Aritic PinPoint
Aritic PinPoint is a full-stack B2B marketing automation platform: landing page builder, web forms, lead capture and tracking, behavioural lead scoring, drag-and-drop nurture journey builder, omnichannel campaigns across email, SMS and push, anonymous visitor tracking and ad retargeting, A/B testing, segmentation and campaign analytics. It is sold as an independent product within the wider Aritic suite (Aritic Sales CRM, Aritic Mail, Aritic Desk, Aritic Swarm), with bi-directional sync to Aritic Sales CRM and native bi-directional integration to Salesforce, SugarCRM and Zoho CRM. Pricing is banded by contact count with a free lifetime plan below 500 contacts.
Aimed at SMB and mid-market B2B marketing teams across e-commerce, SaaS, agencies, financial services, manufacturing and education. NOTE ON SCOPE: the source list names "Aritic Sales CRM", which is a system of record and out of scope for this index; Aritic enters on PinPoint, its separately positioned and independently sold execution surface, on the same basis Salesforce entered via Agentforce Sales.
Capability Axes
A competent marketing automation platform that makes a modest AI claim, which is exactly what C is for. Third-party product descriptions state that automation features are driven by predictive analysis and AI applied to lead behaviour and lead profiling - in practice, behavioural lead scoring. Remove it and the platform is complete: forms, landing pages, journeys, segmentation, campaigns and analytics all function. No D here, because the index reserves D for a marketed AI claim that fails the removal test, and Aritic does not build its positioning on AI at all. It sells automation workflows.
The automation model is deterministic and human-authored - drag-and-drop nurture workflows, lead-score triggers, scheduled campaigns - which is inherently bounded and is a point in its favour. Real controls exist: role-based access control for multi-user collaboration, and audit logs.
The reason this is not higher is that audit logs and enterprise SSO are both gated to the enterprise tier, so the oversight primitives are sold as an upgrade rather than shipped as a floor, and nothing is documented about how the predictive scoring layer reaches its conclusions or whether a human can inspect or override them.
The AI claim is a single functional sentence in third-party product descriptions and is not developed anywhere on the vendor's own surface. No model, provider or method named for the predictive scoring; no explanation of what signals feed it or how they are weighted; no evaluation, accuracy figure or documented failure mode. A buyer routing leads to sales on the strength of a predictive score cannot establish what produces it.
Review-platform presence exists on G2, Capterra and Software Advice with substantive reviewer detail, including a German B2B creative services user describing the nurture builder and consent controls in operational terms. Quantified outcomes appear only inside third-party review text - a pharmaceuticals customer reporting a 40% increase in sales-ready leads - with no named organisation, no methodology and no vendor case study behind it.
One named customer surfaces in vendor testimonials (NicheMktg) and the rest are first-name or unattributed. No published case study library, no enterprise logo wall, no measurement basis for any claim.
The finding on this record, and it is rare enough to reuse as a benchmark: Aritic states as a product policy, in its own pricing faq, that PinPoint cannot be used to send over a purchased email database or list, and works only on permission-based contacts and opt-in lists. Almost every vendor in this index handles list legitimacy by disclaiming it into the customer's terms; Aritic refuses the input.
That is a compliance constraint expressed as a limit on what the product will do, which is the strongest form the posture can take. Supporting: native GDPR consent capture and data retention management are shipped rather than sold as add-ons, confirmed operationally by a reviewer running the platform from Germany, and third-party assessment records GDPR and can-spam compliance.
Held below A because the enforcement mechanism is never described - it is not stated whether purchased lists are detected, attested to at import, or simply prohibited on paper - and no unsubscribe implementation, complaint-rate threshold or statute-by-statute treatment is published.
The product-level privacy tooling is real and specific: native consent capture at the point of collection and configurable data retention management, both cited by a reviewer operating under German data protection requirements as the reason the platform is usable there. The company-level privacy surface is where it falls short.
No Data Processing Addendum located, no sub-processor list, no stated cross-border transfer mechanism, no Data Protection Officer or EU representative named, and no processing notice. Shipping the buyer good GDPR controls while publishing little about the vendor's own processing is a common shape in this category and it is graded as C: the customer can be compliant, but cannot document the vendor.
B on a structural ground rather than a disclosure one, and the distinction matters. Aritic PinPoint is a first-party marketing automation platform with no contact database of its own - it operates exclusively on contacts the customer collects, and the vendor states plainly that purchased lists are not permitted. There is no third-party provenance chain to trace because the vendor supplies no third-party data, and it draws that boundary explicitly rather than leaving it to be inferred.
The one gap, and it is a real one: lead enrichment is offered as an Enterprise-tier feature, and no source, supplier or licensing basis is named for the enrichment data. A platform that refuses purchased lists on the ingest side and then enriches records from an undisclosed source has an unresolved seam.
Low exposure by design, which is the whole reason for the grade. Sending runs on first-party infrastructure (Aritic Mail is a sibling product in the same suite), CRM connections are official bi-directional integrations with Salesforce, SugarCRM and Zoho rather than scraped access, and the 80+ third-party integrations are named published connectors. No LinkedIn automation, no browser extension harvesting profile data, no session credentials held.
The genuine exposure surface is anonymous website visitor tracking and ad retargeting, which is cookie and consent territory rather than platform terms, and the shipped consent capture goes some way to covering it. Meets the stated B condition exactly - own infrastructure plus official connectors - and would need a published conformance position to go higher.
Configurable data retention management is a genuine stewardship control and it is shipped to the customer rather than held by the vendor, which is the right architecture. Everything else is unaddressed: no statement on whether customer contact data, behavioural signal or campaign content is used to train or tune the predictive scoring layer; no cross-tenant boundary described; no sub-processor disclosure; no encryption specification located at rest or in transit. The training question is smaller here than at an agentic vendor because the AI surface is narrow, but it is unanswered all the same.
No Article 50 position, no statement on marking AI-assisted content, and no described disclosure at first contact. What lifts this to the upper end of C rather than the floor: the product does not generate synthetic personas, cloned voices or autonomous conversations, so the Article 50 surface is genuinely narrow, and the permission-based-only policy means recipients have opted in before any message is sent - which is a materially better starting position than any cold-outbound vendor in this index and is disclosure of a different and arguably more useful kind. The gap is that the vendor has taken no position on the question, not that it is behaving badly.
Genuine breadth with counterparties named rather than counted: 80+ third-party integrations including Adobe Commerce, Akamai Identity Cloud, Alchemer, Asana, BigCommerce, Calendly, Chargebee, Constant Contact, Drupal, Eventbrite and Formstack, spanning campaign, billing, CRM, CMS and webinar categories. Bi-directional native CRM integration with Salesforce, SugarCRM and Zoho CRM is the load-bearing piece and is marketed as such.
API access for developer integration, plus bi-directional sync to the sibling Aritic Sales CRM within the suite. Held at B: no object-level field mapping published, no public API reference located, no MCP or agent-facing endpoint, and integration depth per connector undocumented.
Third-party descriptions refer to scalable infrastructure and flexible deployment options with nothing behind either phrase. No hosting region named, no cloud provider named, no residency option documented, no data centre location published, and no on-premise or private-cloud offer described despite the flexible-deployment language.
This matters more than usual here: the platform ships GDPR consent capture and is demonstrably in use by European customers relying on it, and residency is the one question those customers will be asked in their own audits that this vendor does not answer.
A SOC 2, ISO 27001, trust centre, penetration test attestation and security page all failed to surface; third-party review analysis states directly that detailed security certifications are not prominently featured and flags this as a watch item for compliance-sensitive buyers.
C rather than the floor because an enumerated control set does exist and one boundary is stated precisely: role-based access control, enterprise SSO, audit logs, an uptime SLA on Enterprise, and an explicit statement that Aritic does not store customer card details because payment processing and subscription management run through 2Checkout and PayPal. A named payment-data boundary is a real disclosure. Note the pattern, which recurs in this index: SSO and audit logs, the two controls a security reviewer will ask for first, are both Enterprise-tier upgrades.
The structure is published and the numbers are not reliably retrievable. Present: a named tier ladder (Free, Lite, Starter, Professional, Enterprise), contact count stated as the pricing unit with the counting rule defined (unique push subscribers, email subscribers and contact phone numbers), a free lifetime plan below 500 contacts with no credit card and no obligation, an annual discount stated at roughly 10 to 20 percent, named payment processors, and a self-service cancel-anytime path from the billing page.
Against: the vendor's live pricing figures do not resolve from the public surface, third-party figures conflict materially (one source reports $199, $499 and $1,199 per month by contact band against the vendor's own five-tier naming), and Enterprise is quote-only. The sharpest item and the reason this is not a B: a Capterra reviewer reports that Enterprise-only features were enabled on their Professional plan after repeated negotiation.
A published feature gate that moves under negotiation is not a published price - the buyer cannot know what their tier contains, which fails the established test of whether they can budget their own purchase.
A self-disclosed data control defect that sits directly against the product's own compliance pitch: Aritic's pricing faq states that once contacts are uploaded from an imported CSV list, they cannot be deleted manually. That is the vendor telling the buyer, in its own words, that a class of records entering the platform cannot be removed by the ordinary route - in a product marketed on GDPR consent capture and retention management, where erasure on request is the obligation the tooling exists to serve.
Worth re-verifying directly, since the source is a dated faq page and the limitation may be narrower in practice than the wording, but it is the vendor's own published statement and it is graded as such. On the other side: subscription cancellation is genuinely self-service and documented from the billing page with no obligation on the free plan. Nothing published on export format, post-termination data rights, deletion timeline or what happens to campaign and engagement history. Easy to stop paying, unclear how to leave with your data or remove someone else's.
B earned on policy, not on plumbing, and the note should be read that way. The no-purchased-lists, opt-in-only rule is the single most effective deliverability control there is, because bad list provenance is the root cause of most bounce and complaint failure, and Aritic enforces it as a product limit rather than a warning. Sending runs on first-party infrastructure via the sibling Aritic Mail product.
Set against that, the technical surface is entirely undocumented: no warmup, no inbox placement testing, no domain health monitoring, no published bounce or complaint threshold, no dedicated IP discussion, and no SPF, DKIM or DMARC guidance located. Compare Apollo's D on this axis in the same session: Apollo has scale, infrastructure and a documented high-bounce problem; Aritic has no documented infrastructure and a policy that prevents the failure mode arising. The index grades the discipline, and a rule the product enforces counts for more than a feature list.
The vendor's own positioning contradicts itself across its own material, which is the reason for the grade rather than any lack of range. The same platform is described in different vendor-supplied product descriptions as built for small and medium-sized companies and digital marketing teams, as suitable for start-ups through enterprises, and as designed for enterprises and large corporates. Those cannot all be the primary claim.
Industries are named consistently and usefully (financial services, manufacturing, education, technology, marketing, e-commerce, SaaS, digital agencies) and B2B focus is stated throughout. Geography is not addressed at all: no country list, no supported languages, no regional presence, with a German customer evidenced only through a third-party review. The free-to-Enterprise ladder implies real range; the vendor has not decided what to say about it.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.