Compare

Jern Cloud vs Devin.

Devin is built as a general software engineer: it browses, uses a desktop, records video of its testing, and plugs into Slack, Linear, and your own infrastructure. Jern Cloud is narrower on purpose: an agent under a policy the repository owns and the runtime enforces, on a machine it cannot reach out of, with a receipt on every pull request. This page is written from Devin's public documentation as of September 8, 2026 and from ours; if we have something wrong, tell us and we will fix it.

Side by side

Jern CloudDevin
Where the agent runsOne machine per attempt, created for it and destroyed afterwards, with Linux namespaces and seccomp inside the guest boundary. Machine time is metered per size.A virtual machine in Devin's cloud, Ubuntu or Windows, that sleeps when idle and wakes on a message. With Outposts, sessions execute on your own VMs, containers, or Kubernetes while inference stays in Devin's cloud.
What starts workThe dashboard, an issue label, a /jern comment, a failed check on the session's pull request, a schedule, or the MCP server from an editor.The web app, Slack, Linear, the Devin CLI, a hand-off from another agent, or an automation: Slack messages and reactions, GitHub issue comments, pull request events, check runs, pushes, Linear events, schedules, and webhooks.
Where the rules liveA file in the repository, protected by your reviewers and pinned by digest for the session. The runtime enforces it at every tool call: paths that may change, a blast radius in files and lines, protected paths, the shell commands that run without asking, services, and hosts.Security profiles an admin defines and binds to the enterprise, organization, automations, or a session: a network allowlist, an MCP allowlist, read-only or full git access, and whether the machine carries a GitHub CLI token. Knowledge, playbooks, and skills guide the agent; they do not bound it.
Network while it worksDuring the run, one route: a relay to the Jern gateway. Named hosts from the baseline are readable through a tool that counts every contact on the receipt. Package indexes are reachable during setup only.Unrestricted unless a security profile sets an allowlist of hostnames or CIDR ranges, which then applies to shell commands, browsing, package installs, and scripts alike.
Credentials the agent holdsNone. Checkout, evidence upload, checkpoints, and publication each use a short-lived credential the runner holds outside the agent process. The gateway holds your model key.Secrets and site cookies you share so Devin can log in to tools, a git credential at the profile's access level, and optionally a GitHub CLI token. Browser sessions can be saved so later sessions start authenticated.
What the reviewer getsA receipt on every pull request as a check: tokens against cap, files against the blast radius, policy decisions, hosts contacted, the sandbox. Behind it, the exact trace, encrypted before it reaches a database.A pull request, optionally split into a stack; video recordings of Devin's testing; session insights; and per-session usage. Enterprise admins get consumption analytics.
Can it merge?Never. One pull request per session on an isolated branch; your branch protection and reviewers apply.With full git access and a GitHub CLI token the machine can use GitHub's API; what it may do there is your GitHub permissions' call. Read-only git access removes pushing and pull requests entirely.
Models and billingYour own Anthropic, OpenAI, Gemini, or Fireworks key; tokens bill to your provider account and the gateway meters them from the provider's usage report. $19 per workspace per month plus machine hours, after 30 days free.Devin's own models. Free, Pro at $20, Max at $200, and Teams from $80 a month with $40 seats, metered in a usage quota plus on-demand credits; enterprises consume Agent Compute Units. Usage accrues from the actions Devin takes and its VM time.
Self-hostedJern's cloud only. Self-hosted runners are on the roadmap.Yes, through Outposts, on your own machines or on partner platforms; the customer secures and operates those machines.
BreadthGitHub only. Python, Node, .NET, and Java environments. No browser or desktop control, no Windows. The runtime is open source, Apache-2.0. The agent that runs in a session is the one you can read and run on a laptop.Browser and computer use, video recordings, Windows and Android, Slack triage, Linear, DeepWiki, a pull request reviewer, a security scanner, plugins and a skills marketplace, dynamic multi-session workflows. Closed source.

Which to choose

Choose Devin when the work needs hands: a browser to log in to your app, a desktop to test it, a video to prove it, Slack to talk about it, or your own infrastructure to run it on. Its security profiles are a real control plane, and its automations and skills match ours feature for feature. Choose Jern Cloud when you want the smaller thing done with less trust: a policy in the repository your reviewers own, an agent that cannot hold a credential or reach a host you did not name, and a receipt that lets a reviewer see what it did before reading the diff. Jern costs a fixed fee plus the tokens you already pay your provider; Devin's metering is its own.

What Jern does not do

No browser, no desktop, no Slack, no GitLab or Bitbucket, no self-hosted runners yet, and four language environments. Our isolation relies on Fly.io's guest boundary plus namespaces and seccomp inside it, and an independent test of that boundary is planned and not yet published. Your messages and the agent's replies are stored in plaintext so the dashboard can show them; evidence is encrypted, conversation text is not. The security page lists what is not defended against.

See it

The recipes are real sessions on the public demo repository with their pull requests and receipts. A session on your own repository takes a sign-in with GitHub and a provider key; the first 30 days are free.

Sources

Read on September 8, 2026. Products change; the sources are linked so you can check the current state.