Provision record
Cursor · Cursor Security Practices · View original document ↗

Vulnerability reports acknowledged within five business days

Medium severity High confidence Explicit document language Common · 298 of 352 platforms

Key Facts · in the document’s own words

When does Cursor address vulnerability reports?
“We acknowledge vulnerability reports within 5 business days and address them as soon as we are able.”
Version CA-V-006766, captured Sept. 11, 2026 · live source ↗
Our reading, not the document’s words
Cursor acknowledges vulnerability reports within 5 business days and addresses them as soon as it is able.
Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
ⓘ

This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

A stated acknowledgement deadline creates a measurable response commitment, while the 'as soon as we are able' standard governs remediation timing without fixing a specific deadline.

⚠

Interpretive note: 'As soon as we are able' is an indefinite standard; it preserves a commitment without a fixed timeline, which is a meaningful qualifier retained in the canonical claim.

Consumer impact (what this means for users)

Readers who submit vulnerability reports can expect an acknowledgement within 5 business days; remediation timing is not fixed but is committed to occur as soon as Cursor is able.

How other platforms handle this

Stripe Medium

If Stripe makes an Update available, User must implement it by the deadline stated in Stripe's notice. If no deadline is stated, then User must implement the Update within 30 days of the notice date.

Pinterest Medium

To the extent that any provisions in the Business Terms of Service conflict with these Terms, the Business Terms of Service shall govern to the extent of the conflict.

Instacart Medium

Unless otherwise stated, Instacart may change the expiration date of Credits with 30 days' email notice.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
We acknowledge vulnerability reports within 5 business days and address them as soon as we are able.

Excerpt from Cursor's Security Practices

Provision details

Document information
Document
Cursor Security Practices
Entity
Cursor
Date stated by the document
Aug. 25, 2026
As printed in Cursor’s text (version CA-V-006766), not a ConductAtlas date.
Tracking information
First captured by ConductAtlas
May 12, 2026
Text quoted from version
CA-V-006766, captured Sept. 11, 2026
Record ID
CA-P-062765
Document ID
CA-D-000832
Evidence Provenance
Source URL
Wayback Machine
Archived bytes SHA-256 (version CA-V-006766)
3390ea3e7e5a41d3238c2109f3116525496a116160e5d2361d6957358c6d03ea
Analysis generated
May 12, 2026 17:00 UTC
Methodology
Evidence
✓ Excerpt found verbatim in version CA-V-006766 (checked Oct. 5, 2026)
Citation Record
Entity: Cursor
Document: Cursor Security Practices
Record ID: CA-P-062765
Version: CA-V-006766
Captured: 2026-09-11 00:56:25 UTC
SHA-256: 3390ea3e7e5a41d3…
URL: https://conductatlas.com/platform/cursor/cursor-security-practices/provision/CA-P-062765/vulnerability-reports-acknowledged-within-five-business-days/
Accessed: Oct. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Cursor's Vulnerability reports acknowledged within five business days clause do?

A stated acknowledgement deadline creates a measurable response commitment, while the 'as soon as we are able' standard governs remediation timing without fixing a specific deadline.

How does this clause affect you?

Readers who submit vulnerability reports can expect an acknowledgement within 5 business days; remediation timing is not fixed but is committed to occur as soon as Cursor is able.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 298 platforms. See the full comparison.

Is ConductAtlas affiliated with Cursor?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.