Sourcegraph Cody icon

Sourcegraph Cody

AI coding assistant with deep codebase search and enterprise security controls

by SourcegraphUSUnited States🌐US (cloud); customer-controlled region (self-hosted)
TrustKit Score72%Strong

About Sourcegraph Cody

Sourcegraph was founded in 2013 with a focus on code search and intelligence—helping developers understand and navigate large, complex codebases. Cody is Sourcegraph's AI coding assistant, launched in 2023, and its key differentiator is the deep codebase context it can provide. Rather than relying only on files currently open in the editor, Cody uses Sourcegraph's code graph to retrieve relevant code snippets from across an entire codebase at query time, delivering more accurate and contextually appropriate AI suggestions for large enterprise repositories. Cody supports multiple underlying LLM providers—including Anthropic Claude, OpenAI GPT-4, and Google Gemini—and can be configured to use an organisation's preferred model or even a self-hosted LLM endpoint. This flexibility is particularly valuable for enterprises with data sovereignty requirements: the LLM processing can be directed to an approved provider or to an on-premise model deployment, while Sourcegraph handles the code retrieval and context assembly. For European enterprise engineering teams, Cody's enterprise architecture offers meaningful compliance controls. Self-hosted deployment of the Sourcegraph platform (on AWS, GCP, Azure, or bare metal) keeps all code and query data within the organisation's own infrastructure. Enterprise customers can bring their own LLM provider keys, ensuring that AI processing happens under their own contracts with their chosen model provider. SSO, admin controls, audit logging, and GDPR-compliant DPAs are available for enterprise accounts. Sourcegraph is US-incorporated but the enterprise self-hosted architecture enables European businesses to deploy Cody in a way that satisfies EU data residency and sovereignty requirements. This makes it one of the more genuinely enterprise-ready AI coding assistants for regulated European organisations.

Sentiment Score?
4.5/ 5

TrustKit Score Breakdown

?72% Strong
Data Residency
Where is your data stored and processed?
Cloud product uses US infrastructure. Self-hosted enterprise deployment allows organisations to choose their own data centre region, including EU. Score reflects the enterprise self-hosted path which achieves 5; cloud product scores 1.
3/5
Legal Jurisdiction
Which laws govern the company and your data?
US incorporation, Delaware jurisdiction. SOC 2 and ISO 27001 available. Enterprise self-hosted with EU data centres removes US cloud dependency. Bring-your-own-LLM allows choice of EU-incorporated model provider.
3/5
Data Retention & Training
Is your data used for model training?
Code and queries are not used for model training. Self-hosted deployment gives organisations full control over data retention. Enterprise DPA and audit logging available. Strong data governance posture.
5/5
Certifications
ISO 27001, SOC 2, Cyber Essentials, etc.
Holds both SOC 2 Type II and ISO 27001 certifications. Strong certification posture for an enterprise developer tooling company. Appropriate for regulated-industry procurement.
4/5
Regulatory Fit
Suitability for regulated industries and professional services
Self-hosted enterprise deployment with EU data centres and EU-region LLM provider is well-suited for EU regulated industries. Cloud product requires SCCs. ISO 27001 and SOC 2 meet common enterprise procurement thresholds.
3/5

Pricing

FreemiumFree tier
FreeFree
Pro$9/user/mo
Enterprise$19/user/mo
Full pricing details →

Quick Facts

Starting PriceFree / $9/mo ProData HostingUS (cloud); customer-controlled region (self-hosted)Trains on Your DataCode not used for model trainingFounded2013Employees201-1000

Frequently Asked Questions

Is Sourcegraph Cody GDPR compliant?

Sourcegraph Cody has a TrustKit compliance score of 72% (Strong). Data Residency: Cloud product uses US infrastructure. Self-hosted enterprise deployment allows organisations to choose their own data centre region, including EU. Score reflects the enterprise self-hosted path which achieves 5; cloud product scores 1.. Legal Jurisdiction: US incorporation, Delaware jurisdiction. SOC 2 and ISO 27001 available. Enterprise self-hosted with EU data centres removes US cloud dependency. Bring-your-own-LLM allows choice of EU-incorporated model provider..

Where does Sourcegraph Cody store data?

Sourcegraph Cody hosts data in: US (cloud); customer-controlled region (self-hosted). Cloud product uses US infrastructure. Self-hosted enterprise deployment allows organisations to choose their own data centre region, including EU. Score reflects the enterprise self-hosted path which achieves 5; cloud product scores 1.

Does Sourcegraph Cody train on user data?

Sourcegraph Cody: Code not used for model training. Code and queries are not used for model training. Self-hosted deployment gives organisations full control over data retention. Enterprise DPA and audit logging available. Strong data governance posture.

What certifications does Sourcegraph Cody hold?

Sourcegraph Cody holds: SOC 2 Type II, ISO 27001. Holds both SOC 2 Type II and ISO 27001 certifications. Strong certification posture for an enterprise developer tooling company. Appropriate for regulated-industry procurement.

Compare Sourcegraph Cody With

Similar Tools