Devin Desktop FedRAMP
Cognition AI, Inc. · Operations & Productivity
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Devin Desktop (FedRAMP), in partnership with Palantir FedStart, brings our agentic AI code assistant to U.S. public-sector and regulated enterprises that require FedRAMP Moderate, FedRAMP High, DoD IL4, DoD IL5, or ITAR compliance.
The platform accelerates every phase of the software-development life cycle - from code generation and modernization to debugging and testing - while meeting the strictest compliance mandates.
Show the rest of the publisher’s description (3 more lines)
Key security controls include NIST SP 800-53 and NISTSP 800-171 (with mapping to CMMC 2.0) continuous vulnerability scanning, and end-to-end encryption. Customer code data is never stored outside of customer hardware; Windsurf runs in GovCloud VPC where code data flows through in an encrypted and transient manner to serve the user request, ensuring you maintain full data sovereignty.
Teams reduce delivery timelines, eliminate legacy tech debt, and minimize operational AI risk - all under a transparent, fixed-price annual contract.
Multi-tenant and Single-tenant options are available.
Highlights
Highlighted by the publisher on AWS Marketplace.
FedRAMP Moderate/High, DoD IL4/5, ITAR compliant Deployed in AWS GovCloud (US) SOC 2 Type II & ISO 27001 compliant No source-code retention VPC isolation Palantir FedStart Partner Context-aware AI across SDLC to modernize, test & debug code at scale
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

