Coding Assistants
Devin
Medium riskAutonomous AI software engineer that plans and executes multi-step development work with its own shell, browser, and repository access, sold to teams and enterprises.
Is Devin safe for confidential data?
Devin's vendor-side posture is reasonable for its class: Cognition has held SOC 2 Type II certification since September 2024, paid plans offer a training opt-out, and Enterprise adds contractual no-training plus deployment in your own VPC where data stays in your environment. The dominant risk is what the product is: an autonomous agent holding shell access, repository credentials, browser sessions, and secrets, acting over long horizons. A misconfigured Devin with push access to main, production deploy keys, or broad secret scope can do more damage faster than a chat assistant ever could, so the real security review is permission scoping — branch protection, least-privilege tokens, secrets isolation, and audit logging — rather than the data-handling terms.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
Training opt-out available and worth setting on day one; hosted in Cognition's cloud under standard terms.
No training without consent, VPC deployment, SAML/OIDC SSO, audit logs, and fine-grained access controls under a negotiated contract.
Data handling
Training on inputs
Paid plans include a training opt-out (with zero retention after opt-out); Enterprise terms exclude training without consent. Verify the opt-out is actually set for your workspace rather than assuming the default.
Retention
Session data, repositories, and secrets Devin is given persist in the workspace per plan terms; Enterprise VPC deployment keeps data in the customer's controlled environment.
Residency
Cognition-hosted cloud by default; Enterprise supports deployment in the customer's own VPC on any major cloud, which is also the practical answer for Canadian residency requirements under PIPEDA or Quebec Law 25.
Compliance
- SOC 2Yes
- GDPR / DPANot verified
- HIPAA BAANot verified
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- SSO (SAML / OIDC)
- VPC deployment in customer cloud
- Audit logging
- Fine-grained access controls
- Secrets management scoping
Frequently asked questions
Is Devin safe for our codebase?
The vendor side is solid for the category — SOC 2 Type II since September 2024, a paid-plan training opt-out, and Enterprise VPC deployment with contractual no-training. Safety in practice depends on what you hand it: Devin works with real shell, repo, browser, and secret access, so treat it like onboarding a contractor with automation speed, not like installing a plugin.
What are the biggest Devin security risks?
Permission scope, not data leakage. An agent with push rights to main, production deploy keys, or wide secret access can merge, deploy, or exfiltrate mistakes autonomously, and prompt-injected content it reads while browsing or handling issues can steer it. Enforce branch protection and mandatory human review on its PRs, give it least-privilege tokens per repo, isolate its secrets, and keep audit logs on.
Can individual engineers just start using Devin on their own?
They can, and that is the risky version: a personal-plan agent granted a developer's own GitHub credentials operates outside your contract, your SSO, and your audit trail, with the training opt-out left to that individual. Centralize any Devin adoption under a team or enterprise agreement with org-owned credentials, and keep visibility over the AI tools engineers wire into repositories without asking.
Policy changelog
- Initial entry published from Cognition's published security documentation.
Sources
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
Devin is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
AWS's AI coding assistant and agent for IDEs, the CLI, and the AWS console, with completions, chat, and code transformation tied into AWS accounts.
Browser-based AI app builder from StackBlitz that generates, runs, and deploys full-stack JavaScript applications from prompts, popular with founders and rapid prototypers.
AI-first code editor that sends repository context to hosted models for completions, chat, and multi-file agentic edits.
AI pair programmer integrated into editors and the GitHub platform, offering code completion, chat, and agentic coding workflows.