Continue.dev AI Vendor Risk Profile
Open-source AI coding assistant for VS Code and JetBrains. Lets developers configure any LLM backend (cloud or local) and customize context via their own code, docs, and tools.
Risk overview
Risk score: 38/100
Risk tier: Moderate
Safety rating: 62/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Dec 1, 2025 Stale — re-verification queued
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 37/100 |
| IP Exposure | 31/100 |
| Jurisdiction | 8/100 |
| Security | 40/100 |
| Regulatory Compliance | 60/100 |
| Transparency | 80/100 |
| Business Stability | 52/100 |
| Dependency Chain | 33/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Acceptable
Continue is an open-source (Apache 2.0) AI coding assistant for VS Code and JetBrains with ~$5.1M raised from Heavybit and Y Combinator. Strong on developer control — bring-your-own-LLM, including local models — but the commercial entity is small, the privacy notice is thin on training-data treatment of customer code, and there is no published SOC 2 or other enterprise compliance attestation.
Bottom line: Solid as a thin OSS layer in front of an approved LLM; treat compliance as the LLM provider's responsibility, not Continue's.
Strengths
- Apache 2.0 licensed; can be run with self-hosted or local LLMs (Ollama, vLLM) for full data control
- Bring-your-own-key model means customer-code traffic flows directly to the customer's chosen LLM provider
- Telemetry is anonymized via PostHog and is opt-out by extension setting
- Published privacy notice and dedicated docs page on telemetry
Concerns
- No SOC 2 Type II, ISO 27001, or HIPAA BAA disclosed
- Privacy notice does not explicitly address whether customer code submitted via Continue's hosted services is excluded from model training
- Small company (~$5M total raised) without enterprise-grade support and SLA history
- Default-on telemetry needs to be disabled organization-wide for sensitive codebases
Best for
- Engineering teams that already have an approved LLM (Anthropic, OpenAI, Azure OpenAI, self-hosted) and want a thin OSS client
- Privacy-sensitive teams running Continue against on-prem or VPC-hosted models
- Organizations comfortable taking responsibility for their LLM-provider DPA chain
Avoid if
- Your procurement requires a vendor SOC 2 Type II report from Continue itself
- You cannot disable default telemetry organization-wide via configuration management
- You need a HIPAA BAA from the IDE-extension vendor (not the LLM provider)
Citations
- Vendors — License Open Source
- Data Handling — Telemetry Policy
- Vendors — Privacy Policy
- Vendors — Funding Stage