Category evidence snapshot

AI Coding Tools Trust Evidence Snapshot 2026

A public evidence snapshot of trust, security, privacy, legal, AI data usage, and enterprise-readiness surfaces across selected AI coding tools, agentic IDEs, app builders, and developer-workflow AI products.

Public evidence only. Signals are interpretive and do not by themselves prove buying intent, non-compliance, procurement pressure, or active vendor search.

130candidate entities triaged
45priority evidence scans
31public examples

What this category includes

This snapshot covers developer-facing AI systems where public trust evidence may matter because the product can interact with code, repositories, IDEs, CI/CD workflows, tests, prompts, developer workspaces, generated applications, or agent execution environments.

Evidence surfaces tracked

  • Trust Centers, security pages, customer assurance portals, and vulnerability/security reporting surfaces.
  • Privacy, legal, terms, DPA, and subprocessor pages.
  • AI data usage, model training, code access, repository handling, and data retention statements when publicly available.
  • Enterprise controls such as SSO, SCIM, RBAC, audit logs, admin controls, data residency, status, and enterprise plans.

Exclusion rule

Product aliases, wrappers, launch labels, and unresolved rebrands were excluded or deferred unless an official product surface and parent-vendor mapping could be stated conservatively.

Snapshot inclusion requires a verified official product or vendor surface and at least one official public evidence surface.

Representative public evidence patterns

The sample intentionally includes mature, partial, and sparse evidence patterns. It is not a ranking and does not claim that any vendor is more secure, more compliant, or currently buying trust tooling.

10benchmark examples
20partial / evolving examples
1sparse / gap examples

Benchmark evidence examples

AI coding or developer-workflow AI vendors with multiple mature public trust, security, legal, privacy, compliance, or enterprise-readiness evidence surfaces.

Claude Code / Anthropic

core ai coding tool

benchmark evidence mature
Evidence pattern
Parent-vendor trust center, security/legal pages, DPA/subprocessor, and AI/model-training policy surfaces observed as candidate evidence.
Observed surfaces
Trust Center or customer-assurance surface; security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; subprocessor disclosure; AI data usage documentation observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

GitHub Copilot / GitHub

core ai coding tool

benchmark evidence mature
Evidence pattern
GitHub product page plus GitHub security/legal, DPA/subprocessor, Copilot privacy/admin docs candidate evidence.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; subprocessor disclosure; AI data usage documentation; enterprise administration documentation observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Cursor / Anysphere

core ai coding tool

benchmark evidence mature
Evidence pattern
Trust center, security, privacy, terms, DPA, subprocessor, and enterprise candidate URLs observed.
Observed surfaces
Trust Center or customer-assurance surface; security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; subprocessor disclosure; enterprise security or enterprise plan language; code access or repository-handling language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Windsurf / Devin Desktop / Cognition

core ai coding tool

benchmark evidence mature
Evidence pattern
Windsurf now redirects into Devin Desktop; parent-vendor Cognition legal/security surfaces and legacy Windsurf trust center are observed as candidate evidence.
Observed surfaces
official product surface; trust-center candidate surface; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; security page or security documentation; parent-vendor evidence; enterprise-facing language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

JetBrains

core ai coding tool

benchmark evidence mature
Evidence pattern
Security, privacy, terms, DPA, subprocessors, AI terms, and enterprise candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; subprocessor disclosure; AI-specific terms; enterprise security or enterprise plan language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Gemini Code Assist / Google Cloud

core ai coding tool

benchmark evidence mature
Evidence pattern
Google Cloud product page plus Cloud security/legal/DPA/subprocessor/generative-AI governance candidate evidence.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; subprocessor disclosure; compliance-scope documentation; AI data governance documentation observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Lovable

app builder or dev environment

benchmark evidence mature
Evidence pattern
Homepage links to security, trust center, privacy, terms, DPA, subprocessor, and status surfaces; privacy page contains data handling/model-training language.
Observed surfaces
Trust Center or customer-assurance surface; security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; subprocessor disclosure; status page; AI data usage or model-training language; integration data-handling language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Kiro / AWS

core ai coding tool

benchmark evidence mature
Evidence pattern
Kiro product surface plus AWS security/privacy/terms/compliance candidate evidence.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; DPA or GDPR-center evidence; compliance-scope documentation; parent-vendor evidence observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Amp / Sourcegraph

core ai coding tool

benchmark evidence mature
Evidence pattern
Amp product surface plus Sourcegraph security/legal/DPA/subprocessor candidate evidence.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; subprocessor disclosure; parent-vendor evidence observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Testsigma

code quality testing adjacent

benchmark evidence mature
Evidence pattern
Security, privacy, terms, DPA, subprocessors, and enterprise candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; subprocessor disclosure; enterprise security or enterprise plan language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Partial / evolving trust surface examples

Official evidence exists, but the public trust surface is distributed, incomplete, or still evolving.

Vercel v0 / Vercel

app builder or dev environment

partial public trust surface
Evidence pattern
v0 product surface plus Vercel security/privacy/terms parent evidence.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; AI app-builder product surface; repository sync language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Bolt / StackBlitz

app builder or dev environment

partial public trust surface
Evidence pattern
Bolt product surface, Bolt trust-center candidate surface, StackBlitz privacy/terms, and StackBlitz platform context observed.
Observed surfaces
Trust Center or customer-assurance surface; security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; AI app-builder product surface; enterprise-language candidate evidence; browser development environment security language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Replit

app builder or dev environment

partial public trust surface
Evidence pattern
Replit privacy and terms pages observed; security/enterprise pages need final verification.
Observed surfaces
privacy policy or privacy documentation; terms or legal documentation; enterprise-language candidate evidence; AI app-builder product surface observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Zed

core ai coding tool

partial public trust surface
Evidence pattern
Security, privacy, terms, and enterprise candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; enterprise security or enterprise plan language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Cline

core ai coding tool

partial public trust surface
Evidence pattern
Privacy, terms, and open-source/repo evidence candidate observed.
Observed surfaces
privacy policy or privacy documentation; terms or legal documentation; repository or code-access language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Kilo Code / Kilo

core ai coding tool

partial public trust surface
Evidence pattern
Official project page observed; legal or security surfaces were not observed during review.
Observed surfaces
privacy policy or privacy documentation; repository or code-access language; open-source project surface observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Codebuff

core ai coding tool

partial public trust surface
Evidence pattern
Privacy and terms candidate URLs observed.
Observed surfaces
privacy policy or privacy documentation; terms or legal documentation; repository or code-access language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Zencoder

core ai coding tool

partial public trust surface
Evidence pattern
Privacy and terms candidate URLs observed.
Observed surfaces
privacy policy or privacy documentation; terms or legal documentation; repository or code-access language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Qoder

core ai coding tool

partial public trust surface
Evidence pattern
Privacy and terms candidate URLs observed.
Observed surfaces
privacy policy or privacy documentation; terms or legal documentation observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Cosine

core ai coding tool

partial public trust surface
Evidence pattern
Privacy and terms candidate URLs observed.
Observed surfaces
privacy policy or privacy documentation; terms or legal documentation; repository or code-access language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Lightning AI

core ai coding tool

partial public trust surface
Evidence pattern
Security, privacy, terms, and enterprise candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; enterprise security or enterprise plan language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

QA.tech

code quality testing adjacent

partial public trust surface
Evidence pattern
Security, privacy, and terms candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

TestSprite

code quality testing adjacent

partial public trust surface
Evidence pattern
Security, privacy, and terms candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Trunk

code quality testing adjacent

partial public trust surface
Evidence pattern
Security, privacy, terms, and enterprise candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; enterprise security or enterprise plan language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

CodeThreat

code quality testing adjacent

partial public trust surface
Evidence pattern
Security, privacy, terms, and code security positioning candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; repository or code-access language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Signadot

code quality testing adjacent

partial public trust surface
Evidence pattern
Security, privacy, terms, and enterprise/security candidate URLs observed.
Observed surfaces
security page or security documentation; privacy policy or privacy documentation; terms or legal documentation; enterprise security or enterprise plan language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

CodeRabbit

core ai coding tool

partial public trust surface
Evidence pattern
Official homepage, Trust Center URL, privacy, terms, DPA, docs, changelog, status URL, and enterprise pricing language observed. Trust Center content scope, status content, SOC 2 scope, and AI data usage were not promoted in this review.
Observed surfaces
trust-center candidate surface; privacy policy or privacy documentation; terms or legal documentation; data processing agreement or data protection addendum; enterprise-language candidate evidence; repository or code-access language observed during review.
What not to infer
Do not infer trust maturity, security quality, compliance certification, SOC 2 scope, AI data usage practices, procurement pressure, or buying intent from these public evidence surfaces alone.

Tabnine

core ai coding tool

partial public trust surface
Evidence pattern
Official homepage, Trust Center candidate URL, privacy policy, terms, code privacy page, docs, pricing, and careers URL observed. DPA, subprocessors, certification evidence, and broad AI data usage or model-training evidence were not promoted in this review.
Observed surfaces
trust-center candidate surface; privacy policy or privacy documentation; terms or legal documentation; code access or repository-handling language; enterprise-language candidate evidence observed during review.
What not to infer
Do not infer trust maturity, security quality, compliance certification, AI data usage practices, model-training practices, procurement pressure, or buying intent from these public evidence surfaces alone.

Augment Code

core ai coding tool

partial public trust surface
Evidence pattern
Official homepage, Trust Center candidate URL, security page, docs, status page, changelog, and pricing surface identified for conservative source-scope review. Privacy, terms, DPA, subprocessors, certification evidence, and AI data usage or model-training evidence were not promoted in this review.
Observed surfaces
trust-center candidate surface; security page or security documentation; status page; docs; changelog; enterprise-language candidate evidence; code access or repository-handling language observed during review.
What not to infer
Do not infer trust maturity, security quality, compliance status, certification scope, AI data usage practices, procurement pressure, or buying intent from these public evidence surfaces alone.

Qodo

core ai coding tool

partial public trust surface
Evidence pattern
Official homepage, Trust Center candidate URL, docs, enterprise page, and careers surface identified for conservative source-scope review. Privacy, terms, DPA, subprocessors, certification evidence, and AI data usage or model-training evidence were not promoted in this review.
Observed surfaces
trust-center candidate surface; docs; enterprise-language candidate evidence; code access or repository-handling language observed during review.
What not to infer
Do not infer trust maturity, security quality, compliance status, certification scope, AI data usage practices, procurement pressure, or buying intent from these public evidence surfaces alone.

Sparse / gap examples

Serious AI coding tools, open-source-commercial projects, or developer workflow entities with limited public trust surface during review.

opencode

core ai coding tool

sparse or gap pattern
Evidence pattern
Official project page observed; legal or security surfaces were not observed during review.
Observed surfaces
repository or code-access language observed during review.
What not to infer
Do not infer trust maturity, compliance posture, security quality, production readiness, or buying intent from public evidence surfaces alone.

Selected public evidence examples

All rows below are included in the company profile output for this category package. Use the evidence matrix for horizontal comparison across observed public evidence surfaces.

Company / productCategory roleMaturity patternLast checked
Claude Code / Anthropiccore ai coding toolbenchmark evidence mature2026-07-04
GitHub Copilot / GitHubcore ai coding toolbenchmark evidence mature2026-07-04
Cursor / Anyspherecore ai coding toolbenchmark evidence mature2026-07-04
Windsurf / Devin Desktop / Cognitioncore ai coding toolbenchmark evidence mature2026-07-04
JetBrainscore ai coding toolbenchmark evidence mature2026-07-04
Gemini Code Assist / Google Cloudcore ai coding toolbenchmark evidence mature2026-07-04
Vercel v0 / Vercelapp builder or dev environmentpartial public trust surface2026-07-04
Lovableapp builder or dev environmentbenchmark evidence mature2026-07-04
Bolt / StackBlitzapp builder or dev environmentpartial public trust surface2026-07-04
Replitapp builder or dev environmentpartial public trust surface2026-07-04
Kiro / AWScore ai coding toolbenchmark evidence mature2026-07-04
Amp / Sourcegraphcore ai coding toolbenchmark evidence mature2026-07-04
Zedcore ai coding toolpartial public trust surface2026-07-04
Clinecore ai coding toolpartial public trust surface2026-07-04
opencodecore ai coding toolsparse or gap pattern2026-07-04
Kilo Code / Kilocore ai coding toolpartial public trust surface2026-07-04
Codebuffcore ai coding toolpartial public trust surface2026-07-04
Zencodercore ai coding toolpartial public trust surface2026-07-04
Qodercore ai coding toolpartial public trust surface2026-07-04
Cosinecore ai coding toolpartial public trust surface2026-07-04
Lightning AIcore ai coding toolpartial public trust surface2026-07-04
Testsigmacode quality testing adjacentbenchmark evidence mature2026-07-04
QA.techcode quality testing adjacentpartial public trust surface2026-07-04
TestSpritecode quality testing adjacentpartial public trust surface2026-07-04
Trunkcode quality testing adjacentpartial public trust surface2026-07-04
CodeThreatcode quality testing adjacentpartial public trust surface2026-07-04
Signadotcode quality testing adjacentpartial public trust surface2026-07-04
CodeRabbitcore ai coding toolpartial public trust surface2026-07-08
Tabninecore ai coding toolpartial public trust surface2026-07-08
Augment Codecore ai coding toolpartial public trust surface2026-07-08
Qodocore ai coding toolpartial public trust surface2026-07-08