Changelog
Last updated: October 1, 2026
About this page
Notable changes to Escalate, listed once they are live for customers. Each entry is labelled New, Improved, Fixed or Security.
Security fixes are listed after they reach production, without technical detail that could put customers at risk. To report a vulnerability, see our security page.
October 2026
October 1, 2026
- Improved: the call proof page explains each piece of evidence in plain language, decodes signed governance checkpoints and firmware versions, and labels self-reported values clearly.
- Fixed: clicking a field on the proof page no longer shifts the page out of place.
- Improved: every Escalate action in Claude Code gets a clear stamp showing what ran, who approved it and a link, including checks that finish in the background.
- New: the Claude Code status line shows your Escalate CLI version, tells you when an update is available, and keeps your own status lines below Escalate's.
- Improved: the activity log shows who acted, what they did, and the connector and method as separate columns, with a filter for proposals.
- Improved: shorter, readable ids in links and on screen, and the activity log now labels how each action was signed and shows failed approved calls as errors.
- Fixed: Approval duration and call-limit choices clearly show which one is selected.
- Improved: Proof pages can show the exact bytes the chip signed and check they match.
- Improved: The proposals list fits phone screens without sideways scrolling.
- Fixed: Approvals no longer show a held-message warning in Claude Code after you approve.
- Improved: The proof page and escalate verify now check the launcher's own digest against your governed boot record and name the cloud a call ran in from Google's signed evidence, instead of showing those fields as unchecked.
- Improved: The proof page now re-checks your governance chain in your browser, using the same verifier as the offline escalate verify.
- Fixed: Proof pages no longer cut off labels on phones.
- Fixed: Proof summaries read correctly and no longer show a time in the wrong timezone.
- Improved: Proofs label evidence from Google's virtual TPM separately from evidence signed by the processor.
- Improved: Clearer field names in governance proofs.
- New: Proof pages include a diagram showing how the hardware and governance evidence connect.
- Improved: Proof details show keys and signatures more clearly and let you copy any value with one click.
- New: The terminal shows an Escalate marker when an action is proposed and when it is approved.
- Improved: Approval requests no longer open a pop-up over your terminal.
- Improved: Approving future calls shows exactly which words may change.
- Improved: The approval page's action bar is easier to read and no longer covers the page details.
September 2026
September 30, 2026
- Security: Security hardening for how the platform identifies its key-management service.
- Improved: When you connect a compute backend with a sealed API key, the key is checked right away again, inside the credential vault.
- Improved: Postgres, MySQL and SSH connections reach the host and port you enter in the connection settings.
September 29, 2026
- Improved: Kubernetes push compute backends are retired; use the Kubernetes runtime agent instead.
- Security: Security hardening for plugin network isolation.
- Security: Security hardening for self-hosted runtime sandboxes.
- Security: Security hardening for compute backend connections.
- Security: Security hardening for connector network isolation.
- Security: Security hardening for connector network isolation.
- Security: Security hardening for approved connector actions.
- Security: Security hardening for adding sign-in methods.
- Security: Security hardening for signing key custody.
- New: Connector shares between organizations now enforce their hourly and daily request limits.
- Improved: Proof pages now open with a short list of what was checked for each call, how far each check can be trusted, and who could see your credentials, request and result.
- Improved: The Privacy Policy now describes the approximate location used by chat, push notification details and the Android notification provider, and the Terms of Service state a minimum age of 18.
- Improved: The Terms of Service and Privacy Policy now describe deleting your account yourself in the app or on the web.
September 28, 2026
- New: A public page at escalate.me/delete-account explains how to delete your Escalate account in the app, on the web or by email, and what is deleted and kept.
- New: In the Escalate mobile app you can report an AI response as offensive, harmful or wrong: press and hold it, then choose Report.
September 27, 2026
- Security: Security hardening for key release.
- Security: Security hardening for administrator access.
- Fixed: The Grafana, Google Workspace and tldraw connectors can reach their bundled tool servers again.
- Fixed: Downloading Word, PowerPoint and OneDrive files, GitHub job logs and GovInfo text works again.
- Security: Security hardening for sign-in.
- Security: Security hardening for AI spend budgets.
September 26, 2026
- Security: Security hardening for chat images and live agent sessions.
- Security: Security hardening for chat.
- Security: Security hardening for AI provider usage metering and access.
- Security: Security hardening for mobile sign-in and approval methods.
- Security: Security hardening for plugin secrets.
- Security: Security hardening for plugin updates.
- Security: Security hardening for chat sandboxes.
- Security: Security hardening for plugins.
- Security: Security hardening for tool permissions.
- Security: Security hardening for plugin workers.
- Improved: Approvals made with your browser, CLI or passkey now verify end to end with escalate verify.
- Security: Security hardening for policy verification.
- Security: Security hardening for approvals and command-line sign-in.
- Security: Security hardening for proof verification.
- Security: Security hardening for audit logs.
- Security: Security hardening for account sign-in methods.
- Security: The platform core now verifies a measured VM's Google vTPM evidence and governed boot image before it seals credentials to the workload.
- Security: Security hardening for policy integrity.
- Security: The platform core now gives web and the manager separate credentials and permissions, and it can verify a connector workload's attestation itself before it seals credentials to it.
- Fixed: Connector calls no longer fail intermittently after a connector has been idle for a while.
September 25, 2026
- Fixed: Proof verification no longer fails when the transparency log's signer ran on different, approved confidential-computing firmware than the call.
- Improved: Proof pages now show the Platform Core, Policy Writer and launcher behind each call, with their releases, governance status and whether each identity is covered by a hardware measurement or self-reported.
- Improved: Downloaded proofs show each approval signature without repeated or unused fields, and still verify byte for byte.
- Improved: The proof page shows the parsed attestation report and certificate details, so they are easier to read.
- Improved: Google, Spotify, Uber and Lyft connections refresh their sign-in more reliably.
- Security: Security hardening for connected-account credentials.
- Improved: Downloaded proofs now show each governance approval as readable fields instead of one long hex string.
- Improved: Call proofs can name the keymaster that released the workload's key, and escalate verify checks it against governance.
- New: escalate verify --require-software-measured fails any proof that does not itself show which software handled the call.
- New: escalate verify checks each proof's governance chain against the published genesis of its environment and accepts a new genesis only through a handover signed by the previous admins.
- Improved: Downloaded proofs now show every piece of evidence as readable fields, and escalate verify checks the proof from those fields.
- Improved: Downloaded proofs now show their evidence as readable fields instead of encoded blobs, and the CLI verifies them directly.
September 24, 2026
- Improved: Our Privacy Policy and Terms of Service now include a postal address for Escalate Labs.
- Security: Every change to your sign-in or approval credentials is now signed with a credential you already have. The "No signature required" approval option has been removed.
September 23, 2026
- Security: Security hardening for approvals and signer registration.
September 21, 2026
- New: Our Data Processing Agreement is now published at escalate.me/dpa and forms part of the Terms of Service.
September 19, 2026
- Improved: The account deletion section of our Terms of Service now accurately describes the request-based deletion process.
September 15, 2026
- Security: Security hardening across sign-in and the container images that run connectors.
September 14, 2026
- Fixed: Disconnecting a connector now revokes access at the provider, so reconnecting asks for your consent again.
- Fixed: The sign-in page only offers GitHub sign-in where it is available.
- Improved: The escalate code --resume command finds a previous session wherever it was started.
September 8, 2026
- Security: Security hardening for accounts: a shared sign-in lockout across web and mobile, a passkey confirmation for organization administration, and expiring tokens for remote MCP connections.
- Fixed: CLI commands that do not need Docker no longer fail when Docker is not running.
September 5, 2026
- Improved: Quote verification for legal citations now checks the quoted section and shows the court name on each source.
September 4, 2026
- New: Batch approval: review a concrete set of pending actions and approve them in one signing step.
- Improved: Approval method settings list every enrolled credential and let you remove each one.
- Fixed: Microsoft connectors no longer report a missing permission after a successful sign-in.
September 2, 2026
- New: A guided first run that installs the CLI and walks you through a real test approval.
September 1, 2026
- Improved: The agent log is now a paginated table with the detail of the audit trail.
August 2026
August 27, 2026
- New: Antigravity CLI and Hermes Agent are supported as escalate code harnesses.
- Fixed: Signing in with Google or GitHub returns you to the page you started from.
August 25, 2026
- New: Google connectors ask only for the permissions each one needs, and you can grant them individually.
- Security: Support for Google Cross-Account Protection security events.
- Fixed: The audit log no longer labels unsigned records as signed, and shows the actual signature where one exists.
August 24, 2026
- New: Approve several pending requests on mobile with a single Face ID.
- New: A public support page at escalate.me/support.
August 23, 2026
- Improved: Approval links are short enough to send by text message, and tool parameters are shown as readable YAML before you approve.
August 21, 2026
- New: Escalate is available as a remote MCP connector for Claude, Claude Cowork and ChatGPT.
August 20, 2026
- New: The Hyperliquid connector supports signed trading and the full Hyperliquid API.
- Improved: Requests routed through OpenRouter ask providers not to retain or collect your data.
August 19, 2026
- Improved: When an agent would overwrite an existing file, the change is staged for your review instead.
August 14, 2026
- New: Tracked-changes review for Word documents: view each proposed change, accept it in place, or download the redline as a .docx.
- New: Citations open the original court document with the quoted passage highlighted.
August 13, 2026
- Improved: A simpler set of 12 organization roles with no overlapping duplicates.
August 11, 2026
- Improved: Organization members can use the shared AI provider key or add their own.
August 10, 2026
- New: RedPill is available as an AI provider, with a privacy proof for each response from a model running in a trusted execution environment.
- New: Four medical-literature connectors: ClinicalTrials.gov, Europe PMC, openFDA and PubMed.
August 7, 2026
- New: Eight legal and government-data connectors: Clio, eCFR, SEC EDGAR, Federal Register, GovInfo, PACER, Regulations.gov and USPTO.
August 5, 2026
- New: The new escalate doctor command checks your CLI setup and reports what needs attention.
August 3, 2026
- New: A CourtListener connector for legal research.
August 2, 2026
- Improved: A single escalate update command now updates the CLI however it was installed.
July 2026
July 31, 2026
- Fixed: Reconnecting a connector reuses your existing connection instead of creating a duplicate.
What escalate does
escalate is an AI agent workspace. You connect the accounts you already use, then ask agents to handle real tasks: summarize and triage your inbox, schedule meetings, organize files, draft documents, update spreadsheets, file tickets, or run multi-step workflows across several tools at once. Every agent runs under your account, with your permissions, and nothing irreversible happens without you.
How escalate uses your Google account
When you connect Google, escalate requests only the scopes the connectors you enable actually need, and no others: Gmail (read, search, organize and send mail you have reviewed, plus a metadata-only view of labels and headers), Google Calendar (view and manage events and calendars), Google Drive, Docs, Sheets and Slides (find, read, create and update files), and Google Photos (browse and search your library, upload new photos and create albums). It does not request Contacts, Tasks, Meet, Home/Nest, Fit, YouTube or Wallet. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising or to train models, and every write action (sending mail, editing files, changing events) requires your explicit in-product approval first.
escalate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve the user-facing features that are prominent in the escalate interface. It is used for no other purpose: not for advertising, not for advertising or marketing profiles, not for market research, not for product analytics or usage statistics, not for credit or lending decisions, and never to develop, improve or train generalized or non-personalized AI or machine learning models. It is not transferred to anyone except as needed to provide those features, for security purposes, to comply with applicable law, or in a merger or acquisition with your prior notice and consent, and never to advertisers, data brokers, or information resellers. No human reads it except where you have affirmatively agreed to have specific messages or files viewed, for security purposes, or to comply with applicable law. An agent cannot answer a question about your mail, files or photos without a model reading that content, so the content a request needs is sent to the model serving it and to nothing else: an escalate-supplied model on the provider's business or API tier, your organization's own provider account, a gateway it selects, an attested confidential-computing endpoint, or a model your organization hosts itself — in which case the content stays on your organization's own infrastructure and never reaches a model vendor at all. No Workspace or Photos data, raw or aggregated, goes to any service that trains generalized models on it. The full policy is at escalate.me/privacy.
Agent proposes. You authorize. escalate executes.
Agents draft a plan you can inspect, each sensitive step waits for your approval, and everything the agent did is recorded in a full audit trail. Connections can be revoked at any time from your dashboard or from your Google account settings.
escalate is built by Escalate Labs. Privacy policy · Terms of service
Connect 200+ tools through one catalog
escalate ships a catalog of more than 200 connectors covering email, calendars, files and docs, team chat, project management, CRM, finance and payments, developer tools, e-commerce, smart home, and more: Gmail, Google Calendar, Google Drive, Docs, Sheets, Slack, GitHub, GitLab, Linear, Jira, Notion, Stripe, PayPal, Shopify, Square, Salesforce, HubSpot, Dropbox, Figma, Discord, Telegram, Spotify, Zoom, and the long tail of SaaS. Each connector is a typed, sandboxed service wrapping one external API, with a pinned network allowlist so it can only reach the hosts it declares. Browse the full catalog at escalate.me/explore.
A policy gate, not just a chatbot
Hosted chat products let a model act with your full credentials. escalate gates what an agent can actually do: a policy engine classifies every proposed action, read-only calls can flow automatically, and every write (sending mail, editing files, moving money, changing events) queues for explicit human approval with full context. Organizations can set per-agent quotas, per-tool budgets, and approval rules. Every tool call, approval, denial, and result lands in an audit trail you can review per agent, per connector, and per organization.
Security and confidential computing
Credentials live in an encrypted locker and are injected into the connector at call time only; the agent sees tool results, never tokens. Sensitive workloads run on AMD SEV-SNP confidential hardware, with memory encrypted against the cloud host, and each call's proof shows the chip-signed attestation. On today's Google Cloud nodes that proves the hardware rather than which code ran; escalate's measured VM builds identify the code itself. Connections are revocable at any time. Read more at escalate.me/security.
Where you use escalate
The web dashboard gives you agent chat, connector and credential management, an approval inbox, the audit log, and shareable dashboard apps that render live data from your connectors. iOS and Android apps handle chat and one-tap approvals via push notification. The open-source escalate CLI doubles as an MCP server, so local AI tools such as Claude, Claude Code, and Cursor can call escalate-gated tools while policy, approvals, and audit stay enforced server-side. Scheduled routines run agents on a cron without a human at the keyboard, still subject to the same gates.
Plans
escalate offers a Free tier with 2,000 governed tool calls a month and call packs of 1,000 for $8, a Team tier with pooled volume, seats, and team controls, and an Enterprise tier with dedicated or self-hosted workers, SSO, and custom SLAs. Current details at escalate.me/pricing.
Frequently asked questions
What is escalate?
escalate is an AI agent workspace by Escalate Labs. You connect the accounts you already use and AI agents do real work across them: triage email, schedule meetings, organize files, update spreadsheets, file tickets, and run multi-step workflows spanning several tools. Agents propose, you authorize, escalate executes with a full audit trail.
Is my data safe?
Every connector runs in an isolated container with a pinned egress allowlist; credentials are injected at call time and never enter the agent's context. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising, and is never used to train models.
How is escalate different from using Claude or ChatGPT directly?
Chat products talk to you; escalate gates what your agent can actually do. It adds the connector catalog, a policy engine, human-approval flows, per-tool isolation, and an audit trail, and it works with your existing AI tools through MCP rather than replacing them.
Is there a mobile app?
Yes. iOS and Android apps cover chat, notifications, and the approval inbox, so a push notification and one tap approve an agent's pending action.
Can I self-host?
Enterprise customers can run escalate workers on their own Kubernetes cluster; the standard plans are fully managed SaaS.
Machine-readable overview for LLMs and crawlers: escalate.me/llms.txt · full connector directory: escalate.me/llms-full.txt