Agent profile · Coding
Devin
Devin is classified by AgentenCode as an autonomous software agent from Cognition. It belongs to the Coding category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.
AgentenTrust 2.0 · EU & governance evidence
Trust, privacy and control evidence for Devin
Direct answer: AgentenCode currently documents 6 of 36 normalized trust controls for this profile. Missing fields remain Unknown and are never automatically interpreted as “no”.
Important: these numbers show evidence coverage, not a product rating. 0 of 10 means that no field-level public evidence is stored for those ten controls in the current dataset. It does not mean the product lacks those capabilities.
Field-level evidence
Documented controls and values from primary sources.
API · Rest
Devin exposes a documented HTTPS REST-style API.
Scope: devin_api_v3 · verified 2026-10-01 · Primary source ↗Governance · Audit logs · API
Devin Enterprise exposes audit-related resources through its API.
Scope: devin_enterprise_api · verified 2026-10-01 · Primary source ↗Governance · Audit logs · Available
Devin provides audit trails for human and AI activity.
Scope: devin_enterprise_and_government · verified 2026-10-01 · Primary source ↗Governance · RBAC
Devin Enterprise uses role-based permissions for API/service identities.
Scope: devin_enterprise_api · verified 2026-10-01 · Primary source ↗Hosting · Managed
Devin is available as Cognition's managed Devin Cloud service.
Scope: devin_cloud · verified 2026-10-01 · Primary source ↗Hosting · Private Network
Devin supports private-network access through a dedicated single-tenant VPC with PrivateLink or IPSec connectivity.
Scope: devin_customer_dedicated_deployment · verified 2026-10-02 · Primary source ↗Hosting · Self Hosted
Devin supports on-premises and air-gapped deployment in its government/regulated offering.
Scope: devin_government_onprem_airgapped · verified 2026-10-01 · Primary source ↗Protocols · Mcp · Client
Devin can act as an MCP client for configured external MCP servers.
Scope: devin_sessions · verified 2026-10-02 · Primary source ↗Security · Encryption · At rest
Current Devin documentation explicitly states customer data is encrypted at rest.
Scope: devin_customer_dedicated_deployment · verified 2026-10-02 · Primary source ↗Security · Encryption · In transit
Current Devin documentation explicitly states customer data is encrypted in transit.
Scope: devin_customer_dedicated_deployment · verified 2026-10-02 · Primary source ↗Security · Soc2 Type2
Devin documents SOC 2 Type II compliance.
Scope: devin_platform · verified 2026-10-01 · Primary source ↗Evidence-backed overview
What is Devin?
Devin is classified by AgentenCode as an autonomous software agent from Cognition. It belongs to the Coding category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.
Product-specific evidence for Devin
This profile links 5 unique primary sources across the product profile, field-level evidence, trust controls and documented relations. The points below describe this product’s stored evidence rather than generic characteristics of Coding.
Verschlüsselung at rest
Yes · Scope: devin_customer_dedicated_deployment · verified 2026-10-02.
Primary source ↗Verschlüsselung in transit
Yes · Scope: devin_customer_dedicated_deployment · verified 2026-10-02.
Primary source ↗AgentenCode treats this page as a reference profile rather than a ranking. Product facts are separated from editorial classification, and the profile is tied to a specific verification date. If a capability is not backed by sufficiently precise public evidence, it remains unknown instead of being inferred from marketing language or from similar products.
How to read the evidence
The field-level evidence layer records a value, a scope, a confidence level, a verification date and one or more primary sources. Scope matters: an enterprise-only security feature must not be generalized to every plan or deployment surface. The same rule applies to hosting, privacy, audit and protocol claims.
AgentenCode also keeps Unknown distinct from false. A missing claim means the public dataset does not currently contain sufficiently precise evidence for that field. A negative value is used only when a reliable primary source explicitly documents a restriction or non-availability.
Decision context
Provider and category
Devin is documented under Coding and is associated with Cognition. Category labels help navigation but do not replace product-specific evidence.
Verification status
The public profile is marked editorially reviewed and was last checked on September 30, 2026.
Trust coverage
6 of 36 normalized trust controls currently have field-level public evidence. The remaining controls are not treated as negative findings.
Source-first use
For procurement, security or legal decisions, use the linked primary sources and verify the plan, region and configuration that apply to your organization.
Capabilities, strengths and deployment checks for Devin
Devin is classified as Autonomer Software-Agent from Cognition. The profile’s editorial layer is derived from the stored use cases, strengths and checks below; claims about security, privacy or governance remain separate and require field-level evidence.
Backlog-Aufgaben
This use case is part of the stored profile for Devin. The related strength is “Stark delegierbares Arbeiten”. In a production evaluation, the practical boundary to verify is: Aufgaben klar abgrenzen.
Migrationen
This use case is part of the stored profile for Devin. The related strength is “Eigene Entwicklungsumgebung”. In a production evaluation, the practical boundary to verify is: Repository- und Systemzugänge minimal halten.
Bugfixes
This use case is part of the stored profile for Devin. The related strength is “Mehrstufige Aufgaben”. In a production evaluation, the practical boundary to verify is: Ergebnisse und Tests menschlich abnehmen.
Engineering-Automation
This use case is part of the stored profile for Devin. The related strength is “Für Team-Backlogs gedacht”. In a production evaluation, the practical boundary to verify is: Aufgaben klar abgrenzen.
What to verify before adoption
- Aufgaben klar abgrenzen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
- Repository- und Systemzugänge minimal halten. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
- Ergebnisse und Tests menschlich abnehmen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
Verified history
The public history layer records only confirmed profile changes and verification events. Monitoring signals are not published as product facts until they have been reviewed.
- September 30, 2026 · Verification Update
- September 28, 2026 · Schema Upgrade
Official sources
This profile links 5 unique primary sources across the product profile, field-level evidence, trust layer and documented relations. Provider documentation remains authoritative when the product changes between verification cycles.
- Cognition – Devin
- Devin Docs – API Authentication
- Devin Government
- Devin Docs – Enterprise Deployment
- Devin Docs – Devin MCP servers and marketplace
Frequently asked questions
What is Devin?
Devin is listed by AgentenCode as a coding agent or agentic product from Cognition.
How much trust evidence is documented for Devin?
The current trust layer documents 6 of 36 normalized controls. Missing controls remain unknown rather than being treated as false.
When was this profile last checked?
The current profile verification date is September 30, 2026. The linked primary sources remain authoritative if the product changes between checks.
