This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Least-privilege access limits the blast radius of any credential compromise or insider threat by ensuring no actor holds more access than necessary.
Readers can expect that internal access to the infrastructure handling their data is restricted to the minimum necessary under a least-privilege model.
How other platforms handle this
Making sure that any Authorised Users, employees, contractors, professional advisors or agents of ours or yours only have access to confidential information on a 'need-to-know basis'.
If you are separately engaged as an Instacart independent contractor, your Independent Contractor Agreement—not these Terms—governs your relationship with Instacart in that capacity.
If you believe we have taken action against your content or account in a way that does not comply with these Terms, you have the right to bring a claim for breach of contract under UK law.
"Infrastructure access is granted according to the principle of least privilege.Excerpt from Cursor's Security Practices
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Least-privilege access limits the blast radius of any credential compromise or insider threat by ensuring no actor holds more access than necessary.
Readers can expect that internal access to the infrastructure handling their data is restricted to the minimum necessary under a least-privilege model.
ConductAtlas has identified this type of provision across 297 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.