Post

Simon Willison
Simon Willison@simonw·
Made some notes on how Cursor works under the hood based on their security documentation - it turns out an organization's list of subprocessors offers a loose form of "view source" for their infrastructure! simonwillison.net/2025/May/11/cu…
English
18
39
463
41.2K
Raduan Al-Shedivat
Raduan Al-Shedivat@0xRaduan·
@simonw I think their most valuable piece is UX and Custom Models(tab / custom apply model) at this point(which enables differentiation compared to 10 other forks). The next piece of differentiation will be background agents, most likely.
English
0
0
0
854
Kevin Urrutia
Kevin Urrutia@danest·
@simonw Yep, the subprocessor list is a great way to see how some big startups build their infrastructure. I’ve also learned a lot from seeing how others set up their tech stacks
English
0
0
0
82
Matt Arderne 🌊
Matt Arderne 🌊@mattarderne·
@simonw The other way to understand their infrastructure is to look at the linkedin of their junior and mid employees. "implemented a Doodad auth system from scratch" 😅
English
0
0
0
287
Tahir Fayyaz
Tahir Fayyaz@TFayyaz·
@simonw Really interesting to read this and compare it to Windsurf’s architecture. You can see how much effort they have put into being Enterprise ready. Maybe even more than Cursor. windsurf.com/security
English
0
0
0
328
ariel
ariel@parquetgood·
@simonw I’d love to read their SOC2 (cannot believe I said that)
English
0
0
0
791
Naresh R Shah
Naresh R Shah@nareshshah139·
@simonw Windsurf were forced to do it much earlier (they were in Dell)
English
0
0
0
154
protomachine
protomachine@protomachine·
@simonw Yes, an organizations job listings and GDPR subprocessors reveal quite a lot.
English
0
0
0
128
Ken
Ken@kenhorn·
@simonw This. For customers, should be explicit.
English
0
0
0
269
Viralt.ai
Viralt.ai@Viralt_AI·
@simonw peeking under the hood sparks the best hacks!
English
0
0
0
389
Alex
Alex@alexanderOpalic·
@simonw How is Copilot handling security?
English
0
0
0
197
Saimon Sharif
Saimon Sharif@saimonsharif·
@simonw it's pretty interesting to see more and more companies list their subprocessors out publicly! in the past, I've had to sign an MNDA, etc (though, usually in the context for also getting audit reports & more)
English
0
0
0
383
justboulatbek
justboulatbek@1258632·
@simonw What is it about relative paths? Path to what? Why embed it?
English
0
0
0
104
Paylaş