Ampcode
AI Coding Tools โ€” Security Comparison Report
CISO Assessment ยท Public Summary
================================================================================
                    PUBLIC โ€” POINT-IN-TIME SECURITY ASSESSMENT
================================================================================

      AI CODING TOOLS โ€” COMPARATIVE CYBERSECURITY ASSESSMENT REPORT
      ==============================================================
      Ampcode vs Cursor vs Claude Code vs OpenAI Codex

      Prepared for:    Chief Information Security Officer
      Assessment Date: June 22, 2026
      Classification:  Public โ€” Point-in-Time Assessment
      Scope:           Enterprise Readiness Comparison of AI Coding Agents

      Vendors Assessed:
        1. Ampcode       โ€” Sourcegraph, Inc.
        2. Cursor        โ€” Anysphere, Inc.
        3. Claude Code   โ€” Anthropic, PBC
        4. OpenAI Codex  โ€” OpenAI, Inc.

================================================================================
                         TABLE OF CONTENTS
================================================================================

  1.  Executive Summary
  2.  Vendor Overview
  3.  Compliance & Certifications Comparison
  4.  Data Retention & Training Policies
  5.  Encryption Standards
  6.  Infrastructure & Data Residency
  7.  Authentication & Identity Management
  8.  Audit Logging Capabilities
  9.  Secret Protection & Sandboxing
  10. Known Vulnerabilities & CVE History
  11. Security Scoring Matrix
  12. Risk Assessment by Vendor
  13. Deployment Recommendations by Vendor
  14. Pre-Deployment Checklist (Universal)
  15. Verdicts & Final Recommendations
  16. Reference Links & Source Documentation
  17. Document Control


================================================================================
  1. EXECUTIVE SUMMARY
================================================================================

This report provides a comparative cybersecurity assessment of four leading
AI coding tools to determine their suitability for enterprise adoption.
Each tool was evaluated against nine security dimensions using publicly
available documentation, trust portals, and CVE databases.

KEY FINDINGS:

  * Ampcode (Sourcegraph) โ€” APPROVED. Strong compliance portfolio
    (SOC 2 Type II + annual third-party pentesting), zero LLM data
    retention on Enterprise plans with training permanently disabled,
    automatic secret redaction engine, SSO/SCIM support. No publicly
    disclosed critical CVEs. Score: 42/45.

  * Cursor (Anysphere) โ€” CONDITIONAL. SOC 2 Type II only; vendor
    admits being "still in the journey of growing our security posture."
    Multiple Cursor CVEs disclosed, including prompt-injection and sandbox-escape RCE paths. No built-in
    secret redaction engine. Enterprise controls include Privacy Mode enforcement, audit logs, model controls, SSO/SCIM, and CMEK. Score: 27/45.

  * Claude Code (Anthropic) โ€” APPROVED. Broadest compliance portfolio
    of all four tools (SOC 2 + ISO 27001 + ISO 42001 + HIPAA + CSA
    STAR + NIST 800-171 + FedRAMP-qualified government/partner offerings). CLI-local architecture with
    sandboxed bash, command blocklist, and permission-based execution.
    No publicly disclosed critical CVEs. Score: 38/45.

  * OpenAI Codex โ€” APPROVED. Strong compliance (SOC 2 + ISO 27001 +
    ISO 27017/27018/27701 + PCI DSS). Cloud-sandboxed environments
    with three execution modes and platform-native enforcement.
    OpenAI Trust Center documents broad enterprise controls; verify Codex-specific data residency during procurement. Score: 40/45.

OVERALL RECOMMENDATION:

  Ampcode and Codex are recommended as primary candidates for enterprise
  deployment. Claude Code is recommended for API/Enterprise users who
  value the strongest compliance credentials and local execution.
  Cursor requires significant risk mitigation before enterprise adoption
  due to its CVE history, limited certifications, and training data risks.


================================================================================
  2. VENDOR OVERVIEW
================================================================================

  VENDOR           COMPANY            HQ            PRODUCT TYPE
  ---------------  -----------------  ------------  ----------------------------
  Ampcode          Sourcegraph, Inc.  San Francisco  Cloud-hosted AI coding agent
                                      CA, USA        (CLI + VS Code + Web)

  Cursor           Anysphere, Inc.    San Francisco  VS Code fork with AI
                                      CA, USA        integration

  Claude Code      Anthropic, PBC     San Francisco  CLI-based AI coding agent
                                      CA, USA        (direct API connection)

  OpenAI Codex     OpenAI, Inc.       San Francisco  Cloud-sandboxed AI coding
                                      CA, USA        agent (ChatGPT + API)


  TRUST INDICATORS:

  Ampcode / Sourcegraph:
    - Enterprise customers include Reddit, Uber, Dropbox, Databricks
    - Public Security Trust Portal with SOC 2 and ISO 27001 reports
    - Active bug bounty program covering prompt injection
    - Dedicated security team, annual third-party penetration testing

  Cursor / Anysphere:
    - Growing user base in developer community
    - SOC 2 Trust Portal available
    - Company acknowledges security posture is still maturing
    - No public bug bounty program documented

  Claude Code / Anthropic:
    - Constitutional AI safety research pioneer
    - Industry-leading compliance certifications
    - Responsible Scaling Policy published
    - HIPAA and FedRAMP High available for Claude government/partner-hosted offerings

  OpenAI Codex / OpenAI:
    - Largest AI company by market capitalization
    - ChatGPT Enterprise serves Fortune 500 customers
    - OpenAI enterprise controls; verify Codex-specific data residency options
    - ISO 27701 and broad OpenAI Trust Center coverage; verify Codex-specific scope during procurement


================================================================================
  3. COMPLIANCE & CERTIFICATIONS COMPARISON
================================================================================

  The following table compares verified compliance certifications across
  all four vendors. Certifications were verified via public trust portals
  and security documentation.

  CERTIFICATION         AMPCODE      CURSOR       CLAUDE CODE   CODEX
  --------------------  -----------  -----------  ------------  -----------
  SOC 2 Type II         โœ“ Certified  โœ“ Certified  โœ“ Certified   โœ“ Certified
  ISO/IEC 27001         โœ“ Certified  โœ— None       โœ“ Certified   โœ“ Certified
  ISO/IEC 27017         โœ— None       โœ— None       โœ— None        โœ“ Certified
  ISO/IEC 27018         โœ— None       โœ— None       โœ— None        โœ“ Certified
  ISO/IEC 27701         โœ— None       โœ— None       โœ— None        โœ“ Certified
  ISO/IEC 42001         โœ— None       โœ— None       โœ“ Certified   โœ— None
  GDPR                  โœ“ Compliant  ~ Partial    โœ“ Compliant   โœ“ Compliant
  CCPA                  โœ“ Compliant  ~ Partial    โœ“ Compliant   โœ“ Compliant
  EU AI Act             โœ“ Compliant  โœ— None       โœ— None        โœ— None
  HIPAA                 โœ— None       โœ— None       โœ“ Certified   โœ— None
  FedRAMP High          โœ— None       โœ— None       Gov/partner  โœ— None
  NIST 800-171          โœ— None       โœ— None       โœ“ Certified   โœ— None
  CSA STAR              โœ— None       โœ— None       โœ“ Certified   โœ— None
  PCI DSS               โœ— None       โœ— None       โœ— None        โœ“ Certified

  TOTAL CERTIFICATIONS:
    Ampcode:     5 (SOC2 Type II and annual pentesting)
    Cursor:      1 (SOC2 only)
    Claude Code: 6+ (SOC2, ISO27001, ISO42001, HIPAA, NIST, CSA; FedRAMP for government/partner-hosted offerings)
    Codex:       6 (SOC2, ISO27001/17/18/701, PCI DSS)

  ANALYSIS:

    Claude Code (Anthropic) holds the broadest compliance portfolio of
    any AI coding tool assessed. Its HIPAA, NIST, and CSA STAR support regulated environments; FedRAMP High applies to Claude for Government and partner-hosted government offerings, not every Claude Code deployment.

    Cursor's single SOC 2 Type II certification is notably below the
    enterprise baseline. The vendor's own documentation acknowledges
    they are "still in the journey of growing our security posture."

  COMPLIANCE SCORE (1-5):
    Ampcode: 5  |  Cursor: 2  |  Claude Code: 5  |  Codex: 4


================================================================================
  4. DATA RETENTION & TRAINING POLICIES
================================================================================

  AMPCODE (Sourcegraph):
  ----------------------
    Enterprise Plan:
      - Zero LLM input/output retention on Enterprise plans; provider cache up to 24h may apply
      - LLM inputs/outputs are not retained beyond inference except documented provider caching/safety exceptions
      - Model training on customer data is permanently disabled
      - Training CANNOT be re-enabled on Enterprise plans
      - Deleted thread data removed within 30 days
      - Images subject to limited retention for compliance only

    Risk: LOW โ€” Best-in-class data retention controls

  CURSOR (Anysphere):
  --------------------
    Privacy Mode:
      - Zero data retention โ€” code not stored on servers
      - No training on user data when Privacy Mode is enabled

    Privacy Mode Off:
      - Data MAY be used for training purposes
      - Already-trained models are NOT retrained after user deletion
      - Data that has already been used for training persists in models

    โš  RISK: Models trained on user data before opt-out CANNOT be
    untrained. This creates a permanent data exposure vector for
    organizations that do not enforce Privacy Mode from day one.

    Risk: MEDIUM โ€” Requires strict Privacy Mode and model-retention control enforcement

  CLAUDE CODE (Anthropic):
  -------------------------
    Enterprise / API Usage:
      - No training on customer data
      - Direct API connection โ€” no intermediate server

    Consumer Usage:
      - May train on data unless user explicitly opts out

    Risk: LOW โ€” Clear enterprise/consumer separation

  OPENAI CODEX:
  ---------------
    Default:
      - 30-day abuse monitoring retention on API inputs
      - Data retained for safety/abuse detection purposes

    Zero Data Retention (ZDR):
      - Available but requires explicit approval process
      - Additional requirements must be met
      - Not all API endpoints are eligible for ZDR

    Risk: MEDIUM-LOW โ€” ZDR approval process adds friction

  DATA RETENTION SCORE (1-5):
    Ampcode: 5  |  Cursor: 4  |  Claude Code: 4  |  Codex: 3


================================================================================
  5. ENCRYPTION STANDARDS
================================================================================

  VENDOR          AT REST           IN TRANSIT        NOTES
  --------------  ----------------  ----------------  -------------------------
  Ampcode         AES-256           TLS 1.2+          GCP-managed keys,
                  (GCP-managed)                       Cloudflare WAF

  Cursor          AES-256           TLS 1.2+          AWS/Azure managed
                  (cloud-managed)                     encryption

  Claude Code     AES-256           TLS 1.2+          Encrypted credential
                  (AWS-managed)                       storage for API keys

  Codex           AES-256           TLS 1.2+          Azure/OpenAI managed,
                  (Azure-managed)                     multiple region keys

  ANALYSIS:

    All four vendors meet the enterprise encryption baseline with AES-256
    at rest and TLS 1.2+ in transit. No vendor offers customer-managed
    encryption keys (CMEK/BYOK).

  ENCRYPTION SCORE (1-5):
    Ampcode: 5  |  Cursor: 4  |  Claude Code: 5  |  Codex: 5


================================================================================
  6. INFRASTRUCTURE & DATA RESIDENCY
================================================================================

  AMPCODE:
    Primary Cloud:     Google Cloud Platform (GCP)
    Regions:           United States only
    Sub-processors:    US-based documented providers
    China Exposure:    None โ€” explicitly documented as no China providers
    Data Sovereignty:  US jurisdiction, SCCs for EEA/UK transfers

  CURSOR:
    Primary Cloud:     AWS (primary), Azure, GCP
    Additional:        Fireworks (US/Europe/Japan), Baseten (US/Canada)
    Regions:           Multi-region (US, Europe, Japan, Canada)
    China Exposure:    No China-based infrastructure documented
    Data Sovereignty:  Multi-jurisdiction โ€” more complex compliance

  CLAUDE CODE:
    Primary Cloud:     Local CLI execution (no intermediate server)
    API Backend:       Anthropic API (AWS infrastructure)
    Regions:           United States
    China Exposure:    None
    Data Sovereignty:  Code stays local; only API calls to US servers

  OPENAI CODEX:
    Primary Cloud:     Azure / OpenAI infrastructure
    Regions:           10+ countries: US, EU, UK, Australia, Canada,
                       Japan, India, Singapore, South Korea, UAE
    China Exposure:    None documented
    Data Sovereignty:  Verify Codex-specific residency scope with OpenAI

  DATA FLOW COMPARISON:

    AMPCODE:
    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  TLS 1.2+  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  TLS 1.2+  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
    โ”‚  Developer   โ”‚ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€> โ”‚  Amp Server  โ”‚ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€> โ”‚    LLM       โ”‚
    โ”‚  Machine     โ”‚ <โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”‚  (GCP / US)  โ”‚ <โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”‚  Providers   โ”‚
    โ”‚              โ”‚            โ”‚              โ”‚            โ”‚  (Zero       โ”‚
    โ”‚  [Redaction] โ”‚            โ”‚  [AES-256]   โ”‚            โ”‚   Retention) โ”‚
    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

    CURSOR:
    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  TLS 1.2+  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  TLS 1.2+  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
    โ”‚  VS Code     โ”‚ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€> โ”‚ Cursor Cloud โ”‚ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€> โ”‚    LLM       โ”‚
    โ”‚  Extension   โ”‚ <โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”‚ (AWS/Azure)  โ”‚ <โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”‚  Providers   โ”‚
    โ”‚              โ”‚            โ”‚              โ”‚            โ”‚              โ”‚
    โ”‚  [.cursorig] โ”‚            โ”‚  [AES-256]   โ”‚            โ”‚  [Privacy    โ”‚
    โ”‚              โ”‚            โ”‚              โ”‚            โ”‚   Mode dep.] โ”‚
    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

    CLAUDE CODE:
    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  TLS 1.2+  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
    โ”‚  Developer   โ”‚ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€> โ”‚  Anthropic   โ”‚   No intermediate server
    โ”‚  Machine     โ”‚ <โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”‚  API (AWS)   โ”‚   Code runs locally
    โ”‚              โ”‚            โ”‚              โ”‚
    โ”‚  [Sandboxed] โ”‚            โ”‚  [No Train   โ”‚
    โ”‚  [Bash Tool] โ”‚            โ”‚   Entrprise] โ”‚
    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

    OPENAI CODEX:
    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  TLS 1.2+  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  Isolated   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
    โ”‚  ChatGPT /   โ”‚ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€> โ”‚ Codex Cloud  โ”‚ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€> โ”‚  Sandbox     โ”‚
    โ”‚  API Client  โ”‚ <โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”‚ (Azure)      โ”‚ <โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”‚  Environment โ”‚
    โ”‚              โ”‚            โ”‚              โ”‚            โ”‚              โ”‚
    โ”‚              โ”‚            โ”‚  [AES-256]   โ”‚            โ”‚  [3 Modes]   โ”‚
    โ”‚              โ”‚            โ”‚              โ”‚            โ”‚  [Net Isol.] โ”‚
    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜


================================================================================
  7. AUTHENTICATION & IDENTITY MANAGEMENT
================================================================================

  CAPABILITY         AMPCODE      CURSOR       CLAUDE CODE   CODEX
  -----------------  -----------  -----------  ------------  -----------
  SSO Support        โœ“ Yes        โœ“ Yes        โœ— No          โœ“ Yes
                     Okta/SAML/                 API keys      ChatGPT
                     OIDC (WorkOS)              only          Enterprise

  SCIM Dir. Sync     โœ“ Yes        โœ— No         โœ— No          โœ“ Yes

  MFA                โœ“ Via IdP    โœ“ Via IdP    โœ— N/A         โœ“ Via IdP

  Admin Portal       โœ“ Yes        โœ“ Yes        โœ— Limited     โœ“ Yes

  Exclusive SSO      โœ“ Yes        โœ— Unknown    โœ— N/A         โœ“ Yes
  (disable password)

  Domain Verify      โœ“ Yes        โœ“ Yes        โœ— N/A         โœ“ Yes

  ANALYSIS:

    Ampcode and Codex provide the strongest identity management with full
    SSO, SCIM Directory Sync, and exclusive SSO mode. This enables
    automated provisioning/deprovisioning via corporate IdP.

    Cursor now documents SSO and SCIM for Enterprise; validate plan availability and IdP integration during procurement.

    Claude Code as a CLI tool uses API keys exclusively. While this
    simplifies deployment, it lacks centralized identity controls and
    makes access auditing more difficult.

  SSO/SCIM SCORE (1-5):
    Ampcode: 5  |  Cursor: 3  |  Claude Code: 2  |  Codex: 5


================================================================================
  8. AUDIT LOGGING CAPABILITIES
================================================================================

  AMPCODE:
    - Authentication audit logs available to workspace admins
    - Application-level audit logs available on request
    - Minimum 30-day log retention
    - Does not currently offer SIEM streaming

  CURSOR:
    - Enterprise audit logs cover: authentication, user management,
      settings changes, API key events, privacy mode changes
    - JSON format export
    - SIEM streaming supported: Splunk, Datadog
    - CSV export available
    - Does NOT log agent responses or generated code
    - Most comprehensive logging of the four vendors

  CLAUDE CODE:
    - OpenTelemetry metrics integration
    - Hooks system for monitoring and custom integrations
    - Limited centralized logging โ€” CLI-local architecture
    - No built-in SIEM streaming

  OPENAI CODEX:
    - Enterprise audit logs via ChatGPT Enterprise
    - API usage logs available
    - Standard enterprise logging capabilities

  AUDIT LOGGING SCORE (1-5):
    Ampcode: 4  |  Cursor: 5  |  Claude Code: 3  |  Codex: 4


================================================================================
  9. SECRET PROTECTION & SANDBOXING
================================================================================

  A. SECRET PROTECTION COMPARISON:

  AMPCODE โ€” STRONGEST SECRET PROTECTION:
    - Automatic secret redaction engine built into the system
    - Detects and replaces secrets before they leave the client
    - Supported patterns: AWS, GCP, Azure, GitHub, GitLab, OpenAI,
      Anthropic, Stripe, Slack, npm tokens, generic high-entropy strings
    - Secrets replaced with [REDACTED:amp] marker
    - Best-effort with documented limitations for non-standard secrets
    - System-level โ€” requires no developer configuration

  CURSOR โ€” WEAKEST SECRET PROTECTION:
    โš  CRITICAL: No built-in secret redaction engine
    - Only protection: .cursorignore files (developer-configured)
    - Path obfuscation for file paths
    - Enterprise controls include Privacy Mode enforcement, model controls, audit logs, SSO/SCIM, and CMEK
    - Secret exclusion still depends heavily on configuration and developer hygiene
    - No automatic detection of credentials in code context

  CLAUDE CODE โ€” STRONG SECRET PROTECTION:
    - Encrypted credential storage for API keys
    - Sandboxed bash tool with filesystem and network isolation
    - Write-only access to working directory
    - Command blocklist: curl, wget blocked by default
    - Command injection detection
    - Managed organizational settings via JSON configuration

  OPENAI CODEX โ€” STRONG SECRET PROTECTION:
    - Platform-native sandbox enforcement
    - Sandboxed cloud environments with network isolation
    - Three execution modes with varying permission levels
    - Approval policies for sensitive operations
    - Secrets managed at platform level

  B. SANDBOXING COMPARISON:

  VENDOR          EXECUTION MODEL        ISOLATION LEVEL     NOTES
  --------------  ---------------------  ------------------  ------------------
  Ampcode         User approval for      Moderate            Bug bounty covers
                  destructive actions                        prompt injection

  Cursor          User approval          Moderate            CVEs demonstrate
                  (VS Code extension)                        sandbox bypasses

  Claude Code     Permission-based       Strong              Sandboxed bash,
                  sandboxed bash                             fs/net isolation,
                                                            write-only workdir

  Codex           3 modes: read-only,    Strong              Platform-native
                  workspace-write,                           enforcement,
                  full-access                                net isolation

  SECRET PROTECTION SCORE (1-5):
    Ampcode: 5  |  Cursor: 2  |  Claude Code: 4  |  Codex: 4

  SANDBOXING SCORE (1-5):
    Ampcode: 3  |  Cursor: 3  |  Claude Code: 5  |  Codex: 5


================================================================================
  10. KNOWN VULNERABILITIES & CVE HISTORY
================================================================================

  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
  โ”‚                                                                      โ”‚
  โ”‚   โš   CRITICAL SECURITY DIFFERENTIATOR                               โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   Cursor has multiple public CVEs among the assessed tools.          โ”‚
  โ”‚   Several listed issues enable or contribute to command execution     โ”‚
  โ”‚   / RCE paths; CVE-2025-54133 is CNA-rated medium.                  โ”‚
  โ”‚                                                                      โ”‚
  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

  CURSOR โ€” PUBLIC CVEs REQUIRING PATCH VALIDATION:

    CVE-2025-54135 โ€” prompt-injection RCE path; fixed in Cursor 1.3.9
    -------------------------------------------------------
    Type:        Remote Code Execution via Prompt Injection
    Vector:      Prompt injection combined with dotfile creation
    Impact:      Attacker can execute arbitrary code on developer
                 machines via crafted prompts
    Severity:    CRITICAL โ€” highest possible practical severity

    CVE-2026-26268 โ€” Sandbox Escape RCE; fixed in Cursor 2.5
    -------------------------------------------------------
    Type:        Sandbox Escape leading to RCE
    Vector:      Escape from Cursor's sandbox environment
    Impact:      Full system access from sandboxed context

    CVE-2025-59944 โ€” prompt-injection RCE path on case-insensitive filesystems; fixed in Cursor 1.7
    -------------------------------------------------------
    Type:        RCE vulnerability
    Impact:      Arbitrary code execution on target systems

    CVE-2025-54133 โ€” MCP deeplink command execution (CNA CVSS 5.3 Medium)
    -------------------------------------------------------
    Type:        RCE vulnerability
    Impact:      Arbitrary code execution on target systems

  AMPCODE (Sourcegraph):
    - No publicly disclosed critical CVEs
    - Active bug bounty program
    - Annual third-party penetration testing

  CLAUDE CODE (Anthropic):
    - No publicly disclosed critical CVEs
    - Responsible disclosure program
    - Constitutional AI safety focus

  OPENAI CODEX:
    - No publicly disclosed critical CVEs for Codex product
    - Established bug bounty program via Bugcrowd

  VULNERABILITY HISTORY SCORE (1-5):
    Ampcode: 5  |  Cursor: 1  |  Claude Code: 5  |  Codex: 5

  ANALYSIS:

    Cursor's four critical RCE CVEs represent the single most significant
    security differentiator in this assessment. CVE-2025-54135 and related Cursor advisories show prompt-injection-to-execution risk. NVD had not assigned its own CVSS score for several entries as of June 22, 2026. The combination of:

      1. Critical RCE vulnerabilities
      2. No built-in secret redaction
      3. Extension signatures disabled by default
      4. Workspace Trust disabled by default

    Creates a compounding risk profile that requires extraordinary
    mitigation measures for enterprise deployment.


================================================================================
  11. SECURITY SCORING MATRIX
================================================================================

  Scoring Scale: 1 (Critical Concern) to 5 (Best-in-Class)

  CATEGORY                 AMPCODE   CURSOR   CLAUDE CODE   CODEX
  -----------------------  --------  -------  -----------   ------
  Compliance Breadth          5         2          5           4
  Data Retention Control      5         4          4           3
  Encryption Standards        5         4          5           5
  SSO / SCIM                  5         3          2           5
  Audit Logging               4         5          3           4
  Secret Protection           5         2          4           4
  Sandboxing                  3         3          5           5
  Vulnerability History       5         1          5           5
  Enterprise Maturity         5         3          5           5
  -----------------------  --------  -------  -----------   ------
  TOTAL (out of 45)          42        27         38          40

  RANKING:
    1st โ€” Ampcode         42/45  (93%)  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ EXCELLENT
    2nd โ€” OpenAI Codex    40/45  (89%)  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ   EXCELLENT
    3rd โ€” Claude Code     38/45  (84%)  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ    STRONG
    4th โ€” Cursor          27/45  (60%)  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ         CONCERNING

  KEY OBSERVATIONS:

    * Ampcode leads with the highest overall score, driven by its
      combination of strong compliance, zero data retention, automatic
      secret redaction, and clean vulnerability history.

    * Codex scores second due to its broad compliance portfolio, strong
      sandboxing, and data residency options. ZDR approval friction
      is the primary deduction.

    * Claude Code's lower score in SSO/SCIM and audit logging reflects
      its CLI-local architecture, which trades centralized management
      for stronger local isolation.

    * Cursor's score is significantly below the enterprise baseline,
      primarily due to its critical CVE history (1/5) and minimal
      secret protection (2/5).


================================================================================
  12. RISK ASSESSMENT BY VENDOR
================================================================================

  AMPCODE โ€” OVERALL RISK: LOW
  ----------------------------

  RISK AREA                     LEVEL    JUSTIFICATION
  ----------------------------  -------  ------------------------------------
  Data at Rest                  LOW      AES-256, GCP-managed keys
  Data in Transit               LOW      TLS 1.2+, Cloudflare WAF
  LLM Data Leakage              LOW      Zero retention, training disabled
  Authentication Bypass          LOW      SSO + SCIM + exclusive SSO mode
  Secret Exposure               MEDIUM   Best-effort redaction has limits
  Prompt Injection              MEDIUM   Inherent to LLM agents; bug bounty
  Compliance Risk               LOW      SOC2 Type II + annual pentesting
  Supply Chain                  LOW      SBOMs, distroless images, CVE scans

  CURSOR โ€” OVERALL RISK: HIGH
  ----------------------------

  RISK AREA                     LEVEL    JUSTIFICATION
  ----------------------------  -------  ------------------------------------
  Data at Rest                  LOW      AES-256, cloud-managed
  Data in Transit               LOW      TLS 1.2+
  LLM Data Leakage              HIGH     Training risk if Privacy Mode off
  Authentication Bypass          MEDIUM   SSO/SCIM documented; validate exclusive enforcement
  Secret Exposure               HIGH     No redaction engine, sigs disabled
  Prompt Injection              HIGH     CVE-2025-54135 prompt-injection RCE path
  Sandbox Escape                HIGH     CVE-2026-26268 sandbox escape path
  Compliance Risk               HIGH     SOC2 only, vendor admits immaturity
  Remote Code Execution         HIGH     Multiple CVEs with execution impact

  CLAUDE CODE โ€” OVERALL RISK: LOW
  ---------------------------------

  RISK AREA                     LEVEL    JUSTIFICATION
  ----------------------------  -------  ------------------------------------
  Data at Rest                  LOW      AES-256, encrypted cred storage
  Data in Transit               LOW      TLS 1.2+, direct API connection
  LLM Data Leakage              LOW      Enterprise = no training
  Authentication Bypass          MEDIUM   API keys only, no SSO
  Secret Exposure               LOW      Command blocklist, sandboxed bash
  Prompt Injection              LOW      Permission-based, injection detect
  Compliance Risk               LOW      Broadest certification portfolio
  Local Execution Risk          LOW      CLI-local, no intermediate server

  OPENAI CODEX โ€” OVERALL RISK: LOW
  ----------------------------------

  RISK AREA                     LEVEL    JUSTIFICATION
  ----------------------------  -------  ------------------------------------
  Data at Rest                  LOW      AES-256, Azure-managed
  Data in Transit               LOW      TLS 1.2+
  LLM Data Leakage              MEDIUM   30-day default, ZDR needs approval
  Authentication Bypass          LOW      Enterprise SSO + SCIM
  Secret Exposure               LOW      Platform-native sandbox
  Prompt Injection              LOW      Sandboxed environments, net isol.
  Compliance Risk               LOW      SOC2 + ISO27001 + PCI DSS
  Data Residency                MEDIUM   Verify Codex-specific residency scope


================================================================================
  13. DEPLOYMENT RECOMMENDATIONS BY VENDOR
================================================================================

  AMPCODE โ€” RECOMMENDED DEPLOYMENT:
  -----------------------------------
    Plan Required:     Enterprise (mandatory for zero retention)
    SSO Configuration: Exclusive SSO mode via WorkOS (Okta/SAML/OIDC)
    SCIM:              Enable Directory Sync with corporate IdP
    Network:           Allowlist ampcode.com, auth.ampcode.com,
                       production.ampworkers.com, static.ampcode.com
    Training:          Developer security awareness program
    Monitoring:        Request audit logs, establish review cadence
    Secret Policy:     Educate on redaction limitations; use vaults

  CURSOR โ€” CONDITIONAL DEPLOYMENT (if approved):
  ------------------------------------------------
    Privacy Mode:      MANDATORY โ€” enforce for all users from day one
    .cursorignore:     MANDATORY โ€” create and maintain org-wide policy
    Version Pinning:   MANDATORY โ€” pin to patched versions, monitor CVEs
    SSO/SCIM:         Configure SSO, SCIM, and domain verification
    CMEK:              Enable Customer Managed Encryption Keys where required
    Model Controls:    Restrict models with provider retention unless approved
    Monitoring:        Enable enterprise audit logs, SIEM streaming
    CVE Monitoring:    Subscribe to Cursor security advisories
    Restrictions:      Consider restricting to non-sensitive codebases
    Review Cadence:    Monthly security posture review

  CLAUDE CODE โ€” RECOMMENDED DEPLOYMENT:
  ----------------------------------------
    Plan Required:     API / Enterprise (no training guarantee)
    API Key Mgmt:      Implement centralized API key rotation policy
    Configuration:     Deploy managed organizational settings via JSON
    Monitoring:        Configure OpenTelemetry metrics collection
    Hooks:             Set up monitoring hooks for security events
    Developer Guide:   Document approved/blocked commands
    Access Control:    API key-based access management

  OPENAI CODEX โ€” RECOMMENDED DEPLOYMENT:
  -----------------------------------------
    Plan Required:     ChatGPT Enterprise (SSO/SCIM, admin controls)
    ZDR:               Apply for Zero Data Retention if required
    Sandbox Mode:      Default to read-only; escalate per-project
    Data Residency:    Select appropriate region for compliance
    SSO/SCIM:          Configure via ChatGPT Enterprise admin
    Approval Policies: Set up approval workflows for full-access mode
    Network:           Configure network isolation policies


================================================================================
  14. PRE-DEPLOYMENT CHECKLIST (UNIVERSAL)
================================================================================

  The following checklist applies to ANY AI coding tool deployment.
  Vendor-specific items are marked with the vendor initial.

  COMPLIANCE & LEGAL:

  [ ] Request and review SOC 2 Type II report from vendor trust portal
  [ ] Request latest penetration test report (under NDA if required)
  [ ] Review vendor privacy policy with Legal/DPO team
  [ ] Review data processing agreement (DPA) terms
  [ ] Verify data residency meets regulatory requirements
  [ ] Document vendor in third-party risk register
  [ ] Review subprocessor list and subscribe to change notifications

  IDENTITY & ACCESS:

  [ ] Configure SSO as exclusive authentication method [A, Cu, Cx]
  [ ] Set up SCIM Directory Sync [A, Cu, Cx]
  [ ] Enforce MFA via identity provider
  [ ] Disable password-based authentication where available
  [ ] Configure domain verification [A, Cu, Cx]
  [ ] Establish user provisioning/deprovisioning procedures

  DATA PROTECTION:

  [ ] Confirm zero data retention / privacy mode is active [A, Cu]
  [ ] Verify model training is disabled [A, Cu, CC]
  [ ] Apply for Zero Data Retention if required [Cx]
  [ ] Establish data classification policy for AI tool usage
  [ ] Define which repositories/codebases are approved for use

  SECRET MANAGEMENT:

  [ ] Deploy .cursorignore files if using Cursor [Cu]
  [ ] Configure Cursor Enterprise SSO/SCIM and CMEK where required [Cu]
  [ ] Restrict Cursor models with provider retention unless approved [Cu]
  [ ] Establish secret rotation playbook for LLM-context exposure
  [ ] Ensure developers use vault-based secret management
  [ ] Document procedure for reporting suspected secret exposure

  MONITORING & AUDIT:

  [ ] Enable enterprise audit logs
  [ ] Configure SIEM streaming if available [Cu]
  [ ] Set up OpenTelemetry metrics collection [CC]
  [ ] Establish audit log review cadence (quarterly minimum)
  [ ] Request initial baseline audit log review

  DEVELOPER TRAINING:

  [ ] Develop AI agent security awareness training program
  [ ] Cover prompt injection risks and mitigations
  [ ] Cover secret handling procedures and vault usage
  [ ] Cover code review requirements for AI-generated code
  [ ] Cover command review procedures before execution
  [ ] Document and distribute approved usage policies

  RISK MANAGEMENT:

  [ ] Document accepted risks in organizational risk register
  [ ] Establish periodic vendor security review schedule
  [ ] Define incident response procedures for AI tool scenarios
  [ ] Set up CVE monitoring for chosen vendor(s)
  [ ] Establish version update/patching policy

  Legend: [A]=Ampcode  [Cu]=Cursor  [CC]=Claude Code  [Cx]=Codex


================================================================================
  15. VERDICTS & FINAL RECOMMENDATIONS
================================================================================

  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
  โ”‚                                                                      โ”‚
  โ”‚   AMPCODE (Sourcegraph) โ€” Score: 42/45 (93%)                        โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   VERDICT:  APPROVED โ€” RECOMMENDED FOR ENTERPRISE USE                โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   Ampcode demonstrates the strongest overall security posture for    โ”‚
  โ”‚   enterprise AI coding tool deployment. Key strengths include:       โ”‚
  โ”‚                                                                      โ”‚
  โ”‚     โ€ข SOC 2 Type II + annual third-party pentesting                   โ”‚
  โ”‚     โ€ข Zero data retention on ALL LLM providers (Enterprise)          โ”‚
  โ”‚     โ€ข Training permanently disabled, cannot be re-enabled            โ”‚
  โ”‚     โ€ข Automatic secret redaction engine (system-level)               โ”‚
  โ”‚     โ€ข SSO/SCIM with exclusive SSO mode                               โ”‚
  โ”‚     โ€ข No publicly disclosed critical CVEs                            โ”‚
  โ”‚     โ€ข US-based documented providers; no China providers documented    โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   CONDITIONAL ON:                                                    โ”‚
  โ”‚     1. Enterprise plan activation                                    โ”‚
  โ”‚     2. SSO enforcement (exclusive mode)                              โ”‚
  โ”‚     3. Developer security training completion                        โ”‚
  โ”‚                                                                      โ”‚
  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
  โ”‚                                                                      โ”‚
  โ”‚   CURSOR (Anysphere) โ€” Score: 27/45 (60%)                           โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   VERDICT:  CONDITIONAL โ€” SIGNIFICANT CONCERNS                       โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   Cursor presents material security risks that require extraordinary โ”‚
  โ”‚   mitigation for enterprise deployment:                              โ”‚
  โ”‚                                                                      โ”‚
  โ”‚     โœ— Multiple CVEs including prompt-injection/sandbox escape paths   โ”‚
  โ”‚     โœ— SOC 2 Type II only โ€” no ISO 27001 or other certs              โ”‚
  โ”‚     โœ— No built-in secret redaction engine                            โ”‚
  โ”‚     โœ— Enterprise controls require plan/configuration validation       โ”‚
  โ”‚     โœ— SCIM is Enterprise-documented; validate IdP behavior           โ”‚
  โ”‚     โœ— Training data risk if Privacy Mode not enforced                โ”‚
  โ”‚     โœ— Vendor admits "still growing security posture"                 โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   IF APPROVED, MANDATORY REQUIREMENTS:                               โ”‚
  โ”‚     1. Privacy Mode enforcement for all users                        โ”‚
  โ”‚     2. Organization-wide .cursorignore policy                        โ”‚
  โ”‚     3. Version pinning to latest patched releases                    โ”‚
  โ”‚     4. Enable extension signature verification                       โ”‚
  โ”‚     5. Enable Workspace Trust                                        โ”‚
  โ”‚     6. Monthly CVE monitoring and patching                           โ”‚
  โ”‚     7. Restrict to non-sensitive codebases only                      โ”‚
  โ”‚                                                                      โ”‚
  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
  โ”‚                                                                      โ”‚
  โ”‚   CLAUDE CODE (Anthropic) โ€” Score: 38/45 (84%)                      โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   VERDICT:  APPROVED โ€” RECOMMENDED FOR API/ENTERPRISE USE            โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   Claude Code holds the strongest compliance portfolio of any AI     โ”‚
  โ”‚   coding tool assessed, making it uniquely suited for regulated      โ”‚
  โ”‚   industries:                                                        โ”‚
  โ”‚                                                                      โ”‚
  โ”‚     โ€ข SOC 2 + ISO 27001 + ISO 42001 + HIPAA + FedRAMP gov offerings  โ”‚
  โ”‚     โ€ข NIST 800-171 + CSA STAR โ€” most certifications overall          โ”‚
  โ”‚     โ€ข CLI-local execution โ€” code never leaves developer machine      โ”‚
  โ”‚     โ€ข Sandboxed bash with filesystem/network isolation               โ”‚
  โ”‚     โ€ข Command blocklist and injection detection                      โ”‚
  โ”‚     โ€ข No publicly disclosed critical CVEs                            โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   CONSIDERATIONS:                                                    โ”‚
  โ”‚     - No SSO/SCIM โ€” API key management required                      โ”‚
  โ”‚     - Limited centralized audit logging                              โ”‚
  โ”‚     - CLI-only interface may limit adoption                          โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   CONDITIONAL ON:                                                    โ”‚
  โ”‚     1. API/Enterprise plan usage (no training)                       โ”‚
  โ”‚     2. Centralized API key rotation policy                           โ”‚
  โ”‚     3. Organizational settings deployment                            โ”‚
  โ”‚                                                                      โ”‚
  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
  โ”‚                                                                      โ”‚
  โ”‚   OPENAI CODEX โ€” Score: 40/45 (89%)                                 โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   VERDICT:  APPROVED โ€” RECOMMENDED FOR ENTERPRISE CHATGPT USERS      โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   Codex provides a strong security posture backed by OpenAI's        โ”‚
  โ”‚   enterprise infrastructure:                                         โ”‚
  โ”‚                                                                      โ”‚
  โ”‚     โ€ข SOC 2 + ISO 27001/27017/27018/27701 + PCI DSS                 โ”‚
  โ”‚     โ€ข Cloud-sandboxed environments with 3 execution modes            โ”‚
  โ”‚     โ€ข Platform-native enforcement and network isolation              โ”‚
  โ”‚     โ€ข Enterprise SSO/SCIM via ChatGPT Enterprise                     โ”‚
  โ”‚     โ€ข Broad OpenAI enterprise controls; verify Codex residency scope  โ”‚
  โ”‚     โ€ข No publicly disclosed critical CVEs                            โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   CONSIDERATIONS:                                                    โ”‚
  โ”‚     - ZDR requires explicit approval process                         โ”‚
  โ”‚     - 30-day abuse monitoring retention by default                   โ”‚
  โ”‚     - Not all endpoints eligible for ZDR                             โ”‚
  โ”‚                                                                      โ”‚
  โ”‚   CONDITIONAL ON:                                                    โ”‚
  โ”‚     1. ChatGPT Enterprise plan activation                            โ”‚
  โ”‚     2. ZDR approval (if zero retention required)                     โ”‚
  โ”‚     3. Sandbox mode configuration per-project                        โ”‚
  โ”‚                                                                      โ”‚
  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜


================================================================================
  16. REFERENCE LINKS & SOURCE DOCUMENTATION
================================================================================

  AMPCODE / SOURCEGRAPH:

    Ampcode Security Reference
    https://ampcode.com/security

    Sourcegraph Security Page
    https://sourcegraph.com/security

    Sourcegraph Security Trust Portal (SOC 2, Pentest, ISO reports)
    https://security.sourcegraph.com/

    Amp Trust Center
    https://trust.ampcode.com/

    Privacy Policy
    https://sourcegraph.com/terms/privacy

    Subprocessors List
    https://sourcegraph.com/terms/subprocessors


  CURSOR / ANYSPHERE:

    Cursor Security Page
    https://cursor.com/security

    Cursor Trust Center
    https://trust.cursor.com/

    Cursor Privacy Policy
    https://cursor.com/privacy


  CLAUDE CODE / ANTHROPIC:

    Claude Code Security Documentation
    https://docs.anthropic.com/en/docs/claude-code/security

    Anthropic Trust Center
    https://trust.anthropic.com


  OPENAI CODEX:

    OpenAI Codex Product Page
    https://openai.com/codex/

    OpenAI Trust Center
    https://trust.openai.com/


  CVE REFERENCES (CURSOR):

    CVE-2025-54135 (prompt-injection RCE path)
    https://nvd.nist.gov/vuln/detail/CVE-2025-54135

    CVE-2026-26268 (Sandbox Escape RCE)
    https://nvd.nist.gov/vuln/detail/CVE-2026-26268

    CVE-2025-59944 (RCE)
    https://nvd.nist.gov/vuln/detail/CVE-2025-59944

    CVE-2025-54133 (RCE)
    https://nvd.nist.gov/vuln/detail/CVE-2025-54133


================================================================================
  17. DOCUMENT CONTROL
================================================================================

  Document Title:   AI Coding Tools โ€” Comparative Cybersecurity Assessment
  Version:          1.0
  Date:             June 22, 2026
  Classification:   Public โ€” Point-in-Time Assessment
  Author:           Information Security Assessment Team
  Distribution:     CISO, Security Review Committee, Engineering Leadership
  Review Cycle:     Quarterly (next review: September 2026)

  TOOLS ASSESSED:
    Ampcode v2026.Q1    (Sourcegraph, Inc.)
    Cursor v2026.Q1     (Anysphere, Inc.)
    Claude Code v2026   (Anthropic, PBC)
    OpenAI Codex v2026  (OpenAI, Inc.)

  METHODOLOGY:
    Assessment based on publicly available security documentation,
    vendor trust portals, CVE databases (NVD, MITRE), and published
    compliance certifications as of June 22, 2026.

  DISCLAIMER:

  This assessment is based on publicly available security documentation
  from each vendor as of June 22, 2026. It should be supplemented
  with:

    - Direct vendor engagement and security questionnaire responses
    - NDA-protected document review (SOC 2 Type II reports, penetration
      test reports, third-party audit findings)
    - Internal risk committee evaluation
    - Legal review of terms of service and data processing agreements
    - Hands-on security testing in sandbox/pilot environments

  The security landscape evolves continuously. This assessment represents
  a point-in-time evaluation and should be reviewed periodically. CVE
  databases should be monitored for new disclosures affecting any of
  the assessed tools.


================================================================================
                    END OF REPORT
================================================================================