================================================================================
PUBLIC โ POINT-IN-TIME SECURITY ASSESSMENT
================================================================================
AI CODING TOOLS โ COMPARATIVE CYBERSECURITY ASSESSMENT REPORT
==============================================================
Ampcode vs Cursor vs Claude Code vs OpenAI Codex
Prepared for: Chief Information Security Officer
Assessment Date: June 22, 2026
Classification: Public โ Point-in-Time Assessment
Scope: Enterprise Readiness Comparison of AI Coding Agents
Vendors Assessed:
1. Ampcode โ Sourcegraph, Inc.
2. Cursor โ Anysphere, Inc.
3. Claude Code โ Anthropic, PBC
4. OpenAI Codex โ OpenAI, Inc.
================================================================================
TABLE OF CONTENTS
================================================================================
1. Executive Summary
2. Vendor Overview
3. Compliance & Certifications Comparison
4. Data Retention & Training Policies
5. Encryption Standards
6. Infrastructure & Data Residency
7. Authentication & Identity Management
8. Audit Logging Capabilities
9. Secret Protection & Sandboxing
10. Known Vulnerabilities & CVE History
11. Security Scoring Matrix
12. Risk Assessment by Vendor
13. Deployment Recommendations by Vendor
14. Pre-Deployment Checklist (Universal)
15. Verdicts & Final Recommendations
16. Reference Links & Source Documentation
17. Document Control
================================================================================
1. EXECUTIVE SUMMARY
================================================================================
This report provides a comparative cybersecurity assessment of four leading
AI coding tools to determine their suitability for enterprise adoption.
Each tool was evaluated against nine security dimensions using publicly
available documentation, trust portals, and CVE databases.
KEY FINDINGS:
* Ampcode (Sourcegraph) โ APPROVED. Strong compliance portfolio
(SOC 2 Type II + annual third-party pentesting), zero LLM data
retention on Enterprise plans with training permanently disabled,
automatic secret redaction engine, SSO/SCIM support. No publicly
disclosed critical CVEs. Score: 42/45.
* Cursor (Anysphere) โ CONDITIONAL. SOC 2 Type II only; vendor
admits being "still in the journey of growing our security posture."
Multiple Cursor CVEs disclosed, including prompt-injection and sandbox-escape RCE paths. No built-in
secret redaction engine. Enterprise controls include Privacy Mode enforcement, audit logs, model controls, SSO/SCIM, and CMEK. Score: 27/45.
* Claude Code (Anthropic) โ APPROVED. Broadest compliance portfolio
of all four tools (SOC 2 + ISO 27001 + ISO 42001 + HIPAA + CSA
STAR + NIST 800-171 + FedRAMP-qualified government/partner offerings). CLI-local architecture with
sandboxed bash, command blocklist, and permission-based execution.
No publicly disclosed critical CVEs. Score: 38/45.
* OpenAI Codex โ APPROVED. Strong compliance (SOC 2 + ISO 27001 +
ISO 27017/27018/27701 + PCI DSS). Cloud-sandboxed environments
with three execution modes and platform-native enforcement.
OpenAI Trust Center documents broad enterprise controls; verify Codex-specific data residency during procurement. Score: 40/45.
OVERALL RECOMMENDATION:
Ampcode and Codex are recommended as primary candidates for enterprise
deployment. Claude Code is recommended for API/Enterprise users who
value the strongest compliance credentials and local execution.
Cursor requires significant risk mitigation before enterprise adoption
due to its CVE history, limited certifications, and training data risks.
================================================================================
2. VENDOR OVERVIEW
================================================================================
VENDOR COMPANY HQ PRODUCT TYPE
--------------- ----------------- ------------ ----------------------------
Ampcode Sourcegraph, Inc. San Francisco Cloud-hosted AI coding agent
CA, USA (CLI + VS Code + Web)
Cursor Anysphere, Inc. San Francisco VS Code fork with AI
CA, USA integration
Claude Code Anthropic, PBC San Francisco CLI-based AI coding agent
CA, USA (direct API connection)
OpenAI Codex OpenAI, Inc. San Francisco Cloud-sandboxed AI coding
CA, USA agent (ChatGPT + API)
TRUST INDICATORS:
Ampcode / Sourcegraph:
- Enterprise customers include Reddit, Uber, Dropbox, Databricks
- Public Security Trust Portal with SOC 2 and ISO 27001 reports
- Active bug bounty program covering prompt injection
- Dedicated security team, annual third-party penetration testing
Cursor / Anysphere:
- Growing user base in developer community
- SOC 2 Trust Portal available
- Company acknowledges security posture is still maturing
- No public bug bounty program documented
Claude Code / Anthropic:
- Constitutional AI safety research pioneer
- Industry-leading compliance certifications
- Responsible Scaling Policy published
- HIPAA and FedRAMP High available for Claude government/partner-hosted offerings
OpenAI Codex / OpenAI:
- Largest AI company by market capitalization
- ChatGPT Enterprise serves Fortune 500 customers
- OpenAI enterprise controls; verify Codex-specific data residency options
- ISO 27701 and broad OpenAI Trust Center coverage; verify Codex-specific scope during procurement
================================================================================
3. COMPLIANCE & CERTIFICATIONS COMPARISON
================================================================================
The following table compares verified compliance certifications across
all four vendors. Certifications were verified via public trust portals
and security documentation.
CERTIFICATION AMPCODE CURSOR CLAUDE CODE CODEX
-------------------- ----------- ----------- ------------ -----------
SOC 2 Type II โ Certified โ Certified โ Certified โ Certified
ISO/IEC 27001 โ Certified โ None โ Certified โ Certified
ISO/IEC 27017 โ None โ None โ None โ Certified
ISO/IEC 27018 โ None โ None โ None โ Certified
ISO/IEC 27701 โ None โ None โ None โ Certified
ISO/IEC 42001 โ None โ None โ Certified โ None
GDPR โ Compliant ~ Partial โ Compliant โ Compliant
CCPA โ Compliant ~ Partial โ Compliant โ Compliant
EU AI Act โ Compliant โ None โ None โ None
HIPAA โ None โ None โ Certified โ None
FedRAMP High โ None โ None Gov/partner โ None
NIST 800-171 โ None โ None โ Certified โ None
CSA STAR โ None โ None โ Certified โ None
PCI DSS โ None โ None โ None โ Certified
TOTAL CERTIFICATIONS:
Ampcode: 5 (SOC2 Type II and annual pentesting)
Cursor: 1 (SOC2 only)
Claude Code: 6+ (SOC2, ISO27001, ISO42001, HIPAA, NIST, CSA; FedRAMP for government/partner-hosted offerings)
Codex: 6 (SOC2, ISO27001/17/18/701, PCI DSS)
ANALYSIS:
Claude Code (Anthropic) holds the broadest compliance portfolio of
any AI coding tool assessed. Its HIPAA, NIST, and CSA STAR support regulated environments; FedRAMP High applies to Claude for Government and partner-hosted government offerings, not every Claude Code deployment.
Cursor's single SOC 2 Type II certification is notably below the
enterprise baseline. The vendor's own documentation acknowledges
they are "still in the journey of growing our security posture."
COMPLIANCE SCORE (1-5):
Ampcode: 5 | Cursor: 2 | Claude Code: 5 | Codex: 4
================================================================================
4. DATA RETENTION & TRAINING POLICIES
================================================================================
AMPCODE (Sourcegraph):
----------------------
Enterprise Plan:
- Zero LLM input/output retention on Enterprise plans; provider cache up to 24h may apply
- LLM inputs/outputs are not retained beyond inference except documented provider caching/safety exceptions
- Model training on customer data is permanently disabled
- Training CANNOT be re-enabled on Enterprise plans
- Deleted thread data removed within 30 days
- Images subject to limited retention for compliance only
Risk: LOW โ Best-in-class data retention controls
CURSOR (Anysphere):
--------------------
Privacy Mode:
- Zero data retention โ code not stored on servers
- No training on user data when Privacy Mode is enabled
Privacy Mode Off:
- Data MAY be used for training purposes
- Already-trained models are NOT retrained after user deletion
- Data that has already been used for training persists in models
โ RISK: Models trained on user data before opt-out CANNOT be
untrained. This creates a permanent data exposure vector for
organizations that do not enforce Privacy Mode from day one.
Risk: MEDIUM โ Requires strict Privacy Mode and model-retention control enforcement
CLAUDE CODE (Anthropic):
-------------------------
Enterprise / API Usage:
- No training on customer data
- Direct API connection โ no intermediate server
Consumer Usage:
- May train on data unless user explicitly opts out
Risk: LOW โ Clear enterprise/consumer separation
OPENAI CODEX:
---------------
Default:
- 30-day abuse monitoring retention on API inputs
- Data retained for safety/abuse detection purposes
Zero Data Retention (ZDR):
- Available but requires explicit approval process
- Additional requirements must be met
- Not all API endpoints are eligible for ZDR
Risk: MEDIUM-LOW โ ZDR approval process adds friction
DATA RETENTION SCORE (1-5):
Ampcode: 5 | Cursor: 4 | Claude Code: 4 | Codex: 3
================================================================================
5. ENCRYPTION STANDARDS
================================================================================
VENDOR AT REST IN TRANSIT NOTES
-------------- ---------------- ---------------- -------------------------
Ampcode AES-256 TLS 1.2+ GCP-managed keys,
(GCP-managed) Cloudflare WAF
Cursor AES-256 TLS 1.2+ AWS/Azure managed
(cloud-managed) encryption
Claude Code AES-256 TLS 1.2+ Encrypted credential
(AWS-managed) storage for API keys
Codex AES-256 TLS 1.2+ Azure/OpenAI managed,
(Azure-managed) multiple region keys
ANALYSIS:
All four vendors meet the enterprise encryption baseline with AES-256
at rest and TLS 1.2+ in transit. No vendor offers customer-managed
encryption keys (CMEK/BYOK).
ENCRYPTION SCORE (1-5):
Ampcode: 5 | Cursor: 4 | Claude Code: 5 | Codex: 5
================================================================================
6. INFRASTRUCTURE & DATA RESIDENCY
================================================================================
AMPCODE:
Primary Cloud: Google Cloud Platform (GCP)
Regions: United States only
Sub-processors: US-based documented providers
China Exposure: None โ explicitly documented as no China providers
Data Sovereignty: US jurisdiction, SCCs for EEA/UK transfers
CURSOR:
Primary Cloud: AWS (primary), Azure, GCP
Additional: Fireworks (US/Europe/Japan), Baseten (US/Canada)
Regions: Multi-region (US, Europe, Japan, Canada)
China Exposure: No China-based infrastructure documented
Data Sovereignty: Multi-jurisdiction โ more complex compliance
CLAUDE CODE:
Primary Cloud: Local CLI execution (no intermediate server)
API Backend: Anthropic API (AWS infrastructure)
Regions: United States
China Exposure: None
Data Sovereignty: Code stays local; only API calls to US servers
OPENAI CODEX:
Primary Cloud: Azure / OpenAI infrastructure
Regions: 10+ countries: US, EU, UK, Australia, Canada,
Japan, India, Singapore, South Korea, UAE
China Exposure: None documented
Data Sovereignty: Verify Codex-specific residency scope with OpenAI
DATA FLOW COMPARISON:
AMPCODE:
โโโโโโโโโโโโโโโโ TLS 1.2+ โโโโโโโโโโโโโโโโ TLS 1.2+ โโโโโโโโโโโโโโโโ
โ Developer โ โโโโโโโโโ> โ Amp Server โ โโโโโโโโโ> โ LLM โ
โ Machine โ <โโโโโโโโโ โ (GCP / US) โ <โโโโโโโโโ โ Providers โ
โ โ โ โ โ (Zero โ
โ [Redaction] โ โ [AES-256] โ โ Retention) โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโ
CURSOR:
โโโโโโโโโโโโโโโโ TLS 1.2+ โโโโโโโโโโโโโโโโ TLS 1.2+ โโโโโโโโโโโโโโโโ
โ VS Code โ โโโโโโโโโ> โ Cursor Cloud โ โโโโโโโโโ> โ LLM โ
โ Extension โ <โโโโโโโโโ โ (AWS/Azure) โ <โโโโโโโโโ โ Providers โ
โ โ โ โ โ โ
โ [.cursorig] โ โ [AES-256] โ โ [Privacy โ
โ โ โ โ โ Mode dep.] โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโ
CLAUDE CODE:
โโโโโโโโโโโโโโโโ TLS 1.2+ โโโโโโโโโโโโโโโโ
โ Developer โ โโโโโโโโโ> โ Anthropic โ No intermediate server
โ Machine โ <โโโโโโโโโ โ API (AWS) โ Code runs locally
โ โ โ โ
โ [Sandboxed] โ โ [No Train โ
โ [Bash Tool] โ โ Entrprise] โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโ
OPENAI CODEX:
โโโโโโโโโโโโโโโโ TLS 1.2+ โโโโโโโโโโโโโโโโ Isolated โโโโโโโโโโโโโโโโ
โ ChatGPT / โ โโโโโโโโโ> โ Codex Cloud โ โโโโโโโโโ> โ Sandbox โ
โ API Client โ <โโโโโโโโโ โ (Azure) โ <โโโโโโโโโ โ Environment โ
โ โ โ โ โ โ
โ โ โ [AES-256] โ โ [3 Modes] โ
โ โ โ โ โ [Net Isol.] โ
โโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโ
================================================================================
7. AUTHENTICATION & IDENTITY MANAGEMENT
================================================================================
CAPABILITY AMPCODE CURSOR CLAUDE CODE CODEX
----------------- ----------- ----------- ------------ -----------
SSO Support โ Yes โ Yes โ No โ Yes
Okta/SAML/ API keys ChatGPT
OIDC (WorkOS) only Enterprise
SCIM Dir. Sync โ Yes โ No โ No โ Yes
MFA โ Via IdP โ Via IdP โ N/A โ Via IdP
Admin Portal โ Yes โ Yes โ Limited โ Yes
Exclusive SSO โ Yes โ Unknown โ N/A โ Yes
(disable password)
Domain Verify โ Yes โ Yes โ N/A โ Yes
ANALYSIS:
Ampcode and Codex provide the strongest identity management with full
SSO, SCIM Directory Sync, and exclusive SSO mode. This enables
automated provisioning/deprovisioning via corporate IdP.
Cursor now documents SSO and SCIM for Enterprise; validate plan availability and IdP integration during procurement.
Claude Code as a CLI tool uses API keys exclusively. While this
simplifies deployment, it lacks centralized identity controls and
makes access auditing more difficult.
SSO/SCIM SCORE (1-5):
Ampcode: 5 | Cursor: 3 | Claude Code: 2 | Codex: 5
================================================================================
8. AUDIT LOGGING CAPABILITIES
================================================================================
AMPCODE:
- Authentication audit logs available to workspace admins
- Application-level audit logs available on request
- Minimum 30-day log retention
- Does not currently offer SIEM streaming
CURSOR:
- Enterprise audit logs cover: authentication, user management,
settings changes, API key events, privacy mode changes
- JSON format export
- SIEM streaming supported: Splunk, Datadog
- CSV export available
- Does NOT log agent responses or generated code
- Most comprehensive logging of the four vendors
CLAUDE CODE:
- OpenTelemetry metrics integration
- Hooks system for monitoring and custom integrations
- Limited centralized logging โ CLI-local architecture
- No built-in SIEM streaming
OPENAI CODEX:
- Enterprise audit logs via ChatGPT Enterprise
- API usage logs available
- Standard enterprise logging capabilities
AUDIT LOGGING SCORE (1-5):
Ampcode: 4 | Cursor: 5 | Claude Code: 3 | Codex: 4
================================================================================
9. SECRET PROTECTION & SANDBOXING
================================================================================
A. SECRET PROTECTION COMPARISON:
AMPCODE โ STRONGEST SECRET PROTECTION:
- Automatic secret redaction engine built into the system
- Detects and replaces secrets before they leave the client
- Supported patterns: AWS, GCP, Azure, GitHub, GitLab, OpenAI,
Anthropic, Stripe, Slack, npm tokens, generic high-entropy strings
- Secrets replaced with [REDACTED:amp] marker
- Best-effort with documented limitations for non-standard secrets
- System-level โ requires no developer configuration
CURSOR โ WEAKEST SECRET PROTECTION:
โ CRITICAL: No built-in secret redaction engine
- Only protection: .cursorignore files (developer-configured)
- Path obfuscation for file paths
- Enterprise controls include Privacy Mode enforcement, model controls, audit logs, SSO/SCIM, and CMEK
- Secret exclusion still depends heavily on configuration and developer hygiene
- No automatic detection of credentials in code context
CLAUDE CODE โ STRONG SECRET PROTECTION:
- Encrypted credential storage for API keys
- Sandboxed bash tool with filesystem and network isolation
- Write-only access to working directory
- Command blocklist: curl, wget blocked by default
- Command injection detection
- Managed organizational settings via JSON configuration
OPENAI CODEX โ STRONG SECRET PROTECTION:
- Platform-native sandbox enforcement
- Sandboxed cloud environments with network isolation
- Three execution modes with varying permission levels
- Approval policies for sensitive operations
- Secrets managed at platform level
B. SANDBOXING COMPARISON:
VENDOR EXECUTION MODEL ISOLATION LEVEL NOTES
-------------- --------------------- ------------------ ------------------
Ampcode User approval for Moderate Bug bounty covers
destructive actions prompt injection
Cursor User approval Moderate CVEs demonstrate
(VS Code extension) sandbox bypasses
Claude Code Permission-based Strong Sandboxed bash,
sandboxed bash fs/net isolation,
write-only workdir
Codex 3 modes: read-only, Strong Platform-native
workspace-write, enforcement,
full-access net isolation
SECRET PROTECTION SCORE (1-5):
Ampcode: 5 | Cursor: 2 | Claude Code: 4 | Codex: 4
SANDBOXING SCORE (1-5):
Ampcode: 3 | Cursor: 3 | Claude Code: 5 | Codex: 5
================================================================================
10. KNOWN VULNERABILITIES & CVE HISTORY
================================================================================
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ โ
โ โ CRITICAL SECURITY DIFFERENTIATOR โ
โ โ
โ Cursor has multiple public CVEs among the assessed tools. โ
โ Several listed issues enable or contribute to command execution โ
โ / RCE paths; CVE-2025-54133 is CNA-rated medium. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
CURSOR โ PUBLIC CVEs REQUIRING PATCH VALIDATION:
CVE-2025-54135 โ prompt-injection RCE path; fixed in Cursor 1.3.9
-------------------------------------------------------
Type: Remote Code Execution via Prompt Injection
Vector: Prompt injection combined with dotfile creation
Impact: Attacker can execute arbitrary code on developer
machines via crafted prompts
Severity: CRITICAL โ highest possible practical severity
CVE-2026-26268 โ Sandbox Escape RCE; fixed in Cursor 2.5
-------------------------------------------------------
Type: Sandbox Escape leading to RCE
Vector: Escape from Cursor's sandbox environment
Impact: Full system access from sandboxed context
CVE-2025-59944 โ prompt-injection RCE path on case-insensitive filesystems; fixed in Cursor 1.7
-------------------------------------------------------
Type: RCE vulnerability
Impact: Arbitrary code execution on target systems
CVE-2025-54133 โ MCP deeplink command execution (CNA CVSS 5.3 Medium)
-------------------------------------------------------
Type: RCE vulnerability
Impact: Arbitrary code execution on target systems
AMPCODE (Sourcegraph):
- No publicly disclosed critical CVEs
- Active bug bounty program
- Annual third-party penetration testing
CLAUDE CODE (Anthropic):
- No publicly disclosed critical CVEs
- Responsible disclosure program
- Constitutional AI safety focus
OPENAI CODEX:
- No publicly disclosed critical CVEs for Codex product
- Established bug bounty program via Bugcrowd
VULNERABILITY HISTORY SCORE (1-5):
Ampcode: 5 | Cursor: 1 | Claude Code: 5 | Codex: 5
ANALYSIS:
Cursor's four critical RCE CVEs represent the single most significant
security differentiator in this assessment. CVE-2025-54135 and related Cursor advisories show prompt-injection-to-execution risk. NVD had not assigned its own CVSS score for several entries as of June 22, 2026. The combination of:
1. Critical RCE vulnerabilities
2. No built-in secret redaction
3. Extension signatures disabled by default
4. Workspace Trust disabled by default
Creates a compounding risk profile that requires extraordinary
mitigation measures for enterprise deployment.
================================================================================
11. SECURITY SCORING MATRIX
================================================================================
Scoring Scale: 1 (Critical Concern) to 5 (Best-in-Class)
CATEGORY AMPCODE CURSOR CLAUDE CODE CODEX
----------------------- -------- ------- ----------- ------
Compliance Breadth 5 2 5 4
Data Retention Control 5 4 4 3
Encryption Standards 5 4 5 5
SSO / SCIM 5 3 2 5
Audit Logging 4 5 3 4
Secret Protection 5 2 4 4
Sandboxing 3 3 5 5
Vulnerability History 5 1 5 5
Enterprise Maturity 5 3 5 5
----------------------- -------- ------- ----------- ------
TOTAL (out of 45) 42 27 38 40
RANKING:
1st โ Ampcode 42/45 (93%) โโโโโโโโโโโโโโโโโโโโ EXCELLENT
2nd โ OpenAI Codex 40/45 (89%) โโโโโโโโโโโโโโโโโโ EXCELLENT
3rd โ Claude Code 38/45 (84%) โโโโโโโโโโโโโโโโโ STRONG
4th โ Cursor 27/45 (60%) โโโโโโโโโโโโ CONCERNING
KEY OBSERVATIONS:
* Ampcode leads with the highest overall score, driven by its
combination of strong compliance, zero data retention, automatic
secret redaction, and clean vulnerability history.
* Codex scores second due to its broad compliance portfolio, strong
sandboxing, and data residency options. ZDR approval friction
is the primary deduction.
* Claude Code's lower score in SSO/SCIM and audit logging reflects
its CLI-local architecture, which trades centralized management
for stronger local isolation.
* Cursor's score is significantly below the enterprise baseline,
primarily due to its critical CVE history (1/5) and minimal
secret protection (2/5).
================================================================================
12. RISK ASSESSMENT BY VENDOR
================================================================================
AMPCODE โ OVERALL RISK: LOW
----------------------------
RISK AREA LEVEL JUSTIFICATION
---------------------------- ------- ------------------------------------
Data at Rest LOW AES-256, GCP-managed keys
Data in Transit LOW TLS 1.2+, Cloudflare WAF
LLM Data Leakage LOW Zero retention, training disabled
Authentication Bypass LOW SSO + SCIM + exclusive SSO mode
Secret Exposure MEDIUM Best-effort redaction has limits
Prompt Injection MEDIUM Inherent to LLM agents; bug bounty
Compliance Risk LOW SOC2 Type II + annual pentesting
Supply Chain LOW SBOMs, distroless images, CVE scans
CURSOR โ OVERALL RISK: HIGH
----------------------------
RISK AREA LEVEL JUSTIFICATION
---------------------------- ------- ------------------------------------
Data at Rest LOW AES-256, cloud-managed
Data in Transit LOW TLS 1.2+
LLM Data Leakage HIGH Training risk if Privacy Mode off
Authentication Bypass MEDIUM SSO/SCIM documented; validate exclusive enforcement
Secret Exposure HIGH No redaction engine, sigs disabled
Prompt Injection HIGH CVE-2025-54135 prompt-injection RCE path
Sandbox Escape HIGH CVE-2026-26268 sandbox escape path
Compliance Risk HIGH SOC2 only, vendor admits immaturity
Remote Code Execution HIGH Multiple CVEs with execution impact
CLAUDE CODE โ OVERALL RISK: LOW
---------------------------------
RISK AREA LEVEL JUSTIFICATION
---------------------------- ------- ------------------------------------
Data at Rest LOW AES-256, encrypted cred storage
Data in Transit LOW TLS 1.2+, direct API connection
LLM Data Leakage LOW Enterprise = no training
Authentication Bypass MEDIUM API keys only, no SSO
Secret Exposure LOW Command blocklist, sandboxed bash
Prompt Injection LOW Permission-based, injection detect
Compliance Risk LOW Broadest certification portfolio
Local Execution Risk LOW CLI-local, no intermediate server
OPENAI CODEX โ OVERALL RISK: LOW
----------------------------------
RISK AREA LEVEL JUSTIFICATION
---------------------------- ------- ------------------------------------
Data at Rest LOW AES-256, Azure-managed
Data in Transit LOW TLS 1.2+
LLM Data Leakage MEDIUM 30-day default, ZDR needs approval
Authentication Bypass LOW Enterprise SSO + SCIM
Secret Exposure LOW Platform-native sandbox
Prompt Injection LOW Sandboxed environments, net isol.
Compliance Risk LOW SOC2 + ISO27001 + PCI DSS
Data Residency MEDIUM Verify Codex-specific residency scope
================================================================================
13. DEPLOYMENT RECOMMENDATIONS BY VENDOR
================================================================================
AMPCODE โ RECOMMENDED DEPLOYMENT:
-----------------------------------
Plan Required: Enterprise (mandatory for zero retention)
SSO Configuration: Exclusive SSO mode via WorkOS (Okta/SAML/OIDC)
SCIM: Enable Directory Sync with corporate IdP
Network: Allowlist ampcode.com, auth.ampcode.com,
production.ampworkers.com, static.ampcode.com
Training: Developer security awareness program
Monitoring: Request audit logs, establish review cadence
Secret Policy: Educate on redaction limitations; use vaults
CURSOR โ CONDITIONAL DEPLOYMENT (if approved):
------------------------------------------------
Privacy Mode: MANDATORY โ enforce for all users from day one
.cursorignore: MANDATORY โ create and maintain org-wide policy
Version Pinning: MANDATORY โ pin to patched versions, monitor CVEs
SSO/SCIM: Configure SSO, SCIM, and domain verification
CMEK: Enable Customer Managed Encryption Keys where required
Model Controls: Restrict models with provider retention unless approved
Monitoring: Enable enterprise audit logs, SIEM streaming
CVE Monitoring: Subscribe to Cursor security advisories
Restrictions: Consider restricting to non-sensitive codebases
Review Cadence: Monthly security posture review
CLAUDE CODE โ RECOMMENDED DEPLOYMENT:
----------------------------------------
Plan Required: API / Enterprise (no training guarantee)
API Key Mgmt: Implement centralized API key rotation policy
Configuration: Deploy managed organizational settings via JSON
Monitoring: Configure OpenTelemetry metrics collection
Hooks: Set up monitoring hooks for security events
Developer Guide: Document approved/blocked commands
Access Control: API key-based access management
OPENAI CODEX โ RECOMMENDED DEPLOYMENT:
-----------------------------------------
Plan Required: ChatGPT Enterprise (SSO/SCIM, admin controls)
ZDR: Apply for Zero Data Retention if required
Sandbox Mode: Default to read-only; escalate per-project
Data Residency: Select appropriate region for compliance
SSO/SCIM: Configure via ChatGPT Enterprise admin
Approval Policies: Set up approval workflows for full-access mode
Network: Configure network isolation policies
================================================================================
14. PRE-DEPLOYMENT CHECKLIST (UNIVERSAL)
================================================================================
The following checklist applies to ANY AI coding tool deployment.
Vendor-specific items are marked with the vendor initial.
COMPLIANCE & LEGAL:
[ ] Request and review SOC 2 Type II report from vendor trust portal
[ ] Request latest penetration test report (under NDA if required)
[ ] Review vendor privacy policy with Legal/DPO team
[ ] Review data processing agreement (DPA) terms
[ ] Verify data residency meets regulatory requirements
[ ] Document vendor in third-party risk register
[ ] Review subprocessor list and subscribe to change notifications
IDENTITY & ACCESS:
[ ] Configure SSO as exclusive authentication method [A, Cu, Cx]
[ ] Set up SCIM Directory Sync [A, Cu, Cx]
[ ] Enforce MFA via identity provider
[ ] Disable password-based authentication where available
[ ] Configure domain verification [A, Cu, Cx]
[ ] Establish user provisioning/deprovisioning procedures
DATA PROTECTION:
[ ] Confirm zero data retention / privacy mode is active [A, Cu]
[ ] Verify model training is disabled [A, Cu, CC]
[ ] Apply for Zero Data Retention if required [Cx]
[ ] Establish data classification policy for AI tool usage
[ ] Define which repositories/codebases are approved for use
SECRET MANAGEMENT:
[ ] Deploy .cursorignore files if using Cursor [Cu]
[ ] Configure Cursor Enterprise SSO/SCIM and CMEK where required [Cu]
[ ] Restrict Cursor models with provider retention unless approved [Cu]
[ ] Establish secret rotation playbook for LLM-context exposure
[ ] Ensure developers use vault-based secret management
[ ] Document procedure for reporting suspected secret exposure
MONITORING & AUDIT:
[ ] Enable enterprise audit logs
[ ] Configure SIEM streaming if available [Cu]
[ ] Set up OpenTelemetry metrics collection [CC]
[ ] Establish audit log review cadence (quarterly minimum)
[ ] Request initial baseline audit log review
DEVELOPER TRAINING:
[ ] Develop AI agent security awareness training program
[ ] Cover prompt injection risks and mitigations
[ ] Cover secret handling procedures and vault usage
[ ] Cover code review requirements for AI-generated code
[ ] Cover command review procedures before execution
[ ] Document and distribute approved usage policies
RISK MANAGEMENT:
[ ] Document accepted risks in organizational risk register
[ ] Establish periodic vendor security review schedule
[ ] Define incident response procedures for AI tool scenarios
[ ] Set up CVE monitoring for chosen vendor(s)
[ ] Establish version update/patching policy
Legend: [A]=Ampcode [Cu]=Cursor [CC]=Claude Code [Cx]=Codex
================================================================================
15. VERDICTS & FINAL RECOMMENDATIONS
================================================================================
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ โ
โ AMPCODE (Sourcegraph) โ Score: 42/45 (93%) โ
โ โ
โ VERDICT: APPROVED โ RECOMMENDED FOR ENTERPRISE USE โ
โ โ
โ Ampcode demonstrates the strongest overall security posture for โ
โ enterprise AI coding tool deployment. Key strengths include: โ
โ โ
โ โข SOC 2 Type II + annual third-party pentesting โ
โ โข Zero data retention on ALL LLM providers (Enterprise) โ
โ โข Training permanently disabled, cannot be re-enabled โ
โ โข Automatic secret redaction engine (system-level) โ
โ โข SSO/SCIM with exclusive SSO mode โ
โ โข No publicly disclosed critical CVEs โ
โ โข US-based documented providers; no China providers documented โ
โ โ
โ CONDITIONAL ON: โ
โ 1. Enterprise plan activation โ
โ 2. SSO enforcement (exclusive mode) โ
โ 3. Developer security training completion โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ โ
โ CURSOR (Anysphere) โ Score: 27/45 (60%) โ
โ โ
โ VERDICT: CONDITIONAL โ SIGNIFICANT CONCERNS โ
โ โ
โ Cursor presents material security risks that require extraordinary โ
โ mitigation for enterprise deployment: โ
โ โ
โ โ Multiple CVEs including prompt-injection/sandbox escape paths โ
โ โ SOC 2 Type II only โ no ISO 27001 or other certs โ
โ โ No built-in secret redaction engine โ
โ โ Enterprise controls require plan/configuration validation โ
โ โ SCIM is Enterprise-documented; validate IdP behavior โ
โ โ Training data risk if Privacy Mode not enforced โ
โ โ Vendor admits "still growing security posture" โ
โ โ
โ IF APPROVED, MANDATORY REQUIREMENTS: โ
โ 1. Privacy Mode enforcement for all users โ
โ 2. Organization-wide .cursorignore policy โ
โ 3. Version pinning to latest patched releases โ
โ 4. Enable extension signature verification โ
โ 5. Enable Workspace Trust โ
โ 6. Monthly CVE monitoring and patching โ
โ 7. Restrict to non-sensitive codebases only โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ โ
โ CLAUDE CODE (Anthropic) โ Score: 38/45 (84%) โ
โ โ
โ VERDICT: APPROVED โ RECOMMENDED FOR API/ENTERPRISE USE โ
โ โ
โ Claude Code holds the strongest compliance portfolio of any AI โ
โ coding tool assessed, making it uniquely suited for regulated โ
โ industries: โ
โ โ
โ โข SOC 2 + ISO 27001 + ISO 42001 + HIPAA + FedRAMP gov offerings โ
โ โข NIST 800-171 + CSA STAR โ most certifications overall โ
โ โข CLI-local execution โ code never leaves developer machine โ
โ โข Sandboxed bash with filesystem/network isolation โ
โ โข Command blocklist and injection detection โ
โ โข No publicly disclosed critical CVEs โ
โ โ
โ CONSIDERATIONS: โ
โ - No SSO/SCIM โ API key management required โ
โ - Limited centralized audit logging โ
โ - CLI-only interface may limit adoption โ
โ โ
โ CONDITIONAL ON: โ
โ 1. API/Enterprise plan usage (no training) โ
โ 2. Centralized API key rotation policy โ
โ 3. Organizational settings deployment โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ โ
โ OPENAI CODEX โ Score: 40/45 (89%) โ
โ โ
โ VERDICT: APPROVED โ RECOMMENDED FOR ENTERPRISE CHATGPT USERS โ
โ โ
โ Codex provides a strong security posture backed by OpenAI's โ
โ enterprise infrastructure: โ
โ โ
โ โข SOC 2 + ISO 27001/27017/27018/27701 + PCI DSS โ
โ โข Cloud-sandboxed environments with 3 execution modes โ
โ โข Platform-native enforcement and network isolation โ
โ โข Enterprise SSO/SCIM via ChatGPT Enterprise โ
โ โข Broad OpenAI enterprise controls; verify Codex residency scope โ
โ โข No publicly disclosed critical CVEs โ
โ โ
โ CONSIDERATIONS: โ
โ - ZDR requires explicit approval process โ
โ - 30-day abuse monitoring retention by default โ
โ - Not all endpoints eligible for ZDR โ
โ โ
โ CONDITIONAL ON: โ
โ 1. ChatGPT Enterprise plan activation โ
โ 2. ZDR approval (if zero retention required) โ
โ 3. Sandbox mode configuration per-project โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
================================================================================
16. REFERENCE LINKS & SOURCE DOCUMENTATION
================================================================================
AMPCODE / SOURCEGRAPH:
Ampcode Security Reference
https://ampcode.com/security
Sourcegraph Security Page
https://sourcegraph.com/security
Sourcegraph Security Trust Portal (SOC 2, Pentest, ISO reports)
https://security.sourcegraph.com/
Amp Trust Center
https://trust.ampcode.com/
Privacy Policy
https://sourcegraph.com/terms/privacy
Subprocessors List
https://sourcegraph.com/terms/subprocessors
CURSOR / ANYSPHERE:
Cursor Security Page
https://cursor.com/security
Cursor Trust Center
https://trust.cursor.com/
Cursor Privacy Policy
https://cursor.com/privacy
CLAUDE CODE / ANTHROPIC:
Claude Code Security Documentation
https://docs.anthropic.com/en/docs/claude-code/security
Anthropic Trust Center
https://trust.anthropic.com
OPENAI CODEX:
OpenAI Codex Product Page
https://openai.com/codex/
OpenAI Trust Center
https://trust.openai.com/
CVE REFERENCES (CURSOR):
CVE-2025-54135 (prompt-injection RCE path)
https://nvd.nist.gov/vuln/detail/CVE-2025-54135
CVE-2026-26268 (Sandbox Escape RCE)
https://nvd.nist.gov/vuln/detail/CVE-2026-26268
CVE-2025-59944 (RCE)
https://nvd.nist.gov/vuln/detail/CVE-2025-59944
CVE-2025-54133 (RCE)
https://nvd.nist.gov/vuln/detail/CVE-2025-54133
================================================================================
17. DOCUMENT CONTROL
================================================================================
Document Title: AI Coding Tools โ Comparative Cybersecurity Assessment
Version: 1.0
Date: June 22, 2026
Classification: Public โ Point-in-Time Assessment
Author: Information Security Assessment Team
Distribution: CISO, Security Review Committee, Engineering Leadership
Review Cycle: Quarterly (next review: September 2026)
TOOLS ASSESSED:
Ampcode v2026.Q1 (Sourcegraph, Inc.)
Cursor v2026.Q1 (Anysphere, Inc.)
Claude Code v2026 (Anthropic, PBC)
OpenAI Codex v2026 (OpenAI, Inc.)
METHODOLOGY:
Assessment based on publicly available security documentation,
vendor trust portals, CVE databases (NVD, MITRE), and published
compliance certifications as of June 22, 2026.
DISCLAIMER:
This assessment is based on publicly available security documentation
from each vendor as of June 22, 2026. It should be supplemented
with:
- Direct vendor engagement and security questionnaire responses
- NDA-protected document review (SOC 2 Type II reports, penetration
test reports, third-party audit findings)
- Internal risk committee evaluation
- Legal review of terms of service and data processing agreements
- Hands-on security testing in sandbox/pilot environments
The security landscape evolves continuously. This assessment represents
a point-in-time evaluation and should be reviewed periodically. CVE
databases should be monitored for new disclosures affecting any of
the assessed tools.
================================================================================
END OF REPORT
================================================================================