No. Cognition publishes no HIPAA Business Associate Agreement for Devin, Devin CLI or Devin Desktop on any plan, and its Acceptable Use Policy places protected health information in the Prohibited Data category. The Enterprise Master Services Agreement goes further and tells customers not to submit PHI to the Services at all. If your team has already pasted patient data into a Devin session, the work is finding out where that text went and rebuilding the workflow without it — six to ten weeks.
| Fact | Value |
|---|---|
| Tool | Devin |
| Verdict | No |
| Sources checked | August 2026 |
| Typical range | $13,000–$25,000 |
| Typical timeline | 6–10 weeks |
| Last updated | August 2026 |
Which Devin surfaces a BAA reaches
On other pages in this series this table separates covered products from uncovered ones. Here there is nothing to separate. No Cognition document names any product as covered by a HIPAA Business Associate Agreement, because no such agreement is published. The two prohibitions that do exist are written at the level of "the Services" rather than per product, so they land on every surface below equally — including the ones that carry checkmarks on Cognition's federal compliance table. FedRAMP High, IL4, IL5, ITAR, SOC 2 Type II and ISO/IEC 27001:2022 are real and are Cognition's own published claims. None of them is a BAA, and none of them makes PHI permissible under terms that prohibit it.
Your PHI
Your Devin app
Outside it — PHI here is a gap
- Devin (the autonomous cloud agent)
- Devin CLI
- Devin Desktop (formerly Windsurf)
- Devin Desktop Next
- Devin Review
- Windsurf Plugins
- Devin Outposts
- Enterprise Cloud
- Customer Dedicated Deployment
- Enterprise Assured Deployment
- No self-hosted tier is documented (contract text disagrees)
| Service | Under the BAA | Condition |
|---|---|---|
| Devin (the autonomous cloud agent) | Not covered | Runs in Cognition's cloud. On Cognition's own federal compliance table this is the least accredited surface of the three: FedRAMP High, IL4 and IL5 all read "In Process" for Devin, against a checkmark for Devin CLI and Devin Desktop. |
| Devin CLI | Not covered | Carries checkmarks for FedRAMP High, IL4 and IL5 on Cognition's federal compliance table, where Devin itself reads "In Process". That table describes Cognition's federal deployment running on AWS GovCloud, not the commercial CLI a developer installs — and an accreditation is not an agreement about PHI in any case. The Acceptable Use Policy applies here the same way. |
| Devin Desktop (formerly Windsurf) | Not covered | Renamed from Windsurf on 2 June 2026. The Windsurf-era security page that mentioned a BAA does not exist under this brand; nothing equivalent replaced it. |
| Devin Desktop Next | Not covered | No product-specific HIPAA document exists for this or any other Devin surface. The prohibition is written against "the Services", so it covers surfaces we have no separate page for. |
| Devin Review | Not covered | Same position. Nothing product-specific exists to read; the general prohibition applies. |
| Windsurf Plugins | Not covered | Still a distinct product line in Cognition's current documentation, with no reference to the Devin Desktop rename on its own pages. Same terms apply. |
| Devin Outposts | Not covered | The most misread surface. Sessions execute on machines you operate, but Cognition's own documentation says the agent loop — inference and planning — continues to run in Devin's cloud. The part that receives your prompt does not move. |
| Enterprise Cloud | Not covered | Cognition's documentation states that both Devin's brain and Devbox run in its multi-tenant cloud. |
| Customer Dedicated Deployment | Not covered | Single-tenant VPC, still hosted by Cognition. Tenancy isolation is not a Business Associate Agreement, and the Enterprise MSA prohibition applies to Enterprise customers by definition. |
| Enterprise Assured Deployment | Not covered | Adds Customer Managed Keys via AWS KMS and is contact-sales only. It is the nearest thing to a compliance-grade commercial tier, and it still does not come with a published BAA. |
| No self-hosted tier is documented (contract text disagrees) | Unconfirmed | Windsurf documented an Enterprise Self-hosted tier where compute and retention stayed inside a customer-managed tenant. No self-hosted, on-premises or air-gapped tier appears anywhere in Cognition's current product documentation. The contractual Security Exhibit, however, still describes a Data Plane that may be deployed in the customer's own cloud account. The documents disagree, so we are not going to tell you it is gone — ask Cognition directly and get the answer in the contract. |
These readings are from August 2026. The Acceptable Use Policy carried "Last Updated: June 30, 2026", the Master Services Agreement "Last updated: June 8, 2026", and the security page at cognition.com/legal/security "Last updated: June 11, 2026". Every one of those documents is younger than this question is old. The Windsurf security page that offered to entertain a BAA was live on 17 May 2026 and did not survive the 2 June rebrand. Re-read the Acceptable Use Policy and the Master Services Agreement yourself before you rely on this table, and save a dated copy of what you read.
Why other pages say Windsurf offers HIPAA BAAs
What secondary sources say
Comparison articles through mid-2026 credit this platform with the strongest compliance posture among AI code editors: SOC 2 Type II, FedRAMP High accreditation, and HIPAA compliance with BAAs available. Those articles are not inventing it. Windsurf's own security page said so, and we pulled the archived capture to be sure. On 17 May 2026 that page read: "That said, our platform is maintained as HIPAA compliant and for significant implementations, we will entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance." Read the wording closely, because it is softer than the comparison tables make it sound. Maintaining a platform as HIPAA compliant is a self-assertion — HIPAA has no certification body — and an offer to entertain a Business Associate Agreement for significant implementations is an invitation to negotiate rather than a programme you can sign up for. That is our reading of the sentence, not something the page itself says.
- Comparison articles from July 2026 describing this platform as having "SOC 2 Type II, FedRAMP High accreditation, and HIPAA compliance with BAAs available" — traceable to Windsurf's own May 2026 security page, though "BAAs available" is stronger than what that page actually offered, and its FedRAMP leg described a separate federal deployment rather than the editor. Either way it is false for Devin today.
- Any citation to a windsurf.com/security URL. That address now returns a 308 permanent redirect to Cognition's Devin documentation, which contains no HIPAA text at all.
- Vendor comparison tables that treat the Windsurf brand as retired. It is superseded in marketing but still live in the product: the string "Windsurf" appears 1,122 times in Cognition's current documentation against 701 for "Devin Desktop", the config folder is still under ~/.codeium/windsurf, and a separate Windsurf Plugins product line is still documented.
What the vendor's own documentation says
None of it survived the rebrand. Cognition renamed Windsurf to Devin Desktop on 2 June 2026. We searched the entire current documentation corpus — 793,398 bytes across 1,353 page markers — for "hipaa", "business associate" and "protected health", case-insensitively, and got zero matches. The same corpus does contain the FedRAMP, GovCloud, IL5, ITAR and Customer Managed Keys pages, so the search was working; the terms are genuinely absent, not relocated. The only live Cognition page that says the word HIPAA at all is the Acceptable Use Policy, and it says it to prohibit: PHI is Prohibited Data. The Master Services Agreement bans submitting PHI to the Services outright.
How we resolve it
Both things are true at different dates, and the date is the whole answer. If you are reading an article written before June 2026, or a comparison table built from one, it described something real about Windsurf that no longer exists under Devin. Do not cite it, and do not let a vendor cite it at you. The defaults moved the same way: Windsurf applied zero-data-retention by default on teams and enterprise plans, while Devin trains on your data by default and requires a paid plan plus a deliberate opt-out to stop it. On the question of what a developer pastes into a prompt, the rebrand made the position worse, not better.
Where PHI actually reaches Cognition
Devin cloud session prompts, and the files you attach to them
HighThis is not a database question. It is the paragraph a developer types at 6pm, the one that opens by saying the import fails on this row and then pastes the row. Devin's brain runs in Cognition's cloud, so that text leaves your boundary the moment you press send. Cognition's documentation says it may use your data for model training by default, and that it retains data processed through Devin for the duration of the relationship with the customer — a window with no defined end.
How to check
Open your Devin session history and search it for something you know is real: a patient surname, an email domain that belongs to a clinic, the prefix your medical record numbers use. Search the last ninety days, not the last week. One hit is the finding.
Devin Desktop chat, and the files the agent reads to answer it
HighThe editor surface is where fixture data leaks, because it does not feel like sending anything. A developer opens a seed file, a CSV export, or a test fixture built from a real extract, and asks the agent about the code around it. The agent reads the file to answer. If that file holds real records, they went with the question.
How to check
List the files that sit in your repository as test data or seeds. Open the largest three and read actual values, not column headers. Then check whether anything under your workflow and rules files — the config still lives under a .codeium/windsurf path — contains an example row copied from production.
Devin Outposts, which looks like it keeps everything local
HighThis is the surface people get wrong, and it is worth reading twice. Outposts runs sessions inside infrastructure you control — your VMs, your Kubernetes cluster, a Mac Mini on a desk. But Cognition's own documentation says the agent loop, meaning inference and planning, continues to run in Devin's cloud while command execution, file edits and repository access happen on your machines. Execution moved. The prompt did not. Outposts does not remove Cognition as a recipient of prompt content, so it is not a substitute for an agreement you do not have.
How to check
Ask whoever set up Outposts one question: does the model that reads our prompts run on our hardware? The documented answer is no. If someone tells you otherwise, ask them to point at the sentence.
The third-party model providers behind every answer
HighCognition's federal compliance page publishes the roster of models behind the answers — OpenAI GPT models, Anthropic Claude models, Google Gemini models, and SWE 1.6 Federal, as printed on that page's model table — which confirms that prompt content reaches third-party model providers as sub-processors. Cognition's paid-plan opt-out is described as enabling Zero Data Retention "with our model providers", which is scoped to those downstream parties rather than to retention at Cognition itself.
How to check
Try to enumerate Cognition's sub-processors from public materials. You cannot: the Trust Center's sub-processor page loads and names none, and the detail is gated behind an NDA. That itself is the finding — a covered entity cannot complete downstream vendor diligence here without signing something first.
The free-plan or personal account somebody on the team already opened
HighTraining on prompts is opt-out, and the opt-out requires a paid plan. Free-tier prompts have no mechanism to be excluded from training at all. On the Teams plan only an administrator can exercise the opt-out, which means a team can believe it is opted out while an engineer's personal free account beside it is not. The account nobody provisioned is the one with the weakest settings.
How to check
Ask your team, by name, who has a Devin or Devin Desktop login that did not come through your company plan. Then check whether the corporate opt-out on the Data Controls settings page has actually been exercised by an admin, rather than assumed.
What remains after you stop — history, retention and consent
MediumTurning training off is forward-looking. It does not address sessions already sent, and Cognition's stated retention is the duration of the customer relationship, with no fixed window published. Enterprise customers get a stronger sentence — Cognition says it will never train on Enterprise data without express prior written consent — but that is a training commitment, not a deletion commitment, and it does not change the MSA clause that prohibits submitting PHI in the first place.
How to check
Write down two dates: when your team started using Devin, and today. Everything between them is the window you have to account for. Then ask Cognition in writing what is retained from that window and how it can be deleted, and keep the reply.
Six checks, all answerable in about a minute
Four you can answer from admin access, your own session history, or a direct question to your teammates. The other two are questions for whoever holds your contracts. Run them before you pay anybody, us included, because the answers decide whether there is a project here at all.
01Search your Devin session history for a real patient surname, a clinic email domain, or your medical record number prefix. Does anything come back?
02On the Data Controls settings page, has an administrator actually exercised the training opt-out — not planned to, exercised it?
03Does anyone on the team hold a Devin or Devin Desktop login that did not come through your company plan?
04Can someone at your company produce a separate written agreement with Cognition that expressly permits PHI?
05Did your company sign Cognition's Enterprise terms of service?
06Does anyone on your team believe Devin Outposts keeps prompts inside your own infrastructure?
What we do about it
Typical range
$13,000–$25,000
Typical timeline
6–10 weeks
- 01
Prompt-surface inventory
3–5 daysA written list of every place your team's prompts land: Devin sessions, Devin Desktop, any Outposts or Enterprise deployment, and every account we can find including the ones outside your plan. Each entry marked with what the current Cognition terms say about it and the date we read them.
- 02
Stop the flow
1 weekTraining opt-out exercised by a named administrator, personal and free-tier accounts identified and closed or migrated, and a one-page written rule about what may never go into a prompt — agreed by the engineers who will have to follow it, not issued at them.
- 03
Synthetic fixtures
2–3 weeksReal extracts replaced with generated data that has the same shape, edge cases and awkward characters, so that debugging with an agent stops requiring a real row. This is the stage that makes the rule survive contact with a deadline.
- 04
History and vendor accounting
1–2 weeksA dated record of what was submitted and when, as far as your session history reveals it, plus our written questions to Cognition about retention and deletion and whatever answer comes back. This is the document your compliance officer will ask for, and it is the reason to do this properly rather than quietly.
- 05
Tool decision
1–2 weeksA short comparison of your realistic options — keeping Devin strictly PHI-free, pursuing a separate written agreement with Cognition, or moving to a vendor that does publish a BAA — with the actual contract text behind each, and a working pilot of whichever you choose.
- 06
Handover pack
3–5 daysOne document containing the surface inventory, the checks we ran, the dated source pages behind every decision, and an explicit list of what remains yours to do — your risk analysis, your access reviews, your training.
What moves the number
- How long the team has been using Devin, because the accounting window is the single biggest cost and it is set by a date you cannot change.
- How many accounts exist outside the company plan — personal logins and free-tier sessions have no opt-out and no admin console, so each one is found by asking people rather than by querying anything.
- Whether real extracts have been used as test fixtures, which turns a settings change into a data-generation project.
- Whether you are on Enterprise, Outposts or a Customer Dedicated deployment, since each has a different contract text and a different conversation with Cognition attached to it.
- Whether other vendors touch the same prompts — a second coding agent, a chat tool, an error tracker — because each one needs its own reading and its own written answer.
When not to hire us
- Your prompts contain code and nothing else. If your session history search comes back empty, the honest answer is that Cognition's terms permit exactly what you are already doing. Exercise the training opt-out, write the fixture rule down, and move on.
- You have no real PHI yet. A prototype on synthetic data needs none of this, and doing it before the product shape settles usually means doing it twice.
- All you actually need is the settings change. The training opt-out lives on the Data Controls settings page and an administrator can do it this afternoon. Paying an agency to click it is paying an agency to click it.
- You are shopping for a HIPAA certificate. There is no government HIPAA certification for any product or company, so nobody can sell you one — us included, and Cognition included.
Worth knowing either way
There is no government HIPAA certification
No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the administrative, physical and technical safeguards you implement and document yourself.
SOC 2 is not a substitute for a BAA
Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.
An absence of documentation is not a vendor promise
Several answers here rest on what vendor documents do not say. We name which documents we read and when. A vendor that has never published a HIPAA position may still decline to sign, and one that publishes nothing today may publish something next quarter.
The same question, for the other fifteen tools
Firebase
NoOnly the Google Cloud equivalents are covered — no Firebase-branded service is
Supabase
Yes, with conditionsBAA plus a paid HIPAA add-on, on the Team plan or above
v0 by Vercel
PartiallyVercel hosting is covered; v0 itself is contractually off-limits for PHI
Lovable
NoIts terms prohibit uploading protected health information
Bubble
NoIts own documentation says apps built on Bubble won't achieve compliance
Replit
NoIts Terms, Commercial Agreement and DPA carry no HIPAA or BAA terms
Bolt.new
NoNo BAA in the StackBlitz and Bolt documents we read; HIPAA is named only for self-hosted
FlutterFlow
NoIts terms bar processing HIPAA-protected data outright
Claude Code
Yes, with conditionsCovered only with zero data retention, on accounts Anthropic qualifies
Codex
Yes, with conditionsCodex Local on a Regulated or Healthcare tier; Codex Cloud is excluded
Cursor
Yes, with conditionsEnterprise only, with Privacy Mode locked organisation-wide
GitHub Copilot
NoNo BAA offered; the Data Protection Agreement tells customers not to send PHI
Devin
NoPHI is Prohibited Data under the acceptable-use policy
Hermes Agent
Not the right questionSelf-hosted — the agreement you need is with your model provider
OpenClaw
Not the right questionSelf-hosted — but the vendor-run router still receives prompts
Base44
NoNo BAA; its terms ask customers to keep PHI off the platform
Sources, quoted as printed
Every claim above traces to one of these. Quotes are reproduced as printed on the source page on the date shown; where two sentences from one page are cited, each is reproduced on its own line and no adjacency between them is implied. Two entries are our own observations rather than vendor statements, and they say so in plain words rather than sitting inside quotation marks.
PHI is Prohibited Data under Cognition's Acceptable Use Policy, permitted only under a separate written agreement. This is the only live Cognition page that mentions HIPAA at all, and it mentions it to prohibit.
Contains regulated health information, including Protected Health Information as defined under HIPAA, unless you have entered into a separate written agreement with Cognition expressly permitting such use.
Cognition — Acceptable Use Policy, Prohibited DataSource dated: Last Updated: June 30, 2026Checked: August 2026The carve-out is a generic bespoke-contract clause spanning every Prohibited Data category. It names no plan, no tier, and never the words Business Associate Agreement.
Notwithstanding the above, certain categories of Prohibited Data may be permissible where Cognition has entered into a separate written agreement with you expressly authorizing such use and establishing applicable safeguards.
Cognition — Acceptable Use Policy, Data RestrictionsSource dated: Last Updated: June 30, 2026Checked: August 2026The Enterprise Master Services Agreement — the top commercial tier — prohibits submitting PHI with no exception clause attached. The strings HIPAA and Business Associate do not appear anywhere in it.
Customer agrees not to share with Licensor or otherwise submit to the Services any protected health information. Customer further agrees not to share with Licensor or submit to the Services any other categories of sensitive personal data such as social security numbers, birth dates, passport information, bank account, and credit card numbers.
Cognition — Enterprise Terms of Service (Master Services Agreement), §4.3Source dated: Last updated: June 8, 2026Checked: August 2026Our own observation, not a vendor statement: we searched Cognition's full published documentation corpus at docs.devin.ai/llms-full.txt — 793,398 bytes, 1,353 page markers — case-insensitively for "hipaa", "business associate" and "protected health", and found zero matches. The same corpus does contain the FedRAMP, GovCloud, IL5, ITAR and Customer Managed Keys pages, so the search was functioning; the HIPAA vocabulary is genuinely absent rather than relocated. The nearest live vendor sentence names the frameworks Cognition does claim, and HIPAA is not among them.
industry standard security frameworks such as SOC 2 Type II and ISO 27001
Cognition — Security (legal), and our corpus search of docs.devin.ai/llms-full.txtSource dated: Last updated: June 11, 2026Checked: August 2026Windsurf did publish a HIPAA posture before the rebrand. This is an archived capture of the vendor's own security page taken on 17 May 2026, sixteen days before Windsurf became Devin Desktop. Read the wording closely: maintaining a platform as HIPAA compliant is a self-assertion, since HIPAA has no certification body, and an offer to entertain a Business Associate Agreement for significant implementations is an invitation to negotiate rather than a published programme. That reading is ours, not the page's.
HIPAA compliance: In most cases, the data that a customer provides to us is not Personal Health Information (PHI) and does not need special compliance considerations in order to use our platform, even if you are a healthcare organization. This is particularly true for code, which does not carry any PHI itself. That said, our platform is maintained as HIPAA compliant and for significant implementations, we will entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance.
Windsurf — Security (archived capture, Internet Archive)Source dated: Wayback capture 2026-05-17; no last-updated date printed on the page itselfChecked: August 2026The rename that ended that posture, stated by Cognition in its own documentation.
On June 2, 2026, Windsurf is becoming Devin Desktop.
Cognition — Devin Desktop FAQSource dated: no date shown; rename date stated in body textChecked: August 2026Prompt handling today: training is the default and the opt-out requires a paid plan, with only administrators able to exercise it on Teams. The Zero Data Retention that follows is scoped to Cognition's model providers, meaning the downstream third parties, rather than to retention at Cognition itself.
By default, we may use your data for model training purposes to improve and enhance the Services. If you're on a paid plan, you can opt out at any time on the Data Controls settings page. After you opt out, your data will not be used for training and Zero Data Retention will be enabled with our model providers. On the Teams plan, only an administrator can exercise the opt-out.
The default moved the wrong way across the rebrand. Windsurf applied zero-data retention by default on team and enterprise plans; Devin trains by default and requires an opt-out. For a page about what a developer pastes into a prompt, this is the most consequential change of the whole rename.
For any teams or enterprise plans, all inputs and outputs to these requests follow zero-data retention policies by default. For any individual plan, users can opt-in to zero-data retention mode from their profile page.
Windsurf — Security (archived capture, Internet Archive)Source dated: Wayback capture 2026-05-17Checked: August 2026Outposts moves execution onto your machines but not the part that receives your prompt. Cognition states both halves itself.
Outposts lets you run Devin sessions inside infrastructure you control — your own VMs, containers, Kubernetes clusters, or even a Mac Mini on your desk. Devin's agent loop (inference and planning) continues to run in Devin's cloud, while all command execution, file edits, and repository access happen on machines you operate.
Retention has no published window; it is tied to the length of the customer relationship. Enterprise customers get a training commitment, which is not the same as a deletion commitment and does not lift the PHI prohibition.
Cognition only retains data processed through Devin for the duration of the relationship with a given Customer, unless otherwise specified by the Customers. If you are an Enterprise customer, we will never train on your data without your express prior written consent.
The accreditations Cognition does publish, and the surface split inside them. On the federal compliance table, FedRAMP High, IL4 and IL5 read "In Process" for Devin itself while Devin CLI and Devin Desktop carry checkmarks — the autonomous cloud agent is the least accredited surface, which is the inverse of what most buyers assume. The same page names the underlying model providers, confirming that prompt content reaches OpenAI, Anthropic and Google models as third parties. Our own observation about that page: HIPAA appears nowhere on it.
Zero Data Retention (ZDR) is enabled for all Devin Desktop and Devin CLI features in federal deployments.
Cognition — Federal complianceSource dated: "This table was last updated on 25 AUG 26", printed against the models table on the same pageChecked: August 2026The Trust Center lists three items and HIPAA is not one of them. Our own observation alongside it: the sub-processor page loads but names no sub-processors, with the detail gated behind an NDA — so a covered entity cannot complete downstream vendor diligence from public materials. Note also that trust.devin.ai does not resolve; the real portal is trust.cognition.ai.
SOC 2 Type 2 ISO/IEC 27001:2022 CCPA
Whether a customer-hosted data plane still exists is genuinely unsettled. Cognition's current enterprise deployment overview names only Enterprise Cloud, Customer Dedicated Deployment and Enterprise Assured Deployment — no self-hosted, on-premises or air-gapped tier — yet the Security Exhibit still contemplates one contractually. The Exhibit is contract text, and we are not attaching a public URL to it; the URL below is the deployment overview it conflicts with. We are reporting the conflict rather than resolving it for you.
the Data Plane may either be deployed in Customer's own cloud service provider account (known as the 'Customer Data Plane') or in a Licensor-controlled account Licensor cannot access Customer Data stored on the Customer Data Plane.
Cognition — Enterprise deployment overview, set against Security Exhibit contract textSource dated: deployment overview: no date shown; Security Exhibit: Last updated June 11, 2026Checked: August 2026
Frequently asked questions
We're on Enterprise. Doesn't that come with a BAA?
No, and Enterprise is actually the stricter document. The Master Services Agreement says "Customer agrees not to share with Licensor or otherwise submit to the Services any protected health information", and unlike the Acceptable Use Policy it attaches no separate-agreement exception to that sentence. The strings HIPAA and Business Associate do not appear in it at all. Buying the top tier did not buy permission.
Our security review last quarter said Windsurf offers BAAs. Was that wrong?
It was right when it was written and it is wrong now. Windsurf's own security page, captured on 17 May 2026, said "our platform is maintained as HIPAA compliant and for significant implementations, we will entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance." Cognition renamed Windsurf to Devin Desktop on 2 June 2026 and nothing equivalent exists under the new brand — we searched the whole current documentation corpus for HIPAA and business associate and got zero hits. If your review cites a windsurf.com/security URL, follow it: it now redirects to a Devin page with no HIPAA text on it.
If we run Outposts on our own hardware, does the prompt still leave?
Yes. Cognition's documentation is explicit that "Devin's agent loop (inference and planning) continues to run in Devin's cloud, while all command execution, file edits, and repository access happen on machines you operate." Outposts relocates execution, not inference. The component that reads your prompt is the one that stays remote, so Outposts changes nothing about the question on this page. Customer Dedicated Deployment has the same shape — single-tenant, still Cognition-hosted.
We turned off training. Are we clear?
You have stopped the flow forward, which is the right first move and takes ten minutes. Two things it does not do. It does not address sessions already sent, and Cognition's published retention is "for the duration of the relationship with a given Customer" with no fixed window. And it does not lift the prohibition — PHI is Prohibited Data whether or not it is used for training. Also confirm an administrator actually exercised it; on the Teams plan nobody else can.
Is code with patient identifiers in it PHI?
Code by itself generally is not the issue, and Windsurf made that argument reasonably when it wrote that code "does not carry any PHI itself." What carries PHI is what developers paste beside the code: the failing row, the log line with a name in it, the CSV fixture built from a real export, the error message quoting a record. Those go into the same prompt box and travel the same path. That is why the check we recommend is searching your own session history for a real surname rather than auditing your repository.
SOC 2 Type II, ISO 27001, FedRAMP High — none of that helps?
Those are real and they are Cognition's own published claims; they tell you something genuine about how the company operates. None of them is a Business Associate Agreement, and none of them makes PHI permissible under terms that prohibit it. Worth knowing too that the federal accreditations split by surface in a way most buyers get backwards: on Cognition's own federal compliance table — which describes its federal deployment running on AWS GovCloud rather than the commercial editor or CLI you install — FedRAMP High, IL4 and IL5 read "In Process" for Devin itself, while Devin CLI and Devin Desktop carry checkmarks. The autonomous cloud agent is the least accredited surface.
Could we negotiate the separate written agreement the Acceptable Use Policy mentions?
You can ask, and some enterprises will get a conversation. Go in with clear eyes about what that clause is. It is a generic provision covering every Prohibited Data category, it names no plan and no tier, and it never uses the words Business Associate Agreement. So you would be asking Cognition to write something that does not currently exist in published form, and the Enterprise MSA you may already have signed points the other way. Ask in writing, be specific that you need a BAA, and keep the reply whatever it says.
This page reports what Cognition's published documents said on the dates shown and is technical information rather than legal advice; HIPAA compliance is a property of your whole system and the processes around it rather than of any single tool, and vendor terms change — Cognition's changed twice in June 2026 alone — so verify the current Acceptable Use Policy and Master Services Agreement yourself before relying on anything here.
