Evergrowth
Agentic go to market workspace for business to business sales teams. A super agent called Eva runs twelve specialist agents that qualify accounts against a configured ideal customer profile, research buying signals, find persona fit contacts, verify employment and build a communication style profile, cascade through more than twenty data vendors for verified email and phone, plan the account and write the outreach. Two further agents run voice roleplay practice and coaching. Playbooks bundle agents into scheduled or triggered workflows. Evergrowth writes the plays and the customer's existing engagement platform does the sending.
Founded 2014 as a sales consultancy serving more than 100 teams, shut that business down and pivoted to product in late 2023, 6.1 million dollars raised. Priced in credits per agent run with unlimited users on every plan.
Capability Axes
The product is thirteen agents and nothing survives their removal. The packaging proves it more cleanly than any vendor graded here: there is no seat licence at all, every plan carries unlimited users, and the entire price list is denominated in credits per agent run, with a published cost for each of the twelve specialist agents and effort tiers of low, medium and high. A buyer is not purchasing software with a model attached; they are purchasing agent runs.
The described architecture is the most specific in this index outside Agentforce, and it is architectural rather than promissory. Every request enters on a signed token or service key carrying the organisation identifier that scopes all downstream access. Each agent type has a hand picked tool set with no code execution, no filesystem, no shell and no arbitrary network.
Every agent response is bound to a typed schema and outputs failing validation are rejected, which is a withholding guardrail in the strict sense. Every run produces a structured trace covering prompt version, tool calls, inputs, outputs, latency and token usage. Held off the top for two reasons. No configurable approval workflow or risk based escalation is described anywhere.
And the single human gate, that a person reviews any action affecting external parties, is one asserted sentence on a security page while playbooks are documented as running autonomously on schedules and triggers. What reconciles them is architecture rather than policy: this product writes plays and an external platform does the sending, so a human sits structurally in the path.
Five model providers are named outright, which nothing else in this index approaches: Microsoft Azure AI Foundry, AWS Bedrock running Anthropic, the OpenAI enterprise interface, Google AI Studio and Groq, each stated to operate under contractual no training and no retention terms, with consumer endpoints and providers in non aligned jurisdictions both ruled out by name.
Change control is published alongside: system prompts are authored, peer reviewed and versioned in a controlled registry, new versions reach customers only after staging review, and the vendor commits that there are no silent prompt or model swaps. Per run traceability makes the reasoning reconstructible after the fact.
One residual gap belongs in any comparison: the account qualification score and the communication style profile are consequential inferences about a company and about a named person, and no accuracy rate, validation or confidence treatment is published for either.
Six customers carry dedicated case study pages and five carry attributed quotes with name, title and employer: a growth vice president at Luzmo, a head of sales at Telescoped, a revenue vice president at InvestNext, revenue operations at Printful and a solution management executive at ARIS.
The figures are specific rather than promotional and one is unusually concrete: from 89 historic accounts the agents validated 37 as fitting the profile, and of 278 contacts only 4 were still valid personas before the agents found 73 new ones. Another customer reports account research falling from four or five hours per account to eleven or twelve minutes. Held off the top because no methodology, sample or period accompanies any figure, and no independent analyst position or review platform record was located.
This product writes outreach and does not send it, so the axis bites less here and is graded on what is knowable with the structural context recorded. What can be said is that no sending obligation is named anywhere: no consent standard, no legitimate interest analysis, no suppression duty, no unsubscribe mechanic and no reference to the electronic communications rules that decide whether a European customer may lawfully send the cold outreach these agents generate.
The contrast within the vendor's own material is what makes this conspicuous. Data protection is addressed across four jurisdictions in detail, and the question of whether the message may be sent at all is left entirely to the platform downstream.
The disclosure is unusually complete for a company this size. Processor role under a data processing agreement included as a standard annex in every customer contract, standard contractual clauses for transfers outside the European Economic Area and the United Kingdom, named compliance with the Californian, Virginian, Colorado, Connecticut and Utah regimes, the Canadian federal statute and the Quebec law named separately, and a published rule that where frameworks overlap the more protective standard governs.
Data minimisation appears as a shipped constraint rather than a principle: agents process full name, job title, email, phone and professional profile only, and only for contacts matching the customer's approved profile and personas. Held off the top by the seam this index keeps finding.
The people being researched never contracted with anyone, the agents read their professional network activity and derive a communication style profile that the minimisation list does not mention, and no notice route or removal path for those individuals is published. The sub processor list is shared during contracting rather than published.
The waterfall cascades through more than twenty third party data vendors for verified email and phone, and not one of them is named. Contact discovery works across the professional network, company websites and team pages, and contact research reads posts, shares and engagement, with no source licence, lawful basis or collection method stated for any of it. Two things hold this at the top of the band rather than lower.
The commercial disclosure around the same mechanism is excellent, with a flat published rate per verified result and no charge on a failed lookup. And the customer needs no vendor subscriptions of their own, so the licensing question sits squarely with this vendor rather than being pushed onto the buyer. What is absent is any route by which a person in that data can see or remove their record.
The vendor lists scraping among its agent tool sets in its own security documentation, which is candid, and the exposure is what that implies. Contact discovery and contact research read the professional network at scale for profile data and activity, a browser extension operates on that network's pages, and no method, rate discipline or conformance position is stated for any of it.
The offsetting facts are real and keep this at the top of the band: nothing rotates accounts, the vendor takes no credential into custody, no evasion language appears anywhere, and the sending that would carry the sharpest platform risk happens in the customer's own engagement platform rather than here. The convention this index applies to reading a professional network with no stated method puts it here.
The strongest answer on this axis in the index, and it closes the gap every other version leaves open. Customer records, research outputs and agent activity are stated never to be used to train or fine tune any language model, and the sentence covers the vendor's own models as well as its providers'. The providers are named and stated to operate under contractual no training and no retention terms.
Isolation is claimed at two levels, once for stored data and once for vector retrieval and embeddings, so a query inside one customer environment cannot surface another's. The agent service is described as mostly stateless, holding no customer business records of its own and forwarding validated outputs to authenticated downstream systems. Retention on exit carries a stated default of permanent deletion of all personal data within thirty calendar days.
And the risk framing is mapped explicitly to the OWASP risk categories for large language model applications, covering prompt injection, sensitive data disclosure, excessive agency and supply chain poisoning, with the full mapping offered under a non disclosure agreement.
This is the first vendor located in this corpus taking any published position on the European artificial intelligence regulation, and the position is careful: the agents are stated not to make decisions in the high risk domains listed in Annex III, a human is stated to review any action affecting external parties, and outputs are said to carry provenance and reasoning visible to the user. Two things hold it here.
The transparency described runs to the user rather than to the recipient, and nothing reaching the prospect discloses that the message was machine written. And the article cited for the transparency obligation is Article 52, which is the numbering from the 2021 proposal rather than Article 50, the enacted provision that has applied since August 2026, so the mapping appears to have been written against the draft.
Against that sits the most targeted personalisation graded here: openers drawn from the person's own posts and engagement, and a message calibrated to a communication style profile the agents inferred about them without their knowledge.
Bidirectional synchronisation with three named systems of record, HubSpot, Salesforce and Pipedrive, with agent output pushed back into the customer's own records rather than held only here. A browser extension surfaces agent research on professional network and record pages. The waterfall reaches more than twenty data vendors without the customer holding any of those subscriptions.
And the boundary with the sending layer is stated plainly rather than blurred: this writes the plays, the existing engagement platform sequences and sends. Held off the top because the connections run inward. Public interface documentation, webhooks, a marketplace and an agent endpoint were all absent from the pages read, so nothing described lets another system query this one.
The transfer mechanism is named, which is more than most manage: standard contractual clauses or equivalent safeguards under the relevant chapter of the European regulation, used only where necessary to provide the service. The model layer carries a jurisdictional constraint too, with providers in non aligned jurisdictions ruled out. What is absent is the answer a residency constrained buyer actually needs.
No cloud provider, country or region is named for the platform itself, which is described only as managed Kubernetes with encrypted secrets and managed Postgres with multi zone availability. No regional option or customer choice exists and the sub processor list is shared during contracting rather than published. For a vendor with a European office selling into European buyers, the strongest available argument is left unmade.
Independent assurance is real and described rather than asserted: an audit of security controls stated to run annually with an independent auditor, an information security management certification, and an explanation of what each one actually requires instead of a badge row.
Around it sits the most detailed architecture disclosure in this index, covering token scoped entry, encrypted secrets, cluster level audit logging, encryption in transit and at rest, logging and monitoring, vulnerability management and documented incident response, plus an offer of a data flow walkthrough and a live session with the chief technology officer under a non disclosure agreement. Three things hold it at the bottom of the band. The report type is never stated.
The reports themselves are gated behind an account manager or a security review rather than served. And two factor authentication on user logins is sold as a paid yearly add on rather than shipped, which puts a security control on the price list on a platform holding the customer's records.
The most complete commercial disclosure in the index. There is no seat licence at all and every plan carries unlimited users, so the variable that makes bills in this category unpredictable is removed outright. The meter is defined and then priced item by item: a published credit cost for each of the twelve agents with low, medium and high effort tiers, a stated minimum of half a credit per run, a stated doubling for priority speed, and the two data waterfalls priced at a flat rate per verified result in three currencies with failed lookups free.
Around it, four plan tiers with parallel capacity and credit volumes, three currencies, a five percent yearly discount with credits delivered upfront, three month rollover on monthly billing, six top up packages that do not expire, expert hours included per tier, an open upgrade and downgrade policy, a stated absence of overage penalties, and both a credit simulator and a return calculator. Two defects are recorded and neither moves the grade.
Add on and expert hour prices did not survive extraction and are treated as a retrieval limit rather than an absence. And the machine readable product page carries per agent credit costs that disagree with the pricing page dated April 2026, so the surface the vendor built for models to read has drifted from the one it built for buyers.
A defined window, a defined choice and a defined default, which is what this axis asks for and rarely finds. On cancellation the customer chooses whether data is returned or deleted, and where no request is made all personal data is permanently deleted within thirty calendar days of termination.
The architecture supplies the other half: agent output synchronises back into the customer's own system of record continuously, so the research and the contact records already sit somewhere the customer controls before any exit conversation begins, and the agent service is described as holding no customer business records of its own. Two gaps are named and neither is enough to move it. No deletion confirmation artefact is described.
And the asset genuinely unique to this vendor, being the configured profiles, personas, value propositions and playbooks in the training centre, is not addressed by the return commitment as published.
Sending happens elsewhere by design and the vendor states the boundary plainly rather than leaving it ambiguous: it writes the plays and the customer's existing engagement platform handles sequencing and delivery, so sender reputation, authentication, pacing and complaint handling all belong to a system this vendor neither controls nor describes. Graded on what is knowable with that structural context recorded.
The adjacent observation worth keeping is that a product generating individually researched outreach at playbook scale puts volume pressure on a sending system it does not govern, and nothing published advises a buyer on where that boundary sits or what it implies for their own domain.
The buyer is named and the fit is argued rather than claimed universally: business to business mid market and enterprise sales teams, with four roles each carrying a dedicated page covering revenue operations, sales representatives, the chief revenue officer and marketing, and an enterprise tier explicitly sized at forty or more salespeople against a stated assumption of one to two thousand credits per salesperson per month.
The competitive set is named precisely rather than gestured at, with dedicated comparison pages against a spreadsheet style data operations tool, against the major data vendors and against general purpose assistants. Named customers span analytics, energy, staffing, print fulfilment and enterprise software. Held off the top because no headcount floor or explicit ceiling is published, and the clearest statement of where this is the wrong purchase sits in a blog post rather than on the product surface.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.