Graphite · Trust Center
Graphite Com Trust Center
Trust center
Graphite maintains a public trust center documenting SOC 2 Type II compliance.
Code ReviewStacked PRsMerge QueueAI Code ReviewDeveloper ToolsGitHub
Trust center: https://trust.cursor.com
Certifications & Compliance
SOC 2 Type II
Source
Trust Center
generated: '2026-08-04'
method: searched
probe: true
probe_result: >-
probe-security-programs.py returned trust=none — trust.graphite.com does not
resolve, and /trust, /security and /compliance on graphite.com all return 404.
The trust center was found instead in Graphite's own documentation, which
points at the parent company's trust center.
url: https://trust.cursor.com
operated_by: Anysphere (Cursor) — Graphite's parent company since December 2025
own_domain_trust_center: false
certifications:
- SOC 2 Type II
compliance_claims:
- claim: SOC 2 Type II
detail: >-
Audited against the AICPA trust services criteria across security,
availability, processing integrity, confidentiality and privacy, evaluating
the operating effectiveness of controls over a period (typically six months
or more) rather than at a point in time.
report_request: via https://trust.cursor.com
source: https://graphite.com/docs/privacy-and-security
- claim: Continuous penetration testing
detail: '"We also continuously pen test."'
source: https://graphite.com/docs/privacy-and-security
enterprise:
github_enterprise_server: https://graphite.com/docs/github-enterprise-server
vendor_due_diligence: >-
Graphite positions the SOC 2 Type II report as the artifact that streamlines
enterprise vendor due diligence.
evidence:
- source: https://graphite.com/docs/privacy-and-security
keywords: [soc 2 type ii, aicpa, pen test, trust center, encryption, aes-256-cbc]
- source: https://trust.cursor.com
http_status: 200
note: >-
JavaScript application; an anonymous fetch returns only the title "Cursor
Trust Center". The named certifications above are taken from Graphite's own
documentation, not scraped from this page.
x-evidence:
fetched: '2026-08-04'
urls:
- {url: 'https://graphite-58cc94ce.mintlify.dev/docs/privacy-and-security.md', http_status: 200}
- {url: 'https://trust.cursor.com', http_status: 200}
- {url: 'https://trust.graphite.com/', http_status: null, note: DNS does not resolve}
- {url: 'https://graphite.com/trust', http_status: 404}
- {url: 'https://graphite.com/security', http_status: 404}
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/graphite-com-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.