Windsurf (Codeium)
low riskAI Coding Assistantwindsurf.comverified 2026-06-27
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Stated policy of 'no training on non-permissive data' — does not train shared models on private customer code. Zero-data-retention is default on team/enterprise plans; code not stored in logs or used for training unless optional features (remote indexing, memories) are explicitly enabled. Self-hosted/on-prem/VPC deployment available (FedRAMP High, HIPAA, BAA supported).
- Data region
- US
- Certifications
- none listed
- DPA available
- Yes
- Breach history
- Included in a 2025 third-party research report ('Forked and Forgotten') on ~94 unpatched Chromium-derived vulnerabilities affecting Cursor and Windsurf's Electron/Chromium base, exposing an estimated 1.8M developers; vendor-side data-training breach not identified.
- EU AI Act
- Strong enterprise data-isolation and on-prem deployment options support EU AI Act data-governance requirements for sensitive codebases.
Sources
- https://windsurf.com/privacy-policy
- https://windsurf.com/security
- https://www.ox.security/blog/94-vulnerabilities-in-cursor-and-windsurf-put-1-8m-developers-at-risk/
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.