
Cosine
Cosine is a British AI coding agent built around its own Lumen models, running in the terminal, the browser or a desktop app, and deployable anywhere from public cloud to fully air-gapped infrastructure.
What is Cosine?
Cosine is an AI software engineering agent published by Buildt AI Limited, a British research lab that describes itself as the UK's AI lab building autonomous, reasoning systems to work alongside human engineers. Its founding argument is contrarian: specialists outperform generalists. Where most vendors train models to write poetry and solve physics problems, Cosine trains its Lumen family on production code alone, on the premise that a model shaped by real engineering work will beat a generalist at the task developers actually have.
The Lumen family has three members. Scout, post-trained from Devstral 123B, is cheap enough to run on-device and handles the routine work around the coding loop. Outpost, post-trained from Kimi K2.6, covers everyday production implementation. Sovereign, still announced as coming, targets frontier-scale reasoning. Cosine publishes its own benchmarks, Niche-Bench, Vibe-Bench, Slop-Bench and a cost-per-successful-task measure, on which Outpost scores 59.3% against 48.3% for Kimi K2.6 and 47.4% for GPT-5.5.
You meet the product through three surfaces backed by one system, one account and one credit pool: a terminal CLI installed with a single Homebrew command, a browser workspace called Cosine Cloud, and a native desktop app. The CLI turns every agent turn into a lightweight git commit, keeps a live task list, remembers project conventions between sessions, and spawns child agents in Swarm mode. The Cloud runs twenty or more agents at once on isolated worktrees inside hardware-isolated MicroVMs, gates every write action behind an explicit approval, and can execute on your own SSH targets.
The commercial centre of gravity is security. Cosine is sold to organisations that cannot send code to a public cloud, and offers managed cloud, dedicated tenant, VPC, on-premise and fully air-gapped deployment. Its models are post-trained for languages generalists handle badly, COBOL, Fortran and Verilog among them. A separate enterprise product, Cosine Red Team, runs a security scan and then an adversarial penetration test, and the company leads a UK coalition building Lumen Sovereign on national compute.
What it does
- Plan, implement and review code changes without leaving the terminal
- Run more than twenty agents in parallel on isolated worktrees
- Hand long-running work to the cloud and come back to a finished diff
- Undo any agent turn instantly, since each one is a lightweight git commit
- Split a complex task across specialised sub-agents in Swarm mode
- Run the entire agent inside an air-gapped perimeter with no data egress
- Commission an automated security scan and penetration test through Cosine Red Team
When to use Cosine / When not to
A quick filter to help you decide if Cosine is the right fit.
When to use Cosine
- Engineering teams in regulated sectors such as finance, healthcare and defence, whose source code cannot leave an approved perimeter
- Developers maintaining long-lived, legacy or unusually messy codebases rather than greenfield projects
- Teams working in niche or enterprise languages such as COBOL, Fortran, Verilog, Rust and complex SQL
- Organisations that need on-premise, VPC or fully air-gapped deployment before they can adopt an AI coding agent at all
- Teams that want to stay model-agnostic and run long parallel work, from migrations and refactors to batches of tickets, overnight
When not to use Cosine
- Anyone looking for a free tier or a trial, since the cheapest plan starts at USD 19 per month
- Mobile-first users, as there is no iOS or Android application, only a CLI, a browser workspace and a desktop app
- Developers who need a public API, because the documentation contains no API reference at all
- Small teams hoping to buy Cosine Red Team, which sits behind a paywall, a licence and a vetting committee
- Anyone wanting a general-purpose assistant, since Lumen is deliberately trained for software work and nothing else
How to use Cosine
A typical end-to-end flow, from setup to results.
- Create an account through the login page to open Cosine Cloud in your browser
- Install the terminal client with a single Homebrew command, or download the desktop app instead
- Connect a repository from the Cloud so the agent can index your code and its structure
- Pick a model from the catalogue of seventeen, or leave Auto mode to route the task for you
- Describe the task and choose your working mode, from scoped planning to autonomous execution
- Switch between planning, implementation and review in the CLI without breaking your flow
- Let Swarm mode split a large job across specialised sub-agents running in parallel
- Approve or reject each write action, since pushes, pull requests and messages are all gated
- Review the resulting diff, undo any agent turn you dislike, then merge when you are satisfied
- Track credit consumption for your team under Settings and top up when the monthly allocation runs out
Pros & Cons
Pros
- Deployment goes all the way to fully air-gapped, which very few coding agents offer
- In-house models post-trained for COBOL, Fortran and Verilog, where general-purpose models underperform
- Genuinely model-agnostic, with seventeen models available and the option to bring your own subscription
- Every write action is gated behind an explicit approval, and every agent turn is reversible as a git commit
- All customers are opted out of global model training by default, with no configuration required
- The subprocessor list is published in full, with seventeen named companies and their locations
- Unlimited team members at no extra cost on a paid plan, and add-on credits that never expire
Cons
- No free plan and no free trial: the entry point is USD 19 per month
- The site carries two incompatible price lists, and the same plan names sit on different amounts in each
- SOC 2 Type II is only in audit and ISO 27001 still in implementation, on a page that promises certification in 2025 while the site is dated 2026
- No data processing agreement, no Article 27 EU representative and no named DPO, despite an explicit GDPR claim
- No hosting country is committed to, and the privacy policy expressly reserves processing outside the UK and the EEA
- No public API documentation and no mobile application
- One-sided terms: no refunds under any circumstances, and a ban on publishing claims about the product's performance
Pricing & Plans
Cosine publishes no free plan and no free trial. The lowest paid entry point is USD 19 per month for the Starter plan, which includes four million credits, with additional credits sold at USD 6.50 per million on that tier. Credits are consumed across input, output, cached and reasoning tokens and weighted by a per-model multiplier, so actual spend depends on task size, model choice and runtime. Enterprise and private deployment pricing is quoted by the sales team.
- Starter
- USD 19 per month
- 4M credits
- add-on credits at USD 6.50 per million
- aimed at individuals and side projects
- Builder
- USD 49 per month
- 11M credits
- aimed at solo developers (listed in the documentation only)
- Team
- USD 99 per month
- 23M credits
- aimed at small teams (listed in the documentation only)
- Scale
- USD 199 per month
- 47M credits
- add-on credits at USD 5.00 per million
- the pricing page sells this same tier under the name Team
- Professional
- USD 999 per month
- 240M credits
- add-on credits at USD 4.50 per million
- the pricing page sells this same tier under the name Enterprise
- Enterprise
- custom quote
- unlimited credits with private deployment in cloud
- VPC or on-premise
- dedicated support and compliance
- the amounts agree
- but the plan names do not
Data, GDPR & hosting
A consolidated view of how Cosine handles your data.
GDPR overview
GDPR is claimed rather than documented in depth. Buildt AI Limited cites the UK Data Protection Act 2018 and Regulation (EU) 2016/679, and sets out the full set of data-subject rights: access, rectification, erasure, restriction and objection, including objection to legitimate-interest processing and to direct marketing and profiling, plus the right to complain to a supervisory authority. Consent can be withdrawn at any time by writing to privacy@cosine.sh. Transfers outside the United Kingdom and the EEA are anticipated under safeguards including standard contractual clauses, and seventeen named subprocessors are published with their locations. What is missing is just as concrete: no Article 27 EU representative, no named data protection officer, no data processing agreement offered, and no effective date anywhere on the policy.
Who owns the data?
Buildt AI Limited, trading as Cosine, claims no intellectual property rights over the outputs its products generate: whatever the agent writes is yours. The terms also commit the company to using data you supply solely to provide access to the products, and the documentation states that indexed code stays inside the deployment you choose, whether cloud, VPC or on-premise, and is never moved to shared or external environments. Two carve-outs qualify this. The terms allow Cosine to collect anonymised usage data to improve its products, and you remain responsible for backing up your own data, since the company disclaims liability for any loss of it.
Reuse rights
Because Cosine claims no rights over the outputs, you can reuse generated code freely, including commercially, without asking permission. The company undertakes not to use data you supply for any purpose other than delivering the service, and the documentation is explicit that shared models are never trained on customer data: every customer is opted out of global training by default, with no configuration required, and any private fine-tuning runs inside your own environment. Your rights stop at the product itself. The terms forbid copying or reselling the products for commercial purposes, reverse-engineering them, and publishing any claim about their performance, functionality or technical specifications. You are also told to review every output before committing it, since Cosine accepts no liability for the code it produces.
Data retention & training
Hosting summary
Cosine commits to no hosting country. The privacy policy states the opposite of a residency guarantee: personal information may be stored and processed outside the country where it is collected, including outside the United Kingdom and the European Economic Area, under safeguards that may include standard contractual clauses. The security FAQ mentions data residency controls without naming a jurisdiction. What is documented is the supply chain: seventeen subprocessors are named with their locations, and all but a few sit in the United States, among them Amazon Web Services, Google Cloud, Vercel, Stripe, GitHub, Slack, Cloudflare, Microsoft Azure and Perplexity, with PostHog in the European Union and OpenAI and Anthropic operating through both Irish and US entities. Where your code lives is a separate question, answered architecturally rather than geographically: indexed repositories stay inside the deployment you choose and are never moved to shared or external environments, and in VPC or on-premise installations the customer controls storage, backup and deletion outright.
Things to keep in mind
Risks and trade-offs to weigh before adopting Cosine.
- Delegating whole features to an agent erodes your mental model of your own codebase, and the terms themselves insist you review every output before committing it
- Reversible commits and approval gates make it easy to approve quickly and read carelessly, since the safety net only works if you actually look at the diff
- Credit billing has no visible ceiling: a long task on an expensive model can burn an allocation fast, and no refunds are payable under any circumstances
- The site contradicts itself on pricing, attaching the same plan names to different amounts on the pricing page and in the documentation, so confirm your tier before subscribing
- Security claims outrun the certificates, as SOC 2 and ISO 27001 are frameworks followed rather than audits passed, on a page that is visibly out of date
- The terms make you warrant that nothing you send contains personal data while the documentation describes handling incidental PII, a gap worth clarifying in writing if you are bound by the GDPR
- The benchmarks quoted on the homepage are the vendor's own, not independent standards, so treat the numbers as marketing until someone reproduces them
Setup & Integrations
Technical difficulty
Getting started is easy for an individual developer: create an account for the browser workspace, or install the CLI with a single Homebrew command. MCP tooling installs itself with no configuration, and connecting a GitHub repository is documented. Enterprise deployment is a different exercise entirely, beginning with an architecture review, then a controlled pilot, a security and workflow validation, and only then a deployment plan. Hardware for an air-gapped install depends on model choice, concurrency and repository size, and timelines depend on the security review. Cosine Red Team is not self-serve at all.
Deployment
Integrations
Behind Cosine
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Does Cosine have a free plan or a free trial?
What exactly is a credit?
Does Cosine train its models on my code?
Can Cosine run without my source code leaving our network?
Is Cosine SOC 2 or ISO 27001 certified?
Which surfaces can I use?
Can I choose which model runs my task?
Is there a mobile app?
How do I get support?
Who is behind Cosine, and can I delete my data?
Should you pick Cosine?
Cosine is one of the few AI coding agents built for the places most of them cannot go. Its pitch is not raw capability but containment: run the agent inside your own perimeter, keep source code, prompts and logs behind the boundary you approve, and choose between managed cloud, a dedicated tenant, VPC, on-premise or a fully air-gapped install. Around that sits a genuinely useful product, with reversible agent turns as git commits, twenty or more parallel agents in hardware-isolated MicroVMs, approval gates on every write, and a model catalogue spanning its own Lumen family and fifteen third-party models rather than locking you to one provider. The specialisation is real too: Lumen is post-trained on production code and on languages generalists handle badly, COBOL, Fortran and Verilog among them, which matters far more to a bank modernising a mainframe than another point on a general benchmark. The reservations are about maturity and paperwork rather than the product. There is no free plan and no trial, so evaluation starts at nineteen dollars a month. The site carries two price lists whose plan names contradict each other. SOC 2 and ISO 27001 are frameworks followed, not certificates held, and the page saying so still promises certification in 2025. For a vendor selling to regulated buyers, the absence of a data processing agreement, an Article 27 representative and any committed hosting country is a conspicuous gap, and the terms are notably one-sided, with no refunds and a ban on publishing claims about the product. Worth a serious look if your constraint is that code cannot leave the building. If you simply want a coding assistant and can use a public cloud, cheaper and more open options exist.
- Choosing a selection results in a full page refresh.
- Opens in a new window.