Is Devin SOC 2 compliant?
YesCognition · Coding
Yes. Cognition holds a SOC 2 report covering Devin, which gives independent assurance over its security controls.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- SOC 2 report
- Confirmed
- Cognition reports a SOC 2 attestation. Request the current report and relevant bridge letter during procurement.
- ISO 27001
- Confirmed
- Cognition also reports ISO/IEC 27001 certification.
- Default data training
- Opt-out required
- By default Cognition may use non-Enterprise data for model training; toggle off in Devin's Data Controls settings (also enables Zero Data Retention). On the Team plan only admins can toggle it.
- Business-tier training
- No by default
- Enterprise customers are never trained on without express prior written consent.
Practical risk: Devin holds SOC 2 Type II and ISO 27001:2022 with a downloadable DPA and dated all-US subprocessor list. But non-Enterprise customers are opted into model training by default and must turn it off, and there is no EU residency or confirmed BAA.
How to make a decision
Check the precise account tier, written contract and intended data before approving Devin. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Devin
Is Devin HIPAA compliant?Is Devin GDPR compliant?Is Devin ISO 27001 certified?Does Devin train on your data?
See the full Devin risk profile, with every data-handling fact and its source, or browse all rated AI tools.