90 Days Gen AI Risk Trial -Start Now
Book a demo
Code Assistants·Free; Pro $20/mo; Max $200/mo; Teams $40/user/mo; Enterprise custom·codeium.com

Codeium

Codeium (now Windsurf) provides free-to-paid AI code completion and the agentic Windsurf IDE with SOC 2 Type II, FedRAMP High, and zero-retention options for teams.

Risk Score
Low
3/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Originally launched as Codeium — a free AI autocomplete plugin for 40+ IDEs — the company has since pivoted around Windsurf, an agentic IDE with Cascade, Fast Context, and Devin Cloud sessions. The free autocomplete product remains available, but Windsurf is the primary roadmap. Plans span Free, Pro ($20/mo), Max ($200/mo), Teams ($40/user/mo), and Enterprise. Windsurf holds SOC 2 Type II and FedRAMP High, a rare combination for AI code tooling, and offers EU deployment from Frankfurt. Teams and Enterprise plans default to zero code retention and never train on customer code; individual plans can opt-in to zero retention from profile settings. Because agentic features can run shell commands and edit many files at once, enterprises should scope what Windsurf can touch and keep human approval on destructive actions.

Risk factors

2
  • Offers zero-retention options for teams, which is a strong privacy feature.
  • SOC 2 Type II compliance indicates a level of security.

Recommendations

1
  • Utilize zero-retention options to minimize data exposure.

Data handling

Storage
Code processed transiently in memory on Windsurf servers; not serialized to disk in plaintext under zero-retention. US and EU (Frankfurt) regions available. Encryption in transit (TLS) and at rest for account data.
Retention
Zero code retention is default for Teams/Enterprise and opt-in for individuals. Under zero retention, prompts and completions are not persisted after the request.
Training on inputs
Zero-retention users' code is never used for model training. Non-zero-retention users' code may be retained and used for training per the applicable plan terms.