Coding Assistants

Devin

Medium risk

Autonomous AI software engineer that plans and executes multi-step development work with its own shell, browser, and repository access, sold to teams and enterprises.

Verified 2026-08-31Cognitiondevin.ai

Is Devin safe for confidential data?

Devin's vendor-side posture is reasonable for its class: Cognition has held SOC 2 Type II certification since September 2024, paid plans offer a training opt-out, and Enterprise adds contractual no-training plus deployment in your own VPC where data stays in your environment. The dominant risk is what the product is: an autonomous agent holding shell access, repository credentials, browser sessions, and secrets, acting over long horizons. A misconfigured Devin with push access to main, production deploy keys, or broad secret scope can do more damage faster than a chat assistant ever could, so the real security review is permission scoping — branch protection, least-privilege tokens, secrets isolation, and audit logging — rather than the data-handling terms.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Core / Team (paid)
Conditional

Training opt-out available and worth setting on day one; hosted in Cognition's cloud under standard terms.

Enterprise
No training

No training without consent, VPC deployment, SAML/OIDC SSO, audit logs, and fine-grained access controls under a negotiated contract.

Data handling

Training on inputs

Paid plans include a training opt-out (with zero retention after opt-out); Enterprise terms exclude training without consent. Verify the opt-out is actually set for your workspace rather than assuming the default.

Retention

Session data, repositories, and secrets Devin is given persist in the workspace per plan terms; Enterprise VPC deployment keeps data in the customer's controlled environment.

Residency

Cognition-hosted cloud by default; Enterprise supports deployment in the customer's own VPC on any major cloud, which is also the practical answer for Canadian residency requirements under PIPEDA or Quebec Law 25.

Compliance

  • SOC 2Yes
  • GDPR / DPANot verified
  • HIPAA BAANot verified

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • SSO (SAML / OIDC)
  • VPC deployment in customer cloud
  • Audit logging
  • Fine-grained access controls
  • Secrets management scoping

Frequently asked questions

Is Devin safe for our codebase?

The vendor side is solid for the category — SOC 2 Type II since September 2024, a paid-plan training opt-out, and Enterprise VPC deployment with contractual no-training. Safety in practice depends on what you hand it: Devin works with real shell, repo, browser, and secret access, so treat it like onboarding a contractor with automation speed, not like installing a plugin.

What are the biggest Devin security risks?

Permission scope, not data leakage. An agent with push rights to main, production deploy keys, or wide secret access can merge, deploy, or exfiltrate mistakes autonomously, and prompt-injected content it reads while browsing or handling issues can steer it. Enforce branch protection and mandatory human review on its PRs, give it least-privilege tokens per repo, isolate its secrets, and keep audit logs on.

Can individual engineers just start using Devin on their own?

They can, and that is the risky version: a personal-plan agent granted a developer's own GitHub credentials operates outside your contract, your SSO, and your audit trail, with the training opt-out left to that individual. Centralize any Devin adoption under a team or enterprise agreement with org-owned credentials, and keep visibility over the AI tools engineers wire into repositories without asking.

Policy changelog

  • Initial entry published from Cognition's published security documentation.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Devin is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles