visitor's browser, passed 15% of the\ntime, and log injection 13%.",[10,193,194],{},"Veracode's own summary is that the models \"have become excellent at writing\ncode that compiles. They've failed at writing code that's safe.\"",[10,196,197],{},"For you, the person who did not write the code, the gap between those two\nnumbers is the whole finding. The test you run on a Cursor project is whether\nit works: you click through the app and the right things appear. That is the\n95%. The test nobody runs is whether the code decided who is allowed to see\nwhat, and the 55% says that decision was made about half the time. An app can\npass the first test completely and fail the second, because a page that shows\nyou your orders and a page that shows anyone everybody's orders look identical\nto the person who owns the account.",[10,199,200,201,205],{},"Where that decision belongs, and why \"load the orders\" never makes it on its\nown, is the middle of the ",[77,202,204],{"href":203},"\u002Fis-your-cursor-app-safe","Cursor guide",".",[58,207],{"alt":208,"caption":209,"src":210},"Two horizontal bars on one scale. The upper bar, headed by a tick, runs almost the full width and ends in the numeral 95 with a greater-than sign before it. The lower bar, headed by a padlock, stops a little past halfway and ends in the numeral 55.","Veracode's spring 2026 test of over 150 models. The upper bar is code that compiled. The lower bar is code that was secure.","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcompiles-versus-safe-1600x560.png",[25,212,214],{"id":213},"prompt-injection-in-plain-language","Prompt injection, in plain language",[10,216,217],{},"The model treats instructions as instructions wherever it finds them, including\ninside things it was only supposed to read.",[10,219,220],{},"You tell Cursor \"summarise this thread\" or \"tidy this file\", and to do that it\nreads the thread or the file. If the thread contains a sentence written to look\nlike an instruction to an AI, the model may follow it, because it has no\nreliable way to tell your voice from the page's. That is prompt injection, and\nin a coding agent, which can edit files and run commands on your machine, the\nconsequences reach past a bad summary.",[10,222,223,224,229,230,233,234,239,240,243],{},"Two named cases, both against Cursor. In March 2025 Pillar Security published\n",[77,225,228],{"href":226,"rel":227},"https:\u002F\u002Fwww.pillar.security\u002Fblog\u002Fnew-vulnerability-in-github-copilot-and-cursor-how-hackers-can-weaponize-code-agents",[81],"\"Rules File Backdoor\"",":\ninstructions hidden with invisible Unicode characters inside a ",[142,231,232],{},".cursor\u002Frules","\nfile, the configuration file that tells Cursor how you like your code written.\nThe file looked clean in the editor and in a GitHub diff, and it quietly told\nthe AI to add a script from an attacker's domain to every generated page and\nnever to mention it. Cursor's response was that this was not a vulnerability in\nits platform and that the responsibility sits with the user. In August 2025 Aim\nSecurity disclosed\n",[77,235,238],{"href":236,"rel":237},"https:\u002F\u002Fthehackernews.com\u002F2025\u002F08\u002Fcursor-ai-code-editor-fixed-flaw.html",[81],"CVE-2025-54135",",\nwhich they called CurXecute: a message in a public Slack channel, read by Cursor\nthrough an MCP server (a plug-in that lets the agent reach outside tools),\ncould make the agent write an entry into its own ",[142,241,242],{},"mcp.json"," configuration, and\nCursor started that entry, running the attacker's command, before you had\napproved the edit. Cursor fixed it in version 1.3 on 29 July 2025, and every\nchange to that file now waits for your approval.",[10,245,246],{},"What follows for you is short. A rules file you copied from a repository or a\nblog post is code, and it steers everything the agent writes after it, so read\nit like code. Keep Cursor updated, since the fix for CurXecute was a version\nnumber. And every MCP server you plug in that reads text from outside, an inbox,\na ticket queue, a search, hands the agent sentences you did not write.",[25,248,250],{"id":249},"what-a-scan-of-30998-live-apps-says-about-the-third-question","What a scan of 30,998 live apps says about the third question",[10,252,253],{},"That nothing about the editor reaches the app you published. We cannot tell a\nCursor app from any other from outside, and that is the finding.",[10,255,256,257,261],{},"Between 12 and 14 August 2026 we ran the nine external checks anyone can run\nfree on our homepage over 30,998 live apps. We found them by where they were\npublished: 18,554 on Lovable's domain, 5,438 on Base44's, 3,042 on Replit's,\nand so on down. A Cursor project is deployed wherever you put it, on Vercel, on\nNetlify, on a domain you bought, and the page a visitor downloads carries no\nmark of the editor that wrote it. So there is no Cursor column in\n",[77,258,260],{"href":259},"\u002Fresearch\u002Fvibe-coded-app-security-2026","the report",", and there cannot be one.",[10,263,264],{},"What there is, on every builder we measured, is the same short list of things\nan owner had left open, and none of them is decided by the editor. Every share\nbelow is of the apps that check answered on, because a check that could not\nfinish is unknown rather than passed. No app is named here or anywhere else we\npublish.",[266,267,268,284],"table",{},[269,270,271],"thead",{},[272,273,274,278,281],"tr",{},[275,276,277],"th",{},"What we checked",[275,279,280],{},"Apps",[275,282,283],{},"Who decides it on a Cursor project",[285,286,287,299,310,321,331,341,359],"tbody",{},[272,288,289,293,296],{},[290,291,292],"td",{},"A database table readable with no login",[290,294,295],{},"2,096 of 3,680 (57%)",[290,297,298],{},"You, in the database",[272,300,301,304,307],{},[290,302,303],{},"An API route that answered a stranger with data",[290,305,306],{},"3,852 of 30,926 (12%)",[290,308,309],{},"You, in the code",[272,311,312,315,318],{},[290,313,314],{},"Source map served (mostly the platform, on Base44)",[290,316,317],{},"3,885 of 30,987 (13%)",[290,319,320],{},"You, in the build, outside Base44",[272,322,323,326,329],{},[290,324,325],{},"Something key-shaped in the code a visitor downloads",[290,327,328],{},"1,332 of 30,998 (4%)",[290,330,309],{},[272,332,333,336,339],{},[290,334,335],{},"A key that bills an account or bypasses every rule",[290,337,338],{},"52 of 30,998",[290,340,309],{},[272,342,343,353,356],{},[290,344,345,346,348,349,352],{},"A private file such as ",[142,347,174],{}," or ",[142,350,351],{},".git\u002Fconfig"," at a public URL",[290,354,355],{},"8 of 30,749",[290,357,358],{},"You, in the deploy",[272,360,361,364,367],{},[290,362,363],{},"Browser security headers missing",[290,365,366],{},"30,756 of 30,981 (99%)",[290,368,369],{},"You, at the host",[10,371,372,373,377,378,381],{},"The first row is measured over the 3,680 apps that named a Supabase project and\nwhose database answered the question, which is why its base is smaller;\n",[77,374,376],{"href":375},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","what that check does and does not read","\nhas the full ladder. The fifth row is the one that costs money on its own: an\nOpenAI, Anthropic, AWS or Stripe secret key, or a Supabase ",[142,379,380],{},"service_role"," key,\nin the code a browser downloads.",[10,383,384,385,387,388,392],{},"The last column is what changes on Cursor. On a builder's own domain, two of\nthose rows belong to the host: the headers are sent by whatever serves the\npage, and source maps follow the builder's build settings. A Cursor project is\nyour repository, your build and your deploy, so every row in that table is\nyours, including the two a Lovable owner does not control. That is more control\nand more to check, and it is why the ",[77,386,204],{"href":203},"\nspends its time on your build output and your database rather than on the\neditor. The ",[77,389,391],{"href":390},"\u002Fblog\u002Fis-replit-safe","Replit post"," asks the same three questions\nof a platform that both hosts the app and lets you ship a server of your own.",[25,394,396],{"id":395},"the-five-minute-check-from-outside","The five-minute check from outside",[10,398,399],{},"Use a private window for the first three, so your own login does not answer for\na stranger.",[33,401,402,413,416,419,432],{},[36,403,404,405,408,409,412],{},"Open your published address with ",[142,406,407],{},"\u002F.env"," on the end, then ",[142,410,411],{},"\u002F.git\u002Fconfig",".\nBoth should fail. If either shows text, rotate every key in it today, then\nfix the deploy so the file is never served.",[36,414,415],{},"Open one of your own API routes the same way, one you would not want a\nstranger reading. If it answers with data, that route needs a login check.",[36,417,418],{},"Open your live app, then the Sources tab of your browser's developer tools.\nIf you can read your original files with their comments, source maps are on\nin your production build.",[36,420,421,422,424,425,427,428,431],{},"If your data is in Supabase, the inside half of the check is in the\n",[77,423,204],{"href":203},": search the build output for\n",[142,426,380],{}," and ",[142,429,430],{},"sk_live_",", then open the policies page.",[36,433,434,435,205],{},"Or let the scan do it. It runs these and the rest of the nine from outside,\ntakes about 20 seconds, needs no account, and prints \"Couldn't check\" for\nanything it could not answer rather than a tick:\n",[77,436,438],{"href":437},"\u002Fsecurity-scanner","scan your app",[25,440,442],{"id":441},"what-changes-after-the-next-push","What changes after the next push?",[10,444,445],{},"Anything. A Cursor project ships when you push it, and nothing between your\neditor and the internet re-reads the app for a route that lost its login check,\na key pasted in to get past a failing build at midnight, or a source map that\ncame back on with a config change. The Veracode number is why this matters more\nhere than on a builder: every session with the agent is new code that compiles\nand may not be safe, and a scan you ran last month describes last month's app.",[10,447,448,452,453,457],{},[77,449,451],{"href":450},"\u002Fpricing","Reeve Monitor"," is built for that. It re-runs all nine checks every\nhour on up to three apps, watches uptime every 60 seconds, tells you when a\nresult changes rather than waiting for you to look, and sends a monthly report.\nIt is $12 a month at list, with seven days free before it charges you; the\npricing page is sometimes below the figure here and never above it. Monitor\nwatches and nothing more. If your Cursor app keeps its data in Supabase,\n",[77,454,456],{"href":455},"\u002Fsupabase-backups","Care"," is the plan that also holds a copy of that database,\nand of your uploaded files once you connect a Storage credential. If the data\nlives somewhere else, Monitor is the half that fits.",[25,459,461],{"id":460},"what-to-do-this-week","What to do this week",[463,464,465],"key-takeaways",{},[466,467,468,471,477,480,488],"ul",{},[36,469,470],{},"Find Privacy Mode in Cursor's settings and check which version is selected. On a team, have the admin enforce it.",[36,472,473,474,476],{},"Treat any key in the project folder you have open as a key the agent can read. ",[142,475,152],{}," keeps it out of the index, and the terminal does not read that list.",[36,478,479],{},"Read a rules file or an MCP configuration you copied from the internet as code, and keep Cursor updated.",[36,481,482,483,427,485,487],{},"Open ",[142,484,407],{},[142,486,411],{}," on your published address in a private window. Both should fail.",[36,489,490],{},"Open your own API routes with no login. Any route that answers with private data needs a login check.",[10,492,493,494,496,497,501],{},"The inside half of all this, the build output and the database, is the\n",[77,495,204],{"href":203},". The\n",[77,498,500],{"href":499},"\u002Fchecklist","10-minute security checklist"," covers what is worth confirming on\nany newly launched app, whatever wrote it.",{"title":503,"searchDepth":504,"depth":504,"links":505},"",3,[506,508,509,510,511,512,513,514,515],{"id":27,"depth":507,"text":28},2,{"id":65,"depth":507,"text":66},{"id":118,"depth":507,"text":119},{"id":178,"depth":507,"text":179},{"id":213,"depth":507,"text":214},{"id":249,"depth":507,"text":250},{"id":395,"depth":507,"text":396},{"id":441,"depth":507,"text":442},{"id":460,"depth":507,"text":461},"Security basics","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcover-1200x630.png","The Cursor logo on a white tile, an arrow to an editor window with a sparkle over it, then a published page with three visitors at it.","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.",false,"md",[523,526,529,532,535,538],{"q":524,"a":525},"Does Cursor train on my code?","Only with Privacy Mode off. With it on, Cursor states that customer data is not used for training and that it holds zero data retention agreements with every model provider, so nothing is kept on their side either. With it off, Cursor says it may use and store your code, prompts and editor actions to improve its features and train its models. The switch is available on every plan, including the free one, and a team admin can turn it on for everyone.",{"q":527,"a":528},"What does Privacy Mode actually do?","It decides what happens to your code after a request is answered. Your code still leaves your computer on every request, because that is how a cloud editor works. Privacy Mode stops Cursor training on it and binds the model providers to keep nothing. Since mid-2025 there are two versions: the current one lets Cursor store some data for features such as cloud agents and memories, and the one now labelled Legacy stores nothing. If you chose the stricter one, check it is still selected.",{"q":530,"a":531},"Is codebase indexing safe?","Indexing sends pieces of your project to Cursor to be turned into embeddings, a numeric summary that lets it find the right file when you ask a question. Cursor says the file paths are encrypted before they leave your machine and the code itself is never stored as readable text, so what stays on their servers is a map of your project. Files in .gitignore and .env files are skipped by default, and a .cursorignore file keeps anything else out of the index. The caveat is the terminal: Cursor documents that the agent, when it runs a command, can read a file that .cursorignore excludes.",{"q":533,"a":534},"Is Cursor SOC 2 certified?","Cursor lists a SOC 2 Type II attestation on its security page, alongside ISO\u002FIEC 27001 and ISO\u002FIEC 42001. A SOC 2 report means an outside auditor checked that the company has controls over how it handles the data it holds. It says nothing about whether the code Cursor writes is secure, and nothing about the app you deployed with it, which are the two questions most people typing \"is cursor ai safe\" are worried about.",{"q":536,"a":537},"Is AI-generated code less secure than code I write?","The measured answer is about the models rather than about you. Veracode runs 80 programming tasks through every major model, each task offering a secure and an insecure way to do the job, and in its spring 2026 update only 55% of the results were secure while more than 95% compiled. The gap is the thing to hold onto: the code passes the test you run, which is whether it works, and about half the time it did not make the security decision that nothing tests for you.",{"q":539,"a":540},"Is Cursor safe for client work?","That depends on what the client's contract says about where their code may go. Cursor sends the relevant parts of a project to its servers, and on to a model provider, on every request; Privacy Mode changes what is kept afterwards and not whether it travels. If the contract allows a cloud tool under a zero data retention agreement, Privacy Mode is the setting that gives you one, and on a team plan the admin can enforce it so nobody on the project can switch it off.","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",[543,544,545,546,547,548,549,550,551,552],"is cursor ai safe","is cursor safe","is cursor safe to use","cursor ai security","cursor privacy mode","does cursor train on my code","cursor codebase indexing privacy","cursor soc 2","is ai generated code secure","cursor security risks",{},true,"\u002Fblog\u002Fis-cursor-ai-safe","2026-09-16",{"title":5,"description":519},"blog\u002Fis-cursor-ai-safe",[560,561,562],"Is Cursor AI safe? As an editor, it is an ordinary cloud tool: your code goes to its servers to be answered, one switch decides what stays, and it holds a SOC 2 Type II attestation.","The code it writes is a second question. In Veracode's spring 2026 test, over 150 models produced code that compiled more than 95% of the time and was secure 55% of the time.","The app you shipped is the third, and the only one a scan from outside can answer. We cannot tell a Cursor app from any other, which is the point: nothing about the editor reaches what you published.","2026-09-21","cdu4YxWitxQZh6ESwQoHgudsOGIjKxE-oeGl1GyE7eQ",[566,573,579,584,590,596,602,608,609,614,620,626,632,638,644,650,656,662,668,674,680,686,692,698,704,710,716,722,728,734,740,746,752,758,764,769,774,780,786,792,797,803],{"path":567,"title":568,"description":569,"published":570,"category":571,"image":572,"draft":520},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","Backups","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":574,"title":575,"description":576,"published":577,"category":516,"image":578,"draft":520},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":580,"title":581,"description":582,"published":563,"category":516,"image":583,"draft":520},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":585,"title":586,"description":587,"published":588,"category":516,"image":589,"draft":520},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":591,"title":592,"description":593,"published":594,"category":516,"image":595,"draft":520},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":597,"title":598,"description":599,"published":600,"category":516,"image":601,"draft":520},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":603,"title":604,"description":605,"published":606,"category":516,"image":607,"draft":520},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":555,"title":5,"description":519,"published":556,"category":516,"image":541,"draft":520},{"path":390,"title":610,"description":611,"published":612,"category":516,"image":613,"draft":520},"Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":615,"title":616,"description":617,"published":618,"category":571,"image":619,"draft":520},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":621,"title":622,"description":623,"published":624,"category":571,"image":625,"draft":520},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":627,"title":628,"description":629,"published":630,"category":571,"image":631,"draft":520},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":633,"title":634,"description":635,"published":636,"category":516,"image":637,"draft":520},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":639,"title":640,"description":641,"published":642,"category":516,"image":643,"draft":520},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":645,"title":646,"description":647,"published":648,"category":516,"image":649,"draft":520},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":651,"title":652,"description":653,"published":654,"category":516,"image":655,"draft":520},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":657,"title":658,"description":659,"published":660,"category":516,"image":661,"draft":520},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":663,"title":664,"description":665,"published":666,"category":516,"image":667,"draft":520},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":669,"title":670,"description":671,"published":672,"category":516,"image":673,"draft":520},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":675,"title":676,"description":677,"published":678,"category":516,"image":679,"draft":520},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":681,"title":682,"description":683,"published":684,"category":516,"image":685,"draft":520},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":687,"title":688,"description":689,"published":690,"category":516,"image":691,"draft":520},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":693,"title":694,"description":695,"published":696,"category":571,"image":697,"draft":520},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":699,"title":700,"description":701,"published":702,"category":516,"image":703,"draft":520},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":705,"title":706,"description":707,"published":708,"category":571,"image":709,"draft":520},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":711,"title":712,"description":713,"published":714,"category":516,"image":715,"draft":520},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":717,"title":718,"description":719,"published":720,"category":516,"image":721,"draft":520},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":723,"title":724,"description":725,"published":726,"category":516,"image":727,"draft":520},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":729,"title":730,"description":731,"published":732,"category":516,"image":733,"draft":520},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":735,"title":736,"description":737,"published":738,"category":571,"image":739,"draft":520},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":741,"title":742,"description":743,"published":744,"category":571,"image":745,"draft":520},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":747,"title":748,"description":749,"published":750,"category":516,"image":751,"draft":520},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":753,"title":754,"description":755,"published":756,"category":516,"image":757,"draft":520},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":759,"title":760,"description":761,"published":762,"category":571,"image":763,"draft":520},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":375,"title":765,"description":766,"published":767,"category":516,"image":768,"draft":520},"Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":770,"title":771,"description":772,"published":767,"category":516,"image":773,"draft":520},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":775,"title":776,"description":777,"published":778,"category":516,"image":779,"draft":520},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":781,"title":782,"description":783,"published":784,"category":571,"image":785,"draft":520},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":787,"title":788,"description":789,"published":790,"category":516,"image":791,"draft":520},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":793,"title":794,"description":795,"published":790,"category":571,"image":796,"draft":520},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":798,"title":799,"description":800,"published":801,"category":571,"image":802,"draft":520},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":804,"title":805,"description":806,"published":801,"category":516,"image":807,"draft":520},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1790150951364]