Back to vendors
P

Poolside

Also known as: Poolside Malibu, Laguna XS.2, Laguna M.1, Laguna XS 2.1, Laguna S 2.1, Fern Labs

Visit site
Entry priceEnterprise and government deployments are custom and not public; the government page sells on-premises inference with no per-token fees. The open-weight Laguna xs 2.1 and Laguna s 2.1 models are published, and the homepage links per-token access through OpenRouter and Vercel AI Gateway.Full pricing detail

Enterprise coding platform pairing its own foundation models with a governed multi-agent Console, deployed entirely inside the customer's boundary including air-gapped, with full model weights delivered rather than API access and every agent action recorded as a searchable trajectory.

Poolside is a full-stack platform for enterprise software development, combining its own foundation models, developer tools, and a governed agent orchestration layer that runs entirely inside the customer's infrastructure. Founded in 2023 by Jason Warner, the former CTO of GitHub, and Eiso Kant, the company trains its models with Reinforcement Learning from Code Execution Feedback, learning from actually running code rather than only reading it.

The Poolside Platform, announced in May 2026, is the product the company now leads with: production-grade AI agents running inside the customer's security boundary with full auditability and governance. Its stated target is a specific kind of buyer, the team whose approved base images are a matter of policy, whose network architecture ensures no single node has both GPU access and outbound connectivity, and whose CISO has spent two years relaxing controls for AI vendors because no real alternative existed.

The model line has two generations. Malibu handles deep reasoning, refactoring and test writing while Point drives low-latency completion, both fine-tunable on a customer's own codebase, documentation and knowledge bases. The newer Laguna family arrived through 2026: XS.2 and M.1 in April, served at 256K context from May, then XS 2.1 in July and S 2.1 later that month for longer-horizon reasoning work. Laguna XS.2 is released as free open weights for local agentic coding.

Above the models sits the Console, where teams build and govern single and multi-agent systems running in isolated sandboxes. A documented example takes a natural language specification, generates a working pipeline, pushes it to GitHub, builds it through an API and iterates until every step passes. Pipelines are code-first and fully auditable, and meta pipelines review agent trajectories to refine how work gets done.

Poolside acquired Fern Labs, a London forward-deployed research engineering firm, in November 2025 for Bridge, its multi-agent orchestration layer for high-stakes production environments. The Console runs Poolside's own models alongside third-party models such as Claude and GPT, configured per agent through reusable provider settings.

Agents run where developers already work, in VS Code, Visual Studio, Zed, IntelliJ or the terminal, with a macOS Desktop Assistant added in July 2026 for running multiple agents across projects, and connect to Slack, Jira, GitHub, Workday and Salesforce through centrally managed MCP servers. An ACP interface invoked with pool acp lets external environments drive agent workflows.

Poolside's defining choice is sovereignty. Customers receive full model weights, not API access, and deploy the entire stack into an environment they control: their own bare metal, a VPC on AWS, Azure or Google Cloud, Kubernetes or OpenShift clusters, their own NVIDIA hardware via Helm, air-gapped turnkey hardware through partners including Dell, an on-premises rack for hundreds of developers, or a compact offline workstation for small classified teams. Nothing leaves the boundary, and there is no inference path out.

Governance matches that posture. Role-based access control covers human and agent identities, sandboxes carry filesystem and network policies set before an agent starts, credentials are encrypted at rest, injected at runtime and redacted from logs by pattern, step limits are enforced per session, and every tool call, file edit, reasoning step and decision is recorded as a searchable, exportable trajectory with SIEM propagation. Government-grade options add a hardened operating system and IL5 deployability. No SOC 2, ISO 27001 or FedRAMP attestation is published; the government page states an authority to operate has been achieved, without naming the system or agency.

The company raised a $500M Series B in 2024 at a $3B valuation led by Bain Capital, DST Global and eBay, and in 2025 Nvidia committed up to $1B, lifting the valuation toward $12B. Around 150 people work across the US, UK and France, with defense customers including RTX. Poolside sells through Forward Deployed Research Engineers who embed with customer teams, which makes deployment high-touch rather than self-serve, and no public pricing exists.

Vendor details

Canonical URL

https://poolside.ai

Category

Coding agent

Subcategory

Enterprise coding foundation models and governed agent platform

Funding status

Independent and heavily funded. Founded in 2023 by Jason Warner, former chief technology officer of GitHub, and Eiso Kant, Poolside raised roughly 126 million dollars in seed and early rounds, then a 500 million dollar Series B in October 2024 led by Bain Capital, DST Global, and eBay at a 3 billion dollar valuation. In October 2025 Nvidia announced an investment of up to 1 billion dollars, reported to lift the valuation toward 12 billion. The company had about 150 employees as of late 2025, headquartered in San Francisco with a Paris presence.

Company status

independent

Use cases & customers

Primary use cases

governed multi agent development pipelinesenterprise code generation and completionsovereign air gapped AI for defense and governmentcodebase fine tuned developer assistant

Target customers

large enterprises with strict security and compliance needsdefense, government, and regulated industriesengineering organizations wanting models and agents on their own infrastructure

Deployment options

Customer bare metal (on-premises)Air-gapped on turnkey hardware via partners including DellCustomer VPC on AWS, Azure or Google CloudKubernetes or Red Hat OpenShift clustersBring your own NVIDIA hardware via HelmOn-premises enterprise rack (hundreds of developers)On-premises tower / offline workstation (classified or constrained teams)Managed via Amazon BedrockLocal open-weight models (Laguna XS.2)

Integrations

Agents run where developers already work across VS Code, Visual Studio, Zed, IntelliJ and the terminal, plus a macOS Desktop Assistant running multiple coding agents across projects and repositories, a web assistant with conversation search, and the Poolside Console. Centrally managed, admin-approved MCP servers connect Slack, Jira, GitHub, Workday and Salesforce, spanning chat, ticketing, source control, HR and CRM, alongside Linear and Notion. Knowledge bases backed by Git or Amazon S3 were described on Poolside's former enterprise page but do not appear in the current docs. An ACP interface invoked with pool acp lets external development environments send prompts and run agent workflows. Public APIs are exposed and the models are available through a single API in Amazon Bedrock. A strategic partnership with Redpanda's Agentic Data Plane is documented. Agents act by editing files, running terminal commands, calling tools, building through APIs and pushing to source control inside governed sandboxes.

In practice

You are in defense or government and cannot send code off premises. Poolside delivers full model weights into your air gapped environment, so every query and agent action runs inside your boundary with nothing leaving.

You want agents that do real work under control. Through the Console you build multi agent pipelines in sandboxes with per agent permissions, step limits, and full trajectory audit trails, so automation stays governed.

You want a model tuned to your own code. Poolside fine tunes Malibu and Point on your codebase, documentation, and knowledge bases, and can route across its own and third party models per agent.

Agentic Index coverage score

11.0 / 14 capabilities · 79%

Integrations & Tool Calling Full

Agents connect through centrally managed MCP servers with admin-approved connections, named across Slack, Jira, GitHub, Workday and Salesforce, spanning chat, ticketing, source control, HR and CRM, and additionally Linear and Notion. Native editor integration covers VS Code, Visual Studio, Zed and IntelliJ plus a macOS desktop app and the terminal. Agents act by editing files, running terminal commands, calling tools, building through APIs and pushing to source control inside governed sandboxes, and a strategic partnership with Redpanda's Agentic Data Plane is documented.

Sourcepoolside.ai/blog/introducing-the-poolside-platform and poolside.ai/enterpriseread 2026-08-30

Workflow Orchestration Full

The Console builds and governs single and multi-agent systems running in isolated sandboxes, with a documented worked example taking a natural language specification, generating a working pipeline, pushing it to GitHub, building it through an API and iterating until every step passes; pipelines are code-first and fully auditable, meta pipelines review agent trajectories to refine how work gets done, the Desktop Assistant runs multiple coding agents across projects and repositories in parallel, and step limits bound each run. Poolside acquired Fern Labs in November 2025 for Bridge, a multi-agent orchestration layer built for high-stakes production environments.

Sourcepoolside.ai/enterprise, poolside.ai/blog/fern-labs-acquisition and poolside.ai/blog/introducing-poolside-desktop-assistantread 2026-08-30

Knowledge Grounding & RAG Partial

Context is assembled per run: the agent reads the code in its working directory, runs commands, loads local skills and personal MCP servers, and uses built-in web_search and web_fetch tools. AGENTS.md instructions at personal, project and directory scope are instructions the product applies rather than a knowledge store.

No maintained retrieval structure over the customer's knowledge is documented. Fine-tuning Malibu and Point on the customer's codebase puts knowledge in the model weights rather than in a structure agents query, and the Git or S3 backed knowledge bases described on Poolside's former enterprise page are not in the current docs.

Sourcedocs.poolside.ai/agent-instructionsread 2026-09-29

Human Oversight & Guardrails Full

pool asks for approval before any tool call that no allow rule covers: the default approval mode, Always ask, prompts for every action not already allowed, Accept edits auto-approves workspace file changes and prompts for the rest, an Auto mode sends pending actions to a classifier and opens the normal approval dialog for high risk ones, and switching from Plan to Build always requires the user's review, even under Allow all. Deny rules always override allow, pool exec needs --unsafe-auto-allow to run without prompts, and sandboxes add file system and network boundaries.

Sourcedocs.poolside.ai/permissions, /cli/interactive-mode and /sandboxesread 2026-09-29

Security, Identity & Governance Full

The controls are documented in detail; a third party attestation is not. The government page states ATO Achieved, a STIG-hardened OS and IL5 deployability, without naming the system or agency, and no SOC 2, ISO 27001 or FedRAMP attestation is published.

Administrators define boundaries centrally and the platform enforces them, sandboxes carry file system and network policy, credentials are encrypted at rest, injected at runtime and redacted from outputs, a secrets store keeps raw values from agents, and permission rules with deny overriding allow govern what agents may read, write and run. Role-based access control over human and agent identities was described on Poolside's former enterprise page, which now redirects to the homepage.

Sourcepoolside.ai/government, poolside.ai/blog/introducing-the-poolside-platform, docs.poolside.ai/permissions and /secretsread 2026-09-29

Observability & Auditability Full

Every agent action is recorded as a searchable trajectory covering tool calls, file edits, reasoning steps and decisions, retained under configurable audit policy, propagated to SIEM and exportable for compliance and debugging; the Console adds agent metrics for monitoring inference performance including time to first token percentiles, agent dashboards, configuration change tracking over time, and console search across agents and recent activity, with search in the web assistant for finding conversations and navigating to related resources. Meta pipelines review agent trajectories to refine how work is done.

Sourcepoolside.ai/blog/introducing-the-poolside-platform and docs.poolside.ai/release-notes/march-2026read 2026-08-30

Memory & State Persistence Partial

Sessions persist and resume: pool opens a session picker to resume a previous session from the current directory, or resumes a specific session by the ID printed on exit with pool --resume, and prompt history is browsable per directory, so a run carries on where it stopped. No memory layer that the agent writes and reads across sessions is documented; the docs index has no memory page, and AGENTS.md is instructions rather than memory. Trajectories retained under audit policy serve as an execution record.

Sourcedocs.poolside.ai/cli/interactive-mode and the docs llms.txt indexread 2026-09-29

Deployment & Data Residency Full

Four deployment modalities are documented: the customer's own bare metal, air-gapped on turnkey hardware through partners including Dell, and inside an existing VPC on AWS, Azure or Google Cloud, with Kubernetes and Red Hat OpenShift supported for teams already running container orchestration and Helm-based installation onto customer NVIDIA hardware; an on-premises rack serves hundreds of developers and a compact offline workstation serves small classified teams.

Customers receive complete control of model weights rather than third-party API access, so inference runs inside the boundary with no egress, and government-grade options include fully air-gapped operation, a hardened operating system and IL5 deployability. Models are also available managed through Amazon Bedrock.

Sourcepoolside.ai/blog/introducing-the-poolside-platform, poolside.ai/enterprise and docs.poolside.ai/release-notes/march-2026read 2026-08-30

Prebuilt Agents, Templates & Packs Partial

Reusable building blocks are documented but not a catalog: local skills give agents task-specific instructions and resources, subagents come built in or custom with separate context, and the Platform's Console builds single and multi-agent pipelines that are code-first and reusable, delivered with Forward Deployed Research Engineers. No browsable library of prebuilt agents, template gallery or marketplace is documented.

Sourcedocs.poolside.ai/skills, /subagents and poolside.ai/blog/introducing-the-poolside-platformread 2026-09-29

Triggers & Channel Coverage Full

Poolside runs in GitHub Actions on an event, a schedule or on demand: the vendor's examples review pull requests on on: pull_request, scan the repository nightly on a cron schedule and triage issues, so repository work does not wait for someone to open a terminal. Invoked surfaces cover the pool CLI (interactive, pool exec for automated tasks, and ACP for editors), JetBrains, Zed, Neovim and any ACP compatible editor, Poolside Assistant in VS Code and Visual Studio, the desktop Assistant, and the API.

Sourcedocs.poolside.ai/tools/github-actions, /cli/pool and /toolsread 2026-09-29

Model Flexibility & Routing Full

The Console configures models per agent through reusable model provider connection settings with connection testing, running Poolside's own models alongside third-party models including Claude and GPT, so routing is set per agent rather than fixed platform-wide; the vendor states the customer chooses the model and the platform meets that choice. Poolside's own family spans Malibu for deep reasoning and refactoring, Point for low-latency completion, and the Laguna models XS.2, M.1, XS 2.1 and S 2.1, served at 256K context, with Laguna XS.2 released as free open weights for local agentic coding; customers receive complete control of model weights rather than third-party API access, and models can be fine-tuned on the customer's own codebase.

Sourcepoolside.ai/models, poolside.ai/blog/introducing-the-poolside-platform and docs.poolside.ai/release-notes/march-2026read 2026-08-30

APIs, SDKs & MCP Extensibility Full

An ACP interface invoked with pool acp connects external development environments to send prompts, receive responses and run agent workflows; the platform hosts first-class MCP servers with admin-approved connections and exposes reusable model provider connection settings with connection testing; trajectory data is exportable for debugging; public APIs are documented and the models are available through a single API in Amazon Bedrock; and deployment onto customer NVIDIA hardware is driven by Helm with Kubernetes and Red Hat OpenShift supported. No named public SDK package is published.

Sourcedocs.poolside.ai/release-notes/march-2026 and poolside.ai/enterpriseread 2026-08-30

Testing, Debugging & Optimization Partial

Agents run the customer's tests and iterate until pipeline steps pass, pool reviews pull requests and scans repositories in GitHub Actions, and the Platform records searchable trajectories that meta pipelines review to refine how work is done; the models are trained with reinforcement learning from code execution feedback. These check the customer's code and improve Poolside's own models rather than giving the customer a harness to evaluate, replay or regression test agent behavior, and no evals product is documented on the docs index.

Sourcedocs.poolside.ai/tools/github-actions and poolside.ai/blog/introducing-the-poolside-platformread 2026-09-29

Browser & Computer Use Not documented

Agents operate through programmatic interfaces throughout: containerized sandboxes with filesystem and network policies set before a run, terminal command execution covering builds, package installation and git, MCP tool calls to approved servers, source control APIs, and editor extensions. No browser control, screenshot capture, visual verification or capability to operate software lacking a programmatic interface is documented.

Sourcepoolside.ai/blog/introducing-the-poolside-platform and poolside.ai/enterpriseread 2026-08-30

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-07-21·Agent capabilityPartially Verified

Poolside released Laguna S 2.1, a 118-billion-parameter Mixture-of-Experts foundation model optimized for agentic coding and extended reasoning. The open-weight model activates 8 billion parameters per token, features a 1-million-token context window, and introduces separate thinking modes while remaining compact enough to run on a single NVIDIA DGX Spark desktop machine.

Bears on: Agent capability

View source
2026-07-02·Agent capabilityVerified

Poolside released Laguna XS 2.1, a 33B-parameter Mixture-of-Experts model for agentic coding and local deployment, with improved SWE-bench Multilingual and terminal-task performance, multiple quantized checkpoints, and a move to the permissive OpenMDW-1.1 license.

Bears on: Agent capability

View source
View all 2 changes for Poolside →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Enterprise and government deployments are custom and not public; the government page sells on-premises inference with no per-token fees. The open-weight Laguna xs 2.1 and Laguna s 2.1 models are published, and the homepage links per-token access through OpenRouter and Vercel AI Gateway.

Enterprise deployment is a custom contract sized to the environment and developer count, delivered with Forward Deployed Research Engineers. Poolside models are also available usage based in Amazon Bedrock, priced per token. The Laguna XS.2 model is free to run locally under an Apache license.

Free tier

Included quota

Enterprise: the full platform inside the customer boundary, including foundation models with full weights, the Console for agents and orchestration, IDE developer tools, sandboxed execution, governance and audit, and deployment across cloud VPC, on premises rack, offline tower, or customer hardware, with Forward Deployed Research Engineer support. Amazon Bedrock: managed Malibu and Point models billed per token. Laguna XS.2: free open weight model under Apache 2.0 for local use, with preview terminal and agent surfaces. Government options include air gapped operation, a hardened operating system, and IL5 deployability.

What is public

Public: the deployment models, the government offer of on-premises and air-gapped inference with no per-token fees, the open-weight Laguna xs 2.1 (33B) and Laguna s 2.1 (118B) models, and per-token availability through OpenRouter and Vercel AI Gateway linked from the homepage. Not public: enterprise or government contract pricing, minimums and Forward Deployed Research Engineer fees. The former poolside.ai/enterprise page now redirects to the homepage.

Billing mechanics

Enterprise is a custom contract covering software, deployment, and Forward Deployed Research Engineer support, with infrastructure either provided or customer owned. Bedrock is pay as you go per token under AWS. The open weight model is free.

Cost watchouts

The real cost of an enterprise deployment includes infrastructure, whether a Poolside provisioned rack, a cloud VPC, or customer NVIDIA hardware, plus the Forward Deployed Research Engineer engagement. Bedrock usage bills per token and scales with developer activity. Air gapped and government deployments add hardware and compliance overhead.

Variable cost rationale

Exposure depends on the path. An enterprise deployment on committed or customer owned infrastructure behaves largely as a fixed cost, since inference runs on hardware the customer already pays for. Access through Amazon Bedrock is usage based and bills per token, so cost scales with developer activity. The blended picture is moderate: predictable for a committed on premises deployment, variable for Bedrock usage.

Additional watchouts

There is no public self serve price, so budgeting requires a sales conversation. Total cost includes infrastructure and services, not just software. Government and air gapped deployments carry additional hardware and compliance overhead. The free open weight model is not the same as the governed enterprise platform.

Overage / add-ons

Enterprise contracts are custom, so overage terms are negotiated. Amazon Bedrock access bills per token with no fixed seat, so cost scales directly with usage.

Sales call required

Yes, required for paid access

Free / trial

No public self serve trial of the enterprise platform; access starts with a sales conversation. A free path exists through the open weight Laguna XS.2 model, which runs locally under an Apache license, and through Amazon Bedrock usage based access.

Lowest paid plan

No public paid plan for the platform. The lowest cost paths are the free open weight Laguna XS.2 model run locally and usage based access to Poolside models in Amazon Bedrock, both short of the governed enterprise platform.

Commercial notes

Poolside is priced as a high touch enterprise platform, not a self serve tool, aimed at large organizations and the public sector that need models and agents inside their own boundary. Value concentrates where sovereignty, air gapped operation, and joint delivery matter. Teams wanting a low cost entry can start with the open weight model or Bedrock usage, then move to the governed platform.

Key ambiguities

No list price is public for the enterprise platform; cost depends on deployment shape, developer count, hardware, and the Forward Deployed Research Engineer engagement. Bedrock per token rates and any minimums are set through AWS. The boundary between free open weight use and paid platform capabilities is set by which components a team runs.

Cancellation / refund

Enterprise agreements are custom annual or multi year contracts negotiated directly. Bedrock usage is pay as you go under AWS terms. The open weight Laguna XS.2 model carries no contract.

Missing data

All enterprise list pricing, minimums, and Forward Deployed Research Engineer engagement costs are undisclosed. Bedrock per token rates are set through AWS.

Agentic Index verified 2026-09-29

Alternatives to Poolside

The closest documented capability profiles to Poolside among coding agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Ellipsis10.5 / 14A lighter documented profile than Poolside
  • Tabnine11.5 / 14Fuller documented coverage on Knowledge Grounding & RAG
  • Augment Code12.0 / 14Fuller documented coverage on Knowledge Grounding & RAG and Prebuilt Agents, Templates & Packs
  • Charm10.0 / 14A lighter documented profile than Poolside
  • CodeRabbit11.0 / 14Fuller documented coverage on Memory & State Persistence
  • OpenCode10.0 / 14A lighter documented profile than Poolside

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Head to head

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.