Updated: October 6, 2026 · Source-first reference130 documented agents & platforms · No paid rankings
AgentenCode evidence profileCoding
Legacy profile · historical scopeChecked: September 30, 2026

Agent profile · Coding

Windsurf Cascade

This is the historic Windsurf Cascade agent record. Devin Local in Devin Desktop is the successor. Historic evidence, governance and trust scopes remain attached to Windsurf rather than being transferred to Devin automatically.

Source update (2026-10-08): Current lifecycle: Windsurf IDE became Devin Desktop on June 2, 2026, and Devin Local replaced Cascade. Legacy Cascade was supported only through July 1, 2026. Existing Windsurf field-level claims retain their originally documented scope and must not be transferred to Devin Desktop or Devin Local without new evidence. Official primary source ↗

WindsurfCodingDevelopers
Codingeditorial classification
Windsurfprovider
6 primary sourcessource status
September 30, 2026last verification

AgentenTrust 2.0 · EU & governance evidence

Trust, privacy and control evidence for Windsurf Cascade

Direct answer: AgentenCode currently documents 6 of 36 normalized trust controls for this profile. Missing fields remain Unknown and are never automatically interpreted as “no”.

Privacy contextPrivacy & data2 of 8 documentedResidency, training, retention, DPA, subprocessors and processing scope.
Security contextSecurity & access4 of 10 documentedEncryption, SSO, SCIM, RBAC, roles and credential handling.
Human controlHuman control0 of 10 documentedApproval, oversight, permissions and stop or rollback controls.
TraceabilityAudit & traceability0 of 8 documentedAudit logs, APIs, SIEM, observability, tracing and activity history.

Important: these numbers show evidence coverage, not a product rating. 0 of 10 means that no field-level public evidence is stored for those ten controls in the current dataset. It does not mean the product lacks those capabilities.

Field-level evidence

Documented controls and values from primary sources.

Documented yesDocumented valueUnknown remains unknown
High confidence

API · Rest

Yes — documented

Windsurf Enterprise exposes an authenticated analytics API covering Cascade usage.

Scope: windsurf_enterprise_analytics · verified 2026-10-02 · Primary source ↗
High confidence

Governance · RBAC

Yes — documented

Windsurf Enterprise provides RBAC.

Scope: windsurf_enterprise · verified 2026-10-01 · Primary source ↗
High confidence

Governance · SCIM

Yes — documented

Windsurf Enterprise supports SCIM.

Scope: windsurf_enterprise · verified 2026-10-01 · Primary source ↗
High confidence

Hosting · Managed

Yes — documented

Windsurf Cascade is available through a managed cloud deployment.

Scope: windsurf_enterprise_cloud · verified 2026-10-01 · Primary source ↗
High confidence

Hosting · Self Hosted

Yes — documented

Windsurf Enterprise supports self-hosted deployment.

Scope: windsurf_enterprise · verified 2026-10-01 · Primary source ↗
High confidence

Privacy · Data residency · Available

Yes — documented

Windsurf Enterprise provides an EU residency option.

Scope: windsurf_enterprise · verified 2026-10-01 · Primary source ↗
High confidence

Privacy · Data residency · Customer Region Selectable

Yes — documented

Enterprise customers can choose the documented EU cluster deployment option.

Scope: windsurf_enterprise_deployment · verified 2026-10-01 · Primary source ↗
High confidence

Protocols · Mcp · Client

Yes — documented

Cascade can consume capabilities exposed through configured MCP servers.

Scope: windsurf_cascade · verified 2026-10-01 · Primary source ↗
High confidence

Security · Encryption · In transit

Yes — documented

Windsurf documents encryption of customer data in transit.

Scope: windsurf_customer_data · verified 2026-10-01 · Primary source ↗
High confidence

Security · Soc2 Type2

Yes — documented

Windsurf documents SOC 2 Type II compliance.

Scope: windsurf_enterprise · verified 2026-10-01 · Primary source ↗

Evidence-backed overview

What is Windsurf Cascade?

This is the historic Windsurf Cascade agent record. Devin Local in Devin Desktop is the successor. Historic evidence, governance and trust scopes remain attached to Windsurf rather than being transferred to Devin automatically.

Product-specific evidence for Windsurf Cascade

This profile links 6 unique primary sources across the product profile, field-level evidence, trust controls and documented relations. The points below describe this product’s stored evidence rather than generic characteristics of Coding.

Data Residency

Yes · Scope: windsurf_enterprise · verified 2026-10-01.

Primary source ↗

Region auswählbar

Yes · Scope: windsurf_enterprise_deployment · verified 2026-10-01.

Primary source ↗

Verschlüsselung in transit

Yes · Scope: windsurf_customer_data · verified 2026-10-01.

Primary source ↗

SOC 2 Type 2

Yes · Scope: windsurf_enterprise · verified 2026-10-01.

Primary source ↗

RBAC

Yes · Scope: windsurf_enterprise · verified 2026-10-01.

Primary source ↗

SCIM

Yes · Scope: windsurf_enterprise · verified 2026-10-01.

Primary source ↗

AgentenCode treats this page as a reference profile rather than a ranking. Product facts are separated from editorial classification, and the profile is tied to a specific verification date. If a capability is not backed by sufficiently precise public evidence, it remains unknown instead of being inferred from marketing language or from similar products.

1primary source
10field-level evidence claims
6documented trust controls
2history events

How to read the evidence

The field-level evidence layer records a value, a scope, a confidence level, a verification date and one or more primary sources. Scope matters: an enterprise-only security feature must not be generalized to every plan or deployment surface. The same rule applies to hosting, privacy, audit and protocol claims.

AgentenCode also keeps Unknown distinct from false. A missing claim means the public dataset does not currently contain sufficiently precise evidence for that field. A negative value is used only when a reliable primary source explicitly documents a restriction or non-availability.

Decision context

Provider and category

Windsurf Cascade is documented under Coding and is associated with Windsurf. Category labels help navigation but do not replace product-specific evidence.

Verification status

The public profile is marked editorially reviewed and was last checked on September 30, 2026.

Trust coverage

6 of 36 normalized trust controls currently have field-level public evidence. The remaining controls are not treated as negative findings.

Source-first use

For procurement, security or legal decisions, use the linked primary sources and verify the plan, region and configuration that apply to your organization.

Capabilities, strengths and deployment checks for Windsurf Cascade

Windsurf Cascade is classified as IDE-Coding-Agent from Windsurf. The profile’s editorial layer is derived from the stored use cases, strengths and checks below; claims about security, privacy or governance remain separate and require field-level evidence.

Code schreiben

This use case is part of the stored profile for Windsurf Cascade. The related strength is “IDE-zentrierter Agent”. In a production evaluation, the practical boundary to verify is: Agentenaktionen vor Commit prüfen.

Repository verstehen

This use case is part of the stored profile for Windsurf Cascade. The related strength is “Kontext über Codebasis”. In a production evaluation, the practical boundary to verify is: MCP- oder Tool-Zugänge bewusst begrenzen.

Fehler beheben

This use case is part of the stored profile for Windsurf Cascade. The related strength is “Werkzeug- und Terminalnutzung”. In a production evaluation, the practical boundary to verify is: Tests lokal oder in CI bestätigen.

Entwicklungsabläufe beschleunigen

This use case is part of the stored profile for Windsurf Cascade. The related strength is “Agentische Workflows”. In a production evaluation, the practical boundary to verify is: Agentenaktionen vor Commit prüfen.

What to verify before adoption

  • Agentenaktionen vor Commit prüfen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
  • MCP- oder Tool-Zugänge bewusst begrenzen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
  • Tests lokal oder in CI bestätigen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
Editorial boundary: The use-case and strength descriptions are product-specific editorial context based on the stored profile. Trust, privacy and governance statements are only presented as facts when field-level primary-source evidence exists.

Verified history

The public history layer records only confirmed profile changes and verification events. Monitoring signals are not published as product facts until they have been reviewed.

  • September 30, 2026 · Verification Update
  • September 28, 2026 · Schema Upgrade

Official sources

This profile links 6 unique primary sources across the product profile, field-level evidence, trust layer and documented relations. Provider documentation remains authoritative when the product changes between verification cycles.

Frequently asked questions

What is Windsurf Cascade?

Windsurf Cascade is listed by AgentenCode as a coding agent or agentic product from Windsurf.

How much trust evidence is documented for Windsurf Cascade?

The current trust layer documents 6 of 36 normalized controls. Missing controls remain unknown rather than being treated as false.

When was this profile last checked?

The current profile verification date is September 30, 2026. The linked primary sources remain authoritative if the product changes between checks.

Method note: AgentenCode does not certify GDPR or EU AI Act compliance. It documents evidence that can support a separate legal, security or procurement assessment.