DevFlow vs Cursor: 7 dimensions, sourced
DevFlow and Cursor are compared on 7 dimensions below, each read from Cursor's own documentation on 1 Oct 2026; 3 cases where Cursor fits better are listed too.
Cursor's Cloud Agents, formerly called Background Agents, run the same coding agent in isolated cloud VMs with full development environments instead of on your local machine.↗
Each claim about the other product was read on 1 Oct 2026 from the page its ↗ link opens. Cells in the DevFlow column are written from files in DevFlow's own codebase, named next to each cell; that codebase is not public. A comparison left unchecked for 90 days is flagged for review.
| Dimension | DevFlow | Cursor |
|---|---|---|
| Where it runs | On the hosted instance at devflow.fraway.io. A self-hosted install is not self-serve: it is arranged with Fraway on request.site/src/lib/site.tsENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelte | In isolated VMs that Cursor provisions and tears down. With Self-Hosted Machines, a worker you manage performs file edits and terminal commands, while Cursor runs the agent loop, inference and planning.↗ |
| Where your code goes | On the hosted instance at devflow.fraway.io, DevFlow clones repositories into worktrees on the servers that run it. Prompts, which include code, go to the model provider the workspace chooses.CLAUDE.mdsite/src/lib/site.ts | Cloud agents clone your repository from GitHub, GitLab, Azure DevOps Services or Bitbucket Cloud, work on a separate branch, then push changes back to your repository.↗ |
| Model choice | Each workspace stores its own key for OpenRouter, Anthropic, OpenAI or Google. On Pro and higher plans, managed OpenRouter inference can stand in when no OpenRouter key is stored.internal/relay/providers.gointernal/entitlement/entitlement.goCLAUDE.md | Cloud Agents use a curated selection of models, and you can select the context window size for supported models.↗ |
| Isolation | Each task gets its own git worktree. Agent CLIs run under a Landlock sandbox or, when enabled, in a per-invocation container; test and build commands run in non-root containers capped at 4 CPUs and 4 GB of memory by default.CLAUDE.mdinternal/agent/depcache.go | Cursor provisions an isolated VM for each agent and clones the authorized repository into it. Outbound traffic can be restricted to a default set plus your allowlist, or to your allowlist only.↗ |
| Verification | Runs the repository's configured test commands plus an AI code review and records both in a merge evidence report. A repository with no configured commands is not built or tested, and the report shows the skipped check.CLAUDE.mdinternal/agent/evidence.gointernal/agent/gate_command.go | Cloud agents can build, test and interact with the changed software in their VM, and produce screenshots, videos and logs showing how they verified the work.↗ |
| Human gates | A person approves, edits or rejects the plan before code is written, and a person marks the task done, which starts the squash, push and pull request when GitHub is connected. Opt-in autopilot keeps both gates.CLAUDE.mdinternal/agent/evidence.go | Cloud Agents auto-run terminal commands without stopping for approval on every step, then open a draft pull request; nothing merges until a person reviews the change.↗ |
| Pricing model | The self-serve plans are Free, Pro and Team; an Enterprise plan is arranged with Fraway on request. Model usage is paid to the provider whose key the workspace stores, or through managed inference on Pro and above.internal/entitlement/entitlement.goENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelte | Cloud Agents are charged at API pricing for the selected model and need a paid Cursor plan; Cursor asks you to set a spend limit when you first use them.↗ |
How to read the table
- Where it runs compares hosted machines, machines you operate, and the options in between.
- Where your code goes compares where a checkout lives and which hosting services each product works with.
- Model choice compares fixed model sets, model pickers and keys you bring yourself.
- Isolation compares virtual machines, containers, sandboxes and network limits.
- Verification compares test runs, reviewing models and security scans.
- Human gates compares plan approval, pull request review and approval of individual actions.
- Pricing model compares plans, usage credits and the model spend you pay directly.
Where Cursor fits better
- Your team wants to start agent runs from a desktop app, the web, iOS, Slack, GitHub, Linear or an API.↗
- You want to take control of the agent's remote desktop and test the changed software yourself without checking out the branch.↗
- Your repositories live on GitLab, Bitbucket Cloud or Azure DevOps, which Cloud Agents can clone from.↗
What Cursor documents
Every agent commit is signed with an HSM-backed Ed25519 key and shows a Verified badge, so agent-authored changes can satisfy signed-commit branch protection.↗
Secrets marked as Runtime Secrets are stripped from the transcript, tool output and commits, and never reach the model.↗
Cloud agents can run in multi-repo environments, make coordinated changes and open pull requests in each repository they change.↗
Command-based hooks committed to the repository run in cloud agents, so formatters, audit scripts and policy checks stay active in the cloud.↗
How DevFlow runs the work
A DevFlow task moves from planning to a plan review, then to decomposition into at most 8 subtasks, implementation, verification and a written summary. Each task gets its own branch, named after its task ID, in a worktree under the repository's .devflow/worktrees directory.
By default, every agent invocation has a hard limit of 90 minutes and is stopped after 45 minutes without output. A workspace can also set a monthly spend cap, and a task over that cap fails with a reason before it starts.
On Pro and higher plans, finalization also runs dependency scanners for the languages DevFlow detects, such as govulncheck for Go modules and pnpm audit for Node packages, each stopped after 300 seconds by default. Scan results go into the evidence report and do not block the pipeline.
What DevFlow records along the way
A task that finishes implementation gets a merge evidence report listing the models that did the work, each subtask's verifier outcome, the build checks, the security scan summary, the final review and the people who approved the plan and clicked Mark Done. The report is added to the pull request body, and later rework refreshes it there.
Agent processes start with an allowlisted environment instead of inheriting the server's own. Provider keys and GitHub tokens are encrypted at rest with AES-256-GCM.
FAQ
Can Cursor Cloud Agents run on my own machines?
The Self-Hosted Machines option moves file edits and terminal commands to a worker you manage, while the agent loop, inference and planning stay in Cursor's cloud. DevFlow runs at devflow.fraway.io; a self-hosted DevFlow install is not self-serve and is arranged with Fraway on request.
Who approves work in Cursor Cloud Agents and in DevFlow?
Cursor's security overview says Cloud Agents auto-run terminal commands and open draft pull requests that a person reviews before anything merges. DevFlow asks a person to approve the plan before code is written and to mark the task done before the branch is pushed.