Windsurf replaced technical documentation about their Devin AI product with a comprehensive security and data handling disclosure. The previous document described Devin's vulnerability remediation capabilities; the updated document now describes Windsurf's organizational security practices, including encryption, access controls, employee authentication requirements, third-party audits (SOC 2 Type II certification obtained March 2024), and a vulnerability disclosure program. This shift establishes explicit statements about how Windsurf handles data security, operational monitoring, and employee access to production systems.
The updated document establishes explicit commitments about how Windsurf protects data and manages security. The terms state that all data transmission is encrypted in transit and at rest, that access to production systems is restricted to a small number of employees or contractors based on business roles, and that production systems are monitored via logging, error handling, and monitoring dashboards. The document discloses that Windsurf obtained SOC 2 Type II certification as of March 2024 and that all employees and contractors are required to use multi-factor authentication and receive annual security training. These disclosures describe organizational practices rather than establishing new user-facing rights or obligations.
→ Review Windsurf's Trust Center for additional security documentation and certification details
→ Evaluate the SOC 2 Type II certification scope against your organization's data processing requirements
All data transmission is encrypted in transit and at rest; production systems are routinely monitored via logging and error handling.
Access to cloud environment in AWS is granted on as-required basis based on business roles; only a small number of employees or contractors have direct access to production systems.
Windsurf obtained SOC 2 Type II certification as of March 2024, with auditors reviewing security policies, procedures, and controls related to data security, privacy, processing integrity, confidentiality, and availability.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Windsurf replaced product-focused documentation with formal security and data handling disclosures. The updated document asserts SOC 2 Type II certification (March 2024), establishes mandatory employee MFA and annual security training requirements, describes production access controls, …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-003202.
Windsurf's Terms of Service footer navigation was updated in an update detected on July 24, 2026 to add two new …
Windsurf updated its privacy policy footer to add a link to a 'Service Level Agreement' document between the Data Processing …
Windsurf's Security & Data Handling page was updated to remove one sentence from the opening paragraph. The phrase 'Copy page' …
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the …
TikTok's data collection extends to device sensors, clipboard content, geolocation, and cross-site tracking. Here is what their Privacy Pol…
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.