Cursor Alternatives That Survive Security Review Start With Copilot

Cursor cannot be self-hosted and every request is built on its servers. Standardise on Copilot Business, run Claude Code through your own cloud account, and reserve Tabnine or Cline for air-gapped shops.

By Rajesh Beri·September 30, 2026·13 min read
Share:
A laptop on a security reviewer's desk showing a code editor, beside a printed network diagram with a single cable drawn in red pen leading off the page, and a rubber approval stamp resting on the paper. No readable text

Illustration generated using AI

The Cursor alternative that survives a security review is GitHub Copilot Business as the default, plus Claude Code routed through your own cloud account for agentic work. Cursor cannot be self-hosted, and every request, even one using your own API key, is assembled on Cursor's servers. Copilot's IDE path retains nothing; Claude Code on Amazon Bedrock or Google Cloud keeps inference inside a tenant you already audit. Only a genuinely air-gapped shop should pay for Tabnine or Cline. Skip Devin Desktop, the product formerly called Windsurf.

All prices below were read from each vendor's live pricing page on 30 September 2026. The reference workload is 200 engineers, of whom 30 do heavy agentic work.

Option Where your code goes Retention / training Self-host or your-cloud SSO / audit log List price (30 Sep 2026)
GitHub Copilot Business GitHub-operated service IDE prompts not retained; 28 days elsewhere; no training No SSO via GitHub; audit log of settings, not prompts $19 / user / month
Claude Code via Bedrock or Vertex Your AWS or GCP account 30-day standard, ZDR on Enterprise by approval; no training on commercial terms Inference in your cloud tenant; self-hosted gateway IAM + CloudTrail / Cloud Audit Logs Pay-as-you-go via the cloud bill; Enterprise seat $20 + API usage
Tabnine (Tricentis) Your VPC, on-prem or air-gapped Never retained, never trained Yes, fully Enterprise admin Not published — pricing page redirects to Tricentis sales
Cline Whatever inference you point it at Set by your provider Yes — VPC, on-prem, air-gapped SSO on Enterprise Open source free + inference; Enterprise contact sales
Gemini Code Assist Google Cloud Per Google Cloud terms VPC Service Controls perimeter Cloud audit logging Not re-verified today (see below)
Devin Desktop (ex-Windsurf) Cognition's cloud, hybrid, or single-tenant Not stated on pricing page Self-hosted in maintenance mode since May 2025 SSO on Enterprise only Team $80 + $40 / developer; Enterprise contact sales

Why Cursor Fails the Review in the First Place

Cursor's problem is architecture, not intent: there is no deployment in which your code avoids Cursor's servers. Its data-use page says so directly — "Even if you use your API key, your requests will still go through our backend! That's where we do our final prompt building." The same page describes temporarily caching file contents on Cursor's servers. Privacy Mode and its "zero data retention (ZDR) agreements with all providers" are real, and an admin can enforce Privacy Mode so members cannot disable it. But ZDR is a promise about what the model provider keeps. It says nothing about the middle hop, and that hop now belongs to SpaceX.

Two further details from Cursor's own governance page will come up in any review. Its identity layer "Routes through Cursor's identity provider (WorkOS) regardless of region," so a data-residency selection does not cover sign-in. And for Anthropic's top tier, Cursor states that "Anthropic stores their inputs and outputs to run automatic and human harm-prevention reviews" — ZDR has a model-shaped hole in it. We covered the key-swap trap in detail when OpenAI cut Cursor off: bringing your own key changes who bills you, not who builds the prompt.

Be fair to Cursor on controls. Its Enterprise tier lists SCIM, repository, model and MCP access controls, audit logs and an AI code tracking API — the strongest admin surface in this category. The catch is that the self-serve Teams plan at $40 gets SSO and team-wide Privacy Mode but not audit logs or SCIM. If your developers bought Teams seats on a card, the plan they are on would not pass the review even if the architecture did.


Where Code and Context Actually Go, Tool by Tool

The honest question is not "does code leave the laptop" — for every cloud-model tool it does — but whose tenant it lands in and for how long.

GitHub Copilot Business. Code goes to a GitHub-operated service. For Business and Enterprise, GitHub's own product page states that IDE prompts and suggestions are "Not retained," while prompts from web, mobile and CLI are "Retained for 28 days," and user engagement data is "Kept for two years." That split matters: your CLI and github.com chat traffic is on a different retention clock from the editor. Copilot's content-exclusion control has a documented gap exactly where usage is growing — GitHub says content exclusion "is currently not supported in Edit and Agent modes" in VS Code and other editors, and that Copilot "may use semantic information from an excluded file if the information is provided by the IDE indirectly."

Claude Code. The CLI runs locally and sends prompts and outputs to whichever provider you configure. Anthropic's deployment overview lists Amazon Bedrock, Google Cloud's Agent Platform (formerly Vertex AI) and Microsoft Foundry alongside its own plans, with "IAM policies, CloudTrail" and "IAM roles, Cloud Audit Logs" as the enterprise controls on the first two, plus a self-hosted gateway that puts your IdP sign-in in front of any of them. On those cloud providers, Anthropic's data-usage page says "error reporting, telemetry, and bug reporting are disabled" by default. On Anthropic's own plans, commercial retention is 30 days standard, and zero data retention "is not included in the standard Enterprise plan; it is enabled on a per-organization basis by your account team after confirming eligibility." One local detail belongs in your endpoint policy: Claude Code keeps session transcripts "in plaintext under ~/.claude/projects/ for 30 days by default."

Tabnine. The only commercial option here built to never leave your perimeter. Its privacy documentation states "Tabnine does not train its models on your code" and, for self-hosted installs, "No code or PII data is ever sent to Tabnine's servers." Its private installation guide covers running "on-premises or in a VPC," and the Tricentis acquisition announcement says it "deploys on-premises, in a private VPC, or fully air-gapped."

Cline. An Apache 2.0 open-source agent that sends code wherever you point it. The Enterprise offer is "Deploy where you want: VPC, on-prem, air-gapped" with bring-your-own inference on Bedrock, Vertex, Azure OpenAI or local models. The data path is exactly as good as the inference endpoint you choose.

Gemini Code Assist. Google Cloud-hosted, with VPC Service Controls and Private Google Access on both Standard and Enterprise, dedicated code-assist audit logging and IP indemnification on both tiers.

Devin Desktop. Cognition's cloud by default. Its pricing page offers "Deploy in your virtual private cloud (VPC)" on Enterprise, yet the company put self-hosted deployment into maintenance mode on 12 May 2025, saying it is "no longer investing in feature development or bringing on new customers" there, and steering customers to cloud, hybrid or single-tenant hosting. Get the difference between those in writing before you sign.


Zero Retention Is Now a Per-Model Setting, Not a Per-Vendor One

Anthropic's ZDR promise, and so every tool that resells Claude, now carries an exception for its most capable models, and your review has to name which model it approved. Anthropic designated Claude Fable 5 and Mythos 5 as Covered Models that carry 30-day retention wherever they are sold — the Claude API, Bedrock, Google Cloud and Foundry alike. That is why Cursor's page carves them out, and why the same carve-out applies to Claude Code on your own AWS account. We walked through what that does to a ZDR workspace in August.

The practical rule: approve a model list, not a product. "Claude Code on Bedrock, Sonnet and Opus only" is a reviewable statement. "Claude Code" is not. Claude Code lets you pin model versions per provider through environment variables and enforce them through managed settings that local configuration cannot override — the same place to enforce MCP allowlists.


Who Should NOT Pick Each Option

This is the section vendor comparison pages leave out.

Skip Copilot Business if your developers live in agent mode and your threat model depends on content exclusion — it does not apply there. Skip it too if you need prompt-level audit: GitHub's audit log documentation says the log does "not include client session data, such as the prompts a user sends to Copilot locally," and it keeps "the last 180 days" unless you stream it to a SIEM.

Skip Claude Code if you have no appetite for a metered bill or no platform team to own a cloud account. The Enterprise plan is $20 a seat plus "usage at API rates", and the Bedrock route is pure pay-as-you-go through AWS. Audit logs, SCIM and custom retention are Enterprise features; the Team plan has SSO but not those.

Skip Tabnine unless you are genuinely air-gapped. Its website now redirects to Tricentis, its pricing page redirects to a Tricentis contact form, and the new owner bought it for the context engine — as we reported, the only promise to existing customers was a support sentence. You are buying a product whose roadmap sits inside a testing company.

Skip Cline if you do not have an inference platform already. It is free because the hard part — model hosting, retention terms, cost controls — is yours. Also study what happened to its nearest peer: Continue, the other popular open-source assistant, made its repository "no longer actively maintained and … read-only" after a final 2.0.0 release in June 2026. Open source removes the vendor from the data path. It does not remove the vendor risk.

Skip Gemini Code Assist if you are not already on Google Cloud. VPC Service Controls are only a benefit if Google Cloud is where your perimeter already lives. Google's pricing page would not render for our check on 30 September; the prices it listed at our 10 August check were $19 Standard and $45 Enterprise per user per month on annual commitment. Re-confirm before you quote them.

Skip Devin Desktop for this purchase. That is the loser, and the reasons stack. The product has changed name twice — Codeium, Windsurf, Devin Desktop — and its old pricing URL now 308-redirects to Devin's. The self-hosted option a security team would want is frozen. The pricing page lists SSO only on the custom-priced Enterprise tier and does not list audit logs or zero retention on any tier. A tool that asks your reviewers to trust a roadmap it has already reversed once is not the one to standardise on.


Is There a Measured Productivity Difference Between These Tools?

No independent, controlled study compares these products head to head, and the best general evidence says the tool matters less than you think. METR's randomised trial of experienced developers, re-run in 2026, estimated a speedup of "-18% with a confidence interval between -38% and +9%" for returning developers and -4% (-15% to +9%) for new recruits — negative means faster, and both intervals cross zero. METR adds that the true speedup "could be much higher" among developers who declined to take part.

DX, which instruments engineering organisations, found median PR throughput up 7.76% across 400-plus organisations over 14 months, with most in a 5–15% band, and total cost per engineer of "$200–$600/month" once token spend is included. Its conclusion is the one to hold onto: the winners "won't be the ones that deployed the most tools. They'll be the ones that measured what was working."

The implication for this decision is blunt. If the measurable gain is 5–15% and roughly tool-agnostic, you should not trade a clean security posture for the tool a vocal team prefers. Measure your own delta before and after, and treat vendor speedup claims as marketing.


What Standardising Costs Versus Letting Teams Choose

Standardising is cheaper on the invoice and much cheaper in review effort; the only real cost is developer goodwill. At our 200-engineer workload, list prices as of 30 September 2026:

  • Standardise: 200 Copilot Business seats at $19 = $3,800 a month, $45,600 a year, each seat carrying 1,900 AI credits. Add Claude Code on Bedrock for the 30 agentic users as metered AWS spend with no seat fee.
  • Let teams choose — say 120 on Copilot Business, 50 on Cursor Teams at $40 and 30 on Claude Enterprise at $20 plus usage: $4,880 a month, $58,560 a year in seat floors alone, 28% more before anyone runs a token.

The invoice is the smaller cost. Three vendors means three DPAs, three egress allowlists, three audit pipelines and three sets of retention terms to re-read every time a model is designated "covered." And the 50 Cursor Teams seats still lack audit logs and SCIM, so either you buy Cursor Enterprise at a quote you cannot see or you carry an unaudited tool.

The strongest argument for choice is attrition: good engineers have strong tool opinions. Honour it with an exceptions process that has a price attached — the team that wants a non-standard tool funds its security review — rather than a free-for-all.


The Criteria That Actually Predict Regret

1. Can you name the tenant your code lands in, per surface? Editor, CLI, web chat and background agents often run on different paths and different retention clocks. If the vendor cannot answer per surface, in writing, you have not finished the review.

2. Does the control cover the mode people actually use? Content exclusion that skips agent mode, or a model allowlist that personal API keys route around, is a control on paper only.

3. Is ZDR scoped to the model you approved? After the covered-model change it is a per-model property. Approve models by name.

4. Who owns the product in 18 months? Cursor, Windsurf, Tabnine and Continue all changed ownership, name or maintenance status inside the last 16 months. Put a change-of-control notice clause in the contract.

What changes the answer: if you are standardised on Google Cloud, Gemini Code Assist inside your existing VPC Service Controls perimeter beats Copilot. If your code legally cannot leave the building, Tabnine or Cline on local inference is the whole shortlist. If you are already on GitHub Enterprise Cloud, Copilot Enterprise at $39 is worth pricing against Business.


What to Do Before Next Quarter

This Week: Pull expense reports and SSO logs for personal Cursor, Claude and Copilot subscriptions. Anything on a consumer or Teams tier is outside your audit log today. Then check endpoint egress for cursor.sh hosts and ~/.claude/projects/ transcript directories so you know what already exists — as ZCode's silent git-history uploads showed, the first incident is usually the one nobody inventoried.

This Month: Issue Copilot Business as the sanctioned default and stand up Claude Code against a Bedrock or Google Cloud project with an approved model list, pinned versions and managed settings. Stream the GitHub audit log to your SIEM before the 180-day window eats your history.

Before Renewal: Write the exceptions process, capture a clean PR-throughput and change-failure baseline, and re-measure at 90 days. Put change-of-control and model-availability clauses into every AI tooling contract you sign.


The Bottom Line

The question your security team is really asking is not "which AI IDE is best." It is "whose infrastructure holds our source code, and can we prove it." Cursor's answer is always "ours," however good its controls get. Copilot's answer is "ours, briefly, and not in the editor." Claude Code on your own cloud account can answer "yours." That is the whole ranking.

Developers will lose a favourite editor. You will gain a data path you can draw on one slide.

Continue Reading

Share:

Frequently Asked Questions

Can Cursor be self-hosted?

No. Cursor's own data-use page says that even with your own API key, requests still go through Cursor's backend, where the final prompt is built. Privacy Mode and provider ZDR agreements limit what model providers keep, but not the Cursor hop itself.

Does GitHub Copilot Business retain my code?

Per GitHub's Copilot page, for Business and Enterprise, IDE prompts and suggestions are not retained, while prompts from github.com, mobile and the CLI are retained for 28 days. User engagement data is kept for two years, and Business code is not used for training.

How do I keep Claude Code traffic inside my own cloud account?

Configure Claude Code to use Amazon Bedrock, Google Cloud's Agent Platform or Microsoft Foundry instead of Anthropic's API. Inference is billed and logged in your cloud account (CloudTrail or Cloud Audit Logs), and telemetry and error reporting default to off on those providers.

Which AI coding assistant works fully air-gapped?

Tabnine (now owned by Tricentis) supports on-premises, private VPC and fully air-gapped deployment, and Cline's Enterprise tier supports VPC, on-prem and air-gapped installs with bring-your-own inference, including local models. Both need a model-hosting platform you operate.

Is zero data retention available for every model?

No. Anthropic designated Claude Fable 5 and Mythos 5 as Covered Models requiring 30-day retention wherever they are sold, including Bedrock and Google Cloud. Approve AI coding tools with a named model list, not just a product name.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →