DevFlow vs Devin: 7 dimensions, sourced

DevFlow and Devin are compared on 7 dimensions below, each read from Cognition's own documentation on 1 Oct 2026; 3 cases where Devin fits better are listed too.

Devin is an autonomous AI software engineer from Cognition that can write, run and test code; sessions start from a web app, Slack, Microsoft Teams, an API or a command-line client.↗

Each claim about the other product was read on 1 Oct 2026 from the page its ↗ link opens. Cells in the DevFlow column are written from files in DevFlow's own codebase, named next to each cell; that codebase is not public. A comparison left unchecked for 90 days is flagged for review.

Compared on 1 Oct 2026
DimensionDevFlowDevin
Where it runsOn the hosted instance at devflow.fraway.io. A self-hosted install is not self-serve: it is arranged with Fraway on request.site/src/lib/site.tsENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelteAn outpost is a machine option in Devin Cloud, alongside Ubuntu and Windows. With Devin Outposts, sessions run inside infrastructure you control: command execution, file edits and repository access happen on your machines, while the agent loop (inference and planning) continues to run in Devin's cloud.↗
Where your code goesOn the hosted instance at devflow.fraway.io, DevFlow clones repositories into worktrees on the servers that run it. Prompts, which include code, go to the model provider the workspace chooses.CLAUDE.mdsite/src/lib/site.tsIn Enterprise Cloud, Devin's brain and its Devbox both run in Cognition's multi-tenant cloud. Customer Dedicated Deployment moves the Devbox into a single-tenant VPC that Cognition hosts; the brain always resides in Cognition's Cloud.↗
Model choiceEach workspace stores its own key for OpenRouter, Anthropic, OpenAI or Google. On Pro and higher plans, managed OpenRouter inference can stand in when no OpenRouter key is stored.internal/relay/providers.gointernal/entitlement/entitlement.goCLAUDE.mdCognition describes Devin as a compound AI system that does not currently support third-party LLM API keys. The pricing page lists limited model availability on Free and, from Pro, full model availability with frontier models from OpenAI, Claude, Gemini and SpaceXAI plus leading open-source models.↗↗
IsolationEach task gets its own git worktree. Agent CLIs run under a Landlock sandbox or, when enabled, in a per-invocation container; test and build commands run in non-root containers capped at 4 CPUs and 4 GB of memory by default.CLAUDE.mdinternal/agent/depcache.goIn Enterprise Cloud, each Devin session runs on its own isolated machine, and data is encrypted in transit and at rest.↗
VerificationRuns the repository's configured test commands plus an AI code review and records both in a merge evidence report. A repository with no configured commands is not built or tested, and the report shows the skipped check.CLAUDE.mdinternal/agent/evidence.gointernal/agent/gate_command.goAfter creating a PR, Devin can test the app end to end in its browser and send a video recording of the run. Testing starts when you click Test the app, or without asking when Pre-approve testing is on.↗
Human gatesA person approves, edits or rejects the plan before code is written, and a person marks the task done, which starts the squash, push and pull request when GitHub is connected. Opt-in autopilot keeps both gates.CLAUDE.mdinternal/agent/evidence.goDevin opens pull requests and responds to PR comments. The GitHub integration docs recommend branch protection rules so that required checks pass before Devin can merge changes.↗
Pricing modelThe self-serve plans are Free, Pro and Team; an Enterprise plan is arranged with Fraway on request. Model usage is paid to the provider whose key the workspace stores, or through managed inference on Pro and above.internal/entitlement/entitlement.goENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelteThe pricing page lists Free at $0/month, Pro at $20/month, Max at $200/month, Teams at $80/month for the team plan plus $40/month per full dev seat, and Enterprise under "Let's talk".↗

How to read the table

Where Devin fits better

What Cognition documents

Cognition's introduction gives a rule of thumb: if you can do a task in three hours, Devin can most likely do it.↗

For self-hosted tools such as GitHub Enterprise Server or Artifactory, the deployment guide calls for IP allowlisting in Enterprise Cloud or a dedicated deployment. Customer Dedicated Deployment connects your network through AWS PrivateLink or an IPSec tunnel.↗

Usage past a plan's quota draws on prepaid on-demand credits, which roll over from month to month.↗

On paid plans you can opt out of model training on your data, and for Enterprise customers Cognition does not train on customer data without prior written consent.↗

How DevFlow runs the work

A DevFlow task moves from planning to a plan review, then to decomposition into at most 8 subtasks, implementation, verification and a written summary. Each task gets its own branch, named after its task ID, in a worktree under the repository's .devflow/worktrees directory.

By default, every agent invocation has a hard limit of 90 minutes and is stopped after 45 minutes without output. A workspace can also set a monthly spend cap, and a task over that cap fails with a reason before it starts.

On Pro and higher plans, finalization also runs dependency scanners for the languages DevFlow detects, such as govulncheck for Go modules and pnpm audit for Node packages, each stopped after 300 seconds by default. Scan results go into the evidence report and do not block the pipeline.

What DevFlow records along the way

A task that finishes implementation gets a merge evidence report listing the models that did the work, each subtask's verifier outcome, the build checks, the security scan summary, the final review and the people who approved the plan and clicked Mark Done. The report is added to the pull request body, and later rework refreshes it there.

Agent processes start with an allowlisted environment instead of inheriting the server's own. Provider keys and GitHub tokens are encrypted at rest with AES-256-GCM.

FAQ

Can Devin use my own model API keys?

Cognition's deployment guide says Devin does not currently support third-party LLM API keys (checked 1 Oct 2026). DevFlow stores a key per workspace for OpenRouter, Anthropic, OpenAI or Google.

Can Devin run on my own infrastructure?

With the Outposts option, Devin's commands, file edits and repository access run on machines you operate, while inference and planning stay in Devin's cloud. DevFlow runs at devflow.fraway.io; a self-hosted DevFlow install is not self-serve and is arranged with Fraway on request.