Old version
June 2, 2026 20:42 UTC
bcb9b134abe873978bb3d42f93e1a7d30bb231d67d58d1373f714dd1c17cf18b
CA-V-003348
New version
June 23, 2026 00:59 UTC
a7e6dc4f15152ca497f54aeea5cd6134ffd3e6bb2444c8d862ecc41fc8499c34
CA-V-004147
Share 𝕏 Share in Share
Change Summary
Windsurf replaced technical documentation about their Devin AI product with a comprehensive security and data handling disclosure. The previous document described Devin's vulnerability remediation capabilities; the updated document now describes Windsurf's organizational security practices, including encryption, access controls, employee authentication requirements, third-party audits (SOC 2 Type II certification obtained March 2024), and a vulnerability disclosure program. This shift establishes explicit statements about how Windsurf handles data security, operational monitoring, and employee access to production systems.
medium severity
11 Sentences added
0 Sentences removed
26 Sentences modified
26 Sentences before
37 Sentences after
Added
Removed
Modified
BeforeAfter
001 Reduce your security debt Security debt grows when known issues are easy to identify but hard to safely fix.0On this page Security Privacy & Intellectual Property User Best Practices Admin Security at Cognition Copy page We want Devin to be a core contributor in your organization, and have prioritized security, data privacy and compliance to make it possible Copy page ​ Security Secure Transmission and Encryption All data transmission is encrypted in transit and at rest.
1Devin helps teams turn that backlog into maintained code by taking on remediation work across vulnerabilities, dependency updates, insecure configurations, and repeated patterns across one or many repos.1Production software is also routinely monitored via logging, error handling and monitoring dashboards of live metrics.
2Run on demand or on a schedule, Devin helps security teams reduce backlog pressure while keeping fixes inside engineering's existing review process.2Unusual application states (i.e. unusually high error rates, slowness, failures) trigger alerts which are quickly investigated by our team.
3Customer proof — Itaú ~70% of SonarQube, Fortify, and Veracode vulnerabilities resolved automatically.3Access to our cloud environment in AWS is granted on an as-required basis based on business roles and only a small number of employees or contractors are granted direct access to production systems.
4Itaú used Devin to clear a large vulnerability backlog across their scanner findings, reducing remediation burden on their engineering teams at scale.4General Security Practices All employees and contractors are required to use multi-factor authentication on all main work applications.
5Read the case study → Workflows Clear backlog — Address large backlogs across one or many repos, such as stored credentials, insecure configurations, missing best-practice updates, or outdated security patterns.5All employees and contractors also receive annual training about security best practices, including good password management and how to identify social engineering and phishing scams.
6Snyk Vulnerability Burn Down → Routine work — Set Devin to run on a recurring basis to handle routine security maintenance, such as remediating CVEs, performing dependency bumps, or patching SAST/SCA findings.6Third-party audits and certification Cognition obtained SOC 2 Type II certification and conducted Security Training in March 2024 for all employees at Cognition.
7Daily Sentry Error Fixes → Weekly Dependency Update → Risk identification — Run Devin across your repos to find what your scanners miss: logic flaws, insecure patterns, missing auth checks, and chained low-severity CVEs that become critical in context.7As part of the SOC 2 audit, Cognition’s auditors reviewed all of Cognition’s security policies, procedures, internal and third party controls related to data security, privacy, processing integrity, confidentiality and availability.
8Daily Design Audit → 02 Secure every release Devin helps teams turn blocked PRs and failed checks into review-ready fixes by taking on remediation work across failing tests, insufficient coverage, dependency vulnerabilities, and CI/CD or security check failures.8For more details about our security please visit our Trust Center .
9Triggered from PRs, CI/CD, or on demand, Devin helps teams keep releases moving while keeping fixes inside engineering's existing review and merge process.9Vulnerability Disclosure Program If you have identified a potential security issue, we encourage you to share your findings with us.
10In the wild — axios supply-chain attack Caught in under an hour, before the attack was publicly known.10Please send your vulnerability reports to our security team at security@cognition.ai . ​ Privacy & Intellectual Property How does Cognition use and process data run through and/or accessed by Devin?
11On March 31, 2026, a malicious version of axios (1.14.1) shipped with a hidden dependency on an impersonator package masquerading as crypto-js.11Cognition processes data based on the application Customers use to interact with Devin.
12Devin Review flagged it for multiple Cognition customers about 45 minutes after publication — pinpointing the new dependency, the broken-CI publishing pattern, and the impersonator package, and recommending the PR not be merged.12Devin can be accessed via web application, integration with GitHub, or integration with Slack.
13Read Scott Wu's post → CI/CD Remediation Loop 01 Developer opens PR 02 CI, tests, scanners, and policies run 03 Failure detected 04 Devin investigates, traces root cause, and patches 05 CI reruns 06 Devin iterates until checks pass 07 Human reviewer approves (Devin augmented review) Workflows Investigate and fix failed checks — Add Devin to your CI/CD pipeline so that when a vulnerability is detected, Devin automatically generates a fix and pushes commits directly onto the original PR.13For the web application, Cognition only processes data actively provided by the authorized user prompting Devin; for the GitHub and Slack integrations, the administrator installing the integration can review and manage all permissions granted to Devin.
14Autofix GitHub CI Failures → Launch readiness documentation — Automatically update developer guides, implementation notes, and launch checklists.14Cognition uses Customer data to: Deliver, maintain and update services provided to the Customer per their configuration and type of Devin access (e.g. web application, integration with GitHub, or integration with Slack) to make sure the software is up-to-date and operational.
15Autoupdate Documentation → AI-assisted review before merge — Use Devin Review as a consistent first-pass reviewer on every PR.15Troubleshoot, prevent and resolve issues such as product-related issues, software bugs or security incidents to maintain service functionality and reliability.
16It inspects diffs with codebase context, flags bugs and risky patterns, and with Auto-Fix enabled can push fix commits directly to the branch.16What data retention policy does Cognition maintain?
17Enable Devin Review → 03 Accelerate triage and response Triage slows down when every alert, security finding, or incident requires a human to gather context before remediation can begin.17Cognition only retains data processed through Devin for the duration of the relationship with a given Customer, unless otherwise specified by the Customers.
18Devin helps teams turn alerts into action by taking the first pass across security findings, vulnerability reports, and incident follow-up work.18Any Feedback Data and User Interaction Data are retained as long as needed and as determined by Cognition.
19Alert Triage Flow Trigger sources (Slack, GitHub, Jira, Linear, SIEM, Cloud security tools, PagerDuty, or webhooks).19How is your data used to improve Devin?
20Devin helps teams reduce manual investigation time while keeping remediation inside the same PR, CI/CD, and review controls engineers already use.20By default, we do not use any of your data for model training purposes unless you explicitly opt-in in the Data Controls settings page.
21Devin investigates Gathers code context, identifies root cause, proposes or implements the fix. → Review-ready PR Human reviews and approves.21Devin can still learn to fit into your unique workflow via the Knowledge feature.
22Workflows Findings remediation — Tag Devin in Slack, Jira, Linear, or GitHub to investigate and take a first pass at fixing a security finding.22When you share Knowledge, Devin can become more reliable at working on your specific projects over time.
23Bug Fix via Datadog MCP → Bug Fix via Webhook → Automated alert triage — Trigger Devin from your security scanners or SIEM-style workflows to investigate alerts, identify likely causes, and propose or implement remediation.23If you are an Enterprise customer, we will never train on your data.
24Auto-Investigate Datadog Alerts → Post-incident follow through — After an incident, have Devin draft the first version of the postmortem, summarize contributing factors, and update relevant runbooks and documentation.24Please refer to the terms in your agreement with Cognition for details.
25Autogenerate a Runbook →25What are the main IP considerations regarding the output produced by Devin?
26The output — code, work product, or other — produced by Devin is considered the user’s intellectual property and can be used for the Customer’s commercial purposes, with the exception of using the output to train models that would attempt to reverse engineer and/or build a competing product to Devin.
27Integrating with GitHub When setting up the GitHub integration, users can select which repositories Devin can access, with permissions adjustable through GitHub’s App Settings during and post-installation.
28For more details on the requested permissions and security considerations go to GitHub Integration Guide .
29Integrating with Slack In Slack, Devin doesn’t read, process or store any data in your Slack instance other than the information provided when @Devin is tagged, initially prompted and when any additional information is provided within the Slack thread while the session is ongoing.
30For more details on the requested permissions and security considerations go to Integration with Slack Guide . ​ User Best Practices Devin Limitations While Devin’s performance is improving daily, it can still experience hallucinations, introduce bugs into code, or suggest insecure code or procedures.
31Like with any coding best practices, we recommend taking the appropriate precautions with the code written by Devin such as code reviews, enabling branch protections to ensure checks are enforced before Devin can merge any changes, and any practices currently adopted in your organization to review engineers’ work.
32Secrets You may need to provide Devin with credentials and keys such as passwords, API keys, cookies or other for authentication.
33In all cases we advise users to leverage our Secrets feature under the Settings page to share and store those credentials securely.
34Share Feedback We’re still learning and developing Devin to be a great AI software engineer, and our customers’ feedback is crucial for Devin’s development.
35We strongly encourage sharing feedback and feature requests directly with your Cognition account team or by emailing support@cognition.ai , and reporting incidents by emailing security@cognition.ai .
36Self-Hosted SCM & Artifacts Billing ⌘ I linkedin x Powered by This documentation is built and hosted on Mintlify, a developer documentation platform
Stay ahead of the changes

Watch this before it changes again

Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.