Skip to content

Quick Security Checklist

Before using any AI coding tool with real code, complete this checklist.

  • Enable privacy/ghost mode if available
  • Create exclusion rules for sensitive files
  • Disable telemetry where possible
  • Use unique API keys (not production keys)
  • Review privacy policy for training/retention
  • Verify jurisdiction is acceptable

Create .cursorignore, .aiderignore, or equivalent:

# Secrets
.env*
*.pem
*.key
secrets/
credentials/
# Client code
clients/*/
# Sensitive data
data/production/
  1. Settings → Privacy Mode → Enable
  2. Create .cursorignore file
  3. Settings → Telemetry → Disable
  1. Use BYOK (your own API keys)
  2. Settings → Telemetry → Opt-out
  1. Use local models (Ollama)
  2. No cloud = no data leaves machine
  1. Enterprise plan for privacy mode
  2. Consumer plans have training ON by default
Warning SignRisk
No privacy policyUnknown data handling
Training “enabled by default”Your code used for training
No exclusion mechanismCan’t protect sensitive files
China jurisdictionDifferent legal protections
ToolPrivacy Level
Continue.dev + OllamaMaximum (local)
Zed + BYOKHigh (your API terms)
Cursor TeamsHigh (zero retention)
Cursor ProMedium (30-day retention)
Claude Code (consumer)Low (training ON)