Code generation companies, products & suppliers

Products whose job is to produce substantial code or apps from a spec, not inline autocomplete. Jobs: spec-to-code; scaffolding a service; batch generation of tests or clients.

What is Code generation?

Products whose job is to produce substantial code or apps from a spec, not inline autocomplete. Jobs: spec-to-code; scaffolding a service; batch generation of tests or clients.

What problems does it solve?

Greenfield or migration work still starts from a blank repo.

Typical business use cases

  • Spec-to-code
  • Scaffolding a service
  • Batch generation of tests or clients

Important capabilities

  • Repo or spec input
  • Project output
  • Language coverage

What buyers should evaluate

  • IP of output
  • Secret handling
  • Human review gate

Risks and governance considerations

Generated services shipped without review or licence clarity.

Procurement checklist

  • Output ownership
  • Review required
  • Language and framework fit

Relevant AI Trustmark assurance

AI Trustmark independent findings appear only when an assessment or certificate exists. Category membership does not imply verification.

Methodology · How verification works

Companies and providers

Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.

  • We run the open-weight model that you choose as a dedicated deployment, or we route 300+ models through one endpoint. BLACKBOX AI is used for Code generation work. BLACKBOX AI publ

  • Cognition operates Devin, the first autonomous software engineer. Devin plans, writes, tests, and ships production code inside your existing workflows. Cognition publishes Windsurf

  • Anysphere is the US company behind Cursor, an AI code editor sold as a hosted subscription product. Cursor is used for Code generation and Coding assistants work. Cursor is recorde

  • Diffblue Testing Agent generates, verifies, and fixes unit tests autonomously across enterprise codebases. Unlike other AI coding agents, Diffblue is built for automatically genera

  • GitHub, a Microsoft company, sells Git hosting, Actions CI and Copilot AI coding assistance. Public pages cover cloud repositories and developer tools. GitHub publishes GitHub Copi

  • Google is a US technology company that sells consumer and cloud AI products, including Gemini, Search, and related developer APIs on Google Cloud. Google publishes Imagen, Gemini f

  • International Business Machines Corporation sells hybrid-cloud software, Granite models and enterprise AI tooling. Public pages distinguish IBM software and models from IBM Consult

  • JetBrains AI Assistant adds AI chat, code completion, and agent features inside JetBrains IDEs. Public marketing also emphasises native integration across IntelliJ-family IDEs. It

  • Mistral AI is a Paris-headquartered model company selling open-weight and hosted language models. Public pages cover APIs, model licences and enterprise deployments. Mistral AI pub

  • OpenAI is a US AI research company that sells hosted assistants, APIs and developer tools, including ChatGPT and the OpenAI API. OpenAI publishes ChatGPT Work, omni-moderation, and

  • Poolside builds foundation models and products for software engineering aimed at enterprises that want private or custom code models. Poolside is used for Code generation work. Poo

  • Replit publishes Replit Agent as named AI products. Replit is used for Code generation work. Replit publishes product information at replit.com. Replit is grouped with Code generat

  • Bolt.new by StackBlitz lets users build and scale websites and apps from natural-language prompts in the browser. Public marketing also emphasises in-browser full-stack generation

  • Vercel publishes AI SDK, v0, and Vercel AI Gateway as named AI products. Vercel is used for AI SDKs and AI app builders work. Vercel is recorded in San Francisco, United States. Ve

Products

Claimed products appear first. Ranking packs and payment do not change this list.

Also used in this category

These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.

Related categories

Relevant procurement and assurance guides

Frequently asked questions

What is Code generation?

Products whose job is to produce substantial code or apps from a spec, not inline autocomplete. Jobs: spec-to-code; scaffolding a service; batch generation of tests or clients.

What should not be listed as Code generation?

Products whose buyer job is IDE coding assistants, low-code builders, or documentation generators. Those belong on their own category page so search queries are not split.

Has AI Trustmark independently assessed every Code generation supplier?

No. A category listing is descriptive. Independent assessment is shown only on company or product pages that carry Trustmark evidence.

Should coding assistants be allowed to send private source code to third-party models?

That is a buyer policy decision. Procurement should require the default data-use terms, retention, whether snippets leave the organisation, and whether secrets are redacted. A listing under coding assistants does not mean code stays on-premises.

How should prompt injection and tool-output attacks be controlled?

Agents that read untrusted content or tool output can be instructed to exfiltrate data or take writes. Buyers should ask what is treated as untrusted, whether tool output can change the plan, and what tests were run. Scanner marketing is not the same as independent testing.

How can buyers tell whether customer data is used to train models?

Ask whether prompts, files, logs or outputs are used to train, fine-tune or evaluate models, including by subprocessors. Require the contractual default, any opt-out, and whether the setting can be changed silently. Treat marketing 'we do not train' claims as unverified until evidenced.

What model or provider changes should a buyer insist on being told about?

Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.

How should buyers verify where AI customer data is processed?

Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.