Data Processing Agreement
Last updated: September 21, 2026
About this agreement
This Data Processing Agreement (this "DPA") is between Escalate Labs, Inc., a Delaware corporation ("Escalate"), and the customer that has agreed to the Escalate Terms of Service, a Master Services Agreement or an order form with Escalate (the "Controller"). That agreement is the "Principal Agreement". This DPA forms part of the Principal Agreement and applies automatically, without a separate signature, whenever and to the extent that Escalate processes Personal Data on the Controller's behalf and Data Protection Law applies to that processing.
Customers who need a countersigned copy for their records can request one from privacy@escalate.me. A countersigned copy has the same terms as this page unless the parties agree otherwise in writing.
The parties agree as follows.
1. Definitions
"Data Protection Law" means every law and regulation applicable to the Processing of Personal Data under this DPA, including, where and to the extent applicable, Regulation (EU) 2016/679 (the "GDPR"), the GDPR as it forms part of the law of the United Kingdom (the "UK GDPR"), the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended (the "CCPA") and other US state privacy laws, in each case as amended or replaced.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Special Categories of Personal Data" and "Supervisory Authority" have the meanings given in Data Protection Law. "Sub-processor" means any third party engaged by Escalate to Process Personal Data on Escalate's behalf under this DPA.
"Personal Data" in this DPA means only Personal Data Processed by Escalate on behalf of the Controller under the Principal Agreement, and not personal data Escalate Processes as a controller in its own right (for example account administration, billing and security logs), which is governed by the Escalate Privacy Policy.
"SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. "Services" means the Escalate services provided under the Principal Agreement.
2. Roles and scope of Processing
In respect of the Processing described in Annex I, the Controller is the controller (or, where the Controller itself acts as processor for its own customer, a processor, in which case Escalate is its sub-processor) and Escalate is the processor. The Controller determines the purposes and means of that Processing. Escalate Processes Personal Data only as described in Annex I, for the duration stated there, and in accordance with this DPA and the Controller's documented instructions. Each party is responsible for its own compliance with Data Protection Law.
Customer-directed recipients. When the Controller or its users connect a third-party service, configure their own AI model provider or gateway, configure a notification channel, or connect their own compute, the resulting transfer of Personal Data to that service is made on the Controller's instruction. That service is not a Sub-processor of Escalate, and its own terms with the Controller govern it.
3. Documented instructions
Escalate shall Process Personal Data only on the documented instructions of the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by law to which Escalate is subject; in that case Escalate shall inform the Controller of that legal requirement before Processing, unless that law prohibits it on important grounds of public interest. The Principal Agreement, this DPA and the Controller's configuration and use of the Services (including the approvals its users give to proposed actions) constitute the Controller's documented instructions. Escalate shall inform the Controller without undue delay if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until it is confirmed, withdrawn or amended.
No sale, no training. Escalate shall not (a) sell or share Personal Data within the meaning of the CCPA; (b) retain, use or disclose Personal Data for any purpose other than providing the Services under the Principal Agreement, or outside the direct business relationship between the parties; (c) combine Personal Data with personal data it receives from other sources, except as permitted by Data Protection Law; or (d) use Personal Data, or permit a Sub-processor to use it, to train generalized or non-personalized artificial intelligence or machine learning models.
4. Confidentiality of personnel
Escalate shall ensure that every person authorised to Process Personal Data is subject to an appropriate duty of confidentiality, by contract or by statute, and that access to Personal Data is limited to personnel who need it to perform Escalate's obligations under the Principal Agreement. That duty survives the end of the individual's engagement.
5. Security measures
Escalate shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, including the measures described in Annex II. Escalate shall not, during the term of this DPA, make a change that materially reduces the overall level of protection those measures provide.
Save where this DPA or the Principal Agreement expressly provides otherwise, Escalate does not warrant that any particular control, technology, standard, audit report or certification is or will be in place, and the Controller is responsible for satisfying itself that the measures are appropriate to the Personal Data it chooses to submit.
6. Sub-processors
6.1 General authorisation. The Controller gives Escalate a general written authorisation to engage Sub-processors. The Sub-processors engaged at any time are listed at escalate.me/subprocessors (the "Sub-processor Page"), reproduced as Annex III.
6.2 Notice of changes. Escalate shall update the Sub-processor Page, and notify the Controller by email if the Controller has subscribed by writing to privacy@escalate.me, at least thirty (30) days before a new or replacement Sub-processor begins Processing Personal Data. Where a replacement is urgently required to maintain the security or availability of the Services, Escalate may give shorter notice and shall give it as soon as reasonably practicable, with the reason.
6.3 Objection. The Controller may object to a new Sub-processor on reasonable grounds relating to data protection by writing to privacy@escalate.me within fifteen (15) days of the notice. The parties shall discuss the objection in good faith. If they cannot resolve it within thirty (30) days, the Controller may terminate the affected Services on written notice, and Escalate shall refund any prepaid fees for the terminated portion covering the period after termination. That termination and refund are the Controller's sole remedy for the objection.
6.4 Flow-down and liability. Escalate shall impose on each Sub-processor, by written contract, data protection obligations that are in substance no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each Sub-processor's obligations.
7. Assistance with Data Subject rights
Taking into account the nature of the Processing, Escalate shall assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests by Data Subjects exercising their rights under Data Protection Law (including access, rectification, erasure, restriction, portability and objection). Where Escalate receives such a request directly from a Data Subject in respect of Personal Data Processed under this DPA, it shall not respond to its substance except on the Controller's instruction or as required by law, and shall forward the request to the Controller without undue delay and in any event within five (5) business days.
8. Personal Data Breach
8.1 Notification. Escalate shall notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA. The notification shall be sent to the Controller's notice contact and shall describe, to the extent then known: the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its possible adverse effects; and the name and contact details of Escalate's point of contact. Where the information is not all available at once, it may be provided in phases without undue further delay.
8.2 Assistance. Escalate shall cooperate in good faith with and assist the Controller in any way necessary to enable the Controller to comply with its obligations under Data Protection Law, in particular to notify the competent Supervisory Authority and the affected Data Subjects, taking into account the nature of Processing and the information available to Escalate.
8.3 Documentation. Escalate shall document all relevant information related to a Personal Data Breach, including its effects and any remedial action taken, and keep a record of it.
8.4 A notification under this Section is not an acknowledgement of fault or liability.
9. Assistance with compliance obligations
Taking into account the nature of the Processing and the information available to it, Escalate shall assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security of processing, breach notification, data protection impact assessments and prior consultation), and shall provide the Controller with reasonable assistance in carrying out a data protection impact assessment and any prior consultation with a Supervisory Authority, in each case in respect of the Processing under this DPA. Escalate may charge its reasonable costs for assistance that goes beyond providing information it already holds or documentation it already publishes.
10. Deletion or return of Personal Data
On termination or expiry of the Principal Agreement, Escalate shall, at the Controller's election, make Personal Data available for export for thirty (30) days and then delete it, or delete it, together with existing copies, save to the extent that law requires retention. Deletion from active systems shall complete within thirty (30) days of the end of the export window. Personal Data in backups is deleted when those backups expire in the ordinary course, which is within thirty (30) days of deletion from active systems. Retained Personal Data remains subject to this DPA for as long as it is retained. On request, Escalate shall confirm deletion in writing.
11. Audits and information
Escalate shall make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. Escalate may satisfy this obligation in the first instance by providing its security documentation, its responses to a reasonable security questionnaire, and any third-party audit report it then holds.
Where that is not sufficient to meet a requirement of Data Protection Law or of a Supervisory Authority, the Controller may conduct an audit on at least thirty (30) days' written notice, during normal business hours, no more than once in any twelve (12) month period except where required by a Supervisory Authority or following a Personal Data Breach, subject to appropriate confidentiality undertakings, and in a manner that does not unreasonably disrupt Escalate's operations or compromise the confidentiality or security of any other customer's data. Each party bears its own costs, save that the Controller bears Escalate's reasonable costs of an audit that goes beyond the provision of existing documentation.
12. International transfers
12.1 Escalate and its Sub-processors Process Personal Data in the United States (see Annex I and Annex III). Escalate shall not transfer Personal Data outside the territory whose Data Protection Law applies to it unless an appropriate safeguard recognised by that law is in place.
12.2 EU SCCs. Escalate is not certified under the EU-US Data Privacy Framework. To the extent a transfer from the Controller to Escalate is subject to the GDPR and is not covered by an adequacy decision, the SCCs are incorporated into this DPA by reference as follows: Module Two (controller to processor) applies where the Controller is a controller, and Module Three (processor to processor) where the Controller is a processor; Clause 7 (docking clause) applies; in Clause 9(a), Option 2 (general written authorisation) applies with the notice period in Section 6.2; the option in Clause 11(a) does not apply; in Clause 17, Option 1 applies with the law of Ireland; in Clause 18(b), the courts of Ireland; Annexes I, II and III of the SCCs are completed by Annexes I, II and III of this DPA; and the competent supervisory authority under Clause 13 is determined as set out in Annex I.C.
12.3 UK and Switzerland. For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0) applies, completed with the information in this DPA, and neither party may end it under its Section 19. For transfers subject to Swiss law, the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as competent authority, and references to the GDPR are read as references to Swiss law.
12.4 Where the SCCs conflict with this DPA as to a transfer, the SCCs prevail.
13. Controller obligations and warranties
The Controller warrants that it has, and will maintain, a lawful basis for the Processing it instructs; that it has given the notices and obtained any consents required by Data Protection Law; and that its instructions comply with Data Protection Law. The Controller is responsible for the accuracy, quality and legality of Personal Data it submits and for the third-party services, model providers and channels it connects. The Controller shall not submit Special Categories of Personal Data, or personal data relating to children, unless the parties have expressly agreed in writing and the measures in Section 5 have been assessed as appropriate for that data.
14. Liability
Nothing in this DPA increases, extends or removes any limitation or exclusion of liability agreed in the Principal Agreement, and each party's aggregate liability arising out of or in connection with this DPA is subject to those limitations as if the claim arose under the Principal Agreement. Nothing in this DPA limits either party's liability to a Data Subject or a Supervisory Authority under Data Protection Law, or any liability that cannot be limited by law.
15. Order of precedence
This DPA forms part of the Principal Agreement. Where this DPA and the Principal Agreement conflict as to the Processing of Personal Data, this DPA prevails; in every other respect the Principal Agreement prevails. Where this DPA conflicts with the SCCs as to a transfer they govern, the SCCs prevail.
16. Term, survival and changes
This DPA takes effect when the Principal Agreement does, or on the date shown above if later, and continues for as long as Escalate Processes Personal Data on the Controller's behalf. Sections 4, 8, 10, 11 and 14, and any obligation which by its nature is intended to survive, continue after it ends.
Escalate may update this page. An update that materially reduces the Controller's protection does not apply to a Controller without its agreement; Escalate may update Annex II and Annex III as Sections 5 and 6 allow. A countersigned copy may be amended only in writing signed by both parties.
17. Notices
Escalate gives notices under this DPA to the email address of the Controller's account owner or billing contact, or to any notice contact the Controller has designated in writing. The Controller gives notices to Escalate at privacy@escalate.me; Escalate's security contact is security@escalate.me. A notification of a Personal Data Breach under Section 8 may in addition be given by any means reasonably calculated to reach the Controller promptly.
18. Governing law and venue
This DPA is governed by the law that governs the Principal Agreement or, if the Principal Agreement names none, the laws of the State of Delaware, and disputes are subject to the forum agreed in the Principal Agreement. This Section does not displace any governing law or forum required by the SCCs.
19. Severability and entire agreement
If any provision of this DPA is held illegal, invalid or unenforceable, it is limited or eliminated to the minimum extent necessary and the remainder stays in force. This DPA, with the Principal Agreement, is the complete agreement of the parties relating to the Processing of Personal Data. A countersigned copy may be executed in counterparts and by electronic signature.
Annex I: Description of the Processing
A. List of parties
| Data exporter | Data importer | |
|---|---|---|
| Name | The customer party to the Principal Agreement | Escalate Labs, Inc., a Delaware corporation |
| Contact | The Controller's account owner, or the notice contact it designates | Privacy: privacy@escalate.me; Security: security@escalate.me. Postal address on request. |
| Activities | Use of the Escalate Services | Provision of the Escalate Services |
| Role | Controller (or processor) | Processor (or sub-processor) |
Acceptance of the Principal Agreement is each party's signature of this Annex.
B. Description of the transfer and Processing
| Item | Particulars |
|---|---|
| Categories of data subjects | The Controller's employees, contractors and other authorised users of the Services; individuals whose personal data appears in content the Controller's users submit or retrieve through connected services (for example correspondents in email, calendar attendees and file authors). |
| Categories of personal data | Account data (name, email, profile image, authentication identifiers); organisation membership and role data; content submitted to or retrieved through the Services (chat messages, prompts, files, and email, calendar, document and ticket content from connected services); connector credentials (OAuth tokens, API keys), stored sealed; action proposals, approvals and denials; audit logs; technical data (IP address, user agent, session identifiers). |
| Sensitive data | None intended. The Services are not designed for Special Categories of Personal Data; see Section 13. |
| Frequency | Continuous, for the term of the Principal Agreement. |
| Nature of the Processing | Hosting and storage; retrieval from and actions on connected third-party services on the users' instruction and approval; transmission of request content to an AI model to produce the output a user requested; execution in isolated runtimes; notification delivery; logging and security monitoring. |
| Purpose | To provide the Services under the Principal Agreement, including security, support and troubleshooting. |
| Retention | For the term of the Principal Agreement and the deletion period in Section 10. Within the term: chat threads until deleted by the user; audit logs according to plan tier (Free 90 days, Pro 1 year, Team 2 years, Enterprise 7 years); hosted chat workspace files 7 days after last use by default; connector credentials until the connector is disconnected. |
| Sub-processor transfers | As listed in Annex III, for the purposes stated there, for the duration of the Principal Agreement. |
C. Competent supervisory authority
Determined in accordance with Clause 13 of the SCCs: where the Controller is established in an EU Member State, the supervisory authority of that Member State; where the Controller is not established in the EU but is subject to the GDPR under its Article 3(2) and has appointed a representative, the supervisory authority of the Member State where that representative is established; and otherwise the supervisory authority of the Member State in which the Data Subjects whose Personal Data is transferred are located.
Annex II: Technical and organisational measures
| Area | Measure |
|---|---|
| Encryption in transit | All external traffic to escalate.me is served over HTTPS (TLS). Session cookies are marked Secure. Connections to the database require TLS. |
| Encryption at rest | Customer data is stored in Google Cloud SQL, Cloud Storage and persistent disks, which Google encrypts at rest. Connector credentials and other secrets are additionally envelope-encrypted with AES-256-GCM data keys wrapped by a key-management service, and are sealed to the runtime that uses them. |
| Confidential compute | Connectors run on AMD SEV-SNP confidential nodes, which encrypt memory against the cloud hypervisor. Credentials are released to a connector only after hardware attestation of the node it runs on, and signing and unsealing keys are generated and held inside confidential node VMs. |
| Access control (product) | Deny-by-default role-based access control within each organisation. Every HTTP route passes one validation point for authentication, organisation membership and permissions. Sensitive operations require step-up authentication. Write actions on connected services require human approval under the organisation's policy, and the policy gate fails closed. |
| Access control (personnel) | Production access is limited to named personnel, granted through groups and reviewed quarterly. Multi-factor authentication is required on the company Google Workspace (which is also the identity for Google Cloud access) and on the company GitHub organisation. |
| Network security | Kubernetes NetworkPolicies are enforced, with default-deny ingress and egress in every application namespace and explicit allow rules. The database has a private IP address only, with no public address, and uses IAM database authentication. Public traffic reaches the cluster only through Google load balancers, and administrative SSH only through Identity-Aware Proxy. |
| Logging and audit | A per-organisation audit log of action proposals, approvals, denials and executions. Policy decisions are logged, and changes to an organisation's policy state are recorded as signed policy-state commitments. |
| Vulnerability and supply-chain management | Every npm and Rust dependency must have been published for at least 7 days before it can enter the codebase. Dependencies are scanned for known vulnerabilities. Container images are deployed by digest from a committed lockfile. |
| Change management | Changes reach production only through a gated deploy process that deploys built, digest-pinned images, checks database schema compatibility before the rollout, and rolls back automatically on failure. |
| Availability and backups | Multiple application replicas. Cloud SQL runs with regional high availability, daily automated backups retained for 14 days and 7 days of point-in-time recovery. Object storage keeps prior versions for 14 days. |
| Incident response | Security reports to security@escalate.me are acknowledged within 48 hours. Incidents are handled under a written incident response plan, including controller notification under Section 8. |
| Vendor management | Sub-processors are listed publicly, with 30 days' notice of changes (Section 6 and escalate.me/subprocessors). |
| Data minimisation | Only the content a request needs is sent to the AI model serving it. Customer data is not used to train generalised models. |
Annex III: Sub-processors
The Sub-processors currently engaged are listed below and at escalate.me/subprocessors, which is the authoritative, current list. Services the Controller chooses and directs are not Sub-processors (Section 2).
| Subprocessor | Purpose | Personal data processed | Location |
|---|---|---|---|
| Google Cloud Platform (Google LLC) | Hosting, compute, databases, object storage, and key management for the Escalate service | All customer data stored in or processed by the service | United States |
| Anthropic (Anthropic, PBC) | AI model inference when Escalate supplies the model for a request | The request content needed to produce the answer | United States |
| Resend | Transactional email, such as sign-in links, invitations, and approval notifications | Name, email address, and message content | United States |
| Stripe (Stripe, Inc.) | Payment processing and payment fraud prevention | Billing contact and payment details | United States |
| PayPal (PayPal, Inc.) | Payment processing, when you choose to pay with PayPal | Billing contact and payment details | United States |
| Apple Push Notification service (Apple Inc.) | Delivering notifications to the Escalate iOS app | Device token and notification content | United States |
| Google Workspace (Google LLC) | Company email, including support, security, and privacy requests you send us | Content of messages you send to an escalate.me address | United States |
What escalate does
escalate is an AI agent workspace. You connect the accounts you already use, then ask agents to handle real tasks: summarize and triage your inbox, schedule meetings, organize files, draft documents, update spreadsheets, file tickets, or run multi-step workflows across several tools at once. Every agent runs under your account, with your permissions, and nothing irreversible happens without you.
How escalate uses your Google account
When you connect Google, escalate requests only the scopes the connectors you enable actually need, and no others: Gmail (read, search, organize and send mail you have reviewed, plus a metadata-only view of labels and headers), Google Calendar (view and manage events and calendars), Google Drive, Docs, Sheets and Slides (find, read, create and update files), and Google Photos (browse and search your library, upload new photos and create albums). It does not request Contacts, Tasks, Meet, Home/Nest, Fit, YouTube or Wallet. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising or to train models, and every write action (sending mail, editing files, changing events) requires your explicit in-product approval first.
escalate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve the user-facing features that are prominent in the escalate interface. It is used for no other purpose: not for advertising, not for advertising or marketing profiles, not for market research, not for product analytics or usage statistics, not for credit or lending decisions, and never to develop, improve or train generalized or non-personalized AI or machine learning models. It is not transferred to anyone except as needed to provide those features, for security purposes, to comply with applicable law, or in a merger or acquisition with your prior notice and consent, and never to advertisers, data brokers, or information resellers. No human reads it except where you have affirmatively agreed to have specific messages or files viewed, for security purposes, or to comply with applicable law. An agent cannot answer a question about your mail, files or photos without a model reading that content, so the content a request needs is sent to the model serving it and to nothing else: an escalate-supplied model on the provider's business or API tier, your organization's own provider account, a gateway it selects, an attested confidential-computing endpoint, or a model your organization hosts itself — in which case the content stays on your organization's own infrastructure and never reaches a model vendor at all. No Workspace or Photos data, raw or aggregated, goes to any service that trains generalized models on it. The full policy is at escalate.me/privacy.
Agent proposes. You authorize. escalate executes.
Agents draft a plan you can inspect, each sensitive step waits for your approval, and everything the agent did is recorded in a full audit trail. Connections can be revoked at any time from your dashboard or from your Google account settings.
escalate is built by Escalate Labs. Privacy policy · Terms of service
Connect 200+ tools through one catalog
escalate ships a catalog of more than 200 connectors covering email, calendars, files and docs, team chat, project management, CRM, finance and payments, developer tools, e-commerce, smart home, and more: Gmail, Google Calendar, Google Drive, Docs, Sheets, Slack, GitHub, GitLab, Linear, Jira, Notion, Stripe, PayPal, Shopify, Square, Salesforce, HubSpot, Dropbox, Figma, Discord, Telegram, Spotify, Zoom, and the long tail of SaaS. Each connector is a typed, sandboxed service wrapping one external API, with a pinned network allowlist so it can only reach the hosts it declares. Browse the full catalog at escalate.me/explore.
A policy gate, not just a chatbot
Hosted chat products let a model act with your full credentials. escalate gates what an agent can actually do: a policy engine classifies every proposed action, read-only calls can flow automatically, and every write (sending mail, editing files, moving money, changing events) queues for explicit human approval with full context. Organizations can set per-agent quotas, per-tool budgets, and approval rules. Every tool call, approval, denial, and result lands in an audit trail you can review per agent, per connector, and per organization.
Security and confidential computing
Credentials live in an encrypted locker and are injected into the connector at call time only; the agent sees tool results, never tokens. Sensitive workloads run inside hardware-attested confidential computing environments (AMD SEV-SNP trusted execution), and escalate publishes cryptographic measurements so you can verify exactly what code handled your data. Connections are revocable at any time. Read more at escalate.me/security.
Where you use escalate
The web dashboard gives you agent chat, connector and credential management, an approval inbox, the audit log, and shareable dashboard apps that render live data from your connectors. iOS and Android apps handle chat and one-tap approvals via push notification. The open-source escalate CLI doubles as an MCP server, so local AI tools such as Claude, Claude Code, and Cursor can call escalate-gated tools while policy, approvals, and audit stay enforced server-side. Scheduled routines run agents on a cron without a human at the keyboard, still subject to the same gates.
Plans
escalate offers a Free tier with 2,000 governed tool calls a month and call packs of 1,000 for $8, a Team tier with pooled volume, seats, and team controls, and an Enterprise tier with dedicated or self-hosted workers, SSO, and custom SLAs. Current details at escalate.me/pricing.
Frequently asked questions
What is escalate?
escalate is an AI agent workspace by Escalate Labs. You connect the accounts you already use and AI agents do real work across them: triage email, schedule meetings, organize files, update spreadsheets, file tickets, and run multi-step workflows spanning several tools. Agents propose, you authorize, escalate executes with a full audit trail.
Is my data safe?
Every connector runs in an isolated container with a pinned egress allowlist; credentials are injected at call time and never enter the agent's context. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising, and is never used to train models.
How is escalate different from using Claude or ChatGPT directly?
Chat products talk to you; escalate gates what your agent can actually do. It adds the connector catalog, a policy engine, human-approval flows, per-tool isolation, and an audit trail, and it works with your existing AI tools through MCP rather than replacing them.
Is there a mobile app?
Yes. iOS and Android apps cover chat, notifications, and the approval inbox, so a push notification and one tap approve an agent's pending action.
Can I self-host?
Enterprise customers can run escalate workers on their own Kubernetes cluster; the standard plans are fully managed SaaS.
Machine-readable overview for LLMs and crawlers: escalate.me/llms.txt · full connector directory: escalate.me/llms-full.txt