Is Windsurf HIPAA compliant?
UnverifiedCognition (formerly Codeium) · Coding
Not verified. Check directly with Cognition (formerly Codeium) before using Windsurf with protected health information (PHI).
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Business Associate Agreement
- Not verified
- No public BAA was confirmed. Treat PHI use as blocked until Cognition (formerly Codeium) provides written terms.
- Enterprise route
- Enterprise (SSO plus no-training guarantee); any paid tier can also elect Opt-Out plus Zero Data Retention
- For regulated use, validate the BAA, configured service and users under the Enterprise (SSO plus no-training guarantee); any paid tier can also elect Opt-Out plus Zero Data Retention contract.
- Default data training
- Opt-out required
- Cognition may use customer data for model training by default; the free tier has no stated opt-out.
- Business-tier training
- No by default
- Paid tiers can opt out (which also enables Zero Data Retention); Enterprise carries a no-training guarantee.
Practical risk: Cognition holds SOC 2 Type 2 and ISO 27001, but Windsurf's own terms say customer code may be used for training by default; the opt-out with Zero Data Retention is available only on paid tiers, and free-tier users have no documented opt-out. HIPAA and EU residency are unconfirmed.
How to make a decision
Check the precise account tier, written contract and intended data before approving Windsurf. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Windsurf
Is Windsurf GDPR compliant?Is Windsurf SOC 2 compliant?Is Windsurf ISO 27001 certified?Does Windsurf train on your data?
See the full Windsurf risk profile, with every data-handling fact and its source, or browse all rated AI tools.