Ordered by impact, then by how little work they take. Start at the top.
1On the two review surfaces buyers actually check, Ona is still living and dying as 'Gitpod' — 16-42 stale reviews under the old name vs. deep, current corpora at Coder and Cursor
ImpacthighEffortlow
G2's product page for the company is titled 'Gitpod Reviews 2026' with only 16 reviews at 4.3/5 (also listed via the seller profile g2.com/sellers/gitpod), and the visible reviews are dated between 2022 and April 2024, describing the legacy cloud-IDE product with no mention of Ona, background agents, Automations, or Veto. Direct competitors have far deeper, more current review corpora on the same platform: Coder shows 4.3/5 across 212 reviews, and Cursor shows 4.5-4.6/5 across 42-316 reviews depending on the profile checked. A buyer researching 'AI agent infrastructure' on G2 finds a thin, stale entry under a brand name (Gitpod) the company itself no longer leads with in its own marketing, and searching for 'Ona' on G2 returns nothing at all.
Why it matters: Enterprise buyers doing vendor diligence lean on G2 volume and recency as a trust signal, and right now Ona's review footprint reads as an abandoned, stale product rather than the category leader it claims to be, giving competitors with active review pipelines a credibility edge in side-by-side procurement.
Recommended move
Claim/rebrand the G2 profile as Ona, run an in-app review-refresh campaign to recent Enterprise/Core customers, work with G2 to update the listing title/branding from Gitpod to Ona, and build parallel presence on Gartner Peer Insights/TrustRadius if absent.
Buildable
- Expected
- The G2 listing is titled/branded 'Ona', with reviews dated within the current year referencing agents/Automations/Veto, at review volume comparable to Coder (212) or Cursor (42+).
- Actual
- Listing is titled 'Gitpod Reviews 2026', has only 16 reviews, most recent dated 04/03/2024, and none reference Ona, agents, Automations, or Veto.
Evidence · 5 verified claims
Gitpod's G2 product page has only 16 reviews at a 4.3/5 average, still under the Gitpod name.
“Gitpod
By Gitpod
4.3/5 (16)
5 star 75%
4 star 18%
1 star 6%”
Source: www.g2.com/products/gitpod/reviews
The visible reviews are old, dated between 2022 and early 2024, predating the Ona rebrand.
“Jelle D. ... 2/7/2024 ... "In general you see that the market is still quite young for cloud IDEs" ... Adam T. ... 7/19/2022”
Source: www.g2.com/products/gitpod/reviews
Coder has 212 G2 reviews at 4.3/5; Cursor has 316 G2 reviews at 4.6/5 — both far deeper than Gitpod/Ona's 16.
“Coder
By Coder
4.3/5(212)
5 star 55%
4 star 41%
3 star 2%”
Source: www.g2.com/products/coder/reviews
Gitpod's G2 profile shows only 16 reviews, averaging 4.3/5, with content describing the legacy dev-environment product.
“Gitpod has been rated 4.3 stars by 16 verified reviews on G2 ... Gitpod provides very fast VMs for using our codespaces on very end machines...browser version of code editors to directly code through any browser”
Source: www.g2.com/sellers/gitpod
The most recent review visible on Gitpod's G2 profile is dated April 2024.
“Rahul S.
Great platform for faster and reliable codespaces.
Reviewed on Apr 03, 2024
Review provided by G2”
Source: www.g2.com/sellers/gitpod
2Self-hosted deployment and SSO/OIDC are both Enterprise-only and sales-gated, while Coder gives away both for free, self-serve, today
ImpacthighEffortmedium
Ona's pricing page lists 'Bank-grade VPC deployment' and 'SSO and OIDC identity and access controls' exclusively under the Enterprise tier ('Custom pricing'), with Core capped at Ona's own multi-tenant cloud only, and the compare table confirms Core's 'Compute Deployment' as 'Ona Cloud (multi-tenant)' versus Enterprise's 'Self-hosted, Ona-managed VPC.' The only route into that tier from the pricing page is 'Request a demo' — there is no price shown and no self-serve path. Coder's free, self-hosted Community edition already includes 'Single Sign-On (OpenID Connect)' and lets users 'Assign long-running tasks to AI coding agents' at $0, with no seat cap and no sales call required, so a security-conscious mid-market buyer can be running Coder in their own infrastructure the same afternoon while the equivalent Ona capability requires booking and surviving a sales cycle.
Why it matters: Buyers with basic security requirements (SSO) or infra-control requirements (self-hosting) who are not yet ready for a full enterprise contract have no paid self-serve tier to land on at Ona and default to Coder for free — a structural speed and pricing disadvantage in exactly the segment Ona's Enterprise tier targets.
Recommended move
Introduce a mid-tier self-serve SKU (e.g. 'Core+' or 'Team') that unlocks SSO/OIDC at a fixed self-serve price point, and publish indicative Enterprise/VPC starting pricing with a self-serve, time-boxed VPC trial that doesn't require booking a demo first.
Buildable
- Expected
- SSO/OIDC or a self-hosted deployment option is purchasable at a fixed, self-serve price without contacting sales.
- Actual
- SSO/OIDC and self-hosted VPC deployment appear only under the Enterprise column with 'Custom pricing' and a 'Request a demo' CTA — no self-serve price exists.
Evidence · 4 verified claims
Ona's Enterprise tier (only) includes VPC/self-hosted deployment and SSO/OIDC; Core is limited to Ona's multi-tenant cloud.
“Bank-grade VPC deployment ... SSO and OIDC identity and access controls ... Compute Deployment: Ona Cloud (multi-tenant) [Core] / Self-hosted, Ona-managed VPC [Enterprise]”
Source: www.gitpod.io/pricing
Coder's free Community edition includes SSO (OpenID Connect) and AI-agent task assignment, and is self-hosted by definition (open source install).
“## Community
Free
For hobbyists and small teams ready to join Coder's open-source community.
...
- Assign long-running tasks to AI coding agents
- Single Sign-On (OpenID Connect)”
Source: coder.com/pricing
Ona's self-hosted/VPC deployment option is Enterprise-only and has no listed price or self-serve signup path
“Self-hosted, Ona-managed VPC [Enterprise row] ... EnterpriseCustom pricing ... [Get started] [Request a demo]”
Source: www.gitpod.io/pricing
Coder's free Community edition supports self-hosted install with SSO, no sales step required
“## Community
Free
...
[Install open source]
...
- Single Sign-On (OpenID Connect)”
Source: coder.com/pricing
3AWS Marketplace — a channel enterprise buyers actually purchase through — carries two separate, non-identical 'Ona Enterprise' listings still sold under the name 'Gitpod'
ImpacthighEffortmedium
There are two live AWS Marketplace product pages: prodview-752jqvg74yo7k ('Ona Enterprise', sold by 'Gitpod', 4.3/5 from 16 external reviews) and prodview-vn4wpn7u4afrq ('Ona Enterprise (US)', showing a PeerSpot-style review plus teaser titles of the same old Gitpod-era G2 reviews duplicated from the first listing). Competitor Coder has a single AWS listing ('Coder Premium Edition') at 4.7/5 from 7 ratings with visible 'Top 10' accolade badges, and AWS's own 'Product comparison' feature explicitly pairs Coder Premium Edition against 'Ona Enterprise' by seller name 'Gitpod' on the same comparison table — putting the fragmented, lower-rated, still-Gitpod-branded listing directly next to a cleaner competitor at the exact moment procurement teams decide who to shortlist.
Why it matters: Procurement teams comparing vendors inside AWS Marketplace see a fragmented, lower-rated, still-Gitpod-branded footprint sitting right next to a cleaner, higher-rated, badge-decorated Coder listing at the exact moment they're deciding who to shortlist.
Recommended move
Consolidate the two AWS Marketplace listings into one canonical 'Ona Enterprise' entry, rebrand the seller name from Gitpod to Ona, and push for AWS Marketplace accolade eligibility now that review volume is being rebuilt.
Buildable
- Expected
- A single canonical 'Ona Enterprise' AWS Marketplace listing exists, sold under seller name 'Ona'.
- Actual
- Two separate listings exist ('Ona Enterprise' and 'Ona Enterprise (US)'), both sold under seller name 'Gitpod', with duplicated stale review titles.
Evidence · 3 verified claims
A first AWS Marketplace listing for Ona Enterprise is sold under the seller name 'Gitpod' and carries 4.3/5 from 16 external G2 reviews.
“Ona Enterprise
Sold by
Gitpod
...
4.3
16 ratings
...
0 AWS reviews | 16 external reviews
External reviews are from G2”
Source: aws.amazon.com/marketplace/pp/prodview-752jqvg74yo7k
A second, separate 'Ona Enterprise (US)' listing exists with different content, including duplicated titles of the same old Gitpod-branded reviews.
“Rahul S.
Great platform for faster and reliable codespaces.
...
Hannes D.
Elevate Your Development Workflow with Gitpod: A Game-Changer for Efficiency and Collaboration
...
Robbert H.
Cloud IDEs: fast onboarding and isolated reproducible environments
...
Jelle D.
Easy to set up, happy engineers and excellent support”
Source: aws.amazon.com/marketplace/pp/prodview-vn4wpn7u4afrq
Coder's AWS Marketplace listing carries a higher rating (4.7) and displayed 'Top 10' accolade badges, and AWS pairs it directly against Ona Enterprise in its comparison table.
“Coder Premium Edition ... 4.7
(7) ... #### Accolades
Top 10 In Software Development, ML Solutions ... Product comparison ... Ona Enterprise [By Gitpod]”
Source: aws.amazon.com/marketplace/pp/prodview-zaoq7tiogkxhc
4Ona's flagship proof points are anonymized customers and unattributed aggregate stats, while Coder and GitHub name the company and the person behind every number
ImpacthighEffortmedium
Ona's homepage leads its 'what customers achieve' section with a quote from an unnamed 'Top 100 global company' claiming '90-95% of migration work is done by Ona Automations,' and its headline stats (4x productivity, 83% of PRs co-authored, 400% productivity increase, 24/7 runs) are attributed only to anonymized tags like 'Global pharma company' and 'Top 100 global company' — never a named company or person. Named logos on the homepage (BNY, GSR, Vanta, Pearson, EquipmentShare, Hargreaves Lansdown) carry only a 'Since [year]' tag with no attached result. Coder's homepage, by contrast, headlines named-company case studies with quantified outcomes ('Dropbox Boosts Dev Onboarding Speeds by 4x', 'J.B. Hunt Reduces Developer VDI Costs by 90%', 'Palantir Tames Environment Configuration Drift with Coder'), and GitHub Codespaces attributes quotes to named individuals with titles (Clint Chester, Developer Lead, Synergy; Keith Annette, Cloud Capability Lead, KPMG UK).
Why it matters: Enterprise buyers comparing vendors for a security-governance purchase will discount unverifiable anonymous stats against named, checkable case studies from direct competitors, weakening Ona's strongest proof point at the exact moment it's meant to close the deal, and enterprise security/procurement reviewers will use this to slow or stall deals.
Recommended move
Get the 'Top 100 global company' and 'Global pharma company' customers to go on record (name + role + logo), or convert at least 3 of the existing named logos (BNY, GSR, Pearson) into full case studies with named contact, specific metric, and methodology, matching the Coder/GitHub pattern.
Buildable
- Where
- https://ona.com and https://ona.com/cases/dev-productivity
- Expected
- The 4x / 83% / 400% / 90-95% headline stats are each attributed to a named company and/or named person with a title.
- Actual
- Stats are attributed only to anonymized tags: 'Top 100 global company' and 'Global pharma company', with no name disclosed.
Evidence · 6 verified claims
Ona's headline productivity stat is attributed only to an anonymous 'Top 100 global company,' not a named customer or person.
“Top 100 global company
> "90-95% of migration work is done by Ona Automations. We just have to do the final push commands."”
Source: ona.com
Coder attaches quantified outcomes directly to named enterprise customers on its homepage.
“Dropbox Boosts Dev Onboarding Speeds by 4x ... J.B. Hunt Reduces Developer VDI Costs by 90% with Coder”
Source: coder.com
GitHub Codespaces attributes its customer testimonials to named individuals with job titles and companies.
“"What used to be a 15-step process is just one step: open Codespaces and you're off and running."
Clint Chester, Developer Lead, Synergy ... Keith Annette, Cloud Capability Lead, KPMG, UK”
Source: github.com/features/codespaces
Ona's headline productivity stats (4x, 83%, 400%) are attributed only to anonymized customers, not named ones.
“Global pharma company
> "It's really impressive. I've tried other coding agents and it's not comparable."
400% productivity increase across our customers”
Source: ona.com/cases/dev-productivity
Ona's homepage customer logos carry no attached quantified result, only tenure.
“Shipping with Ona
Since 2025 Since 2024 Since 2026 Since 2024 Since 2023 Since 2024 ... Top 100 global company
> "90-95% of migration work is done by Ona Automations..."”
Source: ona.com
Coder attaches a named enterprise customer to each specific quantified outcome on its own homepage.
“Dropbox Boosts Dev Onboarding Speeds by 4x ... J.B. Hunt Reduces Developer VDI Costs by 90%”
Source: coder.com
5Ona's pricing page shows no $0 entry point — every other agent-infra competitor lets a prospect start using the product before paying anything
ImpacthighEffortmedium
Ona's pricing page shows exactly one self-serve tier, 'Core from $20 / month,' with no free plan listed anywhere on the page content fetched. Every named competitor gives a genuine zero-cost way in: GitHub Codespaces is free up to 60 hours/month, Cursor's Hobby tier is free with 'No credit card required,' Daytona gives '$200 in free compute included' on top of a pay-as-you-go floor, and Coder's Community edition is free and open-source indefinitely. For a buyer comparing 'infrastructure to run AI coding agents,' Ona is the only option in this set that requires a paid commitment before first use.
Why it matters: In a category where four out of five named rivals let a developer try the product for free before typing in a credit card, Ona's $20/mo floor is a real conversion tax on the exact self-serve individual/small-team buyer its Core tier claims to target.
Recommended move
Ship a genuinely free (even heavily rate-limited) tier or a no-card-required trial with a fixed OCU allowance, positioned against Cursor's Hobby and GitHub's free Codespaces hours.
Buildable
- Expected
- A $0 tier is listed and purchasable with no credit card, comparable to Cursor's Hobby or GitHub Codespaces' free hours.
- Actual
- Page lists only 'Core from $20/month' and custom-priced 'Enterprise' — no free plan appears anywhere in the page content.
Evidence · 5 verified claims
Ona's Core plan starts at $20/month with no free tier disclosed on the pricing page
“Corefrom$20/month
Ideal for individual users and teams”
Source: www.gitpod.io/pricing
GitHub Codespaces offers a genuinely free individual tier
“Codespaces is free for individual use up to 60 hours a month and comes with simple, pay-as-you-go pricing after that.”
Source: github.com/features/codespaces
Cursor's entry tier is free with no card required
“### Hobby
Free
Includes:
✓ No credit card required
✓ Limited Agent requests
✓ Access to Composer”
Source: cursor.com/pricing
Daytona includes free compute before any charge applies
“Build for free, pay as you scale. ... Use what you need, when you need it. $200 in free compute included.”
Source: www.daytona.io/pricing
Coder's Community edition is free and self-hosted with no sales step
“## Community
Free
For hobbyists and small teams ready to join Coder's open-source community.”
Source: coder.com/pricing
6Ona's free tier is a one-time 40-OCU grant that never refills, while GitHub Codespaces' free tier renews every month forever
ImpactmediumEffortlow
On gitpod.io/pricing, the plan-comparison table lists the Free plan's included OCUs as "40 OCUs (one time)" versus Core's "80 - 2,200 OCUs (monthly recurring)" — the free allocation is explicitly one-off, not a recurring monthly quota. GitHub Codespaces, by contrast, states its free allowance is "120 core hours or 60 hours of run time on a 2 core codespace, plus 15 GB of storage each month," a quota that resets every month indefinitely. This means an individual developer or small team evaluating Ona for free burns through their entire allotment once and then must pay, while the same evaluator can keep using Codespaces for free indefinitely at low volume.
Why it matters: A one-time free grant converts evaluators into paying customers faster but also disqualifies Ona from the low-commitment, indefinitely-free 'try it on a side project' use case that Codespaces still owns, ceding that acquisition channel entirely.
Recommended move
Either make the Free plan's OCU allowance monthly-recurring (even at a lower amount, e.g. 20-40 OCUs/month) or stop competing on the word 'Free' and reposition it explicitly as a one-time trial credit in the marketing copy, since prospects comparing it to Codespaces' free tier will feel misled once they hit the wall.
Buildable
- Expected
- The Free plan's included OCUs are labeled as a recurring monthly allowance, matching the 'monthly recurring' framing used for Core.
- Actual
- The compare-plans table labels the Free plan's OCUs as '40 OCUs (one time)'.
Evidence · 2 verified claims
Ona's Free plan gives 40 OCUs as a one-time grant, not a recurring monthly allowance.
“Included OCUs
40 OCUs(one time)
80 - 2,200 OCUs(monthly recurring)”
Source: www.gitpod.io/pricing
GitHub Codespaces' free tier is a recurring monthly allowance (120 core-hours + 15GB storage), not a one-time grant.
“GitHub will provide users in the free plan 120 core hours or 60 hours of run time on a 2 core codespace, plus 15 GB of storage each month.”
Source: github.com/features/codespaces
7OCU pricing is opaque and unpredictable — real per-hour rates live in a separate docs page and consumption varies 1-8x per task, while Daytona and Cursor publish exact, computable prices upfront
ImpactmediumEffortlow
Ona's pricing page shows "Core from $20/month" and "80 - 2,200 OCUs," but never states what an OCU costs in dollars or how fast it drains; that information ("Standard | 4 vCPUs / 16GB RAM | 1 OCU/hour", "GPU-accelerated | 16 vCPUs / 64GB RAM | 7 OCUs/hour", agent-task costs like "Add a feature to medium codebase | 8" OCUs) only appears in a separate docs page. Ona's own pricing FAQ additionally admits OCU consumption per task is highly variable ('there is a large variability in the number of OCUs consumed for each task'), ranging from 1 OCU to explain a small codebase up to 8 OCUs to add a feature to a medium codebase. Daytona, by contrast, publishes exact per-resource dollar rates directly on its pricing page ('Compute, vCPU, $0.0504/h, Memory, GiB, $0.0162/h, Storage, GiB, $0.000108/h', billed per second), and Cursor's paid tiers are flat, fixed monthly prices ($20/mo Individual, $40/user/mo Teams) rather than a variable usage credit.
Why it matters: Buyers cannot forecast their real monthly spend from Ona's pricing page alone, and a buyer who cannot predict their bill defaults to the competitor whose pricing math is a one-line multiplication — pushing budget-conscious or procurement-gated evaluators toward Daytona or Cursor before they ever request an Ona demo.
Recommended move
Add a visible OCU-to-dollar conversion rate and a runtime/task cost calculator directly on the pricing page (Daytona-style), and publish 3-5 real customer-anonymized monthly OCU totals by team size next to the existing task-cost examples.
Buildable
- Expected
- The pricing page states an OCU-to-dollar conversion rate and/or a cost calculator, without requiring navigation to a separate docs page.
- Actual
- OCU-to-dollar/hour rates (e.g. '1 OCU/hour' standard, '7 OCUs/hour' GPU) appear only at ona.com/docs/ona/billing/usage, and the pricing page FAQ states consumption 'is highly dependent on the workloads you run' with 'large variability... for each task'.
Evidence · 5 verified claims
Ona's OCU consumption rates for both environment runtime and agentic tasks are documented only in a separate docs page, not on the pricing page.
“Standard | 4 vCPUs / 16GB RAM | 1 OCU/hour
GPU-accelerated | 16 vCPUs / 64GB RAM | 7 OCUs/hour ... Add a feature to medium codebase | 8”
Source: ona.com/docs/ona/billing/usage
Daytona publishes itemized dollar-per-resource-hour pricing directly on its pricing page.
“Compute, vCPU, $0.0504/h, Memory, GiB, $0.0162/h, Storage, GiB, $0.000108/h”
Source: www.daytona.io/pricing
Ona explicitly states OCU consumption per task is highly variable and unpredictable
“How much usage does each OCU represent?
This is highly dependent on the workloads you run. ... Keep in mind that there is a large variability in the number of OCUs consumed for each task.”
Source: www.gitpod.io/pricing
Daytona publishes exact per-second unit compute pricing on its public pricing page
“Compute, vCPU, $0.0504/h, Memory, GiB, $0.0162/h, Storage, GiB, $0.000108/h ... All billing is calculated per second.”
Source: www.daytona.io/pricing
Cursor's paid individual and team tiers are flat, fixed monthly prices rather than a variable usage credit
“### Individual
$20 / mo.
...
### Teams
$40 / user / mo.”
Source: cursor.com/pricing
8Ona offers no self-serve volume discount on overage usage — Core customers pay a flat $10/40-OCU add-on rate forever, or must jump straight to a sales-negotiated Enterprise contract
ImpactmediumEffortlow
Ona's pricing page states Core add-on OCUs cost a flat "from $10 / 40 OCUs" with no tiered or volume-based pricing shown, and the only alternative unit economics come from Enterprise's "Custom credits," which requires a sales conversation. Daytona explicitly markets scaling discounts within its self-serve, no-sales-call tier: "Pay as you go with usage-based pricing" and "Unlock volume discounts as you scale." A Core customer on Ona who outgrows the $20-$220ish OCU-add-on range has no self-serve path to better pricing — they must go straight to a custom Enterprise quote, even if all they need is more compute at a better rate, not VPC/SSO/audit features.
Why it matters: Growing Core customers who just need cheaper bulk compute — not enterprise governance features — are forced into a full sales cycle for better pricing, adding friction and sales-cycle cost to a segment Ona could otherwise retain and expand with a simple tiered discount.
Recommended move
Publish a self-serve volume-discount schedule for add-on OCUs at defined usage breakpoints (e.g. 500+, 2,000+ OCUs/month) so scaling Core customers get better unit economics without needing to contact sales.
Buildable
- Expected
- The add-on OCU section shows a tiered price schedule (e.g. lower $/OCU at higher volume breakpoints).
- Actual
- Add-on OCUs are priced at a flat 'from $10 / 40 OCUs' with no volume tiers shown; the only other rate is Enterprise's unlisted 'Custom credits'.
Evidence · 2 verified claims
Ona's Core add-on OCU rate is a flat "from $10 / 40 OCUs" with no published volume discount tier; better rates require moving to Enterprise custom pricing.
“Add-on OCUs
from $10 / 40 OCUs [Core]
Custom credits [Enterprise]”
Source: www.gitpod.io/pricing
Daytona advertises self-serve volume discounts as usage scales, without requiring a move to a sales-negotiated tier.
“Pay as you go with usage-based pricing
Unlock volume discounts as you scale”
Source: www.daytona.io/pricing
9Ona's SOC 2 badge doesn't disclose Type I vs Type II, while Daytona, Coder, and Cursor all state their SOC 2 type explicitly
ImpactmediumEffortlow
Ona's trust center and homepage display a generic 'SOC 2' badge with a document simply labeled 'SOC 2 Report' — no Type I/Type II distinction visible on the page. Daytona's trust center explicitly lists both 'SOC 2 Type 1' and 'SOC 2 Type 2' as separate compliance badges plus HIPAA. Coder's footer displays an explicit 'SOC 2 Type II Certified' badge. Cursor's security page states outright that 'A SOC 2 Type II attestation report is available on request.' For a security-conscious enterprise buyer, Type II (proving controls operated effectively over time) is materially stronger evidence than Type I (a point-in-time design check), and Ona is the only one of the four not stating which it has on the page.
Why it matters: Enterprise security questionnaires and procurement checklists specifically ask for Type II; an ambiguous badge forces extra back-and-forth or reads as weaker than competitors who state it upfront, adding friction at exactly the stage (security review) Ona's own Trust Center is trying to shortcut.
Recommended move
Add explicit 'Type I' or 'Type II' language next to the SOC 2 badge on both ona.com and the SafeBase trust center landing page (not just inside the gated report).
Buildable
- Expected
- The SOC 2 badge/label states 'Type I' or 'Type II' explicitly, matching the pattern on Daytona, Coder, and Cursor's pages.
- Actual
- The badge and document are labeled only 'SOC 2' / 'SOC 2 Report' with no Type qualifier anywhere on the page.
Evidence · 4 verified claims
Ona's Trust Center and homepage list SOC 2 as a certification but do not state a Type on the page.
“## Compliance
- GDPR
- SOC 2
- EU AI Act ... REPORTSSOC 2 Report”
Source: ona.com/security
Ona's homepage repeats the same unqualified 'SOC 2' badge.
“## Enterprise-ready. Compliant, certified, and trusted by Fortune 500 companies.
SOC 2
Fortune
500”
Source: ona.com
Coder displays an explicit SOC 2 Type II certified badge.
“Badge indicating compliance with a SOC 2 Type 2 security audit based on AICPA's Trust Services Criteria SOC 2 Type II Certified”
Source: coder.com
Cursor states explicitly it holds SOC 2 Type II.
“A SOC 2 Type II attestation report is available on request at trust.cursor.com.”
Source: cursor.com/security
10Ona's own public Trust Center discloses a history of authentication and token-exposure security incidents under the Gitpod name — undermining the 'secured at the kernel' positioning it's now selling
ImpactmediumEffortlow
Ona markets itself as 'Orchestrated, governed, secured at the kernel' with a dedicated 'Veto' kernel-level security product, but its own Trust Center's public 'Security Notifications' log lists multiple past incidents: an OAuth token exposure (Aug 2025), an account-impersonation bug that forced re-authentication of all Gitpod Cloud users, and a CVE-2023-0957 vulnerability that could allow shared-workspace takeover. None of the competitor security pages fetched (Cursor's security page, Daytona's trust center summary) surfaced an equivalent public incident log on the page checked. This is a double-edged asset: transparency is good, but a buyer doing diligence on a company now positioning itself as the security layer for AI agents will find a track record of exactly the class of vulnerability (auth/token handling) that agent governance is supposed to prevent.
Why it matters: Buyers evaluating Ona specifically for its security/governance pitch will read this incident history against the current kernel-security claim, and a competitor sales rep can use it directly in a security-review objection.
Recommended move
Add a short 'what we changed since these incidents' narrative near the notification log connecting past auth/token fixes to the current Veto architecture, turning the disclosure into a credibility asset instead of leaving it as a bare incident list.
Buildable
- Expected
- Each historical incident entry (OAuth token exposure, impersonation bug, CVE-2023-0957) is followed by a note connecting the fix to the current Veto/kernel-level security architecture.
- Actual
- Incidents are listed as a bare notification log (dates and descriptions only) with no stated connection to the current security architecture.
Evidence · 4 verified claims
Ona's public Trust Center lists a 2025 Bitbucket OAuth token exposure vulnerability under the Gitpod product.
“August 21, 2025
# Security Vulnerability affecting Gitpod Classic
As part of our ongoing security reviews, we've resolved a vulnerability in our Bitbucket OAuth token handling that, under specific conditions, could have exposed a user's access token if they clicked a malicious link.”
Source: ona.com/security
Ona's Trust Center discloses a prior account-impersonation incident that forced re-authentication of all Gitpod Cloud users.
“Our investigation revealed a technical glitch within Gitpod's authentication logic, resulting in the impersonation of a singular, distinct account. ... Consequently, all Gitpod Cloud users were mandated to re-authenticate.”
Source: ona.com/security
Ona's Trust Center discloses a 2023 CVE for shared workspace takeover.
“Vulnerability affecting Gitpod
Context: Gitpod been notified of a vulnerability that may lead to a takeover of shared workspaces (CVE-2023-0957)”
Source: ona.com/security
Ona positions itself on kernel-level security enforcement as a current core product pillar.
“### Runtime AI security
Runs in your VPC with complete network control. Audit trails, scoped credentials, and kernel-level policy enforcement.”
Source: ona.com