Anysphere, Inc.

United States · owned by Independent (United States) · www.cursor.sh · 18 vendors

Anysphere, Inc. is a US-based applied research company that develops Cursor, an AI-powered code editor designed to make software developers extraordinarily productive. Cursor integrates large language models to provide features such as agentic code generation, intelligent autocomplete, codebase understanding, and code review directly within the development environment. The product is trusted by teams across the Fortune 500 and is used by engineers at companies including Stripe, NVIDIA, Figma, and Salesforce.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 18 sub-vendors.

Insights

Last updated 2026-07-06 · revision 7

18 direct vendors, 224 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Anysphere, Inc. exhibits very high migration readiness, largely driven by its highly modern, cloud-native, and containerized technology stack. The extensive use of AWS, AWS EKS (Elastic Kubernetes Service), Kubernetes, Docker, and Service Mesh signifies an architecture that is inherently modular, portable, and well-suited for migration to new environments or cloud providers. The implied microservices approach, facilitated by Kubernetes and Docker, allows for independent migration of components, further simplifying the process. Support for standardized identity management protocols like SAML/OIDC and integrations with Okta, Azure Active Directory, and Google Workspace streamline user provisioning and authentication during a migration. Key challenges for migration readiness include the lack of public financial data, making it difficult to assess the company's capacity to fund a potentially significant migration effort. The strict data residency requirement for data to be processed in the United States is a critical constraint that must be meticulously maintained in any new environment, potentially limiting global deployment options. Similar to resilience, the contradictory vendor data (Total Vendors: 0 vs. Vendor HQ Countries) makes it impossible to accurately assess vendor lock-in risks, which could influence migration complexity. However, the strong technical foundation significantly mitigates these potential challenges.

Compliance

6 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

No ISO 27001 certification has been found in Anysphere's public disclosures. The company has achieved SOC 2 Type II, which covers overlapping information security management requirements, but ISO 27001 is a separate international standard requiring formal certification by an accredited certification body. The risk is Low because: (1) The company has SOC 2 Type II which provides comparable assurance for US-market customers; (2) ISO 27001 is not legally mandated for US-based SaaS companies; (3) The company's enterprise customers (Fortune 500) may require ISO 27001 in the future, creating business pressure to certify. The absence of ISO 27001 is not a compliance violation but may be a competitive gap for EU/international enterprise sales.

Evidence: https://cursor.com/en-US/security, https://cursor.com/en-US/enterprise, https://trust.cursor.com

US State Privacy Laws — Partially Compliant

Multiple US states have enacted comprehensive privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, Oregon OCPA, etc.) with requirements similar to CCPA. Anysphere's Privacy Policy addresses data subject rights broadly ('Depending on where you live and the laws that apply in your country of residence') which suggests awareness of multi-state obligations. The company's explicit CCPA compliance and GDPR-aligned practices provide a strong foundation. Risk is Low because the company's privacy practices appear to meet the baseline requirements of most US state privacy laws, and the company is not in a high-risk sector for state privacy enforcement.

Evidence: https://cursor.com/en-US/privacy

SOC 2 (source) — Compliant

Anysphere has achieved SOC 2 Type II certification, which is the highest level of SOC 2 attestation, covering the operational effectiveness of security controls over a period of time (typically 6-12 months). This is explicitly confirmed on the company's homepage footer ('SOC 2 Certified'), security page, and enterprise page. The SOC 2 Type II report is available on request via trust.cursor.com. The company also commits to at-least-annual penetration testing. Risk is Low because the certification is current, publicly disclosed, and the company has established a Trust Center. The main residual risk is that the report is available 'on request' rather than publicly, which is standard practice but limits independent verification.

Evidence: https://cursor.com/en-US/security, https://cursor.com/en-US/enterprise, https://trust.cursor.com

Financials

Three-year financials

Financial Resilience Score: 7/10

Anysphere demonstrates exceptional top-line growth, going from approximately $1M ARR to roughly $1B ARR in about 24 months, one of the fastest SaaS trajectories ever recorded. The company is backed by a deep-pocketed investor base including Thrive Capital, Andreessen Horowitz, Benchmark, Accel, OpenAI Startup Fund, and Nvidia, having raised over $1 billion in cumulative equity through 2025. This provides substantial cash runway and financial cushion despite likely operating losses. Enterprise adoption is strong, with Cursor reportedly used inside more than half of the Fortune 500. However, resilience is materially constrained by structural gross-margin pressure: a large share of every revenue dollar flows through to foundation-model providers (Anthropic, OpenAI) for inference. The company had to restructure pricing in mid-2025 (causing user backlash) partly to defend margins. Operating income, net income, and cash burn are not disclosed, and no audited financials exist since the company is private. Competition is intense from GitHub Copilot (Microsoft), Windsurf/Cognition, Replit, Anthropic's Claude Code, Google's Gemini Code Assist, and Devin. Given Microsoft/GitHub owns the VS Code fork underlying Cursor, and frontier labs could disintermediate Cursor with their own IDE agents, resilience depends on continued differentiation and fundraising access.

Key strengths: Explosive ARR growth from ~$1M to ~$1B in ~24 months, Over $1B in cumulative equity raised from top-tier investors (Thrive, a16z, Benchmark, Accel, OpenAI Fund, Nvidia), Enterprise adoption across >50% of the Fortune 500, Strong product-led growth and viral bottom-up developer adoption, High talent density (ex-OpenAI, ex-Google researchers), Valuation trajectory from ~$400M (Aug 2024) to ~$18-20B (late 2025)

Risk factors: Gross-margin exposure to foundation-model providers (Anthropic, OpenAI) for inference costs, Intense competition from GitHub Copilot, Windsurf/Cognition, Replit, Claude Code, Gemini Code Assist, Devin, Platform risk: Microsoft/GitHub owns VS Code, which Cursor is forked from, Model commoditization / disintermediation risk if frontier labs release their own IDE agents, Customer concentration in cyclical tech-sector developer base, No audited financials, opaque burn and margin profile, Regulatory/IP risk from AI-generated code trained on copyrighted material, Pricing changes have already caused user backlash

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report