Cadivra
Cadivra Ltd is a very new British outbound tool, registered in England and Wales as company 17130844 with its domain first registered in April 2026, built around an explicit rejection of the volume playbook. The run is four steps: find prospects by role, industry, location and company size from a B2B database or an uploaded list with verified work emails, research each company's site, filings and recent buying signals, write a genuinely distinct email per prospect rather than a template with merge tags, and send it from the operator's own existing mailbox on Microsoft 365 or Gmail. Two design choices define it.
Nothing sends without human sign off, with a sample preview before committing and per email editing afterwards, and there is no secondary domain to warm because the buyer sends from the address they already use and inherits their own reputation. Around that sits a deliberately deep deliverability layer, SPF, DKIM and DMARC checking, blocklist monitoring, provider limit pacing, business hours windows, optional contact verification before a credit is spent, automatic halting of follow ups the moment someone replies, and a single sender health score with remediation prompts.
Pricing starts at 24 GBP per month with 100 free credits and no card, metered at one credit per contact. The vendor names its model provider outright in its FAQ, which no other vendor in this index has done.
Capability Axes
Capability grades
17 of 17 axes rated · 7 graded A or B
Nothing survives removal of the model. The product is research plus generation: it reads each company's site, filings and recent signals, then writes an individually composed email connecting a specific observation to a reason for contact.
The vendor makes the point negatively and repeatedly, that this is never a template with a name dropped in, no merge tags, a fresh email per prospect, and its stated competitive line against Apollo, Lemlist and Instantly is precisely that it does not use templates. Strip the model out and what remains is a mailbox connector and a scheduler.
The vendor also argues its own pricing on this basis, positioning 24 GBP a month against a 20 GBP chatbot subscription on the grounds that a chatbot writes one email only after the operator spends ten to fifteen minutes doing the research by hand.
Top of band, and the reason is a distinction no other vendor in this index has offered. Everywhere else human approval is configurable, a setting an administrator may enable or an autonomy dial the customer may turn up; Artisan even publishes that more than 90 percent of its customers run the agent fully autonomously.
Here approval is unconditional and marketed as the guarantee: you review every email before it sends, nothing leaves your mailbox without your sign off, preview a sample before committing to a campaign, then edit any individual email by hand. Two further containment controls ship: follow ups stop the moment a recipient replies, and a suppression list is a first class object in the product.
Not A because none of the surrounding apparatus exists, no audit trail of what the model produced versus what the human changed, no guardrail that withholds a non compliant draft rather than presenting it, no escalation by risk, and no evidence that approval is enforced rather than merely offered.
The first vendor in this index to name its model provider. In answering how personalisation works, Cadivra states plainly that Claude remixes a library of reusable blocks, offers, problems, proof points, calls to action and tone, for each recipient using their role, company and the operator's own notes. Every other vendor graded here, including vendors with hundreds of millions in funding and enterprise customer lists, describes its AI functionally and names nothing.
The mechanism is also described honestly, as recombination of operator supplied material against per prospect research rather than as invention. It is B and not A because naming the provider is where the disclosure stops: no model version, nothing on where inference runs, no statement of what prospect data is transmitted to the provider or under what terms, no retention position, and nothing on the accuracy or failure modes of the research step that supplies the observations the email is built on.
There is no customer evidence of any kind. No named customer, no logo, no testimonial, no case study, no quantified outcome, no funding record, and no presence located on G2, Capterra or any other review platform. Recorded as observed rather than concluded: the site's demonstration section is headed A Real Example and This Email Was Written by Cadivra, and shows a composed email to a named contact at a named company followed by a reply timestamped eight minutes later; the companies appearing in it could not be located as real businesses.
This is graded as a stage fact rather than as concealment. The company was incorporated recently and its domain registered in April 2026, so it has had months rather than years to accumulate a record, and a vendor cannot publish customers it does not yet have. The grade reflects what a buyer can currently verify, which is nothing, and should be revisited as the vendor matures.
The apparatus is unusually complete for the stage and, importantly, most of it is shipped behaviour rather than paperwork. A suppression list is a named object in the product interface; follow ups halt automatically on reply; contacts can be verified before a credit is spent so dead addresses are not mailed; sends are paced under provider limits within a configurable business hours window.
On the document side a dedicated Acceptable Use Policy is published alongside the terms, privacy policy, cookie policy and a data processing addendum, which is a fuller legal set than most vendors several years older ship. The positioning is consistent with all of it, built for replies not volume, and built for sales not for spam.
Not A because no regulation is named anywhere: not GDPR by article, not PECR, which is the operative UK rule for the vendor's own jurisdiction, not CAN-SPAM for the US recipients its database will produce. The document bodies were not read this pass, so the substance behind the Acceptable Use Policy remains to be verified.
The instruments exist and that is worth real credit at this stage: a privacy policy, a cookie policy and a published data processing addendum, from a company incorporated within the last year, under an identifiable UK legal entity with a Companies House number on the page. Many vendors in this index with a decade of trading publish less. What holds the grade at C is the population the product touches but the disclosures do not reach.
Cadivra supplies verified work email addresses for people who have not been contacted before and have no relationship with the vendor, and nothing published addresses their position: no lawful basis for the processing, no Article 14 notification of the kind Apollo publishes and is the benchmark for, no self service lookup or removal route, and no controller or processor designation for the database. GDPR-ready appears as a footer badge rather than as a statement with content behind it.
The single largest gap in an otherwise well documented record. The product searches a B2B database by role, industry, location and company size, returns verified work emails, cleans the list, and flags buying signals such as funding rounds and new hires, and nothing anywhere identifies where that database comes from.
No supplier named, no licensing arrangement described, no collection method, no refresh cadence, no accuracy claim, no data broker registration, and no route for a person in it to see or remove their record. The vendor is explicit and specific about almost everything else it does, which makes the silence here conspicuous rather than merely absent.
Apollo holds the A on this axis for naming three sourcing routes, naming the features that convert customer activity into inventory, and publishing a genuine Article 14 discharge; none of those three pieces is present.
Low exposure by design, and the design is stated rather than accidental. The product sends email only, through the operator's own Microsoft 365 or Gmail account, with no LinkedIn automation, no social messaging, no browser extension and no platform scraping described anywhere. The other integrations are Zapier, Make and n8n, all first party automation surfaces.
Most importantly the vendor explicitly rejects the practice that creates most platform exposure in cold email: no warmed secondary domains, no throwaway sending infrastructure, no new domain to warm, because the buyer sends from the address they already use. That is the opposite of the disposable domain playbook and it means the reputational consequences land where the accountability does. Not A because the mailbox connection method is not stated in terms a buyer can check, so whether it is revocable scoped OAuth or something weaker is inferred from the pattern rather than documented.
Recorded as observed rather than concluded: nothing located states whether operator or prospect data is used for training, how tenants are separated, what is retained after a campaign ends, or on what terms prospect research and email content are passed to the named model provider. Naming Claude answers who processes the data, which is more than any other vendor here supplies, and leaves entirely open what happens to it. A data processing addendum is published and is the obvious place for the answer to live, but its text was not read this pass. Re verify against the DPA before quoting this grade.
This is manufactured effort in its purest graded form, and the vendor markets the indistinguishability directly: every email lands looking like you sent it, because you did. The recipient is meant to conclude that a named person read about their company, noticed something specific about their situation and wrote to them about it, and the specific observation is real while the reading and the writing are not.
No Article 50 position, no disclosure line, no acknowledgement that the question exists. Two genuine mitigations keep it in the upper part of the band rather than the bottom. A human approves and may rewrite every message before it leaves, so the sender did in a meaningful sense choose to send it and carries responsibility for its contents, which is not true of an autonomous agent handling its own replies. And follow ups stop on reply, so the conversation that follows is between two people.
Five named connectors and no depth behind any of them: Microsoft 365 and Gmail for sending, and Zapier, Make and n8n as general automation bridges. The notable absence is a CRM. For a sales tool there is no Salesforce, HubSpot or Pipedrive integration described, and contacts live in an in app object instead, which means activity does not reach the buyer's system of record without building the bridge yourself through one of the automation tools. No public API or developer documentation was located, no marketplace listing, and no third party verifiable evidence of any integration. Reasonable for the stage and thin on the axis.
Recorded as observed rather than concluded: no hosting provider, region, residency option or sub processor list was located. What is establishable is jurisdictional rather than technical, that the vendor is a UK entity registered in England and Wales, and that the product defaults to UK time with automatic British Summer Time handling, which indicates where it was built rather than where data sits.
For a vendor selling into GDPR jurisdictions and passing prospect research to a model provider, the absence of any statement about where processing occurs is material. This is a failure to locate, not a finding of absence.
Two claims appear as a footer badge, MFA and encrypted at rest, alongside GDPR-ready. There is no security page behind them, no control set enumerated, no certification of any kind, no trust centre, no penetration test and no vulnerability disclosure route, so a buyer has the assertion and nothing to check it against.
The stage explains most of this, since a company incorporated within the last year has not had time to complete a SOC 2 or ISO audit, and the honest reading is that certification is absent rather than concealed. What matters for a buyer is what is at stake meanwhile: the platform holds a live connection to the operator's primary work mailbox, which is the most sensitive access any tool in this index requests.
The entry price is stated plainly in the vendor's own FAQ at 24 GBP per month, with 100 free credits on signup and no card required, and a dedicated pricing page is published. The piece that earns the grade is the consumption economics, which most credit metered vendors leave invisible: one credit per contact, stated explicitly, with the preview email for the first contact reused at no extra charge, and a running credit ledger shown in the interface before a campaign is generated.
That is the disclosure Autotouch was credited for making and Buzz was marked down for withholding, and it is what lets a buyer calculate cost per prospect rather than cost per seat. Not A because the pricing page itself was not read this pass, so the tier structure above the entry price, any seat minimums and any annual commitment remain unverified.
Recorded as observed rather than concluded: no export path, deletion timeline, post termination data right or retention period was located, and a published data processing addendum exists but was not read. One structural point deserves naming because it is real and unusual.
Because every message is sent from the operator's own mailbox rather than from vendor infrastructure, the entire outbound record, sent items, replies and threads, already lives permanently in a system the buyer owns and would still have if Cadivra disappeared overnight. That is a meaningful portability property even though the vendor never claims it, and it does not extend to the contact lists, research, campaign configuration or generated copy held in the platform.
The most complete published deliverability posture in this index for the email channel, and it comes from the newest and smallest vendor in the session. The architectural decision does most of the work: sending happens from the operator's existing mailbox so the buyer inherits their own established reputation, and there is deliberately no secondary domain to warm, which is a direct rejection of the throwaway domain playbook the category runs on.
On top of that sits a specific, named control set rather than a claim of care: SPF, DKIM and DMARC checked and explained in plain terms, four major blocklists monitored, sends paced under provider limits, a configurable delay between messages and a daily business hours window, optional verification of each contact before a credit is spent so bounces are prevented rather than absorbed, follow ups halted on reply, and a single sender health score from 0 to 100 with one tap remediation for whatever is failing.
The comparison that matters is Apollo, which took the first D on this axis for sequencing from a connected mailbox with none of this. Two honest caveats: the controls are described rather than independently verified, and the sender health score is a proprietary number with no published methodology.
The intended buyer is stated coherently and the commercial shape matches it: B2B sales teams, founders and agencies, at 24 GBP per month with self service signup, free credits and no card, positioned explicitly against Apollo, Lemlist and Instantly rather than against enterprise platforms. What is missing is any evidence that the segment has been reached.
No customer of any size is named, no geography beyond a UK operating default is described, no vertical concentration is visible, and no enterprise apparatus exists, no single sign on, role based access, team administration or procurement surface. The positioning is a plan rather than a demonstrated market position, which is the honest read on a vendor at this stage.
Compared With
Editorial comparisons are published only where the index assesses two vendors as direct competitors for the same buyer. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Pricing
What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.
- ›One credit is one researched, individually written email. That single sentence is the clearest thing any company in this index has said about what you are buying.
- ›There is a free tier with 100 credits to start. Then £24 a month for 300 credits and one seat, £49 for 750 credits and up to three seats, and £124 for 2,500 credits and up to ten seats, all billed yearly.
- ›Because the unit is defined you can work out the real cost per email: about 8p, then 6.5p, then 5p as you move up. Compare that against what a person or an agency charges for the same thing, which is the comparison this product is inviting.
- ›Everything is priced in pounds with no dollar equivalent, so if you are buying from outside the UK check which currency your contract is in and who carries the exchange risk.
- ›One good behavioral term: when someone replies, follow ups stop automatically. In this category the opposite does real damage.
How the price works
What you are charged for, and what makes the bill go up.
Credit metered with seats bundled by tier, priced natively in sterling with no other currency published. The vendor defines the unit explicitly: one credit is one researched, individually written email.
Four levels are published, all quoted as billed annually. A free tier granting 100 credits on signup with 1 seat. An entry tier at £24 per month for 300 credits monthly with 1 seat. A middle tier at £49 per month for 750 credits monthly with up to 3 seats. An upper tier at £124 per month for 2,500 credits monthly with up to 10 seats.
The annual arrangement is described as two months free rather than as a percentage discount, and applies across the ladder.
Because the credit unit is defined, effective unit costs are computable from published figures at approximately 8.0, 6.5 and 5.0 pence per researched email across the three paid tiers.
No overage rate for credits beyond a monthly allowance is published, and no rate is published for seats beyond a tier's allowance.
Published entitlements include reply detection that halts follow ups automatically and routes the reply to the vendor's inbox, domain authentication scanning that surfaces deliverability problems before sending, a weekly summary covering bounce trends and reply rates, and enforceable two step login across every seat on a workspace at the upper tiers.
What the contract says about your data
What the vendor commits to in writing once your data is in the product.
Partially established from the pricing page itself, which is unusual, because two security relevant capabilities are published as tier entitlements rather than as marketing claims. Two step login is stated as requirable across every seat on a workspace at the upper tiers, and domain authentication scanning is described as surfacing deliverability problems before sending rather than after. The second is a sending hygiene feature rather than a data protection one, but publishing both on the pricing page rather than a separate trust surface means a buyer can see which tier carries them before committing.
What was not established: a processing agreement, an enumerated sub processor list, a named certification or attestation, a retention period expressed as a duration, and a residency or hosting statement. Only the pricing page was followed on this vendor.
The custody question is defined by what a research and generation product necessarily holds. Each credit produces an individually researched email, which means the platform gathers material about a named individual at a named company from sources it selects, and retains both the research and the generated message. That is a richer record about a prospect than a contact database entry, because it is assembled and inferential rather than merely stored.
A buyer should establish what sources the research draws on, whether the research and generated copy are retained after sending, and whether either informs the vendor's models beyond the individual account. For a European vendor pricing in sterling those questions have direct regulatory weight.
Getting started
What it costs and what is included before the product is running.
None charged and none located. No setup fee, onboarding charge, migration rate, professional services rate or contract length was found, and a free tier granting 100 credits on signup allows evaluation without a trial clock or a card.
The annual arrangement is stated as a mechanism rather than a percentage: annual billing gives two months free, and every published figure is quoted on that basis. A buyer choosing monthly should expect approximately a sixth more, though the monthly figures themselves were not served.
Seat allowances are bundled into the tiers rather than charged separately, at one seat on the free and entry tiers, up to three on the middle tier and up to ten on the upper tier. No rate is published for seats beyond a tier's allowance, so a team exceeding ten has no published route other than a conversation.
The cost that cannot be modeled is credits beyond an allowance. No overage rate is published and no statement appears describing what happens when a monthly allowance is exhausted, which for a product whose entire meter is credits is the one gap in an otherwise complete disclosure.
Two capabilities that reduce cost elsewhere are included rather than charged: domain authentication scanning, which surfaces deliverability problems before sending, and a weekly summary reporting bounce trends and reply rates. In this category deliverability monitoring is frequently a separate subscription.
What to watch for
Where this pricing can surprise a buyer who has not read it closely.
The cleanest credit definition in this index, published in a single sentence, and the first vendor here to price natively in sterling.
The vendor states that one credit is one researched, individually written email. That is the whole definition, it appears on the page and in the metadata, and it converts every allowance on the ladder directly into output. After forty five records in which vendors published credit allowances without ever saying what a credit buys, this is the sentence the rest of the tranche has been missing, and it is more useful than most because the unit is the deliverable rather than an intermediate step.
The ladder is complete and consistent. A free tier granting 100 credits on signup with one seat. £24 monthly for 300 credits and one seat. £49 monthly for 750 credits and up to three seats. £124 monthly for 2,500 credits and up to ten seats. All figures are stated as billed annually, with the annual arrangement described as two months free, which is a stated mechanism rather than a percentage claim and computes consistently across the ladder.
Because the unit is defined, the ladder can be evaluated on unit economics, which almost nothing else in this index permits. The three paid tiers work out at 8.0, 6.5 and 5.0 pence per researched email respectively, so the volume discount is real, computable and modest, and a buyer can compare that directly against what a person or an agency would charge for the same output. That is the comparison this product invites and the pricing page makes it possible.
Currency is the second finding. Every figure is published in sterling with no dollar equivalent offered, which is the first sterling native vendor recorded in this index. Under the standing rule this record does not convert, and the numeric field is left empty rather than carrying a converted figure that the vendor never published. A buyer outside the United Kingdom should establish which currency their contract is denominated in and who carries the conversion risk.
One further disclosure is worth crediting. Reply detection is published as stopping follow ups automatically when a prospect responds, with the reply landing in the vendor's own inbox. Publishing that sequences halt on reply rather than continuing is a real behavioral commitment in a category where the opposite causes genuine harm.
The numeric field is empty because the vendor prices in sterling and converting would attribute a figure it never published.