| Before | After | ||
|---|---|---|---|
| 0 | 01 Reduce your security debt Security debt grows when known issues are easy to identify but hard to safely fix. | 0 | On this page Security Privacy & Intellectual Property User Best Practices Admin Security at Cognition Copy page We want Devin to be a core contributor in your organization, and have prioritized security, data privacy and compliance to make it possible Copy page Security Secure Transmission and Encryption All data transmission is encrypted in transit and at rest. |
| 1 | Devin helps teams turn that backlog into maintained code by taking on remediation work across vulnerabilities, dependency updates, insecure configurations, and repeated patterns across one or many repos. | 1 | Production software is also routinely monitored via logging, error handling and monitoring dashboards of live metrics. |
| 2 | Run on demand or on a schedule, Devin helps security teams reduce backlog pressure while keeping fixes inside engineering's existing review process. | 2 | Unusual application states (i.e. unusually high error rates, slowness, failures) trigger alerts which are quickly investigated by our team. |
| 3 | Customer proof — Itaú ~70% of SonarQube, Fortify, and Veracode vulnerabilities resolved automatically. | 3 | Access to our cloud environment in AWS is granted on an as-required basis based on business roles and only a small number of employees or contractors are granted direct access to production systems. |
| 4 | Itaú used Devin to clear a large vulnerability backlog across their scanner findings, reducing remediation burden on their engineering teams at scale. | 4 | General Security Practices All employees and contractors are required to use multi-factor authentication on all main work applications. |
| 5 | Read the case study → Workflows Clear backlog — Address large backlogs across one or many repos, such as stored credentials, insecure configurations, missing best-practice updates, or outdated security patterns. | 5 | All employees and contractors also receive annual training about security best practices, including good password management and how to identify social engineering and phishing scams. |
| 6 | Snyk Vulnerability Burn Down → Routine work — Set Devin to run on a recurring basis to handle routine security maintenance, such as remediating CVEs, performing dependency bumps, or patching SAST/SCA findings. | 6 | Third-party audits and certification Cognition obtained SOC 2 Type II certification and conducted Security Training in March 2024 for all employees at Cognition. |
| 7 | Daily Sentry Error Fixes → Weekly Dependency Update → Risk identification — Run Devin across your repos to find what your scanners miss: logic flaws, insecure patterns, missing auth checks, and chained low-severity CVEs that become critical in context. | 7 | As part of the SOC 2 audit, Cognition’s auditors reviewed all of Cognition’s security policies, procedures, internal and third party controls related to data security, privacy, processing integrity, confidentiality and availability. |
| 8 | Daily Design Audit → 02 Secure every release Devin helps teams turn blocked PRs and failed checks into review-ready fixes by taking on remediation work across failing tests, insufficient coverage, dependency vulnerabilities, and CI/CD or security check failures. | 8 | For more details about our security please visit our Trust Center . |
| 9 | Triggered from PRs, CI/CD, or on demand, Devin helps teams keep releases moving while keeping fixes inside engineering's existing review and merge process. | 9 | Vulnerability Disclosure Program If you have identified a potential security issue, we encourage you to share your findings with us. |
| 10 | In the wild — axios supply-chain attack Caught in under an hour, before the attack was publicly known. | 10 | Please send your vulnerability reports to our security team at security@cognition.ai . Privacy & Intellectual Property How does Cognition use and process data run through and/or accessed by Devin? |
| 11 | On March 31, 2026, a malicious version of axios (1.14.1) shipped with a hidden dependency on an impersonator package masquerading as crypto-js. | 11 | Cognition processes data based on the application Customers use to interact with Devin. |
| 12 | Devin Review flagged it for multiple Cognition customers about 45 minutes after publication — pinpointing the new dependency, the broken-CI publishing pattern, and the impersonator package, and recommending the PR not be merged. | 12 | Devin can be accessed via web application, integration with GitHub, or integration with Slack. |
| 13 | Read Scott Wu's post → CI/CD Remediation Loop 01 Developer opens PR 02 CI, tests, scanners, and policies run 03 Failure detected 04 Devin investigates, traces root cause, and patches 05 CI reruns 06 Devin iterates until checks pass 07 Human reviewer approves (Devin augmented review) Workflows Investigate and fix failed checks — Add Devin to your CI/CD pipeline so that when a vulnerability is detected, Devin automatically generates a fix and pushes commits directly onto the original PR. | 13 | For the web application, Cognition only processes data actively provided by the authorized user prompting Devin; for the GitHub and Slack integrations, the administrator installing the integration can review and manage all permissions granted to Devin. |
| 14 | Autofix GitHub CI Failures → Launch readiness documentation — Automatically update developer guides, implementation notes, and launch checklists. | 14 | Cognition uses Customer data to: Deliver, maintain and update services provided to the Customer per their configuration and type of Devin access (e.g. web application, integration with GitHub, or integration with Slack) to make sure the software is up-to-date and operational. |
| 15 | Autoupdate Documentation → AI-assisted review before merge — Use Devin Review as a consistent first-pass reviewer on every PR. | 15 | Troubleshoot, prevent and resolve issues such as product-related issues, software bugs or security incidents to maintain service functionality and reliability. |
| 16 | It inspects diffs with codebase context, flags bugs and risky patterns, and with Auto-Fix enabled can push fix commits directly to the branch. | 16 | What data retention policy does Cognition maintain? |
| 17 | Enable Devin Review → 03 Accelerate triage and response Triage slows down when every alert, security finding, or incident requires a human to gather context before remediation can begin. | 17 | Cognition only retains data processed through Devin for the duration of the relationship with a given Customer, unless otherwise specified by the Customers. |
| 18 | Devin helps teams turn alerts into action by taking the first pass across security findings, vulnerability reports, and incident follow-up work. | 18 | Any Feedback Data and User Interaction Data are retained as long as needed and as determined by Cognition. |
| 19 | Alert Triage Flow Trigger sources (Slack, GitHub, Jira, Linear, SIEM, Cloud security tools, PagerDuty, or webhooks). | 19 | How is your data used to improve Devin? |
| 20 | Devin helps teams reduce manual investigation time while keeping remediation inside the same PR, CI/CD, and review controls engineers already use. | 20 | By default, we do not use any of your data for model training purposes unless you explicitly opt-in in the Data Controls settings page. |
| 21 | Devin investigates Gathers code context, identifies root cause, proposes or implements the fix. → Review-ready PR Human reviews and approves. | 21 | Devin can still learn to fit into your unique workflow via the Knowledge feature. |
| 22 | Workflows Findings remediation — Tag Devin in Slack, Jira, Linear, or GitHub to investigate and take a first pass at fixing a security finding. | 22 | When you share Knowledge, Devin can become more reliable at working on your specific projects over time. |
| 23 | Bug Fix via Datadog MCP → Bug Fix via Webhook → Automated alert triage — Trigger Devin from your security scanners or SIEM-style workflows to investigate alerts, identify likely causes, and propose or implement remediation. | 23 | If you are an Enterprise customer, we will never train on your data. |
| 24 | Auto-Investigate Datadog Alerts → Post-incident follow through — After an incident, have Devin draft the first version of the postmortem, summarize contributing factors, and update relevant runbooks and documentation. | 24 | Please refer to the terms in your agreement with Cognition for details. |
| 25 | Autogenerate a Runbook → | 25 | What are the main IP considerations regarding the output produced by Devin? |
| 26 | The output — code, work product, or other — produced by Devin is considered the user’s intellectual property and can be used for the Customer’s commercial purposes, with the exception of using the output to train models that would attempt to reverse engineer and/or build a competing product to Devin. | ||
| 27 | Integrating with GitHub When setting up the GitHub integration, users can select which repositories Devin can access, with permissions adjustable through GitHub’s App Settings during and post-installation. | ||
| 28 | For more details on the requested permissions and security considerations go to GitHub Integration Guide . | ||
| 29 | Integrating with Slack In Slack, Devin doesn’t read, process or store any data in your Slack instance other than the information provided when @Devin is tagged, initially prompted and when any additional information is provided within the Slack thread while the session is ongoing. | ||
| 30 | For more details on the requested permissions and security considerations go to Integration with Slack Guide . User Best Practices Devin Limitations While Devin’s performance is improving daily, it can still experience hallucinations, introduce bugs into code, or suggest insecure code or procedures. | ||
| 31 | Like with any coding best practices, we recommend taking the appropriate precautions with the code written by Devin such as code reviews, enabling branch protections to ensure checks are enforced before Devin can merge any changes, and any practices currently adopted in your organization to review engineers’ work. | ||
| 32 | Secrets You may need to provide Devin with credentials and keys such as passwords, API keys, cookies or other for authentication. | ||
| 33 | In all cases we advise users to leverage our Secrets feature under the Settings page to share and store those credentials securely. | ||
| 34 | Share Feedback We’re still learning and developing Devin to be a great AI software engineer, and our customers’ feedback is crucial for Devin’s development. | ||
| 35 | We strongly encourage sharing feedback and feature requests directly with your Cognition account team or by emailing support@cognition.ai , and reporting incidents by emailing security@cognition.ai . | ||
| 36 | Self-Hosted SCM & Artifacts Billing ⌘ I linkedin x Powered by This documentation is built and hosted on Mintlify, a developer documentation platform | ||
Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.