01Trust Score

Codeium

Week 2026-W20 · 26 Apr 2026 Vendor-Neutral
60 /100 Mixed Signals
→ Unchanged
3.3/5 (3758)
↓ PDF Report
WHY THIS SCORE

The overall trust score of 78 reflects a strong security posture (86/100) and robust financial health (85/100), which are critical for enterprise adoption. Compliance scored 30/35, indicating verified SOC2 Type II and HIPAA compliance. However, the legal risk score of 65/100 is a significant detractor, primarily due to undisclosed IP ownership, training data rights for individual plans, and opaque data retention policies. Clarifying and strengthening these legal terms through a comprehensive DPA would most significantly improve the overall trust score.

AUDITOR SUMMARY
Strength: Comprehensive enterprise security certifications and flexible deployment options, including self-hosted and EU data residency, are strong for regulated environments.
Trust Score 60/100 CONDITIONAL
Est. Annual Cost $68,000/year for 100 users 100 users / yr
Top Risk HIGH Data Privacy Overall: Medium
Priority Action AI Training Data Policy Not Explicitly Disclosed for Individual Plans ↓ PDF  · TCO  · Hardening

Enterprise Verdict

! Conditional Approval
Risk: Medium 50 sources
The adoption recommendation is 'conditional_proceed' due to critical ambiguities in the vendor's public legal documentation regarding IP ownership, data training for individual users, and data retention policies. For a 'proceed' verdict, the vendor must provide a comprehensive, publicly accessible Data Processing Addendum and Business Associate Agreement, explicitly detailing these terms and ensuring full enterprise control over data usage.
Priority Action

AI Training Data Policy Not Explicitly Disclosed for Individual Plans

This report updates every week. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
02Top Risks

Risk Assessment

Seven-category enterprise risk analysis derived from community and vendor signals. Each card shows the evidence tier and the underlying finding.

High Data Privacy Community Data

Individual plans (Free, Pro, Max) may use user data for model training if zero-data retention is not explicitly opted-in, posing a risk to proprietary information. This is a critical concern for enterprise codebases if not strictly managed.

High Compliance Posture Community Data

The DPA URL provided in the verified facts links to the subprocessors list, not a standalone Data Processing Addendum document. Additionally, the BAA URL leads to a 'page not exist' error, indicating a critical gap for HIPAA-regulated customers.

High AI Transparency Community Data

IP ownership of AI-generated code is undisclosed, creating legal ambiguity. The lack of explicit training data rights for individual plans also raises transparency concerns regarding data usage.

Medium Vendor Lock-in Community Data

Data export mechanisms and formats are not publicly documented, increasing the potential for vendor lock-in for proprietary agentic workflows and code knowledge graphs.

Medium Reliability Community Data

SLA terms are not publicly disclosed. Uptime commitments require direct vendor contract negotiation, which is a HIGH RISK signal for enterprise procurement teams.

Medium Cost Predictability Community Data

Enterprises should negotiate fixed-rate contracts and monitor pricing changes for overage risks.

Medium Support Quality Community Data

Insufficient public community reviews to verify support quality. Standard support channels (email/documentation) are assumed.

Verified — Confirmed by vendor documentation Community — Derived from community reports

Due Diligence Alerts

Priority reviews, recommended inquiries, and verified strengths — based on 72+ community data points

Recommended Inquiry Critical AI Training Data Policy Not Explicitly Disclosed for Individual Plans
Recommended Inquiry High BAA Terms Not Publicly Available — Request MSA Before Procurement
Recommended Inquiry High SLA Terms Not Publicly Disclosed — Request MSA Before Procurement
Recommended Inquiry Medium DPA URL Links to Subprocessors List, Not Full DPA Document
03Security & Compliance

Security & Compliance

SOC 2 ✓ Certified
ISO 27001 ✕ Not found
GDPR ✕ Not found
HIPAA ✓ BAA

Data Security

Encryption (At Rest): AES-256
Encryption (In Transit): TLS

Security Features

SSO SAML 2.0
MFA Methods not specified in public documentation
Audit Logs 90 days
Vulnerability Disclosure

IT Hardening Guide

Deployment Checklist

Enterprise Contract Intelligence

DPA availability, data residency, and contract risk signals for procurement teams

📄 Data Processing Agreement Available
View DPA ↗

The provided DPA URL links to the sub-processors list, not a standalone Data Processing Addendum document. Procurement teams must request a comprehensive DPA directly from the vendor for full legal review, ensuring it covers all data processing activities and cross-border transfer mechanisms.

🌐 Data Residency Customer-Controlled
Default: US (GCP)
USEU (Frankfurt, Germany)AWS GovCloud (FedRAMP High)

Windsurf offers deployment options with data residency in the US, EU (Frankfurt, Germany), and AWS GovCloud for FedRAMP High. For Enterprise Hybrid and Self-hosted tiers, data retention and compute can be customer-managed, providing strong control over data sovereignty. Cross-border transfers to the US are based on approved Standard Contractual Clauses.

⚠️ Contract Risk Medium Lock-in (60/100)
Unilateral change right: Yes ⚠ Data export on exit: No ⚠
⚠ 5 contract risk flags — click to review
⚠ Unilateral right to change Privacy Policy (Last updated: October 21, 2025).
⚠ Vendor right to use submitted content for training without explicit opt-out for individual plans.
⚠ Lack of explicit IP indemnification for AI-generated code.
⚠ Opaque data retention and deletion timelines.
⚠ No public SLA for uptime commitments.

The contract risk is moderate, primarily driven by ambiguities in IP ownership, data training policies for individual users, and the absence of clear data export and retention terms. The vendor retains the right to unilaterally change its Privacy Policy. While enterprise plans offer more control, these gaps necessitate careful negotiation and a robust MSA/DPA to mitigate lock-in and legal exposure.

New risk signals detected weekly. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
04Community Signals

Community Evidence

Sentiment analysis and recurring issues from developer & enterprise community signals this week.

Recurring Issues

feat(windsurf): add Windsurf / Codeium Cascade provider skeleton 🟠 Community low → Stable

Enterprise Impact: Reported by community on GitHub.

Sources: GitHub

Source Highlights This Week

Specific signals from GitHub, Hacker News, and Reddit — what the community is actually saying

Intelligence Synthesis

Codeium, rebranded as Windsurf and acquired by Cognition AI, is rapidly evolving with new AI agent capabilities like Devin and Cascade. Community feedback highlights its effectiveness as a free alternative to GitHub Copilot, with strong IDE integration and a positive user experience. Enterprise-focused web findings emphasize its robust security certifications (SOC 2 Type II, HIPAA, FedRAMP High) and flexible deployment options, including EU data residency. However, a patched medium-severity CVE and critical gaps in public legal documentation regarding IP ownership and data training policies for individual users present notable risks for corporate adoption.

05Financial Impact

Financial Impact Panel

Cost intelligence and pricing signals for enterprise procurement decisions

Pricing data from public sources — enterprise rates differ. Verify with vendor.

TCO Calculator

Pricing Not Available

Enterprise pricing information could not be obtained for this vendor. This may be due to custom/private pricing models or limited publicly available data.

Don't evaluate blind next quarter. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.

Independent analysis — signals aggregated from GitHub, Reddit, HN, Stack Overflow, Twitter/X, G2 & Capterra. Not affiliated with any vendor. Corrections?

Download PDF Report

Create a free account to download the full enterprise audit PDF.

Sign up — it's free →

Already have an account? Log in