Alta
Alta positions itself as an "AI GTM System of Actions": three coordinated AI agents (Katie for outbound prospecting and multichannel outreach, Alex for inbound and outbound calling and qualification, Luna for pipeline and revenue analytics) running on a shared data layer the company calls a Company Brain. The agents pull from CRM data plus a stated 50+ external data sources and hundreds of buying signals, and execute across email, LinkedIn, phone, SMS and WhatsApp. Alta sells consolidation of a point-solution stack rather than a single-function tool, and runs on top of existing systems of record via 60+ connectors.
Founded 2023 by Stav Levi-Neumark and Tom Hoffen (both ex-monday.com) with Mor Shabtai; raised a $25M round announced July 2026. Named customers include Snowflake, Deel, Atlassian, Riverside.fm, Atoms and Sabio Group.
Capability Axes
Passes the removal test cleanly. The product is three AI agents; there is no underlying non-AI platform left if the models are removed. Founded 2023 as an agent company rather than an established tool with an AI programme bolted on, and the positioning ("a System of Actions is a platform that doesn't just store data, it acts on it") is a claim about autonomous execution, not about a feature. Consistent with the index pattern to date: AI-native vintage takes A on this axis, incumbents take C.
The autonomy claim is maximal and the published oversight is account-level, not agent-level. Third-party analysis describes the agents as making decisions and handling conversations without requiring human intervention for each task, and Alta's own material says the agents act, learn from every interaction and continuously improve.
What is documented: four built-in RBAC roles (Owner, Admin, Manager, Rep), SAML 2.0 and OAuth SSO, SCIM on Professional and above, and an immutable audit log retained one year covering logins, settings changes and data exports. That is administrative control over the account, not containment of the agent.
Nothing published on approval gates, human review before send or dial, escalation thresholds, guardrails that withhold a violating output, or an audit trail of agent actions and the reasoning behind them. Measured against the Agentforce A on this axis (admin-defined engagement rules, guardrails that withhold rather than display, configurable approval by risk, agent action audit trail), the gap is the whole oversight layer. Marketing states the agents are best used to augment rather than replace humans; that is a positioning sentence, not a control.
No model provider, model family or version is named anywhere in the public surface. The product is described in terms of a proprietary "Company Brain" intelligence layer, "advanced AI models" and 50+ data sources, with no model cards, no evaluation results, no accuracy figures for the voice agent, and no statement on fine-tuning versus retrieval.
The sharpest tell: the published sub-processor list on the security page names AWS, Twilio, Postmark and Slack and contains no LLM provider at all, for a product that is entirely composed of language model agents. Either the model layer is in-house and undisclosed, or the sub-processor list is incomplete. Neither reading is disclosure.
Named enterprise customers published (Snowflake, Deel, Atlassian, Riverside.fm, Atoms, Sabio Group) alongside quantified claims: 3x more qualified meetings, 3.5x more email replies stated as measured across 2M+ prospects, 72% faster lead response, sub-30-second inbound response, 20 hours saved per rep per week, one customer reaching seven-figure pipeline in six months with a one-person GTM team. One claim carries a stated measurement base, which is more than most.
Held at B because none of the numbers is attributed to any of the named logos, no methodology is published, and the company-issued figures (first million in revenue within months, 800% revenue growth) are corporate rather than customer outcomes. Credit for an unusual published caveat on Alta's own site that results depend on market, ICP definition and feedback quality. Independent hands-on third-party testing exists (a three-week evaluation in April to May 2026 scoring 7/10, praising targeting and criticising transparency).
Better than most agent vendors and short of the dialer bar. What is published: CAN-SPAM and CASL footers automatically inserted by the sending agent; an opt-out mechanism surfaced in every Alta-sent email footer; the calling agent stated to check local time zone before dialling to stay within TCPA quiet hours; a CCPA Service Provider position with a statement that no data is sold; and a customer responsibilities section that states plainly where the duty transfers, including honouring local consent laws when uploading contact lists.
Naming the statutes and describing the enforcement mechanism rather than asserting compliance is what earns B. Held below A because the telephony compliance stack that Aloware's A was built on is entirely absent here: no DNC list management, no registry scrubbing, no A2P 10DLC registration, no STIR/SHAKEN attestation, and no abandoned-call handling, for a product that places autonomous outbound calls. Also weighed: the whole compliance description lives in a single help-centre article bylined to an AI persona and containing an unfilled "link-placeholder" where the diagram should be.
A properly scoped processor-role privacy policy, which is more than several indexed vendors manage. It states that Alta processes Customer Information on behalf of the customer under a DPA, that the customer is the controller responsible for consents, permissions, data subject rights and fair-processing notices, and that individuals interacting with the AI agent should direct requests to the customer they are dealing with.
Supporting evidence: a published sub-processor list (AWS Frankfurt and Oregon, Twilio, Postmark, Slack) with 30-day notice on changes, a DPA available for e-signature in the admin portal, custom DPA or SCCs on request with a stated five-business-day turnaround, and a data subject export or erase turnaround of seven days or less.
Held at B: the policy pushes essentially the entire consent and notice burden to the buyer, including for the individuals the voice agent speaks to, and the live policy text carries at least one uncorrected error in the company's own name.
Alta repeatedly quantifies its data breadth (50+ data sources, hundreds of buying signals, first-, second- and third-party data, verified emails and phone numbers, titles, social activity, company news) and names not one supplier. For a prospecting agent whose core value is building target lists from aggregated contact and intent data, no provenance chain, no licensing basis, no statement on how contact records were obtained or under what terms they may be resold or acted on.
The published sub-processor list covers infrastructure and channel delivery only and contains no data supplier. Buyers taking on GDPR controller responsibility for records Alta supplies cannot establish the lawful basis of those records from anything public.
LinkedIn is a first-class outreach channel here, listed in the table as an egress path alongside email and voice, and third-party coverage adds SMS and WhatsApp. Better than the automation tools at the bottom of this axis: Alta explicitly instructs customers to keep LinkedIn and email credentials in their own SSO and never share passwords with Alta, which is the opposite of the credential-custody model that earned Alsona a D. But no position is stated on LinkedIn's platform terms, no conformance claim is made, and the mechanism by which agent-generated LinkedIn messages are actually delivered is never described.
Email egress runs through named reputable infrastructure (Postmark, Twilio), which is the stronger half. C reflects an undescribed sending method on a platform whose terms restrict exactly this activity, with the account risk sitting on the buyer.
The training question is raised by Alta's own content and left unanswered. A published help article is titled "Why Connecting Your CRM as Train Data Unlocks Alta's Full Power" and the platform is marketed on agents that learn from every interaction and compound across a shared Company Brain.
Nothing states whether that learning is confined to the contributing tenant or whether signal from one customer's CRM and conversations improves the models or the Brain serving other customers, including competitors. Cross-tenant boundary is the central question this axis asks, and a vendor selling a shared brain has the strongest possible obligation to answer it.
What is published and does count: a numeric retention schedule (ingress ephemeral at 24 hours or less, processing artefacts 30 days, storage 90 days after contract end, custom schedules on Enterprise), AES-256 at rest and TLS 1.2+ in transit, and a stated CCPA position that no data is sold. Compare Adobe Marketo Engage, the index's only A on this axis, which answers the training question contractually.
No stated position on whether the agents identify themselves as AI to the people they contact, and no reference to Article 50 of the EU AI Act anywhere, for a product selling autonomous email, LinkedIn and real-time voice conversations into the EU and UK as well as the US.
The design choice compounds it: all three agents carry human first names (Katie, Alex, Luna), the voice agent speaks in real time and books meetings, and the vendor's own security and compliance help article is bylined "Written by Katie Supporté" - the agent persona presented as a human author of the compliance documentation.
Alta does publish an ethics position stating that AI in sales is ethical when it is transparent and traceable, but the transparency described is traceability of actions back to data and logic for the buyer, not disclosure to the recipient. Bottom of the C band: this is silence plus active human presentation, one step above the D reserved for marketing that celebrates evading detection.
Deep and specifically named. Native integrations with HubSpot, Salesforce, Google Ads, Meta and Slack plus a stated 50 to 60+ additional platforms including Attio and Clay; bi-directional CRM sync included in the platform fee; named partnerships with Salesforce, HubSpot, IBM and Google; API and OAuth ingress; SAML 2.0 and OAuth SSO across Google, Okta, Azure AD and OneLogin; SCIM auto-provisioning and de-provisioning on Professional and above.
The architectural position is stated as running on top of the stack teams already use rather than locking them into a closed box, which is a design commitment rather than a connector count. Held at B: no public API documentation surface, no object-level sync mapping published, and connector depth per integration is not described.
Multi-tenant SaaS on AWS with a stated default region of US-East (N. Virginia), multi-AZ, encrypted EBS and S3, isolated private VPC on a zero-trust network model. Custom DPA or SCCs available on request with a five-business-day turnaround. The problem is that the two published residency statements do not agree: the customer-facing FAQ says data is stored in U.S. data centers, while the sub-processor list on the security page names AWS Frankfurt alongside Oregon.
No customer-selectable region is offered or documented, and no EU residency option is described despite European customers being explicitly claimed. A clearly disclosed single-region posture with no options would grade B; two published statements that conflict, with no mechanism for the buyer to resolve them, is C.
The broadest published control set in the GTM index so far, held below A on the report-access bar this index has already set. Present: SOC 2 Type II described as passed and renewed annually; ISO 27001:2022 certified with a certificate number; independent penetration testing twice yearly; an ongoing HackerOne bug bounty; AWS Shield and CloudFront for WAF and DDoS; AWS KMS with rotation under 90 days; Snyk scanning on every build with high and critical CVEs remediated within 14 days; immutable audit logs retained one year; and incident response SLAs with real numbers (customer notification within 24 hours, status updates every four hours, root-cause analysis within five business days).
A trust centre at trust.altahq.com serves the ISO certificate, a security white paper and the SLA self-service, while the SOC 2 report, penetration test report and DPA sit behind request access. The index bar is that a self-service SOC 2 report earns A and a gated one earns B. Two further reasons for caution: the single document carrying the entire control catalogue is bylined to an AI agent persona and contains an unfilled "link-placeholder" where the diagram should be, which is a tell that it shipped without review; and the trust centre states a founding year of 2022 while the company's own funding announcement says 2023. HIPAA is explicitly not supported, stated plainly, which is good disclosure.
No price, no tier names, no unit of pricing, no free plan, no self-serve trial. The faq answer to the cost question is that pricing depends on volume, team size and channels and the buyer should contact sales. Third parties place enterprise deployments in a $30k to $65k+ annual range and an entry point around $1,000 per month, all estimated.
The finding worth reusing: Alta's own comparison pages publish competitors' pricing in specific numbers - AiSDR at roughly $900 per month for about 1,200 messages and $2,000 for about 3,600, 11x sold per digital worker on annual contracts, Amplemarket sold as per-user annual plans - while describing its own model only as outcome-based and scaling with pipeline rather than seats. A vendor that publishes its competitors' prices and not its own has decided price disclosure is a competitive weapon rather than an inability. Fifth D on this axis in the first eleven vendors.
The best exit answer in the GTM index so far, and the first B on this axis. A self-service workspace purge is documented at Admin then Settings then "Purge workspace", with data erased within 72 hours and a confirmation log emailed to the customer - an artefact the buyer can retain as evidence of deletion, which nothing else in the index provides.
Supporting: storage retention stated at 90 days after contract end, data subject export or erase turnaround of seven days or less, data exports recorded in the immutable audit log, and a published Terms of Service and DPA rather than a website-use notice.
Held below A because no export format or completeness is documented, post-termination data rights are not addressed in the public terms, and nothing states what happens to enriched contact records, conversation transcripts, call recordings or the model artefacts derived from the customer's data once the workspace is purged - which is the load-bearing question for a product whose pitch is that it learns from every interaction.
The Agentforce finding applies here and applies harder. Autonomous agents send across email, LinkedIn, SMS, WhatsApp and voice at machine speed, and the customer connects their own Gmail or Outlook mailbox to the platform, so it is the buyer's own domain reputation the agent is spending.
Nothing is published on warmup ramps, per-mailbox volume caps, mailbox or domain rotation policy, bounce or complaint rate thresholds, spam-rate monitoring, or what the system does when reputation degrades. What counts in Alta's favour and keeps it out of the lower band: named reputable delivery infrastructure (Postmark for email, Twilio for telephony) rather than raw SMTP, automatic CAN-SPAM and CASL footer insertion, and an opt-out link in every sent message. Sending hygiene is asserted through compliance features; sending discipline as volume governance is undocumented.
Clearly stated and evidenced at both ends of the range. Named customers span large enterprise (Snowflake, Atlassian, Deel) and growth-stage companies (Riverside.fm, Atoms, Sabio Group). Geography stated as the United States and Europe, with regional posture claimed for the EU, UK and US. Industries named as technology, financial services and SaaS.
The vendor takes an explicit position on the small end rather than leaving it vague, stating that lean teams and one-person GTM functions often see the clearest return because the agents close the headcount gap, and publishing a customer example on exactly that shape.
Held at B: no enumerated country list, no published segment definitions or employee-count bands, and no coverage detail on which of the 50+ data sources apply to which geographies, which is the practical limit on non-US prospecting.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.