CA-C-003202
Windsurf — Windsurf Security & Data Handling
Entity
Date detected
June 23, 2026
Effective date
June 23, 2026
Severity
Direction
Positive
Affected users
all users enterprise customers data controllers
Taxonomy
Disclosure requirement change
Changes
+11 sentences added · 26 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch Windsurf Get alerts when this policy changes.
Watch — Free

Event Summary

Windsurf replaced technical documentation about their Devin AI product with a comprehensive security and data handling disclosure. The previous document described Devin's vulnerability remediation capabilities; the updated document now describes Windsurf's organizational security practices, including encryption, access controls, employee authentication requirements, third-party audits (SOC 2 Type II certification obtained March 2024), and a vulnerability disclosure program. This shift establishes explicit statements about how Windsurf handles data security, operational monitoring, and employee access to production systems.

MEDIUM

Consumer Impact

The updated document establishes explicit commitments about how Windsurf protects data and manages security. The terms state that all data transmission is encrypted in transit and at rest, that access to production systems is restricted to a small number of employees or contractors based on business roles, and that production systems are monitored via logging, error handling, and monitoring dashboards. The document discloses that Windsurf obtained SOC 2 Type II certification as of March 2024 and that all employees and contractors are required to use multi-factor authentication and receive annual security training. These disclosures describe organizational practices rather than establishing new user-facing rights or obligations.

Governance Analysis

The updated document establishes formal security commitments previously absent from public Windsurf documentation. By disclosing SOC 2 Type II certification, encryption practices, access controls, and employee security requirements, Windsurf creates a documented baseline against which procurement teams and compliance officers can evaluate the platform's data protection measures. This materialization of security practices may reduce vendor assessment friction for organizations subject to GDPR, CCPA, or internal data protection governance.

Available Actions

Review Windsurf's Trust Center for additional security documentation and certification details

Evaluate the SOC 2 Type II certification scope against your organization's data processing requirements

If No Action Is Taken

The updated security practices will apply to all data processed by Windsurf as described in the updated terms

Organizations that do not review the updated security disclosures may not have documented evidence of Windsurf's security controls for vendor governance or audit purposes

Key Clauses Affected

Data Encryption and Transmission

All data transmission is encrypted in transit and at rest; production systems are routinely monitored via logging and error handling.

Production Access Controls

Access to cloud environment in AWS is granted on as-required basis based on business roles; only a small number of employees or contractors have direct access to production systems.

SOC 2 Type II Certification

Windsurf obtained SOC 2 Type II certification as of March 2024, with auditors reviewing security policies, procedures, and controls related to data security, privacy, processing integrity, confidentiality, and availability.

Full clause-by-clause analysis available with Compliance.
These clauses may change again. Get alerted when they do. Watch Windsurf — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
bcb9b134abe873978bb3d42f93e1a7d30bb231d67d58d1373f714dd1c17cf18b
June 2, 2026 20:42 UTC
✓ Verified
Current Version
a7e6dc4f15152ca497f54aeea5cd6134ffd3e6bb2444c8d862ecc41fc8499c34
June 23, 2026 00:59 UTC
✓ Verified
Change Detected
June 23, 2026 00:59 UTC
Analysis Methodology
✓ Verified
Source Document
https://windsurf.com/security
Citation Record
Entity: Windsurf
Document: Windsurf Security & Data Handling
Record ID: CA-C-003202
Captured: 2026-06-23 00:59:15 UTC
URL: https://conductatlas.com/change/2026-06-23-windsurf-windsurf-security-data-handling-3202/
Accessed: June 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

Windsurf replaced product-focused documentation with formal security and data handling disclosures. The updated document asserts SOC 2 Type II certification (March 2024), establishes mandatory employee MFA and annual security training requirements, describes production access controls, and commits to routine system monitoring and alerting. For organizations evaluating Windsurf as a vendor, this change materializes security commitments previously absent from public documentation. No specific regulatory article citation is indicated in the change text, but SOC 2 Type II certification is generally recognized as addressing AICPA Trust Service Criteria and may support compliance with data security requirements under GDPR, CCPA, and similar frameworks. No new vendor obligations appear to be imposed on downstream users.

Regulatory Exposure

GDPR (data security and controller-processor responsibilities), CCPA (service provider obligations), FTC Act Section 5 (unfair or deceptive practices regarding data security)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Monitor $19/mo Compliance $249/mo

Monitor: regulatory citations + obligations. Compliance: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-003202.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Monitor

Document Context

Version history → Policy drift analysis → Document page →
Document
Windsurf Security & Data Handling
Entity
Windsurf
Captured
June 23, 2026
Source URL
https://windsurf.com/security
Other changes to Windsurf Security & Data Handling
Previous change May 16, 2026
Windsurf updated its Security & Data Handling policy on May 16, 2026 to disclose two practices involving data exposure. The …
Low Neutral
View full version history →
More from Windsurf
Jun 21, 2026 Low
Windsurf Privacy Policy

Windsurf's privacy policy was updated on June 21, 2026 to change the company website URL from www.cognition.ai to cognition.com in …

Jun 13, 2026 Unknown
Windsurf Terms of Service
Jun 12, 2026 Low
Windsurf Privacy Policy

Windsurf reordered the navigation links in their privacy policy footer on June 12, 2026. The 'Privacy Policy' link moved from …

Related Analysis
Privacy · April 29, 2026
What 38 AI Companies Actually Say About Your Data (2026)

We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and lia…

Track Windsurf policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.