Is Sourcegraph Cody GDPR compliant?
YesSourcegraph · Coding
Yes. Sourcegraph offers a Data Processing Agreement (DPA) for Sourcegraph Cody, the baseline GDPR control when a vendor processes personal data on your behalf.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Data Processing Agreement
- Confirmed
- Sourcegraph publishes a DPA. A DPA is necessary but does not replace your own lawful-basis, DPIA and transfer assessment.
- EU data residency
- Not offered
- No EU-residency option was confirmed in the sources reviewed for this profile.
- Default data training
- No by default
- Sourcegraph and its partner LLMs do not use Cody Enterprise or Pro code to train models. Cody Free and Pro were sunset in July 2025, so the product is now Enterprise-only.
- Business-tier training
- No by default
- Cody Enterprise (self-hosted or single-tenant): the only generally-available tier is the business tier recorded for this profile.
Practical risk: A strong disclosure posture: SOC 2 Type II, ISO 27001:2022, a public DPA and subprocessor list, and a contractual no-training and zero-retention policy. The managed offering is US only (EU residency needs self-hosting).
How to make a decision
Check the precise account tier, written contract and intended data before approving Sourcegraph Cody. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Sourcegraph Cody
Is Sourcegraph Cody HIPAA compliant?Is Sourcegraph Cody SOC 2 compliant?Is Sourcegraph Cody ISO 27001 certified?Does Sourcegraph Cody train on your data?
See the full Sourcegraph Cody risk profile, with every data-handling fact and its source, or browse all rated AI tools.