Coinbase uses Sourcegraph Cody to save developers 5-6 hours per week while meeting strict security standards
The problem
Coinbase wanted to adopt AI code assistants to improve developer productivity but faced strict security requirements around code exposure, model training data use, and potential attack vectors in an industry where handling digital assets demands an especially high security bar, at a time when little public data existed on large-scale AI code assistant adoption.
Workflow diagram · grounded in source
1
Security threat model built
Validation
Coinbase's security team developed a threat model to identify risks and severities across AI code assistants in key areas.
▾ source quote
“Brady says the team came up with a threat model to identify risks and their severities across AI code assistants in a few key areas”
2
Statistical security experiment
Validation
Coinbase designed and conducted an experiment comparing AI-generated code to human-written code, determining that AI coding assistants made no statistically significant difference in the rate of security issues.
▾ source quote
“we designed and conducted an experiment to look for security issues across a number of groups, per PR, per business unit and after comparing our groups we determined using AI coding assistants made no statistically significant difference in the rate …”
3
Blind PR security review
Human review
Reviewers randomly sampled PRs and reviewed them for security issues without knowing whether the code was written with or without AI assistance.
▾ source quote
“Brady randomly sampled PRs from these groups, again ensuring statistical significance, and had people review them for potential security issues. The reviews were blind, meaning reviewers didn't know whether the PR was written with or without AI assistance.”
4
Cody deployed on Amazon Bedrock VPC
Integration
Cody runs on Amazon Bedrock within Coinbase's Virtual Private Cloud, ensuring data does not leave the company's environment.
▾ source quote
“One of the reasons we felt confident moving forward with Cody is because it runs on Amazon Bedrock. It integrates well with our existing cloud infrastructure. We must have full control over our data and environment to keep our customer …”
5
Context-aware code generation
Ai action
Cody generates boilerplate code based on Coinbase's internal SDKs and frameworks using context awareness of the codebase.
▾ source quote
“It wasn't just suggesting random pieces of code; it generated boilerplate code based on our internal SDKs and frameworks”
Reported outcome
Coinbase developers save roughly 5-6 hours per week using Cody, write code 2x faster, and 75% noted they were more productive in a recent survey.
Reported metrics
Developer time saved per weekroughly 5-6 hours per week
Code writing speed increase2x faster
Developers reporting more productive75%
Reported stack
CodyAmazon Bedrock
◆ Does this fit your context?
Compare to your context
Tell us your scale, team, and constraints. We'll show what changes at your size, what fails at your scale, and whether this case is a fit, needs adaptation, or won't scale to you. Free demo, no signup.
Coinbase developers save roughly 5-6 hours per week using Cody, write code 2x faster, and 75% noted they were more productive in a recent survey.
What tools did this team use?
Cody, Amazon Bedrock.
What results were reported?
Developer time saved per week: roughly 5-6 hours per week; Code writing speed increase: 2x faster; Developers reporting more productive: 75% (source-reported, not independently verified).
How is this back office ops AI workflow structured?
Security threat model built → Statistical security experiment → Blind PR security review → Cody deployed on Amazon Bedrock VPC → Context-aware code generation.
This case is one data point. Whether its pattern fits you depends on your volumes, your stack, and your exception load — that comparison is the step no case study can do for you.