← Cursor Agents · ENGINEERING
SOC2 & Compliance Expert
compliance-engineer
Ensures data retention policies, audit logs, GDPR compliance, and encryption.
Where it installs
# .cursor/agents/compliance-engineer.md
---
name: compliance-engineer
description: ...
---# .claude/agents/compliance-engineer.md
---
name: compliance-engineer
description: ...
tools: Read, Write, Edit, Glob, Grep, Skill, Bash, TodoWrite
model: inherit
---What it does
SOC2 & Compliance Expert is a Cursor agent playbook named compliance-engineer. AgenticKit installs it so a session can adopt this role instead of acting as a generic coding assistant.
The compliance-engineer agent ensures your software satisfies enterprise security and privacy standards. It designs user data deletion pipelines, creates tamper-evident audit logs, enforces data retention policies, and guides SOC2 readiness.
Ensures data retention policies, audit logs, GDPR compliance, and encryption. Compliance engineer for Cursor that audits systems for GDPR, SOC2, HIPAA, data retention policies, and cryptographic security.
Why it exists
A pile of agent files is not a team. compliance-engineer exists so one job, soc2 & compliance expert, has a written brief, required skills, and a stop condition.
It ships in the Engineering Kit. Skills it must read: SOC2 Compliance & Data Privacy Controls; Web Security Fundamentals & OWASP Defense; Authentication & Session Security Patterns. Commands that adopt this role: /compliance-audit: GDPR & SOC2 Privacy Compliance Auditor; /audit: Codebase Quality & Security Auditor; /write-docs: Technical Documentation & API Reference Writer.
When to use it
- Adding user export and account deletion endpoints
- Auditing data retention and privacy compliance
- Preparing your SaaS product for enterprise customer reviews
When not to use it
- Do not ask compliance-engineer to do a different role's job. If you need a launch post, switch agents.
- Do not keep the same chat after this agent has finished its artifact. Start a reviewer in a new thread.
- Do not invoke every agent in the kit for a small change.
Example workflow
- Install the Engineering Kit so .cursor/agents/compliance-engineer is on disk.
- Run /compliance-audit: GDPR & SOC2 Privacy Compliance Auditor, or start a chat and tell Cursor to adopt the compliance-engineer role.
- The agent should read: SOC2 Compliance & Data Privacy Controls; Web Security Fundamentals & OWASP Defense; Authentication & Session Security Patterns.
- It produces the artifact for this role only, then stops.
- A different agent or you review. Same-chat self-review is not a review.
Example usage
Example: "You are compliance-engineer. Adding user export and account deletion endpoints. Read compliance-soc2 before you edit."
Or let the pipeline invoke it: /compliance-audit: GDPR & SOC2 Privacy Compliance Auditor.
Capabilities you should actually see: GDPR 'Right to be Forgotten' user data deletion workflows
Example output
- compliance-engineer should leave files or a written verdict, not a vibe check. GDPR 'Right to be Forgotten' user data deletion workflows Immutable audit trail logging for sensitive user actions
- Engineering agents should touch the slice they were given (schema, route, test, or review note) and nothing else.
Best practices
- GDPR 'Right to be Forgotten' user data deletion workflows
- Immutable audit trail logging for sensitive user actions
- Data at rest and in transit encryption verification
- SOC2 Type I and Type II technical controls checklist
- One role per chat unless a command is explicitly orchestrating a sequence.
Common mistakes
- Using compliance-engineer as a synonym for 'the Cursor agent'. It is a brief, not the product.
- Skipping the required skills and hoping the role name is enough.
- Letting the writer approve its own PR.
- Invoking this agent and three unrelated ones in the same prompt.
Frequently asked questions
What is the compliance-engineer Cursor agent?
SOC2 & Compliance Expert: Compliance engineer for Cursor that audits systems for GDPR, SOC2, HIPAA, data retention policies, and cryptographic security.When should I invoke compliance-engineer?
Adding user export and account deletion endpoints Auditing data retention and privacy compliance Preparing your SaaS product for enterprise customer reviewsWhat skills does compliance-engineer use?
SOC2 Compliance & Data Privacy Controls; Web Security Fundamentals & OWASP Defense; Authentication & Session Security PatternsHow do I run compliance-engineer in Cursor?
Run /compliance-audit: GDPR & SOC2 Privacy Compliance Auditor or /audit: Codebase Quality & Security Auditor or /write-docs: Technical Documentation & API Reference Writer, or start a chat and adopt the compliance-engineer role.Is compliance-engineer the same as Cursor's built-in Agent?
No. Cursor Agent is the product harness. This file is a specialist brief you install so that harness takes a named role.
Install compliance-engineer with the rest of the team
46 agents, 61 skills, and 47 slash commands, installed into .cursor/ and .claude/. Engineering and marketing kits, one license.