Coder has introduced Agent Relay, a self-hosted execution layer that lets enterprises run Cursor Cloud Agents inside Coder workspaces on infrastructure they control. SpaceXAI is the launch partner, and the Cursor integration is currently in private preview with design partners.

What actually moves inside the customer perimeter

The important change is execution placement. Coder says each workspace can start a Cursor worker while the workspace itself runs in the customer cloud, VPC or on-premises environment. Tool calls therefore execute against code, secrets and internal services under the organization’s own network and access policies.

That does not make Cursor a fully local model stack. Cursor continues to run the agent loop, including inference and planning. Independent coverage from The New Stack likewise describes the setup as customer-controlled execution with Cursor handling cloud inference and planning. The practical distinction is between where the agent acts and where model reasoning is provided.

Why regulated teams may care

Agent Relay is aimed at organizations where coding agents have been difficult to approve because autonomous tools need access to private repositories, credentials, custom hardware or internal services. Coder’s design uses isolated task workspaces, centrally enforced network policy, approved-model controls and run logging so platform teams can govern agent execution using the same infrastructure layer they already manage for developers.

Coder also frames prompt-injection containment as an environment-level control: an agent should be unable to reach unauthorized resources even if the model itself attempts an unsafe tool call. That is a stronger architecture claim than relying only on model refusal, although buyers should validate the controls against their own threat model rather than treating vendor language as independent security proof.

Availability and review impact

Agent Relay for Cursor is in private preview, not general availability, and Coder has not published broad self-serve pricing for this integration. AiToolMap therefore treats this as a material Cursor workflow and enterprise-deployment update rather than a claim that every Cursor user can self-host Cloud Agents today.

The change is material enough to trigger a Cursor review refresh because deployment model, governance and enterprise accessibility are part of the product’s workflow and trust profile.