Windsurf Is Now Devin, and Your Vendor Register Still Lists a Product That No Longer Exists
Cognition renamed the Windsurf editor to Devin Desktop in an over-the-air update, windsurf.com now permanently redirects to devin.ai, and the old pricing page resolves to Devin plans. Nothing changed on developer laptops except a name, which is exactly why this will not reach your change process. Here is what it does to your SOC 2 and ISO 27001 supplier evidence, and the short list of records to fix.
The sequence is short and each step was quiet. Cognition, the company behind the Devin autonomous coding agent, acquired the Windsurf brand, product and remaining team in July 2025, after Google hired away the original leadership. On 2 June 2026 the Windsurf editor was renamed Devin Desktop through an over-the-air update, so most users woke up to a new splash screen and nothing else. Since then windsurf.com has answered with a permanent 308 redirect to devin.ai, and by 18 September the old Windsurf pricing page resolved to Devin plans: Free, Pro at 20 dollars a month, Max at 200 dollars, Teams starting at 80 dollars with full developer seats at 40 dollars each, and Enterprise on request. Cognition says plans, extensions, keybindings and accounts carry over, and long-standing Windsurf Pro subscribers are reported to keep their original 15 dollar rate.
For a developer this is a cosmetic change. For whoever owns the vendor register it is a small integrity problem, and it is the kind that survives audits by accident. Your register, your SOC 2 vendor inventory and your ISO 27001 supplier list almost certainly name Windsurf, or Codeium, or the Exafunction legal entity from the earlier era. The terms, privacy notice and security documentation you attached at onboarding were fetched from a domain that now redirects somewhere else. No ticket was raised, because no tool was added or removed. An auditor sampling supplier evidence in the next cycle will find a record for a product that is no longer sold under that name, with documents that point at a site which no longer serves them. That is not a finding by itself, but it is the thread an auditor pulls.
The billing model moved too, and that deserves its own line in the review. The Devin plans meter usage as a quota by model, with anything beyond the quota charged at API list prices, rather than the older credit model many teams originally approved. It lands in the same season as two other pricing shifts we have covered. Cursor changed on 24 August so that Auto requests routed to Claude, GPT or Gemini now draw down the paid pool instead of feeling unlimited, and GitHub Copilot promotional credits ran out at the start of September, which we covered in The Copilot Credit Cliff. Three coding assistants, three metering changes in one quarter. If your approval for these tools was a fixed per seat cost signed off by finance, the approval no longer describes what you are paying for, and a budget owner should re-approve it against current usage rather than last year.
The data questions are the ones worth asking directly, and the honest position is that we have not seen evidence that data handling changed. The point is narrower: the evidence on file predates the rename, and the product now sits inside a vendor whose flagship is an autonomous agent that executes work in its own environment. So re-confirm the things you relied on at onboarding from the documents served today, not the PDF saved in 2025. Which legal entity holds the contract and processes the data. Whether the zero data retention or no training setting you enabled still exists under the same name and default. Whether the subprocessor list and hosting regions match what your privacy assessment recorded. Whether the security attestations cover the product as it is now named. Each answer takes minutes to check and is exactly what a supplier review is for.
The rename also breaks things in configuration that nobody thinks of as vendor management. Egress and DLP allow lists keyed on windsurf.com or codeium.com may still work through the redirect today and fail the day the old domains are retired. SSO applications in Okta or Entra carry the old display name, so a SaaS discovery tool may show Devin as a new, unreviewed application while the reviewed Windsurf entry appears to go quiet. EDR rules and software inventory keyed on the old process or bundle name will drift. Open source tooling is already adjusting: GitHub spec-kit retired its dedicated Windsurf integration in June, noting that the product had been absorbed into Devin. Project rule files and MCP server configuration that lived under Windsurf paths should be checked against where Devin Desktop now reads them, and any MCP allow list you enforce should name the client as it is actually installed.
The control mapping is straightforward, which makes the gap easy to close. SOC 2 CC9.2 expects you to assess and manage risk from vendors and business partners, and a stale vendor record is weak evidence of ongoing management. ISO 27001 Annex A 5.19 to 5.23 cover supplier relationships, supplier agreements, the ICT supply chain, monitoring and review of supplier services, and information security for cloud services, and 5.22 in particular expects you to notice and assess changes to a supplier service. ISO 42001 carries the same expectation for AI systems in A.10, where suppliers of AI components and services sit inside your AI management system scope. A coding assistant that sends your source code to a model provider belongs in that scope whether or not the paperwork says so.
If you run the program in Vanta, Drata, Secureframe or Sprinto, resist the instinct to create a new vendor. Rename the existing record so its history, risk rating and past reviews stay attached, add the former names as aliases so SSO and spend integrations keep matching it, replace the attached documents with current copies from devin.ai, and log a short change note that records the date and the reason. If your platform linked the vendor to discovered applications, relink the new SSO app to the same record rather than letting it appear as shadow IT. Then set a review date. A rename is a change to a supplier service, and recording it as one is the cheapest evidence of 5.22 you will produce all year.
The whole exercise is perhaps an hour of work, and it is worth doing now rather than in the week before fieldwork. Update the register entry, pull current legal and security documents, re-confirm retention and training settings in the admin console, re-approve the spend under the new metering, and fix the domain and process names in egress rules, DLP, EDR and SSO. If the rename has prompted a wider rethink of which assistant to standardise on, our Devin, Windsurf and Cursor tool pages and the Devin vs Cursor and Windsurf vs Cursor comparisons are the place to start. The product your developers use did not change on 2 June. The name on your evidence did, and only one of those will be sampled.
Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.
Get the next post by email
One short email when something worth knowing ships. No spam, unsubscribe anytime.
Comments
Moderation policyLoading comments...
Add a comment
Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.