Enterprise
Cursor Data Residency: Regions, US-Only Mode, EU Gaps
Cursor offers one formal data-residency control: an enterprise opt-in program that keeps inference, processing and storage for supported features US-only. Non-enterprise plans get no residency guarantee. Region behaviour otherwise follows each model provider's footprint. Launch-phase exceptions exist, like Grok 4.5 being unavailable in the EU.

On this page
What data residency does Cursor actually guarantee?
Cursor publishes one residency program and it is enterprise-only. Enterprise customers can opt in to US-only data residency, which Cursor describes as keeping "inference, processing, and storage for supported features" in the United States. Enrollment is required, so no tenant gets it by default, and no other region is offered as a residency program today.
- Enterprise, enrolled
- US-only inference, processing and storage for supported features. Model pricing carries a 10% uplift for eligible models; supported models, functions and exclusions live in Cursor's privacy and data-governance docs.
- Enterprise, not enrolled
- Same as everyone else, with no published residency guarantee.
- Pro / Teams plans
- No documented data-residency controls beyond choosing which models you allow.
- EU / UK / AU residency
- Not offered today. Cursor describes EU and APAC residency as in active development, with no published date.
Per cursor.com/help/security-and-privacy/regions (checked 2026-07-16) and cursor.com/docs/models-and-pricing.
The phrase "supported features" is the part I would read twice. Residency applies to supported features and, in the pricing docs, to eligible models. Neither list sits on the regions page. Cursor's pricing page sends you to its privacy and data-governance documentation for supported regions, models and functions, so get that page during procurement and keep a dated copy in the security review file.
Residency also costs money. Cursor's models and pricing page puts opting in to regional data residency at a 10% uplift on model pricing for eligible models, so the charge scales with usage rather than arriving as a flat platform fee. A cost model that treats it as a fixed add-on will read low for heavy agent users.
Get that number into the budget while the residency requirement is still being drafted, since the two usually get priced by different people weeks apart.
Cursor does not publish an EU-residency option today, and describes EU and APAC residency as in active development with no date attached. Four levers remain: DPAData Processing Agreement. The contract spelling out exactly how a vendor may process your data: purposes, subprocessors, retention and breach duties. The document privacy reviews actually read. Press Enter for the full definition. terms, self-hosted cloud-agent runtimes that keep tool execution on your infrastructure, Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. and Zero Data Retention to shrink what is stored at all, and a model allowlist limited to providers whose own EU documentation you have checked. None of them pins model inference to an EU region.
This exact topic is a hands-on Lesson: Privacy and data governance — about 6 minutes, free to read.
Rather do it than read about it? Run 11 interactive Cursor walkthroughs in a simulated editor. Free, no account needed.
Where do the models themselves run?
Cursor routes requests to multiple model providers, and each provider has its own regional footprint. Cursor's regions page defers to provider documentation rather than promising anything on their behalf. Anthropic, OpenAI and Google each publish their own supported-regions lists.
- Provider
- Anthropic (Claude)
- Region authority
- Anthropic's supported-regions documentation
- What that means for you
- Region behaviour follows Anthropic's infrastructure, not Cursor's
- Provider
- OpenAI (GPT)
- Region authority
- OpenAI's supported countries and territories list
- What that means for you
- Same pattern: check the provider list, not Cursor's docs
- Provider
- Google (Gemini)
- Region authority
- Google's availability documentation
- What that means for you
- Same pattern
- Provider
- Cursor ComposerCursor's own fast coding model, tuned for the editor and priced well below frontier models; the recommended day-to-day model for executing a plan. Press Enter for the full definition.
- Region authority
- Cursor's infrastructure and model documentation
- What that means for you
- Cursor is the model and region authority for ComposerCursor's own fast coding model, tuned for the editor and priced well below frontier models; the recommended day-to-day model for executing a plan. Press Enter for the full definition.
- Provider
- Grok (Cursor with SpaceXAI)
- Region authority
- Cursor's model and availability docs plus applicable partner terms
- What that means for you
- Grok sits in Cursor ModelsCursor's plan and usage pool for models it labels as Cursor Models, kept separate from the third-party Other Models pool. Press Enter for the full definition. for billing, but the pool label does not mean Cursor developed it alone
| Provider | Region authority | What that means for you |
|---|---|---|
| Anthropic (Claude) | Anthropic's supported-regions documentation | Region behaviour follows Anthropic's infrastructure, not Cursor's |
| OpenAI (GPT) | OpenAI's supported countries and territories list | Same pattern: check the provider list, not Cursor's docs |
| Google (Gemini) | Google's availability documentation | Same pattern |
| Cursor ComposerCursor's own fast coding model, tuned for the editor and priced well below frontier models; the recommended day-to-day model for executing a plan. Press Enter for the full definition. | Cursor's infrastructure and model documentation | Cursor is the model and region authority for ComposerCursor's own fast coding model, tuned for the editor and priced well below frontier models; the recommended day-to-day model for executing a plan. Press Enter for the full definition. |
| Grok (Cursor with SpaceXAI) | Cursor's model and availability docs plus applicable partner terms | Grok sits in Cursor ModelsCursor's plan and usage pool for models it labels as Cursor Models, kept separate from the third-party Other Models pool. Press Enter for the full definition. for billing, but the pool label does not mean Cursor developed it alone |
Compliance reviews should cite the provider's own region documentation for third-party models.
The deferral reads like a dodge at first and holds up under scrutiny. Cursor is not the region authority for a Claude or Gemini request, and a commitment made on Anthropic's behalf would not survive an audit. What it costs you is paperwork: your compliance file needs each provider's own region documentation, cited and dated, for every third-party model you allow.
The concrete example that surprises teams: Grok 4.5, developed by Cursor with SpaceXAI and included in Cursor ModelsCursor's plan and usage pool for models it labels as Cursor Models, kept separate from the third-party Other Models pool. Press Enter for the full definition. for billing, launched unavailable in the EU. Cursor states it was "available in every country where Cursor normally offers models, except the EU at launch," with EU availability planned. Pool membership is not an ownership claim. If your rollout standardises on a model, check its current geographic availability before writing the policy.
Firewall reviews turn up a detail that invites the wrong conclusion. The granular allowlist in Cursor's network documentation includes us-only.gcpp.cursor.sh, us-eu.gcpp.cursor.sh and us-asia.gcpp.cursor.sh, described there as Cursor TabCursor's original autocomplete: multi-line, edit-aware suggestions you accept with the Tab key. Press Enter for the full definition. endpoints used depending on your location. I would keep those hostnames out of the residency section of a security review. There is an APAC hostname on that list and no APAC residency program, which is the sharpest evidence that these describe where a Tab request gets served rather than anything Cursor has committed to. Ask Cursor what they imply if your auditor pushes on it.
Can we get EU residency by bringing our own API key?
Partly, and only on the provider side. A BYO key routes the model call through your own provider account, so the region question for that call becomes a term in your contract with the provider.
Cursor supports bringing your own API key for OpenAI, Anthropic, Google, Azure OpenAI and AWS Bedrock. One of the documented reasons to use it is a team needing particular rate limits or a residency guarantee from the provider itself. Nothing published says a BYO key relocates Cursor's own processing or storage.
That move carries the retention guarantee with it, which is the part that catches people out. Cursor's Zero Data Retention policy does not apply to requests made with your own keys, and retention then follows whatever you have agreed with the provider. Billing does not get simpler either. Cursor's pricing page puts the Token Rate at $0.25 per million tokens on third-party model requests for Teams and Enterprise plans, and names BYOK usage alongside included and on-demand usage, so your own key moves the model charge without moving that fee.
Cursor's own hardening guidance points the other way and says to restrict personal API keys. Both positions hold, because an org-held key under a negotiated provider contract is a different object from one an engineer pastes into settings. Reading the docs the first time, BYOK looked to me like the EU workaround. It is narrower than that, closer to a way to move one contract, so reach for it only when your provider agreement is already the document your auditor reads.
What can admins actually control?
Residency is one lever among several; most regulated-industry deployments combine four. Only the first is a residency control in the strict sense.
- 1Enroll in US-only residency (enterprise): the formal program covering inference, processing and storage for supported features. Confirm the supported-model list and exclusions during procurement, not after.
- 2Constrain the model list: admins can allowlist models team-wide, which indirectly pins your traffic to providers whose regions you have vetted. Grok 4.5 shows the pattern: on team plans an admin switches it on in team settings before anyone sees it in the picker.
- 3Reduce what is retained: Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. and Zero Data Retention govern storage duration rather than location, often what the auditor actually cares about.
- 4Move execution on-prem where offered: self-hosted cloud-agent runtimes keep tool execution and code checkouts on infrastructure you control, while Cursor's cloud still orchestrates.
The order matters because only the first step touches your contract, while the other three are settings you can revise on a Tuesday. Teams that run it backwards tend to start with self-hosted runtimes, the engineering-shaped task of the four, and end up spending the most effort for the least residency, because execution moves onto hardware you own while inference still leaves it. Locking the model allowlist before you have the eligible-model list is the cheaper version of the same mistake, and you unpick the allowlist afterwards.
Below Enterprise the first step is not available at all, so a smaller team's honest answer to a customer questionnaire is about retention and model choice rather than location. That means Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. locked on where you have an admin dashboard, and an allowlist of providers whose own region documentation someone has read rather than filed. What those two settings promise, and what they pointedly do not, is set out in Cursor security and Privacy Mode.
At Enterprise scale the work moves almost entirely into procurement. Put the review hour into the exclusion list and the DPAData Processing Agreement. The contract spelling out exactly how a vendor may process your data: purposes, subprocessors, retention and breach duties. The document privacy reviews actually read. Press Enter for the full definition. wording rather than the dashboard.
If a request that was supposed to stay in the US looks like it did not, establish which model served it before anything else. Auto routing picks per request and will switch models on degraded performance or provider downtime, so the model in the picker is not necessarily the model that ran. Then check whether a BYO key signed it. Whether either of those actually affects residency is a question for Cursor, and the answer belongs in writing before anyone repeats it to an auditor.
Which features are excluded from US-only residency today? Which models are eligible under it, and what happens when someone selects one that is not? Does the 10% residency uplift apply to every model we allow? Is residency contractually committed in the DPAData Processing Agreement. The contract spelling out exactly how a vendor may process your data: purposes, subprocessors, retention and breach duties. The document privacy reviews actually read. Press Enter for the full definition. or described as best-effort? Each answer belongs in the security review file, dated.
Frequently asked questions
Does Cursor offer EU data residency?
No. The only published residency program is US-only, for enterprise customers who enroll. EU-based teams can constrain models, use Privacy Mode and Zero Data Retention, and self-host agent execution, but cannot pin Cursor's inference or storage to the EU today.
Is US data residency on by default for enterprise plans?
No. It is an opt-in program requiring enrollment. Unenrolled enterprise tenants get the same regional behaviour as other plans. Supported models, exclusions, pricing and how to enable it are documented in Cursor's privacy and data-governance pages.
Does US data residency cost extra?
Yes. Cursor's models and pricing page states that opting in to regional data residency adds a 10% uplift on model pricing for eligible models, and points to the privacy and data-governance docs for supported regions, models and functions. Because the uplift lands on model pricing, it scales with how much your team runs rather than with seat count.
Where is my code processed on a normal Pro or Teams plan?
Cursor does not publish per-plan processing locations for non-enterprise tiers. Requests route according to the selected model and provider, so the practical answer follows each provider's regional documentation, including Anthropic, OpenAI and Google, plus Cursor's own documentation for Composer, Grok work developed with SpaceXAI and its product infrastructure.
Why can't EU users access Grok 4.5?
Cursor launched Grok 4.5 in every country it normally supported except the EU, with EU availability planned at the time. Cursor describes the model as developed with SpaceXAI and includes it in the Cursor Models billing pool; neither fact means Cursor developed it alone. Check current availability before standardising a European team on it.
Does data residency cover Cloud Agents too?
The US-only program covers 'supported features'. Confirm during procurement whether cloud-agent execution is on that list for your contract. Teams needing execution locality regardless can use self-hosted runtimes, which keep tool calls and checkouts on infrastructure they operate.
Sources & last verified
- Cursor Help - Regions and data residency
- Cursor Help - Grok 4.5
- Cursor Docs - Cloud agent security and network
- Cursor Docs - Models and pricing
- Cursor Docs - Network configuration
- Cursor Docs - Security hardening
- Cursor Docs - Model and integration management
Cursor ships frequently. Last updated August 14, 2026.