Enterprise
Cursor Cyber Safeguards & Anthropic CVP for Security Teams
Anthropic's latest Opus models include cyber safeguards that can block legitimate defensive security prompts. Enterprise admins can apply to Anthropic's Cyber Verification Program (CVP) through Cursor, scoped to an Organization Group, then enable Cyber mode for Opus 4.7 and 4.8 for that group only. CVP requests run with Privacy Mode and zero data retention off for those models only; the agreement is between your org and Anthropic, not Cursor.
On this page
Why do security teams hit blocks in Cursor?
Blocks on sensitive but legitimate security tasks (pentest planning, malware analysis write-ups, defensive tooling) come from Anthropic's API safeguards, not Cursor policy. Cursor surfaces CVP application and model toggles in the dashboard, but Anthropic sets program terms, approval and data handling for cyber-verified models.
That distinction decides who you escalate to. A declined response on a malware write-up is Anthropic's API refusing, so a support ticket to Cursor will not move it. What Cursor provides is the application workflow and the model toggles, while the decision, the terms and the review all sit with Anthropic.
Before assuming a block is a safeguard, check whether the same prompt fails on a model from another provider. Anthropic applies these safeguards to its latest Opus generations, so a request that works elsewhere and fails on Opus is the pattern you are looking for. One that fails everywhere is usually the prompt.
Which also sets expectations on timing. This is an application reviewed by a third party rather than a setting you flip, so if your security team is blocked today, the timeline is Anthropic's: the docs say approval is not instant, and Cursor rechecks status about every two hours. Plan the near-term work around models you can already use.
This is covered hands-on in Teams and Enterprise Admin — 6 short modules, free to read.
Where are cyber safeguards configured?
Cyber Safeguards apply at Organization Group level (Organization → Groups), not billing groups or SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. directory groups. Only members of the approved group get cyber-verified model access; the rest of the org keeps normal Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. behavior.
Group type is the thing people get wrong, and the symptom is specific. You open a group's settings, find Spend Limit Overrides and Auto-RunThe Cursor Settings > Agents setting that decides which commands the agent runs automatically and which wait for your approval, via allow and block lists. Press Enter for the full definition. Controls, and no Cyber Safeguards section anywhere. That means you are in team directory groups or billing groups instead of Organization Groups, which are reached from your profile menu in the bottom-left corner. A group synced from Okta through SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. does not change the answer, because directory groups are a separate concept used for team-level spend and policy. Links in the program email can also drop you on the org Overview page, which is not where these settings live.
Scoping to a group is not a formality. The Cyber toggle grants access to that group's members and to nobody else, so the right size is the smallest group that covers the people doing defensive work. Everyone outside it keeps normal Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. behaviour, which is the argument for keeping the group small rather than convenient.
When Cyber is enabled for a model, Anthropic's CVP terms apply and zero data retention is off for those requests. Other models in the same chat and all other account activity still follow your standard Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. settings.
How does an admin apply for CVP?
Applying is a group-scoped request, not an org-wide switch. You stand up a dedicated group, accept Anthropic's terms as an authorized representative, then wait for approval before the Cyber toggle does anything. The steps below are the full path.
- 1Open Organization → Groups and create or select a dedicated group (for example
SecurityorCVP). - 2Add only the members who need cyber-verified model access.
- 3In Cyber Safeguards Models Settings, click Apply and accept Anthropic's terms as an authorized representative.
- 4Wait for Anthropic approval; Cursor rechecks status about every two hours and shows Approved when cleared.
- 5Enable the Cyber toggle for Opus 4.7 or 4.8 on that group.
The Apply step is worth reading properly before anyone clicks it. It opens Anthropic's terms, and confirming them means confirming you are an authorized representative of your company, which is a real statement rather than a checkbox to tick on a manager's behalf. The agreement that results is between your organization and Anthropic: Cursor is not a party to it, sets none of the terms and carries none of the obligations. Only Organization admins can submit it, since the group has to exist first, so this lands with whoever owns your org structure.
The waiting step is the one that generates support tickets. Anthropic reviews the application and contacts you directly, and Cursor rechecks status about every two hours, flipping the group to Approved on its own. Nothing needs resubmitting in the meantime, and the Cyber option belongs to the post-approval step, so there is nothing to gain from turning it on early.
Put the privacy consequence in the change request rather than the rollout note. The exception is narrow, covering one model for one group, and narrow exceptions are still the kind a reviewer would rather approve in advance than read about afterwards. Name the group and the model in the request, and record who signed it.
Which models support Cyber mode today?
Cursor documents Cyber mode for Opus 4.7 and Opus 4.8 only. Pricing matches the base model rates in the models and pricing doc. If approval is pending, check back after Anthropic completes review; instant approval is not guaranteed.
Mythos is the model people ask about, and it is explicitly not in the program. Two Opus versions, and that is the list. If your security group's usual model is something else again, CVP approval changes nothing for that workflow: they have to move onto an eligible Opus version for the work that needs the safeguards relaxed, which is a change of habit as much as a change of permissions.
Pricing at the base model rate takes one question out of the business case and leaves the harder one. Somebody has to own the decision that a named set of people works under different retention terms from everyone else, which is far easier to get signed while that set is five people.
Frequently asked questions
Does enabling Cyber disable Privacy Mode for everyone?
No. It affects only cyber-verified Opus requests from members of the approved Organization Group. Organization-wide Privacy Mode stays intact for everyone else and for other models.
Who can submit the CVP application?
Organization admins, because they must create or manage the target Organization Group first.
Is Cursor party to the CVP agreement?
No. Anthropic sets terms and obligations. Cursor provides the application workflow and model controls in the dashboard.
Sources & last verified
Cursor ships frequently. Last updated July 28, 2026.
Keep reading
Rather do it than read about it? Run 11 interactive Cursor walkthroughs in a simulated editor. Free, no account needed.