GitHub Copilot, Cursor, Devin, Claude Code, Amazon Q Developer and Windsurf can now open pull requests, run shell commands, and merge code with limited supervision. That is a materially different risk surface from a chat assistant: repository and secrets access, execution sandboxing, and whether a human has to approve an irreversible action before it happens. This compares what each vendor documents on exactly those points, sourced and dated.
Last updated 27 July 2026 · Sourced from each vendor's own trust centre and product documentation, per cell, then independently re-checked before publication.
Three statuses appear per cell. Documented means we found a clear, sourced vendor statement or feature. Partly documented means we found something with a real gap or a condition attached (for example, a control that only applies on one plan tier, or that requires an NDA to verify in full). Not confirmed means this pass did not turn up a citation for that specific control on that specific tool, and nothing more, it is a gap in our research, not a claim the vendor lacks the control.
Many of these facts genuinely depend on which plan is in use. Several tools below train on data by default on free or individual tiers but not on Business or Enterprise tiers, and several offer stronger data controls only once an admin turns them on. Where that is the case, the cell says so rather than flattening it into one answer.
No tool here paid for placement, there are no referral or affiliate links on this page, and AIRiskAware is not affiliated with, sponsored by, or endorsed by any vendor named here, this is an independent comparison for informational purposes. See editorial standards for the full policy. Spotted a gap or an error, or work at one of these companies and can point us to a better source? Tell us, corrections get investigated and published promptly.
| Governance axis | GitHub Copilot (coding agent) Microsoft / GitHub · as of 27 Jul 2026 | Cursor Anysphere · as of 27 Jul 2026 | Devin Cognition · as of 27 Jul 2026 | Claude Code Anthropic · as of 27 Jul 2026 | Amazon Q Developer AWS · as of 27 Jul 2026 | Windsurf Cognition (formerly Codeium) · as of 27 Jul 2026 |
|---|---|---|---|---|---|---|
Trains on your data by default Whether prompts/code are used to train the vendor's models without an opt-in, and whether this varies by plan tier | Partly documented Business and Enterprise plans are not used to train GitHub's public models. As of 24 Apr 2026, Free, Pro and Pro+ tier interaction data, including coding-agent sessions, trains models by default unless the user opts out. GitHub Copilot Trust Center FAQ | Partly documented Privacy Mode, which excludes data from training, is on by default for Enterprise teams. For Business/Teams and individual plans it is available but admin- or user-enabled rather than confirmed on by default. Cursor Docs, enterprise privacy | Partly documented Standard paid plans train on customer data by default, though users can opt out at any time via Data Controls. Enterprise customers get a contractual commitment that Cognition will not train on their data without express written consent. Devin Docs, security | Documented Team, Enterprise and API accounts are not used to train generative models on Claude Code prompts or code by default; only Free/Pro/Max consumer accounts train on data, and only if the user opts in. Claude Code Docs, data usage | Partly documented Q Developer Pro and Amazon Q Business content is not used for service improvement or model training. Free-tier content (questions, responses, code) may be used for service improvement, including training, unless the customer opts out. AWS Docs, service improvement | Partly documented Training on user data is on by default; paid-plan users can opt out at any time via Data Controls, and Enterprise customers require express prior written consent before any training use. Cognition/Devin Docs, security |
Data retention control Admin or user control over how long session/code data is kept, including any zero-retention option | Partly documented Coding-agent sessions can be archived but not deleted by the user or admin; only local IDE/CLI sessions can be deleted. No admin-configurable retention window is documented for coding-agent session logs specifically. GitHub Docs, managing agent sessions | Documented Privacy Mode maintains zero-data-retention agreements with all model providers and is on by default for Enterprise; a team-wide toggle is available at the Business tier too. Cursor, data use overview ·Cursor Docs, privacy and data governance | Documented Data is retained only for the duration of the customer relationship unless otherwise specified, with a Data Controls opt-out enabling zero data retention with model providers; the Data Processing Agreement commits to deleting Customer Data within thirty (30) days of termination. Devin Docs, security; Cognition DPA | Documented Standard commercial retention is 30 days, with a Zero Data Retention option available for Claude for Enterprise where prompts and responses are not stored after the response is returned; ZDR requires enablement by an Anthropic account team rather than a self-serve toggle. Claude Code Docs, zero data retention | Partly documented Free-tier users can opt out of content being used for service improvement via an AWS Organizations policy or IDE settings; Pro tier is excluded from this use by default. No separate configurable data-retention or deletion window is documented beyond this opt-out. AWS Docs, service improvement | Partly documented Zero Data Retention with model providers is available but opt-in, enabled when a paid-plan user turns on Data Controls (admin-only for Teams), rather than a default posture. A self-hosted, fully-on-customer-infrastructure option exists but has been placed into maintenance mode. Cognition/Devin Docs, security ·Devin blog, self-hosted maintenance mode |
Data residency / sovereignty Documented options to keep code, execution or data within a chosen region or the customer's own environment | Documented Enterprise-configurable data residency is available in the US and EU (aligned with Microsoft's EU Data Boundary), keeping inference and associated data within the chosen region for an additional fee. GitHub Enterprise Cloud Docs | Partly documented Cursor does not use infrastructure or subprocessors headquartered in China. Self-hosted Cloud Agents can keep code, execution and build artifacts entirely inside a customer's own environment; no dedicated EU/regional residency option was found for the standard hosted product. Cursor, security ·Cursor Docs, self-hosted agents | Partly documented Enterprise "Customer Dedicated Deployment" runs in a customer-isolated environment that Cognition itself operates and connects to the customer's network via PrivateLink or an IPSec tunnel, rather than inside the customer's own cloud account; no public region list is published, and residency specifics require contacting sales. Devin Docs, enterprise deployment | Partly documented The Claude API offers only a binary "US" or "global" inference-region control, with workspace storage currently only available in the US; there is no EU or other sovereign-region residency option. Claude Platform Docs, data residency | Partly documented For IAM Identity Center Pro-tier users, a subset of features store data in the region where the profile was created; most other features and all Free-tier usage process data in US regions regardless of customer location, though an SCP can block US-region processing for non-US profiles. AWS Docs, data storage | Documented A dedicated EU (Frankfurt) GPU cluster keeps European customer code, processing and retention within EU borders; separately, Cognition says Windsurf deployments are DoD IL4/5/6 accredited and SOC 2 Type II certified, supporting CUI and ITAR compliance with zero data retention, and that Windsurf is the only FedRAMP High AI IDE. Devin is available in AWS GovCloud, with a FedRAMP High authorised version described as forthcoming rather than in place. Cognition for Government, 25 Feb 2026 |
Independent certifications SOC 2, ISO 27001, ISO 42001, FedRAMP, HIPAA and similar third-party attestations | Documented SOC 1, SOC 2 and SOC 3 (Type II) reports explicitly cover Copilot Business and Enterprise, alongside ISO/IEC 27001:2013 certification for the same products. GitHub Changelog | Partly documented A SOC 2 Type II attestation is available on request via the trust portal, alongside an annual third-party penetration-testing commitment. No ISO 27001 or ISO 42001 certification was confirmed. Cursor, security | Documented SOC 2 Type II and ISO/IEC 27001:2022 are listed on Cognition's Trust Center, with enterprise terms committing to annual third-party audits against both; no HIPAA or ISO 42001 certification is listed. Cognition Trust Center | Documented SOC 2 Type I and Type II, ISO/IEC 27001:2022 and ISO/IEC 42001:2023, with HIPAA support available via a Business Associate Agreement; full report copies are requested through the Trust Portal. Claude Help Center | Not confirmed AWS's compliance pages point to AWS-wide programmes (SOC, ISO, HIPAA) and AWS Artifact for audit reports, but do not name which specific certifications apply to Amazon Q Developer itself. Not finding a citation here does not mean the product lacks certifications. AWS Docs, compliance validation | Partly documented SOC 2 Type II (since September 2024, per Cognition's own enterprise security documentation) and ISO/IEC 27001:2022 are confirmed on the Trust Center, gated behind an NDA portal for the full report. No HIPAA or ISO 42001 certification is listed. Devin Docs, enterprise security |
Admin identity & access controls SSO, SCIM provisioning, role-based access control, and clean deprovisioning on offboarding | Partly documented SAML SSO is available as an add-on for Business/Enterprise accounts, but full SCIM provisioning requires the account to be set up as an Enterprise Managed User organisation, not available to every account by default. GitHub Docs, Copilot Business enterprise accounts | Documented Enterprise supports SAML SSO with major identity providers, SCIM 2.0 provisioning, and role-based access control in the admin dashboard. Cursor for Enterprise | Documented SSO via Okta, Microsoft Entra ID, SAML or generic OIDC with IdP group-sync into role-based access. SCIM provisioning is available and deprovisions users automatically when they are removed at the identity provider; the login-triggered alternative, for teams that do not configure SCIM, provisions on first sign-in and needs a manual removal step at offboarding. Devin Docs, SSO onboarding | Documented Claude for Enterprise adds SSO, domain capture and role-based permissions, with console-based bulk invites for managing members. Claude Code Docs, authentication | Documented Pro-tier workforce users are managed through AWS IAM Identity Center, where admins can subscribe users in bulk, cancel individual subscriptions, and track usage on an admin dashboard, with access separately governed by IAM policies. AWS Docs, getting started with IAM Identity Center | Documented Enterprise supports SSO via Okta, Microsoft Entra ID, Google or generic SAML, SCIM-based user and team provisioning, and role-based access control including custom roles through the Admin Portal. Devin Docs, guide for admins |
Agent / tool-action permission model What admins can scope the agent to reach or run (repos, commands, MCP servers, network) | Documented The coding agent runs behind a network firewall, enabled by default, that blocks outbound connections to unauthorised hosts; admins and users can customise the allowlist. GitHub Docs, agent firewall | Documented A default auto-review mode runs allowlisted commands and sandboxes shell commands where possible, routing the rest through a classifier; admins can configure command allowlists team-wide, though Cursor's own docs describe the allowlist as best-effort rather than a security boundary. Cursor Docs, LLM safety and controls | Documented Admins scope Devin's access per integration, for example selecting which GitHub repositories it can reach or restricting which Slack messages it processes; the CLI additionally enforces OS-level read/write restrictions and an optional network allowlist, failing closed if isolation tooling is unavailable. Devin Docs, security ·Devin Docs, CLI sandbox | Documented Read-only by default; file edits, system-modifying commands and network-fetch tools require explicit one-time or allowlisted approval, and admins can enforce allow/deny rules and MCP server scoping via managed settings checked into source control. Claude Code Docs, security | Documented The CLI agent exposes a tool-permission model letting users and admins scope which actions (running shell commands, writing files, using AWS APIs) it may take without prompting; reading files is the only action trusted by default. AWS Docs, managing tool permissions | Documented A four-tier command auto-execution model (Disabled, Allowlist Only, Auto, Turbo) plus org-wide and per-user allow/deny command lists lets admins cap what runs without approval; once a team allowlists even one MCP server, all non-allowlisted servers are blocked, and Enterprise teams can point users at a custom, admin-controlled MCP registry instead. Devin Docs, Cascade MCP integration ·Devin Docs, terminal |
Audit logging of agent activity A reviewable log of agent sessions or actions for security and compliance teams | Documented Enterprise admins can review agent activity in the audit log (retained roughly 180 days) and stream events to a SIEM; a dedicated agent-control dashboard (general availability Feb 2026) adds session-level activity tracing. GitHub Docs, reviewing audit logs | Documented An Enterprise audit log covers authentication, role changes, API keys, spend limits, and Privacy Mode changes, viewable in the dashboard and exportable to a SIEM; Cursor's docs note agent responses and generated code are not logged. Cursor Docs, compliance and monitoring | Partly documented An Enterprise Audit Logs API lets admins pull organisation activity with date filtering and pagination, though the public reference does not enumerate which specific agent actions are captured or the retention window. Devin Docs, audit logs API | Documented Team guidance directs admins to monitor usage through OpenTelemetry metrics, and for Claude Code on the web, all operations in cloud environments are logged for compliance and audit purposes. Claude Code Docs, security | Partly documented For Pro-tier accounts, AWS CloudTrail captures console and API calls as management events, recording the request, source IP, actor and timestamp; this integration is scoped to Pro accounts and the Free tier cannot produce equivalent logs. AWS Docs, logging with CloudTrail | Documented An Enterprise Audit Logs API (admin-only) returns organisation activity with date filtering and pagination. Devin Docs, audit logs API |
Public trust-centre transparency Whether compliance documentation is published self-serve or requires a request/NDA | Not confirmed A public Copilot Trust Center exists with an FAQ, and compliance reports are described as accessible through enterprise account settings, but whether the underlying SOC/ISO reports are obtainable without a registration or active-subscription gate was not confirmed this pass. GitHub Copilot Trust Center | Partly documented A named trust centre (trust.cursor.com) is referenced from Cursor's security page, with the SOC 2 report available on request rather than an instant self-serve download. Cursor, security | Partly documented A public Trust Center shows a security overview and certification list self-serve, but the underlying SOC 2 report, ISO certificate and penetration-test reports are gated behind a request-and-NDA workflow. Cognition Trust Center | Partly documented A public Trust Center lists certifications and security practices self-serve, but the underlying SOC 2 Type II report and other detailed compliance documentation must be requested through the Trust Portal. Claude Help Center | Documented Security documentation covering data protection, identity and access management, compliance, resilience and network controls is published openly with no login or account required. AWS Docs, security in Amazon Q Developer | Partly documented A public Trust Center surfaces certifications and security posture self-serve, but the underlying SOC 2 report and ISO certificate require NDA-gated portal access rather than open download. Cognition Trust Center |
Execution sandboxing / isolation Whether the agent runs code and commands in an environment isolated from the user's own machine or production systems | Documented Each cloud coding-agent session runs in an ephemeral, isolated development environment destroyed after the session ends; additional local and cloud sandbox modes (public preview, Jun 2026) further restrict filesystem and network access. GitHub Changelog, sandboxes preview | Partly documented Locally-run agents have the same file, command and network access as the signed-in user by default, with no security boundary unless the user opts into local sandboxing; Cloud Agents instead each run in their own isolated virtual machine. Cursor Docs, LLM safety and controls | Documented Each session runs in a dedicated microVM with isolated storage, networking and compute, built so a compromised session cannot reach other sessions' files or credentials; enterprise terms separately commit to default-deny network isolation between development and production, and the CLI adds its own OS-level sandbox that fails closed if unavailable. Cognition Blog ·Devin Docs, CLI sandbox | Documented A sandboxed Bash tool with filesystem and network isolation is available for local use; Claude Code on the web runs each session in an isolated, Anthropic-managed VM with limited, configurable network access, separate from production systems. Claude Code Docs, security | Not confirmed AWS's own documentation does not state that agent-executed commands run in an isolated sandbox separate from the developer's own machine or production systems; a 2026 third-party-disclosed and since-patched CLI vulnerability also indicated commands execute with the local user's own credentials. This does not confirm the product lacks sandboxing, only that no citation was found this pass. AWS Docs, managing tool permissions | Not confirmed No vendor documentation found this pass states whether the local desktop terminal's commands run in an isolated sandbox versus directly on the developer's machine; a separate cloud agent product is documented as running each session in an isolated VM, but that claim covers the cloud product, not the local desktop terminal specifically. Devin Docs, terminal |
Human approval for irreversible actions Whether the agent must pause for explicit approval before actions like merging code, running destructive commands, or spending money, and whether that gate can be disabled | Partly documented A Copilot-authored pull request's own approval does not count toward required-reviewer branch protection where a repository owner has configured that protection, so a human must approve it; an "agent merge" capability otherwise lets the agent merge once existing checks pass. GitHub Docs, reviewing a Copilot PR | Partly documented Terminal commands require user approval by default, with teams able to allowlist low-risk commands; an optional "Run Everything" auto-run mode removes per-action approval entirely, which Cursor's own docs warn can let agents run destructive commands unnoticed. Cursor Docs, LLM safety and controls | Partly documented Interactive Planning lets a user require plan approval, but by default Devin waits only 30 seconds for feedback before proceeding automatically (user-adjustable), and an "Agency" toggle can skip plan approval entirely per session; standard pull-request review is the documented merge workflow but is not described as an enforced, non-removable gate. Devin Docs, interactive planning | Documented Explicit user approval is required by default before running system-modifying Bash commands, editing files, or making network requests; an optional mode auto-approves only a fixed, narrow set of filesystem actions while everything else still prompts. Claude Code Docs, security | Documented The CLI agent must ask for explicit approval before using any tool other than reading files, letting the user allow, deny or trust each action per session. AWS Docs, managing tool permissions | Partly documented Three of four auto-execution tiers require manual approval for non-allowlisted commands, but the top "Turbo" tier auto-executes every command except those an admin has explicitly denylisted, so destructive actions not on that list run without a human check. Devin Docs, terminal |
General information, not procurement or legal advice. Vendor documentation changes frequently, particularly for fast-moving coding-agent products; verify current detail against the linked primary source before relying on it in a vendor risk assessment.
Every product and vendor named here is named for identification in a truthful, factual comparison, text only, no logos. Nothing on this page is presented as AIRiskAware's opinion of which tool is "better", only what each vendor documents about its own controls.
This page is a pilot, published as at 27 July 2026, and will be revised as we source deeper primary documentation for each tool. It is general information, not legal or procurement advice, and not a certification or endorsement of any product.