1 / 14
Ampcode

AI Coding Tools
Security Comparison

CISO-Level Enterprise Readiness Assessment
Ampcode vs Cursor vs Claude Code vs OpenAI Codex

Prepared for: Chief Information Security Officer
Assessment Date: June 22, 2026 — Re-verified July 27, 2026
Classification: Public โ€” Point-in-Time Assessment
Scope: Comparative Security Analysis of Four AI Coding Agents

Public โ€” Point-in-Time Assessment
Updated July 27, 2026 — re-verification & new capability notes (click to expand)
  • No scorecard conclusions changed. All scores and verdicts stand as assessed June 22, 2026; no new CVE or policy evidence warranted a change.
  • Claude Code — new surfaces, same governance: Since the June assessment, Claude Code added background subagents, agent teams, and web/desktop surfaces, plus expanded managed policy and permission modes. These expand the operational attack surface but inherit the existing permission-gated, sandboxed-bash, fs/net-isolation model already scored 5/5 on Slide 8. Enterprises should confirm managed-policy enforcement covers background/agent-team execution before broad rollout.
  • Amp — mode rename only: Amp retired the Smart/Deep/Rush mode names in favour of Low/Medium/High/Ultra. The security controls assessed here (user approval for destructive actions, automatic secret redaction, bug-bounty prompt-injection coverage) are unchanged by the rename.
  • Re-verification: CVE sources, vendor trust portals, and data-retention claims were re-checked July 27, 2026; no new qualifying CVEs found against Amp, Claude Code, or Codex in the review window.
  • Not changed: All compliance, data-retention, auth, audit, architecture, shared-responsibility, scoring, and verdict slides remain as originally assessed.
02 / 13

Security Posture at a Glance

Four AI coding tools evaluated across nine security dimensions. Each tool was assessed using publicly available documentation, trust portals, and CVE databases.

๐Ÿ›ก๏ธ

Ampcode Sourcegraph

  • SOC 2 Type II + annual third-party pentesting
  • Enterprise zero LLM data retention; provider cache up to 24h may apply
  • Automatic secret redaction engine
  • SSO/SCIM with exclusive SSO mode

APPROVED โ€” 42/45
โš ๏ธ

Cursor Anysphere

  • SOC 2 Type II; additional controls documented for Enterprise
  • Multiple Cursor CVEs, including prompt-injection and sandbox-escape RCE paths
  • No built-in secret redaction engine
  • CMEK, Privacy Mode, SSO/SCIM available on Enterprise; validate defaults

CONDITIONAL โ€” 27/45
๐Ÿ›๏ธ

Claude Code Anthropic

  • Most certifications: SOC2+ISO27001+ISO42001+HIPAA
  • HIPAA, NIST 800-171, CSA STAR; FedRAMP High for Claude government/partner-hosted offerings
  • CLI-local execution, sandboxed bash
  • Command blocklist + injection detection

APPROVED โ€” 38/45
๐Ÿ”

OpenAI Codex OpenAI

  • SOC 2 + ISO 27001/27017/27018/27701 + PCI DSS
  • Cloud-sandboxed environments, 3 execution modes
  • OpenAI Trust Center documents broad enterprise controls; verify Codex-specific data residency during procurement
  • Enterprise SSO/SCIM via ChatGPT Enterprise

APPROVED โ€” 40/45
03 / 13

Certification Comparison Matrix

Claude Code (Anthropic) holds the broadest compliance portfolio. Cursor publicly documents SOC 2 Type II, Privacy Mode, SSO/SCIM, audit logging, and Enterprise controls; ISO 27001 was not verified in public sources.

Certification Ampcode Cursor Claude Code Codex
SOC 2 Type II โœ“ โœ“ โœ“ โœ“
ISO/IEC 27001 โœ“ โœ— โœ“ โœ“
ISO 42001 (AI Management) โœ— โœ— โœ“ โœ—
ISO 27017 / 27018 / 27701 โœ— โœ— โœ— โœ“
GDPR Compliant โœ“ ~ โœ“ โœ“
CCPA Compliant โœ“ ~ โœ“ โœ“
EU AI Act โœ“ โœ— โœ— โœ—
HIPAA โœ— โœ— โœ“ โœ—
FedRAMP High โœ— โœ— โœ“ โœ—
NIST 800-171 โœ— โœ— โœ“ โœ—
CSA STAR โœ— โœ— โœ“ โœ—
PCI DSS โœ— โœ— โœ— โœ“
โš ๏ธ
Cursor Note: Cursor publishes SOC 2 Type II and Enterprise controls. ISO 27001 was not verified in public sources; review trust portal artifacts directly before enterprise approval.
04 / 13

Data Retention & Training Policies

How each vendor handles customer code data, retention periods, and whether data is used for model training.

๐ŸŸข

Ampcode โ€” Zero Retention

  • Enterprise: zero LLM input/output retention; provider cache up to 24h may apply
  • Training permanently disabled, cannot be re-enabled
  • Deleted thread data removed within 30 days
  • Severe policy-violation safety exceptions may apply per provider terms

Best-in-Class
๐Ÿ”ด

Cursor โ€” Mixed Modes

  • Privacy Mode: no training; Enterprise/team admins can enforce org-wide
  • If Privacy Mode is off, data may be used according to Cursor data-use terms
  • Already-trained models NOT retrained after deletion
  • Already-trained models may not be practically untrained

Caution Required
๐Ÿ”ต

Claude Code โ€” API Separation

  • Enterprise / API: no training on customer data
  • Consumer: may train unless user opts out
  • CLI-local: code never stored on intermediate server
  • Clear enterprise vs. consumer boundary

Strong
๐ŸŸก

Codex โ€” ZDR on Request

  • Default: 30-day abuse monitoring retention
  • Zero Data Retention requires approval process
  • Not all API endpoints eligible for ZDR
  • Additional requirements must be met for ZDR

Adequate
๐Ÿšจ
Cursor Training Risk: If Privacy Mode is not enforced from day one, code may be used for model training. Once data has been incorporated into model weights, deletion requests cannot remove it. This creates a permanent, irrecoverable data exposure.
05 / 13

Infrastructure & Data Residency

Where your code data is processed, stored, and which cloud providers are involved.

Capability Ampcode Cursor Claude Code Codex
Primary Cloud GCP AWS, Azure, GCP Local CLI + Anthropic API (AWS) Azure / OpenAI
Regions ๐Ÿ‡บ๐Ÿ‡ธ US only ๐Ÿ‡บ๐Ÿ‡ธ US, ๐Ÿ‡ช๐Ÿ‡บ EU, ๐Ÿ‡ฏ๐Ÿ‡ต JP, ๐Ÿ‡จ๐Ÿ‡ฆ CA ๐Ÿ‡บ๐Ÿ‡ธ US (API) 10+ countries incl. ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ฆ๐Ÿ‡ช
Sub-processors US-based documented providers Fireworks (US/EU/JP), Baseten (US/CA) Anthropic API only Azure-managed
China Exposure None None documented None None documented
Encryption at Rest AES-256 (GCP) AES-256 (AWS/Azure) AES-256 (AWS) AES-256 (Azure)
Encryption in Transit TLS 1.2+ TLS 1.2+ TLS 1.2+ TLS 1.2+
๐Ÿ’ก
Data Residency Leader: OpenAI Codex offers the broadest data residency with 10+ country options (US, EU, UK, Australia, Canada, Japan, India, Singapore, South Korea, UAE), making it ideal for organizations with strict data sovereignty requirements.
06 / 13

Authentication & SSO Comparison

Enterprise identity management capabilities determine how tightly each tool integrates with your corporate IdP and access lifecycle.

Capability Ampcode Cursor Claude Code Codex
SSO Support โœ“ Okta/SAML/OIDC โœ“ SSO โœ— API Keys Only โœ“ Enterprise SSO
SCIM Directory Sync โœ“ Yes โœ“ Enterprise โœ— No โœ“ Yes
MFA Via IdP Via IdP N/A Via IdP
Admin Portal โœ“ โœ“ Limited โœ“
Exclusive SSO Mode โœ“ Yes โœ— Unknown โœ— N/A โœ“ Yes
Domain Verification โœ“ โœ“ โœ— โœ“
๐Ÿ†
Leaders: Ampcode & Codex โ€” Full SSO + SCIM + exclusive mode enables automated provisioning/deprovisioning and eliminates password-based auth risk.
โš ๏ธ
Cursor Update: Cursor now documents SSO and SCIM for Enterprise; validate plan availability, enforcement, and IdP behavior during procurement.
07 / 13

Audit Logging Capabilities

Enterprise audit logging is critical for incident response, compliance evidence, and security monitoring.

Capability Ampcode Cursor Claude Code Codex
Auth Logs โœ“ Admin access โœ“ Enterprise Limited โœ“ Enterprise
App-Level Logs Available on request Auth, user mgmt, settings, API keys, privacy changes OpenTelemetry metrics API usage logs
SIEM Streaming โœ— Not offered โœ“ Splunk, Datadog โœ— Not offered ~ Enterprise
Export Format On request JSON, CSV OpenTelemetry Enterprise format
Retention 30-day minimum Enterprise-defined Local Enterprise-defined
Agent Response Logging On request โœ— Not logged Local only Enterprise
๐Ÿ“Š
Cursor leads in audit logging with the most comprehensive event coverage and native SIEM integration (Splunk, Datadog). However, it notably does not log agent responses or generated code, which limits forensic capability for code-related incidents.
08 / 13

How Each Tool Protects Secrets & Isolates Execution

Secret Protection

BEST
Ampcode โ€” Automatic Redaction

System-level engine detects AWS, GCP, Azure, GitHub, GitLab, OpenAI, Anthropic, Stripe, Slack, npm tokens + generic patterns. Replaces with [REDACTED:amp]. No developer config needed.

WEAK
Cursor โ€” No Redaction Engine

Only .cursorignore files (developer-configured). No automatic detection. Extension sigs DISABLED by default. Workspace Trust DISABLED by default. Entire burden on developers.

STRONG
Claude Code โ€” Defense in Depth

Encrypted cred storage, command blocklist (curl/wget blocked), command injection detection, sandboxed bash with filesystem/network isolation.

STRONG
Codex โ€” Platform Sandbox

Platform-native enforcement in sandboxed cloud environments. Network isolation configurable. Approval policies for sensitive operations.

Sandboxing & Execution Isolation

Vendor Model Score
Claude Code Permission-based, sandboxed bash, fs/net isolation, write-only workdir 5/5
Codex 3 modes (read-only, workspace-write, full-access), platform-native, net isolation 5/5
Ampcode User approval for destructive actions, bug bounty covers prompt injection 3/5
Cursor User approval (VS Code), but CVEs demonstrate sandbox bypass vulnerabilities 3/5
July 27, 2026 update — new surfaces, unchanged scores: Claude Code's background agents, agent teams, and web/desktop run under the same permission-gated sandbox model scored above (no score change). Amp's Low/Medium/High/Ultra mode rename does not alter approval-gate or redaction controls. No new qualifying CVEs in the re-check window.
๐Ÿšจ
Cursor's sandbox has been breached: CVE-2026-26268 demonstrates a proven sandbox escape leading to RCE. This undermines the 3/5 sandboxing score โ€” the effective isolation is lower than architectural design suggests.
09 / 13

Known Vulnerabilities & CVE History

Cursor has multiple publicly disclosed CVEs; several enable or contribute to command execution / RCE paths and require strict patch validation.

๐Ÿ”ด
CURSOR โ€” Public CVEs Requiring Patch Validation

CVE-2025-54135 โ€” prompt-injection RCE path; fixed in Cursor 1.3.9
Remote Code Execution via prompt injection combined with dotfile creation. Attacker can execute arbitrary code on developer machines via crafted prompts. Highest practical severity.

CVE-2026-26268 โ€” Sandbox Escape RCE; fixed in Cursor 2.5
Escape from Cursor's sandbox environment leading to full system access from sandboxed context.

CVE-2025-59944 โ€” prompt-injection RCE path on case-insensitive filesystems; fixed in Cursor 1.7
Command execution via social-engineering / UI disclosure path; fixed in Cursor 1.3.

CVE-2025-54133 โ€” MCP deeplink command execution (CNA CVSS 5.3 Medium)
Command execution via social-engineering / UI disclosure path; fixed in Cursor 1.3.

Ampcode

๐ŸŸข

No Critical CVEs

Active bug bounty program. Annual penetration testing.

Claude Code

๐ŸŸข

No Critical CVEs

Responsible disclosure program. Constitutional AI safety focus.

OpenAI Codex

๐ŸŸข

No Critical CVEs

Established Bugcrowd bug bounty program.

10 / 13

Architecture & Data Flow Comparison

Each tool uses a fundamentally different architecture pattern with varying security implications.

Ampcode (Sourcegraph)
Amp Client
CLI / VS Code
โ†’
Amp Server
GCP / US
โ†’
LLM Providers
Zero Retention
Secret redaction at client ยท AES-256 at server ยท TLS 1.2+ everywhere
Cursor (Anysphere)
VS Code Fork
Extension
โ†’
Cursor Cloud
AWS / Azure
โ†’
LLM Providers
Privacy Mode dep.
.cursorignore only ยท No redaction engine ยท Multi-cloud
Claude Code (Anthropic)
CLI Tool
Local Execution
โ†’
Anthropic API
Direct / AWS
No intermediate server ยท Code stays local ยท Sandboxed bash
OpenAI Codex
ChatGPT / API
Client
โ†’
Codex Cloud
Azure
โ†’
Sandbox Env
3 Modes
Platform-native sandboxing ยท Network isolation ยท Approval policies
11 / 13

What Vendors Secure vs. What You Must Secure

Regardless of which tool you deploy, your organization retains critical security responsibilities.

๐ŸŸข Vendor Responsibility (All Tools)

  • Application security (secure SDLC, code reviews, pentesting)
  • Infrastructure security (cloud hardening, firewall, WAF)
  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Compliance certification maintenance
  • Security patch management and vulnerability remediation
  • Incident response and security monitoring
  • LLM provider agreement enforcement

๐ŸŸก Your Organization's Responsibility

  • Tool selection โ€” choose tools matching your risk tolerance
  • Access management โ€” SSO config, user lifecycle, offboarding
  • Privacy mode enforcement โ€” ensure training is disabled
  • Secret hygiene โ€” vault usage, rotation, .cursorignore / .env
  • Developer training โ€” AI agent risks, prompt injection awareness
  • Code review โ€” review all AI-generated code before merge
  • CVE monitoring โ€” track vendor vulnerability disclosures
  • Version management โ€” pin and update tool versions
  • Incident response โ€” playbooks for secret exposure scenarios
  • Compliance โ€” understand regulatory impact of AI tool usage
๐Ÿšจ
Critical for ALL Tools: AI coding agents can execute commands and read files on developer machines. Developers must: Never paste production secrets into prompts ยท Review agent-suggested commands before execution ยท Rotate any secret exposed in a session ยท Report security concerns immediately
12 / 13

Comparative Scoring Matrix (1โ€“5)

Each tool scored across nine security dimensions. Green (4-5) = strong, Yellow (3) = adequate, Red (1-2) = concerning.

Security Dimension Ampcode Cursor Claude Code Codex
Compliance Breadth 5 2 5 4
Data Retention Control 5 4 4 3
Encryption Standards 5 4 5 5
SSO / SCIM 5 3 2 5
Audit Logging 4 5 3 4
Secret Protection 5 2 4 4
Sandboxing 3 3 5 5
Vulnerability History 5 1 5 5
Enterprise Maturity 5 3 5 5
TOTAL (out of 45) 42 27 38 40
Percentage 93% 60% 84% 89%

๐Ÿฅ‡ 1st

Ampcode

42/45

๐Ÿฅˆ 2nd

OpenAI Codex

40/45

๐Ÿฅ‰ 3rd

Claude Code

38/45

4th

Cursor

27/45

13 / 13

CISO Final Security Verdicts

Ampcode Sourcegraph

APPROVED

42/45 โ€” RECOMMENDED

Strongest overall security posture. Zero retention on all LLMs, automatic secret redaction, SSO/SCIM, no critical CVEs. Conditional on: Enterprise plan, SSO enforcement, developer training.

Cursor Anysphere

CONDITIONAL

27/45 โ€” SIGNIFICANT CONCERNS

multiple Cursor CVEs with RCE-relevant paths, SOC 2 only, no secret redaction, training data risk. Requires: Privacy Mode enforcement, .cursorignore policy, version pinning, CVE monitoring, restrict to non-sensitive codebases.

Claude Code Anthropic

APPROVED

38/45 โ€” STRONGEST COMPLIANCE

Broadest certification portfolio; FedRAMP High is specific to Claude government/partner-hosted offerings. CLI-local execution with sandboxed bash. Ideal for: regulated industries, government, healthcare. API key management required.

OpenAI Codex OpenAI

APPROVED

40/45 โ€” ENTERPRISE READY

Strong compliance, cloud-sandboxed environments, broad OpenAI enterprise controls; verify Codex-specific residency. Note: ZDR requires approval process. Best for ChatGPT Enterprise organizations.

๐Ÿ“ž
Security Contacts:
Ampcode: security@ampcode.com ยท Cursor: cursor.com/security ยท Anthropic: trust.anthropic.com ยท OpenAI: trust.openai.com

Reference Links & Source Documentation

Vendor Document URL Type
AmpcodeSecurity Referenceampcode.com/securityPrimary Source
AmpcodeSourcegraph Securitysourcegraph.com/securityPrimary Source
AmpcodeTrust Portalsecurity.sourcegraph.comSOC 2 / Pentest / ISO
AmpcodeAmp Trust Centertrust.ampcode.comSOC 2 / Reports
CursorSecurity Pagecursor.com/securityPrimary Source
CursorTrust Centertrust.cursor.comSOC 2
CursorPrivacy Policycursor.com/privacyLegal / Privacy
Claude CodeSecurity Documentationdocs.anthropic.com/.../securityPrimary Source
Claude CodeTrust Centertrust.anthropic.comCompliance / Reports
CodexProduct Pageopenai.com/codexPrimary Source
CodexTrust Centertrust.openai.comCompliance / Reports

ยฉ 2026 โ€” AI Coding Tools CISO Security Comparison โ€” Prepared with Ampcode

This document is based on publicly available security documentation and should be supplemented with direct vendor engagement, NDA-protected document review (SOC 2, pentest reports), and internal risk committee evaluation.