30 Days Gen AI Risk Trial -Start Now
Book a demo
C
HR·Free for individuals (personal use); Pro $9/user/mo; Enterprise (custom)·sourcegraph.com

Cody

Sourcegraph's AI coding assistant — code completion and chat with deep repository context.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Cody is the AI coding assistant from Sourcegraph. It connects to a Sourcegraph instance (cloud or self-hosted) to provide repository-grounded answers and completions. Routes inference through configurable LLM providers (Anthropic Claude, OpenAI GPT-4, Mixtral). Sourcegraph carries SOC 2 Type II. Code from the user's editor is sent to the configured LLM provider for inference; choice of provider determines the trust boundary.

Risk factors

3
  • Code from the developer's editor is transmitted to the configured LLM provider for inference
  • Inference routes via Anthropic / OpenAI by default — those providers' terms apply in addition to Sourcegraph's
  • Free / personal tier lacks SSO and centralized administrative controls

Recommendations

3
  • Use Cody Enterprise so SSO + organisation-level retention controls apply
  • Self-host the Sourcegraph instance for code that must never leave the customer environment
  • Pin a specific inference provider (Anthropic Claude on commercial terms) and document the BAA / DPA chain

Data handling

Storage
Sourcegraph Cloud or self-hosted; LLM inference routed through configured provider (Anthropic / OpenAI / others)
Retention
Configurable per tenant; zero-retention available on enterprise
Training on inputs
Off by default — neither Sourcegraph nor the routed providers train on customer data on commercial / enterprise plans