
Coding agents now do work that used to require a trusted engineer. They read repositories, write and execute code, install dependencies, and open pull requests. Close to 70% of the Fortune 500 use Cursor, and as coding agent autonomy grows, so does the blast radius of an agent that misbehaves: a secret surfaced in a commit, a package installed against policy, an instruction obeyed because someone planted it in a README. Traditional security certifications answer how data is stored, protected, and governed. They say little about how an agent behaves when it is asked to write insecure code, expose a credential, or take an action it should refuse.
Interview with Kenneth Moras, Cursor Security, and Emil Lassen, AIUC-1
Certifying an agent that writes and runs code Coding agents pose a distinct certification challenge. A consumer service agent can be assessed largely on what it says. A coding agent must be assessed on what it does: the files it reads, the commands it runs, the dependencies it pulls in, and the code it leaves behind. Cursor's agents were subjected to thousands of technical evaluations across two rounds, covering 12 risk categories including:
Testing ran against Cursor's key product surfaces - the agent in the IDE and cloud agents - using a representative enterprise configuration with rules, hooks, .cursorignore, and Auto-review enabled. This ensures the results reflect the collective defenses operating across the model and application layers rather than a single control in isolation. Alongside the technical testing, Schellman - the first ANAB-accredited ISO 42001 certification body and the first authorized AIUC-1 auditor - reviewed Cursor's operational, governance, and security controls, including Privacy Mode enforcement, data retention, subprocessor governance, access controls, incident response, and human oversight. Setting the bar for coding agents AIUC-1 is developed with input from 250+ Fortune 500 CISOs and risk leaders, and technical contributions from MITRE, the Cloud Security Alliance, and Stanford researchers. The standard is updated quarterly to evolve alongside AI capabilities, risks, and regulation. In the latest version, released publicly on July 15th, new requirements specific to coding agents were integrated. These include:
Cursor’s certification included these coding-agent specific requirements, validating their real-world applicability. Read more here. The scope of Cursor's certification and detailed testing results are available upon request through Cursor's trust portal at trust.cursor.com.
