Security & Privacy: what each Coding tool records (2026)
What the AiRecMark archive records about security and privacy for all 55 Coding & Engineering tools (channel overall median 81.4/100). Only fields captured in the public archives are shown — a tool without a recorded security entry is marked not recorded, which is a statement about the archive, not a certification that the tool lacks or meets any standard. No audit, certification or compliance conclusion is asserted on this page.
Recorded Security & Privacy Entries (5 of 55 tools)
Verbatim archive entries whose spec key is security-related (specs[].k), each with its first-party source and fetch date.
| Tool | Overall | Recorded entry (verbatim) | Source |
|---|---|---|---|
| Amazon Q Developer | 84.3 | Security: Pro: IP indemnity; customer data not used for training by default | aws.amazon.com · 2026-09-13 |
| Cline | 83.7 | Security: Runs locally in VS Code; keys stay with the user; enterprise SSO/RBAC available | cline.bot · 2026-09-13 |
| Tabnine | 82.5 | Security: Air-gapped / on-prem / VPC deployment; zero code retention | www.tabnine.com · 2026-09-13 |
| Sourcegraph Cody | 79.7 | Security: Enterprise SSO/SAML, RBAC and audit controls via Sourcegraph platform | sourcegraph.com · 2026-09-13 |
| Devin | 78.5 | Security: Cloud execution sandbox; enterprise controls via Cognition platform | cognition.ai · 2026-09-13 |
Other Recorded Signals
| Signal | Tools |
|---|---|
| openSource recorded as true | — |
| No security/privacy spec entry recorded | 50 of 55 tools — not recorded in the archive (not an assertion about the products) |
Methodology — aggregates read only data/tools/<slug>.json recorded fields (specs[] with security-related keys; openSource flag; snapshot dates 2026-09-06 – 2026-09-17). Channel overall median computed exactly as the deterministic index defines it (55 tools). "Not recorded" is an archive statement; no certification, audit or compliance conclusion is made.