Rox
Agent swarm platform that assigns a persistent artificial intelligence agent to each customer account. Rather than holding the pipeline itself, it sits above the systems that do, integrating with customer record platforms, support ticketing and enterprise resource planning and turning that data into always on agents that monitor accounts, research prospects, draft and run outreach, join and transcribe meetings, and write updates back into the system of record.
That architecture is why this record sits in the agent category rather than under customer relationship management. The product depends on a system of record existing beneath it and does not attempt to be one, which is the test this index applies. The marketing positions it as an alternative to buying separate software, enrichment and record keeping, and the underlying integration story from the company and its investors is consistently one of sitting on top of existing systems rather than replacing them.
Founded 2024 by Ishan Mukherjee, previously chief growth officer at New Relic and co founder of an observability company acquired by it. Launched from stealth in November 2024 having already raised fifty million dollars across seed and Series A rounds led by Sequoia Capital and General Catalyst, acquired a workflow automation company in September 2025, and reached a reported one point two billion dollar valuation in March 2026 in a round press coverage attributes to sources rather than to company confirmation. Named customers include several well known technology companies, one of them the founder's former employer. Both a dot com and a dot ai domain appear across sources for this company.
Capability Axes
Capability grades
17 of 17 axes rated · 4 graded A or B
There is no product here without the models, which is the clearest removal test failure recorded in this index. The company was founded in 2024 around agent swarms and nothing predates them: strip the agents and what remains is an integration layer that reads a customer record platform and a support system, which is plumbing rather than a product and is not something anyone would buy.
Every named capability is model dependent, covering account research from public filings, news and job postings, prospect identification, outreach drafting, reply handling, meeting transcription and record maintenance, and the unit of consumption the vendor meters is the agent action itself rather than a seat or a record.
Investors describe the architecture in the same terms, as company data transformed into an agent swarm that autonomously monitors, engages and manages customer relationships. This is the vintage split the grading convention describes working exactly as intended: incumbents whose assistants sit on complete products take the middle band, and a company built as agents from its first line of code takes the top. Ask what a deployment does on day one before any agent is configured.
The highest autonomy surface in this index, bounded by a billing meter and nothing else that was located. Agents are described as always on and assigned per account, monitoring continuously, researching, running outreach sequences, handling replies, booking meetings, joining calls and writing updates back into the customer record system.
That last one matters more than the rest combined: an agent writing into the system of record changes data that forecasting, reporting and other teams depend on, and does so without a person entering it. The one constraint located is the metered agent action, which gives a spend ceiling visible to the operator on the free tier, and that is a cost control rather than a behavioural one.
Nothing published describes what an agent may not do, whether any action requires approval, what an administrator can constrain by account or role, whether outreach can be held for review, or what halts a swarm mid execution. Source quality is a caveat worth recording: the fullest descriptions of autonomous behaviour come from third party product write ups rather than vendor documentation, though the lead investor's own account uses the same language. Ask what an agent can write to the system of record, what requires approval, and what stops a swarm.
An entirely model driven product with nothing published about the models. No provider, family or version is named anywhere, no model card exists, and no evaluation or accuracy figure appears for any component, which covers account research, prospect identification, message generation, reply handling and meeting transcription.
The gap is more consequential here than for vendors where models sit on top of working software, because at this vendor the model output is the product and there is no deterministic layer beneath it to fall back on. Two specific measurements are absent and would matter most. Research accuracy, since agents synthesise account intelligence from public filings, news and job postings that representatives then rely on in live conversations.
And write accuracy, since agents update the customer record system, so a wrong inference becomes a wrong record that other systems inherit. The metered agent action is described as a billing unit without any published account of what computation it represents. Ask which models power research, generation and reply handling, and what evaluation covers agent output before it reaches a buyer or the system of record.
A reach claim that does not reconcile with the company's own reported revenue. The vendor states it has served more than five thousand organisations globally across financial institutions, energy, healthcare, manufacturing, semiconductors and sovereign deployments.
Press reporting of the funding round puts projected annual recurring revenue at eight million dollars closing 2025, which across five thousand organisations averages roughly sixteen hundred dollars each, a figure incompatible with the enterprise profile described and consistent instead with counting free tier signups as organisations served. Those two claims appear in the same announcement.
What is genuinely evidenced is a small number of named and recognisable technology customers, one of which is the founder's former employer, and a platform partnership making the agents available inside a major software vendor's assistant. The performance claims carry no method: strategic account managers closing two and a half times more annual recurring revenue, and forty five day average prototype to production, both stated without population, baseline or period. Ask how organisations served is counted and whether it includes free tier accounts, and how the two and a half times figure was measured.
Autonomous outbound at agent speed, with no published compliance apparatus. Agents identify prospects, personalise sequences, send, handle replies and book meetings, which places every obligation this axis examines squarely on the product rather than downstream.
Nothing published describes consent basis for contacting a prospect surfaced by research, suppression list handling, unsubscribe mechanics, whether an objection recorded anywhere prevents an agent re engaging, or what volume ceiling applies per account or per day. The always on framing sharpens the question, because an agent assigned permanently to an account and monitoring it continuously has no natural stopping point the way a human authored sequence does.
One structural mitigation exists and is worth recording: agent actions are metered, so outreach volume is bounded by a purchased allowance rather than being unlimited, which caps blast radius even though it is a commercial rather than a compliance control. Ask what suppression state agents check before contacting a prospect, what per account and per day volume limits apply, and what the consent basis is for research sourced contacts.
No privacy documentation was reached on the routes taken this pass. No privacy policy contents, processing agreement, subprocessor list, transfer mechanism, retention period or data protection officer was located. One product write up states that agents keep data secure within the customer's existing systems, which if accurate would be a genuinely favourable architectural position, since it would mean the vendor reads rather than accumulates and the customer's own residency and retention decisions would largely govern.
That claim comes from a third party product summary rather than vendor documentation and was not verified, and it sits awkwardly beside a product that also researches external prospects and records meetings, both of which generate data that did not previously exist in the customer's systems. This grade records what a buyer could establish before contacting sales.
The corpus at stake includes prospect research on individuals who never contacted the company, meeting recordings involving external parties, and agent generated correspondence. Ask what data the vendor stores versus reads, the processing agreement, the subprocessor list and the retention period for research and recordings.
Source categories are named and the suppliers behind them are not. Research agents are described as drawing on public filings, news, job postings and the customer's internal data to build organisation charts, surface buying signals and consolidate insights, which is more specific than the usual claim of proprietary intelligence and tells a buyer the general shape of the inputs. What is missing is everything underneath.
No data provider, aggregator or licensing arrangement is named for the news, filings or job posting sources, no statement describes whether the material is licensed or gathered directly, and nothing addresses what basis supports building profiles of named individuals at prospect organisations who have no relationship with either party.
The positioning as an alternative to buying enrichment implies the vendor supplies what an enrichment provider would, which makes the provenance question a direct one rather than a peripheral one. No indemnification position was located. Ask which providers supply filings, news and job posting data, whether it is licensed, and whether provenance is indemnified.
Integration runs through sanctioned routes and one platform relationship is formal rather than technical. The architecture depends on reading from and writing to customer record platforms, support ticketing and enterprise resource planning systems through their own published interfaces, and the company and its investors consistently describe integrating with existing systems rather than circumventing them.
The distinguishing element is a partnership placing the revenue agents inside a major software vendor's enterprise assistant, which is a sanctioned distribution channel requiring that vendor's own review and approval, and is a stronger signal about platform standing than a connector list. Nothing resembling credential storage, scraping or unsanctioned automation appears anywhere. Held below the top band on two counts.
No stated conformance position against any specific platform's terms was located, which is the distinction the convention draws. And the write back capability means the agents hold write permissions into systems of record across multiple platforms, an exposure that grows with the number of platforms and that nothing published scopes. Ask what permission scopes the agents request in each connected system, and whether write access can be limited to named objects.
An entirely agent driven platform with no stewardship position located. Nothing published states whether customer data, prospect research or meeting recordings train or tune any model, which providers process material when agents run, what retention applies to prompts and generated output, or whether anything crosses a tenant boundary. No governance document, evaluation record, red teaming artifact or independently audited management standard for artificial intelligence was located.
Two features make these questions weightier here than for a vendor with a smaller model surface. Agents operate continuously rather than on request, so the volume of model processing per customer is high and ongoing rather than occasional.
And the customer base is described as including financial institutions, healthcare organisations and sovereign deployments, which are precisely the buyers who require documented model governance, so material almost certainly exists behind a sales conversation even though none is public. Ask whether customer data, research output or recordings train any model, which providers process them, what retention applies, and what governance documentation is available.
Agents conduct multi turn exchanges with buyers and no disclosure position was located. The lead investor's own description has agents autonomously monitoring, engaging and managing customer relationships, and product material describes an outbound agent that finds leads, personalises sequences, handles replies and books meetings without human intervention.
Handling replies is the consequential phrase: a prospect who answers a message receives another machine written response, and can hold a complete exchange culminating in a booked meeting while believing they are corresponding with the person whose name is on the message. Nothing published states whether the recipient is told, whether disclosure can be enabled by the operator, or what an agent says if asked directly.
A meeting agent separately joins calls to record and transcribe, adding a second surface where an external participant's data is captured. This lands at the bottom of the published scale for the same reason as the other records at this grade in this index, which is that the concealment is not incidental to the product but produced by its central design, and the vendor markets the absence of human involvement as the benefit. Ask whether agent sent messages disclose machine authorship, and what a prospect asking whether they are talking to a person is told.
Integration is the architecture rather than an accessory, since a platform that deliberately does not hold the system of record has no product without it. Named connections span customer record platforms, support ticketing and enterprise resource planning systems, which is a wider ingestion footprint than most agent products attempt and reflects the positioning as a layer above the whole stack.
A workflow automation company was acquired in September 2025 to extend the agentic execution capability, which is capability bought rather than integrated. The most substantive item is distribution: the revenue agents are available inside a major enterprise assistant through a platform partnership, so the agents reach users in a surface the vendor does not own.
Held below the top band on verification and scope: no developer documentation, interface reference, authentication model, rate limits or integration inventory was reached on this pass, and the company is two years old, so the connector breadth described is largely a positioning claim rather than a catalogue a buyer can inspect. Ask for the interface documentation and the current verified integration list.
No deployment or residency information was reached on the routes taken this pass. No hosting provider or region is named, no European or United Kingdom residency election is described, no tenancy model is stated, and no recovery objective appears.
One phrase in the vendor's own reach claim is suggestive and unverified: the customer base is described as including sovereign deployments, a term normally denoting infrastructure operated within a specific national jurisdiction under that state's control, which would imply a deployment model considerably more flexible than standard multi tenant cloud.
Nothing published describes what that arrangement involves, who it is available to, or whether it is a shipped capability or a bespoke engagement. For a two year old company that would be an unusual capability and it deserves direct verification rather than acceptance. Ask what sovereign deployment means in practice, which regions the standard service runs in, whether regional residency is available, and what the tenancy model is.
No certification, attestation or trust surface was reached on the routes taken this pass. No trust centre, service organisation control report, international information security certification, penetration testing statement, vulnerability disclosure route or enumerated control page was located. This records verifiability before a sales conversation rather than a judgement about the underlying programme.
The stated customer profile makes documentation near certain: financial institutions, healthcare organisations and semiconductor companies do not deploy an agent platform with write access to their system of record without an attestation, and the platform partnership placing these agents inside a major enterprise assistant would itself have required a security review by that platform owner.
That partnership is worth noting as indirect evidence of a programme even though it is not a substitute for a report. The company is two years old, which is early for a full certification set, so the audit period is a fair question in itself. Ask which certifications and attestations are held, with audit periods and auditors, and what security review the platform partnership required.
Public pricing with a free entry point, which independent analysis notes is unusual for an enterprise targeted agent platform and which almost nothing else in this cohort offers. Published: a free tier carrying two thousand agent actions a month at no cost, a core tier at fifty dollars a month, and custom enterprise contracts.
The vendor also states that capabilities come in a single subscription rather than being sold à la carte, which is a meaningful commitment in a category where module stacking routinely multiplies a headline rate several times over, and it is the opposite of the pattern found repeatedly elsewhere in this project. Three things hold it below the top band.
The agent action is the unit that decides the bill and is never defined, so a buyer cannot tell whether researching an account, sending a message and logging a reply is one action or several, which makes the free allowance and any overage unforecastable. No overage rate is published.
And the distance between a fifty dollar monthly tier and the enterprise contracts underpinning the company's reported valuation is enormous and entirely unexplained, so the published ladder describes the small end of the market rather than the one the company sells into. Ask what counts as an agent action, the overage rate, and where enterprise pricing begins.
Nothing published addresses leaving, and the architecture cuts in the customer's favour in a way worth recording. Because the platform deliberately does not hold the system of record, the customer's core account, contact and opportunity data remains in the systems it already owns throughout and after the relationship, so an exit does not strand the primary asset in the way it would with a platform holding the only copy. That is a genuine structural mitigation.
What it does not cover is everything the agents generate: accumulated account research, agent authored correspondence and its history, meeting recordings and transcripts, configured plays and the per account agent context built up over time. Nothing states whether any of that exports, in what format, what retention applies after termination, or what the deletion timeline is.
The per account agent context is the least reproducible piece, since it accumulates continuously rather than being configured once. Ask what the agents generate that does not live in the customer record system, whether it exports, and what the deletion timeline is.
Agents send at machine speed and nothing about the sending is described. Outbound sequences are composed and delivered by agents rather than by people, which makes this a sending product in full and places domain reputation squarely in scope.
Nothing published states whether messages leave from the customer's own connected mailboxes or from vendor infrastructure, who configures authentication records, whether mailbox warmup exists, what bounce or complaint thresholds trigger intervention, or how one customer's sending is isolated from another's. Two factors raise the stakes above a conventional sequencer.
Recipients are surfaced by research rather than drawn from a list the customer verified, so address quality depends on the agent's inference. And always on agents assigned per account generate volume continuously rather than in campaign bursts, which is a different sending pattern from the one mailbox providers are used to seeing. The metered agent action caps total volume commercially. Ask which infrastructure sends, whether addresses are validated before an agent sends, and what bounce handling applies.
A sector list and a reach figure that does not survive arithmetic. The vendor names financial institutions, energy, healthcare, manufacturing, semiconductors and sovereign deployments as served sectors, and the named customer references are recognisable technology companies, so there is genuine enterprise validation at the top.
The problem is the claim of more than five thousand organisations served, which set against reported annual recurring revenue of roughly eight million dollars implies an average well under two thousand dollars per organisation, incompatible with the enterprise sectors listed and consistent instead with counting free tier registrations. A coverage claim a buyer cannot rely on is worth less than a smaller one they can.
The commercial ladder does span genuinely, from a free tier through a fifty dollar monthly tier to enterprise contracts, so the range is real even if the reach figure is not. No industry pages, localisation or stated minimum deployment were located, and the company is two years old, which limits what any coverage claim can yet mean. Ask how organisations served is counted, and what the smallest and largest paying deployments look like.
Pricing
What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.
- ›Rox publishes its prices, which is unusual for this kind of enterprise AI product. There is a free version giving you two thousand agent actions a month, then fifty dollars a month for the main tier, then custom pricing for large companies.
- ›Everything is included in one subscription rather than sold as separate add ons, which is genuinely better than most tools in this index.
- ›The catch is the thing you are actually buying. The bill is measured in agent actions, and nowhere does the company explain what counts as one. If an agent researches a company, writes an email, sends it, reads the reply and updates your records, is that one action or five? Nobody publishes an answer, and there is no published price for going over your allowance.
- ›Also worth noting: fifty dollars a month and the contracts this company signs with banks and healthcare firms are clearly very different purchases, and only the small one has a published price.
How the price works
What you are charged for, and what makes the bill go up.
Subscription metered in agent actions rather than seats or records. Three tiers: a permanent free tier at two thousand agent actions per month, a core tier at fifty dollars per month, and custom enterprise contracts. All capabilities are stated to be included in a single subscription rather than sold as separate modules. The agent action is not defined on any published surface and no overage rate appears. Because agents are described as always on and assigned per account, consumption scales with account coverage and agent activity rather than with team size.
What the contract says about your data
What the vendor commits to in writing once your data is in the product.
No processing agreement, subprocessor list, transfer mechanism, retention period, data protection officer, certificate or trust surface was reached on the routes taken this pass. Recorded as a retrieval limit rather than an absence: the stated customer profile spanning financial institutions, healthcare and semiconductors, plus a partnership placing these agents inside a major enterprise assistant, both imply security documentation exists behind a sales conversation. Two questions matter more here than for most vendors. The agents hold write access into the customer's system of record, so permission scope and audit logging are load bearing.
And one product summary states that data stays within the customer's existing systems, which if accurate would materially change the residency and retention picture, but it comes from a third party rather than vendor documentation and was not verified.
Getting started
What it costs and what is included before the product is running.
No implementation fee is published and the lower tiers are self serve with a free entry path. Product material reports prototype to production deployments averaging forty five days, which for an enterprise platform integrating with a customer record system, support ticketing and enterprise resource planning implies vendor involvement rather than pure self service, and no fee is stated for that work. Enterprise arrangements are quoted and no services schedule was located.
The material variable cost is consumption rather than setup, since agent actions meter continuously and the agents are described as always on, so a deployment's running cost scales with how many accounts are covered and how actively agents work them.
What to watch for
Where this pricing can surprise a buyer who has not read it closely.
Public pricing with a free entry point, which independent analysis specifically notes as unusual for an enterprise targeted agent platform and which distinguishes this record from most of the cohort. Published: a free tier carrying two thousand agent actions per month at no cost, a core tier at fifty dollars per month, and custom enterprise contracts. The vendor also states that capabilities are included in a single subscription rather than sold as separate modules, which is a real commitment in a category where module stacking routinely multiplies the headline rate. Three gaps keep this short of the top band and a buyer should close all three before committing.
The agent action is the billing unit and is never defined, so it is impossible to tell whether researching an account, sending a message and logging the reply counts as one action or four, which makes both the free allowance and any overage unforecastable. No overage rate is published. And the gap between a fifty dollar monthly tier and the enterprise contracts implied by the company's reported valuation and customer profile is enormous and unexplained, so the published ladder describes the small end of the market rather than the segment the company is selling into. entryPriceUsd recorded at 50, the vendor's published lowest recurring paid rate, with the free tier not treated as the entry point per the standing convention.