
Devin
Devin is an autonomous AI software engineer from Cognition AI. Parallel cloud agents plan, write, test and ship production code inside your own repositories, reachable from the web app, a desktop client, a CLI, JetBrains and an API.
What is Devin?
Devin is presented as "the AI software engineer": an autonomous coding agent built by Cognition AI, Inc., an independent agent lab that says it works with every foundation model lab rather than betting on one. The promise is not autocompletion. Devin plans, writes, tests and ships production code on its own, inside your codebase and the tools your team already uses.
It reaches you through four surfaces. Devin Cloud runs parallel agents in secure cloud VMs. Devin Desktop, the former Windsurf, is an IDE and agent command centre for Mac, Windows and Linux. Devin CLI puts the same agent in the terminal, and a JetBrains plugin covers IntelliJ IDEA, PyCharm and WebStorm. A public API and Devin Review complete the set.
Around those surfaces sit named modules. DeepWiki indexes and maps the codebase, Ask Devin explores it in natural language, Devin Review handles pull request review and visual QA, Devin Automations fires runs from events, Security Swarm hunts and remediates vulnerabilities, and a Devin Windows VM covers Windows workloads. MultiDevin lets manager Devins supervise worker Devins so a large backlog can be split across a fleet.
Devin is deliberately model-agnostic: it routes between frontier models from Anthropic, OpenAI, Google and Cognition, including Cognition's own SWE-1.7. It learns the codebase, absorbs a team's tacit knowledge, and improves by replaying the trajectories of its past sessions. Computer use gives it a browser, a terminal and a graphical interface, so it verifies its own work on Linux, Windows or Android.
The claimed use cases run from PR review and visual QA to documentation, migrations and refactors (COBOL, .NET, Talend, legacy ETL), scheduled tasks, incident triage, bug fixing, testing, performance work and web research. Cognition publishes numbers behind them: 89% of the code its own engineers commit is written by Devin, annual recurring revenue reached USD 492 million, and enterprise usage grew more than tenfold since the start of the year. Named customers include Nubank, Itaú, Ramp, athenahealth, Anduril, Mercedes-Benz, Citi, Goldman Sachs, Dell, Santander, the U.S. Army and the U.S. Navy. Devin nonetheless stays a developer tool, assuming a repository and human approval before merge.
What it does
- Plan and run complex engineering tasks end to end, from code migrations to on-call incident resolution
- Find and fix bugs automatically, with visual QA driven by full browser and desktop use
- Review pull requests by organising code diffs intelligently before a human looks at them
- Assign a fleet of agents to migrate every repository in parallel
- Generate documentation and system diagrams for undocumented legacy codebases
- Investigate Datadog incidents, route Slack bug reports and repair failing CI builds
- Schedule daily QA runs and release notes, write unit and end-to-end tests, optimise performance and automate repetitive browser research
When to use Devin / When not to
A quick filter to help you decide if Devin is the right fit.
When to use Devin
- Engineering teams running complex, multi-repository projects who want several tickets worked in parallel rather than one agent at a time
- Modernisation teams facing large-scale migrations and refactors, including COBOL, .NET, Talend and legacy ETL pipelines
- Teams that want pull request review, visual QA, test generation and documentation of legacy codebases handled automatically, with DeepWiki mapping the code first
- On-call and application security teams: incident triage from Datadog, Slack, Linear and failing CI builds, plus Security Swarm remediation credited with 72% recall on 50 real GHSA vulnerabilities
- Regulated enterprises in banking, government, defence and healthcare that need a VPC deployment, with cited customers including Citi, Santander, Nubank, Elevance, Mercedes-Benz, the U.S. Army and the U.S. Navy
When not to use Devin
- Non-technical users: the whole product assumes a code repository, a CI pipeline and an established pull request review habit
- Mobile-first or consumer users: there is no iOS or Android application, and no App Store or Google Play listing anywhere on the site
- Free-plan users who need their data kept out of model training: the opt-out in clause 3.3.1 of the terms is reserved for paid tiers
- Small teams that need enterprise controls on a small budget: VPC, SAML/OIDC SSO, centralised admin controls and dedicated deployment are Enterprise-only, and concurrent sessions are capped at 10 on Free, Pro and Max
- Organisations bound by strict European data residency: every disclosed subprocessor sits outside the EU, in the United States plus India for a support flow
How to use Devin
A typical end-to-end flow, from setup to results.
- Sign up at app.devin.ai/signup, or log in at app.devin.ai/login, and link the git provider that holds your code: GitHub, GitLab, Bitbucket or a custom provider
- Let DeepWiki index the repository, which takes minutes, so Devin knows the structure, the dependencies and the undocumented business logic before it touches anything
- Pick your surface: the Devin Cloud web app, Devin Desktop for Mac (Apple Silicon or Intel), Windows (x64 or arm64) and Linux, the Devin CLI installed with curl -fsSL https://cli.devin.ai/install.sh | bash, or the JetBrains plugin for IntelliJ IDEA, PyCharm and WebStorm
- Connect the tools your team already lives in: Slack, Microsoft Teams, Linear and Jira
- Assign the work as you would to a colleague: mention Devin in a Slack or Teams thread to pull context, dig into a problem or turn a discussion into a PR, or hand over a Linear ticket or a Devin label
- Let Devin run autonomously through the task, using the browser, terminal and desktop it needs to verify its own work
- Review the pull request it opens and merge natively, exactly as with a human contributor; Devin takes review comments and CI results into account until the branch lands
- Keep a human in the loop to steer and approve the changes, as the published Nubank case explicitly recommends
- Scale out with Devin Automations and the Devin API: trigger runs from Slack mentions, Linear tickets, CI failures, Snyk alerts or PagerDuty incidents
- Get help through the in-app chat at app.devin.ai/settings/support once logged in, the documentation at docs.devin.ai, or support@cognition.ai
Pros & Cons
Pros
- Covers the whole development cycle rather than a slice of it: planning, code, tests, review, delivery, incident response and security remediation
- Real parallelism, with a fleet of agents able to work every repository at once and unlimited concurrent sessions from the Teams plan upwards
- Model-agnostic routing across Anthropic, OpenAI, Google and Cognition models instead of a single imposed engine, with SWE-1.7 and leading open-source models free on paid tiers
- Slots into existing tooling (GitHub, GitLab, Bitbucket, Slack, Microsoft Teams, Linear, Jira) instead of imposing yet another dashboard
- Unusually detailed public security and compliance material: SOC 2 Type II and ISO 27001 audited annually by independent third parties, TLS 1.2 or above, AES-256, annual penetration test, bug bounty, audit logs kept at least a year, and a public DPA naming every subprocessor and its location
- Documented training opt-out with Zero Data Retention at the model providers on paid tiers, and a VPC deployment where Cognition states it cannot read the Customer Data Plane
- Low barrier to entry with a permanent free plan and a USD 20 per month paid tier, published and quantified customer results, and a productivity guarantee worth up to USD 10 million in credits for eligible Enterprise customers
Cons
- Real cost is not predictable from the pricing grid: quotas refill daily and weekly, and the site states that the cost per message varies with the model, the size and complexity of the task and the reasoning required
- Usage beyond the included quota is billed at API pricing, a rate that is not published on the pricing page
- Concurrent sessions are capped at 10 on Free, Pro and Max, while VPC, SAML/OIDC SSO, centralised admin controls and dedicated deployment are Enterprise-only
- The training opt-out is a paid-tier privilege: on the free plan, Customer Data can be used to train models
- The site contradicts itself on the minimum age, with terms of 30 June 2026 setting 13 years and a privacy policy of 9 March 2026 stating that the terms require 18
- No European data residency option is published, every subprocessor being in the United States plus India for support, and there is no iOS or Android application
- The licences granted to Cognition over Customer Data in clause 3.2 are broad, being worldwide, royalty-free, sublicensable and extended to affiliates and assigns, while the terms still point to a third entity, Exafunction, Inc., for some unassigned licences
Pricing & Plans
Devin offers a permanent free plan at USD 0, and there is no time-limited free trial. The lowest paid entry point is the Pro plan at USD 20.00 per month, billed monthly in US dollars. Higher tiers are Max at USD 200 per month, Teams at USD 80 per month for the team plan plus USD 40 per month for each full developer seat, and Enterprise on quotation. Prospective buyers should note that quotas refill automatically on a daily and weekly basis, that the cost per message varies with the model, the size and complexity of the task, and that any usage beyond the included allowance is charged at API pricing.
- USD 0 per month
- 1 member. A light usage quota for coding with agents
- limited model availability
- unlimited Tab completions and unlimited inline edits
- up to 10 concurrent sessions.
- USD 20 per month
- 1 member. Everything in Free plus increased quotas
- access to frontier models from OpenAI
- Claude and Gemini
- full model availability
- SWE-1.7 and open-source models at no extra cost
- access to cloud agents on Devin Cloud
- the option to buy extra usage at API pricing
- USD 200 per month
- 1 member. Everything in Pro with significantly higher quotas
- aimed at heavy users.
- USD 80 per month for the team plan plus USD 40 per month per full user
- unlimited members. Sharing and collaboration
- centralised billing
- an admin dashboard with analytics
- priority support and unlimited concurrent sessions.
- on quotation. Everything in Teams plus highest-priority support
- dedicated account management
- SAML/OIDC SSO
- centralised enterprise admin controls
- dedicated deployment and VPC options
- teamspace isolation
- custom contractual terms and early access to new releases.
- Devin Desktop
- unlimited Tab
- DeepWiki
- the Devin API and Ask Devin
- with integrations for Slack and Microsoft Teams
- Linear and Jira
- GitHub
- GitLab and Bitbucket
Data, GDPR & hosting
A consolidated view of how Devin handles your data.
GDPR overview
GDPR is addressed through documents rather than a marketing claim. The public data processing statement incorporates by reference the standard contractual clauses adopted by the European Commission on 4 June 2021, using module 2 or 3 depending on the customer's role, and defines EU/UK Privacy Laws as GDPR 2016/679, Directive 2002/58/EC, the UK Data Protection Act 2018 and the UK GDPR: "Licensor and Customer each agree to comply with their respective obligations under Data Protection Laws." Transfers to the EU, the UK and the United States rely on those clauses plus the UK IDTA addendum. The privacy policy of 9 March 2026 grants access and portability, erasure, rectification, objection, restriction, consent withdrawal, appeal and complaint rights, exercised at privacy@cognition.ai with possible identity verification. Two gaps: no Article 27 EU representative and no named DPO. The SCC annex lists Cognition AI, Inc. as processor and data importer.
Who owns the data?
Clause 1.2 of the terms defines Customer Data as the inputs you submit plus the data the Service generates and makes available to you, and clause 1.1 states that Cognition IP expressly excludes Customer Data: "For the avoidance of doubt, Cognition IP does not include Customer Data." The Enterprise page is blunt about it: "All inputs and outputs are your intellectual property." Ownership therefore stays with the customer. In return, clause 3.2 grants Cognition, its affiliates, successors and assigns a non-exclusive, worldwide, royalty-free, fully paid and sublicensable licence over that data. Under a VPC deployment, data stays in your controlled environment and Cognition states it cannot access the Customer Data Plane.
Reuse rights
Because inputs and outputs remain the customer's intellectual property, generated code can be reused, modified, shipped and resold without asking Cognition for permission. The reverse direction is where the detail matters. Clause 3.3.1 allows Cognition to use Customer Data to train models and improve the Services, and offers a way out only to paying customers: "If you subscribe to a paid Service Tier, you may opt out of this use (“Opt-Out”). Following an Opt-Out election: (A) Customer Data will not be used for any other purpose, including training language models; and (B) Zero Data Retention will be enabled with our model providers." On Enterprise, data is never used for training, and section 4 of the data processing statement extends equivalent restrictions to subprocessors, by contract or by technical configuration. The privacy policy relies on legitimate interest to train, fine-tune and improve models "depending on the terms that apply to your use of the Services". No data is sold or shared for targeted advertising, neither today nor over the past twelve months, and the privacy choices page adds a CCPA/CPRA opt-out that honours Global Privacy Control and blocks Meta, Reddit, X, LinkedIn, Bing and Google pixels when enabled.
Data retention & training
Hosting summary
Cognition splits the architecture into a Licensor Control Plane, which drives the service, and a Data Plane, which runs the compute. That Data Plane can be a Customer Data Plane inside the customer's own cloud account or a Licensor Data Plane, and Cognition states it cannot access Customer Data stored on the Customer Data Plane. Enterprise customers can deploy inside their own VPC, with support for all major clouds. Appendix C of the data processing statement names every subprocessor and its location: Microsoft Azure, AWS, Google Cloud, Auth0, Hex, Sentry, Datadog, Zendesk, Pylon and Decagon, all in the United States, plus Agumbe, or Cognition India, in India for a support flow. Model providers receiving inputs that contain personal data are OpenAI, Anthropic, Microsoft Azure and Google Vertex in the United States, with Databricks, xAI and Snowflake added only when enabled in Devin Desktop. Cloud and on-site data centres are reviewed regularly for ISO 27001 and SOC 2 conformity, traffic is encrypted with TLS 1.2 or above and data at rest with AES-256 or equivalent, and transfers between the EU, the UK and the United States rely on the standard contractual clauses and the UK IDTA addendum.
Things to keep in mind
Risks and trade-offs to weigh before adopting Devin.
- Spending is hard to forecast: quotas and cost per message depend on the model, the size and the complexity of the task, and anything above the allowance is billed at API pricing, a rate absent from the pricing page. Budget from measured usage, not from the grid.
- Training is on by default. Clause 3.3.1 allows Customer Data to be used to train models, and the opt-out is open only to paid tiers, so free-plan experiments with proprietary code carry a real exposure.
- The licence granted over Customer Data in clause 3.2 is broad: non-exclusive but worldwide, royalty-free, sublicensable and extended to affiliates, successors and assigns. Have counsel read it before pushing sensitive repositories through the service.
- The two contractual documents disagree on the minimum age, with terms of 30 June 2026 requiring 13 years and a privacy policy of 9 March 2026 stating 18. The terms may also designate a third entity, Exafunction, Inc., for licences not reassigned to Cognition AI, Inc., so the contracting party is not always obvious.
- No subprocessor sits in the European Union, hosting being in the United States plus India for a support flow, and no Article 27 EU representative is designated even though the service is sold to European customers.
- Disputes go to mandatory arbitration under New York law, with arbitration notices sent to 550 Third Street, San Francisco, which is a long way from a European buyer's usual forum.
- An autonomous agent writing production code invites two human failures: reviewers rubber-stamping pull requests they no longer read closely, and teams losing familiarity with a codebase an agent maintains. The site itself insists a human stays in the loop to approve changes, and the terms disclaim liability for the consequences of using outputs, including security posture and vulnerability assessments.
Setup & Integrations
Technical difficulty
Low to start, higher to industrialise. Cloud use needs no installation: sign up and connect a git provider. Devin Desktop is a direct download for Mac, Windows and Linux with published prerequisites, the CLI is a single curl command advertised as under a minute, and a JetBrains plugin covers the main IDEs. The real prerequisites are organisational: a repository, a connected git provider, a pull request review practice and connected team tools. Enterprise raises the bar with VPC deployment, SAML 2.0 identity provider integration and SCIM, supported by an optional onboarding call and a forward deployed engineer.
Deployment
Integrations
Supported languages
Behind Devin
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Devin.
Frequently asked questions
Is there a free plan, and what does it include?
How much does Devin cost?
How does usage work, and what happens when I hit my limit?
How can I make my quota last longer?
What is Devin Desktop?
Is there an API?
Is my data used to train models?
Which security certifications does Cognition hold, and where is data hosted?
Can Devin run inside my own infrastructure?
How long is my data kept, and is there any guarantee on results?
Should you pick Devin?
Devin is a mature, heavily funded product rather than an experiment: over USD 1 billion raised at a USD 26 billion valuation, USD 492 million in announced annualised revenue, and adoption claimed across regulated banks, government agencies, healthcare and systems integrators. Its positioning is clear and deliberately ambitious. This is not autocompletion but autonomous software engineering at enterprise scale, with parallel agents, PR review, migrations, incident triage and security remediation packaged around a codebase Devin indexes and learns.
The compliance story is unusually solid for the category. SOC 2 Type II and ISO 27001 audited annually, a public data processing statement naming every subprocessor and its location, standard contractual clauses incorporated by reference, a documented deletion window and a VPC option where Cognition states it cannot read your data plane. Buyers who normally have to chase this material by email will find most of it published.
The reservations are just as concrete. The pricing grid does not let you predict real spend, since quotas depend on model, task size and complexity, and overage is billed at an API rate that is not published. Keeping your data out of model training is a paid-tier privilege, not a default. There is no European data residency option and no Article 27 representative, which matters for EU buyers. And the site contradicts itself on the minimum age, with terms saying 13 and the privacy policy saying 18.
Entry is genuinely easy: a permanent free plan, then USD 20 per month for Pro. Try it on a real repository, measure what it actually consumes before committing a team budget, and keep a human reviewing every pull request it opens, as Cognition itself recommends.
- Choosing a selection results in a full page refresh.
- Opens in a new window.