Your Source Code Moved House Twice in One Week: Cursor Origin, SpaceX, and Default-On Data Egress
SpaceX closed its 60 billion dollar acquisition of Cursor on 14 August. Three days later Cursor shipped Origin, a native code hosting platform that is on by default for every paid plan, with no published retention, residency, training-use or subprocessor terms. The combination is a change of control and a new data flow arriving in the same week, and almost nobody raised a ticket for either.
Two things happened to a very widely deployed developer tool in the space of four days. On 14 August 2026 SpaceX closed its 60 billion dollar all-stock acquisition of Anysphere, the company behind Cursor, issuing roughly 391 million Class A shares and folding the business into a new division called SpaceXAI. It is the largest acquisition of a venture-backed startup on record. Then on 17 August, three days later, Cursor launched Origin, a native code hosting platform built into the editor and positioned as an alternative to GitHub for teams building with AI agents. Origin shipped in early beta on all paid plans, which is Pro, Teams and Enterprise, and it is on by default. The only exception is enterprise organisations whose administrators explicitly opted out. Reporting on the launch notes it landed during a significant GitHub outage, which is good timing for Cursor and awkward timing for anyone trying to think clearly about it.
The detail that matters for anyone responsible for security or compliance is not the product and not the price. It is that at the time of launch Cursor had published no data terms covering Origin: no retention schedule, no residency statement, no training-use policy, no subprocessor disclosure, and no migration tooling for getting repositories back out. Set the ownership question aside entirely and you still have a new location for proprietary source code, enabled without an affirmative decision by the customer, governed by documentation that does not yet exist. That is a straightforward gap in the supplier assurance chain, and it is the sort of gap that is trivially cheap to close in the first week and expensive to unwind six months later once repositories, pull requests and agent history have accumulated inside it.
Default-on is the crux, so it is worth naming exactly what it does. A feature that is opt-in produces a decision, and a decision produces a record: someone weighed it, someone approved it, and there is a date attached. A feature that is on by default produces neither. The data flow starts, the control question is never asked, and the first time anyone in the business learns that code is being hosted somewhere new is when an assessor asks where it lives. Enterprise administrators could opt out, which is a genuinely meaningful carve out, but it only helps organisations that knew to act inside a three day window. Everyone on Pro and Teams, including the many small engineering groups and contractors who sit outside a formal enterprise agreement, got the new destination without being asked. Cursor is reported to be in use at 64 percent of Fortune 500 companies against roughly 2 billion dollars of annual revenue, so the population affected is not a niche.
Now layer the ownership change back on. A change of control does not automatically rewrite your contract, and anyone telling you the terms evaporated on 14 August is overstating it. What a change of control does is move the counterparty, the corporate group, the incentives and eventually the infrastructure. Analysts covering the deal put the zero data retention guarantee at the top of the list of enterprise concerns, and one made a point that deserves repeating because it predates the acquisition entirely: the standard Privacy Mode still permits some code data to be stored to support product features, and only the stricter legacy setting retains nothing at all. If your procurement approval rested on the phrase "zero data retention" without anyone checking which specific setting was enabled on which specific tenant, then the control you documented and the control you have may already have differed before SpaceX was ever involved.
The compliance mapping here is unglamorous and completely standard, which is the point. ISO 27001 gives you supplier relationships, monitoring and review of supplier services, and change management, and a new parent company plus a new data destination triggers all three. The SOC 2 common criteria expect you to identify changes that could affect the control environment and respond to them, and expect vendor management to be a live process rather than an annual spreadsheet refresh. ISO 42001 adds the obligation to know which AI systems you operate, what data they touch, and who owns each one by name, and an AI coding assistant that now also stores your repositories is squarely inside that scope. If any of that source code renders or handles a payment page, PCI DSS expectations around inventory and integrity of the scripts you ship follow the code wherever it is stored. It is worth saying plainly that Vanta, Drata, Secureframe and Sprinto will not catch this on your behalf. They will confirm your vendor policy exists and your access reviews ran. They cannot tell you that a checkbox flipped on inside an editor on 17 August and started replicating your repositories somewhere new.
There is a real counterargument and it should be given its due. Access to SpaceX compute is a genuine benefit, and a coding tool with more GPU capacity behind it plausibly gets better rather than worse. Origin is designed to interoperate with GitHub rather than replace it outright, so code can pass between the two, which lowers the switching cost in both directions. Early beta products routinely ship ahead of their documentation, and it is entirely likely that Cursor publishes proper Origin data terms within weeks. A larger, better capitalised owner can also fund a stronger compliance function than an independent startup could. None of that is an argument for waiting. It is an argument for asking now, while the answer is still being written and while a customer question can still influence what gets written.
Two further questions belong in the same conversation. The first is model routing. Cursor documentation on data use already names SpaceXAI alongside OpenAI and Anthropic among the providers whose terms govern retention, and analysts have asked directly whether Cursor will continue to point at models other than Grok. Your model choice is a data processing decision, so if the roster changes, your subprocessor list changes with it, and that should reach you through contractual notice rather than through a release note. The second is residency. If repositories are hosted on infrastructure operated by a new corporate group, the question of which country your code is stored and processed in is open until somebody answers it in writing. Under the EU AI Act transparency and record keeping duties now in force, and under the ordinary expectations of any customer who asked you where their data lives, "we are not sure" is not a position you want to occupy.
Our recommendation this week is short and takes an afternoon. First, find out who in your business is on a paid Cursor plan, including contractors and anyone expensing a personal subscription, because the enterprise opt-out only covers the tenant your administrators control. Second, check whether Origin is enabled and whether any repository has already been pushed to it, then decide deliberately rather than by default, and keep GitHub or your existing provider as the authoritative system of record until Origin terms are published. Third, confirm which retention setting is actually live on your tenant instead of trusting the phrase used during procurement. Fourth, put the change of control in your vendor register and your change log with the 14 August date attached, and check your contract for change of control and subprocessor notice clauses. Fifth, send Cursor five written questions and keep the reply: retention period for Origin repositories, residency, training use, the current subprocessor list, and the export path for getting your code out. Then apply the same five questions to GitHub Copilot, Claude Code and every MCP server your engineers have wired into their editors, because the lesson of this week is not really about one vendor. It is that the tools sitting closest to your source code can change owners, change destinations and change defaults faster than any quarterly review cycle is built to notice.
Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.
Get the next post by email
One short email when something worth knowing ships. No spam, unsubscribe anytime.