Background
Cursor is the AI-native code editor transforming how developers write, debug, and understand code. Launched in 2023, Cursor rapidly gained popularity, attracting over 1 million registered developers globally, with more than 360,000 subscribing to paid plans entirely through word-of-mouth growth. Today, Cursor is used by development teams at over 14,000 innovative companies, including OpenAI, Shopify, Notion, and Uber, dramatically improving productivity and developer experience.
To best support its rapidly growing developer community, Cursor ensures that they keep users safe thanks to automated penetration testing provided by RunSybil.
"Sybil has been great. Super helpful. Quick. Only positive things."
— Michael Truell, Cursor CEO
The Challenge
As Cursor expanded into development teams at top innovators, they needed a thorough security assessment to reassure teams that they take user security seriously. Their goals were to validate the security of their APIs, application, and cloud environment; get a pentest report ready for sharing with prospective customers; and move quickly to avoid blocking the sales process.
"We like to feel confident that each new feature we're releasing is not going to be a security hazard."
— Arvid Lunnemark, Cursor co-founder
Commodity penetration tests are fast but essentially vulnerability scans, while high-end penetration tests take too long to schedule — Sybil was a great fit because it is both faster and provides deeper coverage.
The Solution
Working with Sybil was a game changer. Cursor was able to get a pentest within two weeks from start to finish, allowing them to quickly meet sales requirements for customers that were previously out of reach. Cursor also utilized the retest features on the platform, managing their own testing without needing to talk to a human again, reducing developer friction and letting the team stay focused on shipping.
Result
With Sybil, Cursor integrated on-demand, deep security testing into their development process without slowing down engineering velocity or adding management overhead, allowing the team to meet enterprise-level security expectations while continuing to ship quickly and confidently.
"Some of the findings motivated us to build middleware. It was a meaningful improvement." — Henry Wildermuth, Cursor software engineer
Sybil's penetration testing delivered actionable insights, not just a list of bugs, surfacing vulnerabilities while also validating the secure systems already in place across Cursor's application code, running environments, and cloud deployment.
Key benefits Cursor experienced:
Fast turnaround: End-to-end penetration testing completed within two weeks of first contact, helping unblock high-value deals.
Self-serve retesting: Engineers can trigger retests at any time with no coordination required, ensuring quick verification of fixes without interrupting development.
Enterprise-ready compliance: Every Sybil pentest report is guaranteed to pass SOC 2 review, making them immediately usable in security questionnaires and procurement processes.
Code and infrastructure coverage: Testing included application code, running environments, and cloud infrastructure, giving Cursor full confidence in their production security.
Real-world impact: Sybil delivered dynamic PoCs and thoughtful analysis that informed internal security investments, helping build better systems rather than just checking boxes.
What's Next
Speed is critical for security, allowing organizations to stay ahead of risk, audits, and hackers. With Sybil, Cursor is able to continue shipping a beloved world-class tool while keeping users secure, and looking forward, the team is excited to maintain optimal speed of deployment and experimentation without compromise.
Sybil is building towards being a trusted, automated extension of every security team, a security engineer, pentester, and software engineer that works without needing constant attention or coordination, freeing humans to focus on building world-class products used by millions.
