DevFlow vs Devin: 7 dimensions, sourced
DevFlow and Devin are compared on 7 dimensions below, each read from Cognition's own documentation on 1 Oct 2026; 3 cases where Devin fits better are listed too.
Devin is an autonomous AI software engineer from Cognition that can write, run and test code; sessions start from a web app, Slack, Microsoft Teams, an API or a command-line client.↗
Each claim about the other product was read on 1 Oct 2026 from the page its ↗ link opens. Cells in the DevFlow column are written from files in DevFlow's own codebase, named next to each cell; that codebase is not public. A comparison left unchecked for 90 days is flagged for review.
| Dimension | DevFlow | Devin |
|---|---|---|
| Where it runs | On the hosted instance at devflow.fraway.io. A self-hosted install is not self-serve: it is arranged with Fraway on request.site/src/lib/site.tsENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelte | An outpost is a machine option in Devin Cloud, alongside Ubuntu and Windows. With Devin Outposts, sessions run inside infrastructure you control: command execution, file edits and repository access happen on your machines, while the agent loop (inference and planning) continues to run in Devin's cloud.↗ |
| Where your code goes | On the hosted instance at devflow.fraway.io, DevFlow clones repositories into worktrees on the servers that run it. Prompts, which include code, go to the model provider the workspace chooses.CLAUDE.mdsite/src/lib/site.ts | In Enterprise Cloud, Devin's brain and its Devbox both run in Cognition's multi-tenant cloud. Customer Dedicated Deployment moves the Devbox into a single-tenant VPC that Cognition hosts; the brain always resides in Cognition's Cloud.↗ |
| Model choice | Each workspace stores its own key for OpenRouter, Anthropic, OpenAI or Google. On Pro and higher plans, managed OpenRouter inference can stand in when no OpenRouter key is stored.internal/relay/providers.gointernal/entitlement/entitlement.goCLAUDE.md | Cognition describes Devin as a compound AI system that does not currently support third-party LLM API keys. The pricing page lists limited model availability on Free and, from Pro, full model availability with frontier models from OpenAI, Claude, Gemini and SpaceXAI plus leading open-source models.↗↗ |
| Isolation | Each task gets its own git worktree. Agent CLIs run under a Landlock sandbox or, when enabled, in a per-invocation container; test and build commands run in non-root containers capped at 4 CPUs and 4 GB of memory by default.CLAUDE.mdinternal/agent/depcache.go | In Enterprise Cloud, each Devin session runs on its own isolated machine, and data is encrypted in transit and at rest.↗ |
| Verification | Runs the repository's configured test commands plus an AI code review and records both in a merge evidence report. A repository with no configured commands is not built or tested, and the report shows the skipped check.CLAUDE.mdinternal/agent/evidence.gointernal/agent/gate_command.go | After creating a PR, Devin can test the app end to end in its browser and send a video recording of the run. Testing starts when you click Test the app, or without asking when Pre-approve testing is on.↗ |
| Human gates | A person approves, edits or rejects the plan before code is written, and a person marks the task done, which starts the squash, push and pull request when GitHub is connected. Opt-in autopilot keeps both gates.CLAUDE.mdinternal/agent/evidence.go | Devin opens pull requests and responds to PR comments. The GitHub integration docs recommend branch protection rules so that required checks pass before Devin can merge changes.↗ |
| Pricing model | The self-serve plans are Free, Pro and Team; an Enterprise plan is arranged with Fraway on request. Model usage is paid to the provider whose key the workspace stores, or through managed inference on Pro and above.internal/entitlement/entitlement.goENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelte | The pricing page lists Free at $0/month, Pro at $20/month, Max at $200/month, Teams at $80/month for the team plan plus $40/month per full dev seat, and Enterprise under "Let's talk".↗ |
How to read the table
- Where it runs compares hosted machines, machines you operate, and the options in between.
- Where your code goes compares where a checkout lives and which hosting services each product works with.
- Model choice compares fixed model sets, model pickers and keys you bring yourself.
- Isolation compares virtual machines, containers, sandboxes and network limits.
- Verification compares test runs, reviewing models and security scans.
- Human gates compares plan approval, pull request review and approval of individual actions.
- Pricing model compares plans, usage credits and the model spend you pay directly.
Where Devin fits better
- You want Cognition to operate everything: its deployment guide says an Enterprise Cloud deployment can be completed within minutes.↗
- You want a screen recording of each end-to-end app test sent to you once the pull request is open.↗
- You need sessions on macOS virtual machines to build and test iOS and macOS apps.↗
What Cognition documents
Cognition's introduction gives a rule of thumb: if you can do a task in three hours, Devin can most likely do it.↗
For self-hosted tools such as GitHub Enterprise Server or Artifactory, the deployment guide calls for IP allowlisting in Enterprise Cloud or a dedicated deployment. Customer Dedicated Deployment connects your network through AWS PrivateLink or an IPSec tunnel.↗
Usage past a plan's quota draws on prepaid on-demand credits, which roll over from month to month.↗
On paid plans you can opt out of model training on your data, and for Enterprise customers Cognition does not train on customer data without prior written consent.↗
How DevFlow runs the work
A DevFlow task moves from planning to a plan review, then to decomposition into at most 8 subtasks, implementation, verification and a written summary. Each task gets its own branch, named after its task ID, in a worktree under the repository's .devflow/worktrees directory.
By default, every agent invocation has a hard limit of 90 minutes and is stopped after 45 minutes without output. A workspace can also set a monthly spend cap, and a task over that cap fails with a reason before it starts.
On Pro and higher plans, finalization also runs dependency scanners for the languages DevFlow detects, such as govulncheck for Go modules and pnpm audit for Node packages, each stopped after 300 seconds by default. Scan results go into the evidence report and do not block the pipeline.
What DevFlow records along the way
A task that finishes implementation gets a merge evidence report listing the models that did the work, each subtask's verifier outcome, the build checks, the security scan summary, the final review and the people who approved the plan and clicked Mark Done. The report is added to the pull request body, and later rework refreshes it there.
Agent processes start with an allowlisted environment instead of inheriting the server's own. Provider keys and GitHub tokens are encrypted at rest with AES-256-GCM.
FAQ
Can Devin use my own model API keys?
Cognition's deployment guide says Devin does not currently support third-party LLM API keys (checked 1 Oct 2026). DevFlow stores a key per workspace for OpenRouter, Anthropic, OpenAI or Google.
Can Devin run on my own infrastructure?
With the Outposts option, Devin's commands, file edits and repository access run on machines you operate, while inference and planning stay in Devin's cloud. DevFlow runs at devflow.fraway.io; a self-hosted DevFlow install is not self-serve and is arranged with Fraway on request.