Independent Product Analysis · Public sources + first-hand beta access

Coconut is betting that context outlives the tool

Coconut AI sells a shared, governed context layer that every AI tool in an organization draws from. The thesis is sound and unusually well validated. The problem is that roughly a dozen other teams reached it in the same twelve months, one of them is free and written by the president of Y Combinator, and the runtime Coconut is built on belongs to a company that could ship this itself.

Compiled 8 Aug 2026 Subject Coconut AI Inc. · coconut.dev Status Invite-only · v1.0 shipped 3 Jun 2026 Company age ~12 months Competitors mapped 47 Sourcing Public · plus 1 first-hand tab

01 — The product

What Coconut actually does

Coconut connects an organization's scattered documents, tools, and undocumented know-how into one living, governed source that any AI tool draws from through a permission-aware MCP connector. It is not a chatbot, not a search box, and not a wiki. It is the layer underneath all three.

The problem, stated precisely

Coconut argues organizational AI context fails in three compounding ways, and the framing is worth repeating because it is the sharpest part of the pitch:

  • Fragmented — AI tools do not share context with each other, so every session starts from zero.
  • Stale — context goes out of date the moment things change, so AI works from last month's reality.
  • Inconsistent — without a shared source, output varies across every tool, team, and session.

The distinction Coconut draws against enterprise search is the crispest sentence on the site: search helps people find information; a context layer gives AI the knowledge to act on it. That is a real difference, and it is the argument that has to survive contact with Glean.

The five layers

Context is organized into a fixed taxonomy running from stable facts to live state. This is the most opinionated thing about the product and the thing most likely to be either its moat or its onboarding tax.

#LayerWhat it holdsInvestor-firm example
01IdentityWho you are and what you are trying to do — mission, goals, OKRsFund thesis, mandate, investment criteria
02DomainWhat you work on and the language around it — product, segments, competitorsFocus areas, markets, portfolio, live deals
03ProcessHow work gets done — templates, frameworks, checklistsSourcing, diligence, the IC process
04RelationshipsThe human layer — stakeholder maps, who owns what, landminesFounders, co-investors, LPs, network
05StateThe living layer — current initiatives, recent decisions, open questions, metricsSame

Naming conflict on Coconut's own site

The platform page calls layer 02 Domain. The FAQ still calls it Product. Both were live on 8 August 2026. Prior research — including the Notion brief — carried "Product" forward. For a company whose entire pitch is that inconsistent context produces inconsistent answers, having two names for the same layer on two pages of its own marketing site is the kind of detail a sharp prospect will notice.

What is genuinely differentiated

Three things hold up under scrutiny, and none of them is the five-layer taxonomy.

Metadata as a query surface

Every page carries typed key-value metadata — scores, stages, dates, owners, sources — that stays queryable across a space. "Every deal in diligence with conviction above 0.7, ranked" becomes one query instead of a spreadsheet someone re-keys. Prose carries judgment, metadata carries the facts that churn.

Lineage, not overwrite

When a decision changes, the previous version is superseded, not overwritten. Every page is versioned, any two versions diff, and rollback is one step. That is a real governance primitive, not a marketing word.

Space agents as principals

Each space has a dedicated agent with standing instructions that runs on a schedule — folding transcripts into memos, appending sources, flagging stale coverage. It is treated as a permissioned principal: read-only outside explicit grants, every run recorded.

What is claimed but not yet shipped

Marked "coming soon" on the platform page

Propose-then-publish review. The review-and-approval workflow is the load-bearing beam of the governance pitch — tiered propagation where low-risk updates flow automatically and high-impact changes require confirmation. The FAQ describes it in the present tense. The platform page labels it Coming soon.

Governance is the wedge Coconut has chosen against both the free open-source option and the platform incumbents. Shipping the rest of it is the highest-leverage thing on the roadmap.

Pricing and access

Three contact-sales tiers, no public figures. Team for a first pilot, Company for multi-team workspaces, Enterprise for org-wide rollout with SSO/SCIM and procurement support. Access is still invite-only and demo-gated as of 8 August 2026; the docs site says so on its front page.

Prior research recorded these tiers as Starter / Growth / Enterprise. They are now Team / Company / Enterprise. Small, but it dates every document that still says otherwise.

Security posture

AWS, AES-256 at rest, TLS 1.2+ in transit, RBAC, MFA, least privilege, audit logging, regular penetration testing. Three deployment models: multi-tenant SaaS, single-tenant hosted, and self-hosted in your own environment.

The gap an enterprise buyer will find in minute one

No SOC 2 claim appears anywhere on the public site. Not on the security page, not in the FAQ. The language is "assurance artifacts available to customers under NDA." Meanwhile Dust advertises SOC 2 Type II and GDPR, and Mem0 advertises SOC 2 Type II — both smaller-scoped products. For a company selling governance to regulated buyers, an unstated certification status is read as an absent one.