Devin
Fully autonomous AI software engineer operating from web, Slack/Teams, CLI/Terminal, Windsurf IDE, and REST API v3.
Dimension breakdown
Score · confidenceFully autonomous AI software engineer operating from web, Slack/Teams, CLI/Terminal, Windsurf IDE, and REST API v3. Devin 2.2 (Feb 24) self-review + auto-fix; through May 2026 ships Devin-Manages-Devins parallel orchestration, Review auto-fix/auto-merge, PR resuming, GitLab interactive PR review, and Adaptive model routing (SWE-1.6 default, opus/sonnet/codex selectable).
Windsurf acquisition thesis now realized — Devin runs embedded in the IDE, not a separate tab. Series D CLOSED May 27: $1B at $25B pre / $26B post (2.5x in 8 months), ~$492M ARR run-rate, enterprise usage +50% MoM for 6 months; Devin now writes 89% of Cognition's own code.
Enterprise base deepened: Mercedes-Benz (8-month legacy modernization in 8 days), NASA, Goldman Sachs, Citi, Santander, Itaú (70% of security vulns auto-fixed), Infosys multi-vertical. SOC 2 Type II + ISO 27001:2022 + CCPA; VPC dedicated deployment, training opt-in by default.
SWE-bench 45.8% now mid-field as Cursor (65.7%) and frontier agents reach 80%+. Under active evaluation for backlog/migration offload. Monitor for: hands-on WWT validation, unaddressed prompt-injection attack surface (Critic + egress allowlist are partial mitigations), and ACU cost unpredictability.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
No active caps — no risk flags apply to this tool right now.
Status rationale
Assessed because strong enterprise deployment evidence (Infosys multi-vertical, Goldman Sachs, Citi, Mercedes-Benz, NASA, Santander, Nubank, Mercari, Itaú), major capability advances (Devin 2.2 self-review/auto-fix, Devin-Manages-Devins orchestration, Adaptive model routing, Windsurf embedded), and extraordinary company momentum (Series D closed May 27 — $1B at $26B post-money, ~$492M ARR, +50% MoM for six months). Blockers for Validated: hands-on internal evaluation not completed; prompt-injection attack surface unaddressed (Critic + default-deny egress allowlist are partial mitigations, no published CVE/patch closing it); mixed community sentiment (Trustpilot 3.0/5, score 3, need 4+); ACU pricing unpredictability (no pre-task cost disclosure).
Movement triggers
Upgrade to Validated if: hands-on internal testing completed at ≥40% complex task success on representative WWT workloads; prompt injection vulnerability addressed with published patch/CVE disclosure; community sentiment improves to 4+; ACU billing adds pre-task cost estimation (addresses predictability concern); and explicit human approval granted. Downgrade to Tracked if: $25B funding round fails with significant valuation reset; prompt injection produces a named enterprise security incident; or community sentiment drops to 2 or below.
Risks & limitations
Not yet assessed — this section fills in as ACES research covers the tool.
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category