Cirrus Insight
Cirrus Insight, a Cirruspath, Inc. company founded in 2011 and now based in Raleigh, North Carolina, has spent over a decade doing one unglamorous thing: capturing every email, calendar event and task from Gmail and Outlook into Salesforce so the CRM reflects what actually happened. Around that spine sit a Salesforce sidebar that surfaces customer and pipeline records inside the inbox, bi directional sync with configurable capture policies, mappings and retention control for administrators, Smart Scheduler for logic based lead routing to the right rep's calendar, personal and team scheduling, Email Blast for one to many templated sends using Salesforce merge fields, and attachment and link tracking.
The company is now repositioning that decade of captured relationship data as the foundation for an agentic layer, arguing that AI is only as good as the history it can learn from: Meeting AI generates pre meeting briefs and research, CRM AI queues opportunity hygiene for one tap Salesforce updates, and Conversation Intelligence captures and organises what was said with live coaching prompts and retrospective coaching for managers.
Sold per seat from 14 to 49 USD per user per month across Salesforce Sync, Pro and Expert tiers plus a custom tier, to over 50,000 customer facing teams including Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor, with concentrations in financial services, higher education, technology and energy.
Capability Axes
The vendor settles this itself, and unusually it does so as a boast rather than a concession: AI is inevitable but it is only as good as the history it can learn from, and for over a decade Cirrus has been capturing the relationship data that fuels it. That is a company arguing that its pre AI decade is the moat. The removal test agrees.
Strip the models out and Salesforce Sync, the sidebar, Email Blast, attachment tracking, Smart Scheduler, calendar scheduling and buyer signals all remain, which is the entire historical product and effectively the whole price ladder, since the tiers are built on sync, sidebar and scheduling rather than on agents. Meeting AI, CRM AI and Conversation Intelligence sit on top of that layer, not underneath it.
Oversight is designed into the agentic layer rather than offered as a setting, and the vendor's own description of CRM AI is the cleanest statement of it in the index: a background assistant that queues up opportunity hygiene for one tap Salesforce updates. The agent prepares, the human confirms, and the confirmation is the mechanism rather than an option an administrator may switch off.
The rest of the layer is assistive by construction: Meeting AI produces briefs a person reads, live coaching prompts a person on a call, proposal and ROI drafting drafts. Critically, nothing in the product contacts a prospect on its own initiative; the only outbound is Email Blast, which a human composes and triggers.
Not A because there is no audit trail of what the model proposed against what the human accepted, no guardrail that withholds a bad suggestion rather than queueing it, and no documented policy governing what the background assistant may touch.
The AI features are named and scoped clearly, Meeting AI, CRM AI and Conversation Intelligence, and the data foundation they run on is described at length, but the models themselves are not. No provider, family or version is named anywhere including on the trust page, nothing states where inference runs relative to the customer selected data centre, and no accuracy or error position is published for meeting summaries, conversation capture or the coaching prompts.
That last gap matters more than usual because Conversation Intelligence transcribes and organises what was said in customer meetings and feeds retrospective coaching of employees, so transcription error has consequences for people as well as for forecasts.
Scale and logo quality are real: over 50,000 customer facing teams, with Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor named on the homepage and Logitech, Kaplan and Ecolab reported elsewhere, plus a customer stories library, Salesforce AppExchange partner status and a decade of trading. What holds this at C is a specific and checkable substitution.
The three headline statistics on the homepage sit exactly where product results normally sit and none of them is about Cirrus: 60 percent more meetings booked weekly when using AI tools, 11.5 hours saved on admin per week when using AI sales tools, and two minutes as the average interval between interruptions. Those are category claims about AI sales software in general, presented in the product's own results slot. The one customer quote on the homepage is qualitative. For a vendor with this customer list, the absence of a single named, quantified, method backed outcome is the gap.
Email Blast is described as sending one to many emails with tracking and compliance, and naming compliance as a shipped property is more than most vendors bother with, but nothing published says what it consists of. No unsubscribe handling, suppression list, CAN-SPAM position or consent framework for the product's outbound was located.
What the trust page does cover is the vendor's own marketing rather than the customer's: opt out honoured with unsubscribe links, a transactional carve out, and a statement that certain clients may opt out of marketing on behalf of their end users. The tracking side raises an unaddressed question of its own, since open and link tracking are pixel based and ePrivacy treats that as terminal equipment access, and nothing on the trust page reaches it.
Top of band, and the substance is the best in the index while the execution is not. The instrument is built around a properly worked controller and processor split, with a customisable viewer that filters the policy by topic, by role and by location across the United States, Canada and the EU, which is a privacy interface no other vendor here offers.
Substantively it publishes: a legitimate interest balancing assessment having been conducted; a named DPO channel; a full CCPA notice with 45 day response and authorised agent verification; a Canadian FIPPA section; a FERPA school official section with AB 1584 compliance for education clients; IP address anonymisation by removing the last octet; an explicit statement that no device fingerprinting is used in logs; Do Not Track actually honoured, logging the action while declining to store user agent or IP, which is the first working DNT implementation graded here after CallSine and Boomerang both disclosed they have none; support tickets assigned anonymous IDs with representatives required to delete PII immediately on resolution; a published sub processor list; and repeated statements that data is not sold.
Three copy paste defects keep it off A and they are not typos. The employment section twice refers to career opportunities at Google and improving Google's recruitment process. Stray references to test takers survive from an assessment vendor's template. And the CCPA verifiable request phone channel reads Toll Free xxxxx, an unfilled placeholder standing in for a statutory contact route, in a policy dated 20 July 2026.
The Privacy Shield section is handled correctly rather than as the 9Lenses failure, since it is prefaced in bold by the CJEU invalidation and names SCCs plus supplemental measures as the operative mechanism, though it never mentions the EU US Data Privacy Framework that replaced it.
Determinate by construction and disclosed with unusual specificity. Cirrus ships no purchased contact database and buys no third party data; everything originates in the customer's own mailboxes, calendars and Salesforce org, and the privacy policy states plainly that end user records obtained from a client are the property of that client, under that client's control, processed only on that client's instructions.
It then enumerates exactly what those records may contain, field by field, down to the authentication material. The vendor also states repeatedly and without qualification that it does not sell data to third parties, and confines secondary use to de identified aggregate business analytics.
Not A because no position is taken on the one genuinely contested thing the product does, which is capturing correspondence with third parties, the prospects and customers on the other side of those emails, into a system of record they never interacted with.
Sanctioned access throughout, and the credential position is disclosed rather than inferred, which is what earns the grade. The company is a Salesforce AppExchange partner with the badge on its own site, connects to Gmail, Office 365, Microsoft Teams, Zoom, HubSpot and Zapier through supported integrations, states adherence to the Google API Services User Data Policy including the Limited Use requirements, and does no scraping, social automation or platform evasion of any kind.
The detail worth naming: the enumerated end user record list shows the modern paths hold revocable tokens, Office 365 OAuth token, Gmail OAuth token and Salesforce OAuth token, while the legacy path holds an Exchange username AND an Exchange password. That is credential custody rather than delegated authorisation, and it is on the wrong side of the line this index draws between OAuth and custody.
It is graded generously because the vendor discloses it in a list rather than hiding it, states all such data is encrypted and decryptable only by authorised representatives, and confirms it does not receive or store passwords for the OAuth based services.
Top of band, and the gap is specific rather than general. Two partial answers exist: adherence to the Google API Services User Data Policy including the Limited Use requirements is stated, which imports Google's prohibition on using Workspace data to train generalised models for that data source, and secondary use is otherwise confined to de identified information maintained, used and disclosed in aggregated form only.
Neither is an explicit statement about model training, which is what CallSine wrote down in plain words and earned a higher grade for. The reason this matters here more than for most vendors is the vendor's own pitch: it markets a decade of captured relationship data across more than 50,000 teams as the thing that makes its AI work, which invites the reading that the corpus has value in aggregate, and nothing published says whether models are trained per tenant or across the base. Recorded as a question the marketing raises and the documentation does not answer, not as a finding that data is pooled.
A clean record on impersonation and the worst on surveillance, which is an unusual combination worth stating. Nothing in this product pretends to be a person: no synthetic voice, no agent under a human first name, no manufactured research, no local presence dialling, and the only outbound is composed and sent by a real rep from their own mailbox. Against that, the telemetry aimed at the recipient is the most detailed graded so far.
Buyer Signals tracks and surfaces every touchpoint including opens, link clicks and replies; attachment tracking is marketed as knowing what happens to your attachments after you hit send, which means the sender learns how a document was read after it left; and Conversation Intelligence captures what is said in meetings.
None of it is disclosed to the person on the other end, and nothing published addresses recording notification or consent, which is the position Airspeed took credit for by having its recorder announce itself as a named participant.
Narrow by design and deep where it counts. Salesforce AppExchange partner status is displayed and verifiable, and the integration is object level and bi directional rather than a data push, covering emails, calendar events, tasks, contacts, leads and opportunities with administrator configurable capture policies and field mappings, which is the standard this index looks for.
Around it: Gmail, Outlook, Microsoft Teams, Zoom, HubSpot, Zapier and a Chrome extension, plus a self service hub, two maintained knowledge bases including one for the legacy 2019 interface, and a published sub processor list. Not A because the surface is deliberately confined to one CRM and two mail providers, and because no public API or developer documentation was located, so there is no programmatic extension path for a buyer who wants one.
The first customer selectable data residency in this index, and it is stated plainly: data is stored in data centres requested or chosen by the partnered client, and clients can choose to store data in a centre geographically relevant to their location or in another. Every other A on this axis has been an absolute posture with no choice in it, Ringover committing that nothing leaves France and Bindago putting everything on the buyer's own disk; this is the buyer deciding.
Around it the architecture is named rather than gestured at: built on Microsoft Azure, with controller side data residing exclusively in North America unless specifically noted, a published sub processor list as a downloadable document, and a stated 90 day post termination retention window before production data is deleted. The one gap is that the available regions are not enumerated, so a buyer knows choice exists without knowing the menu.
Top of band, and it does something no other vendor in this index has done: it names both auditors. SOC 2 Type 1 and Type 2 compliance is stated with the auditing firm named, Insight Assurance, and third party penetration testing is attributed to Bishop Fox by name. Apollo named its auditor and took a lower grade only because it routed the report through sales; naming the pen test provider as well is rarer still.
The control set is specific rather than reassuring: 256 bit encryption in transit, transparent data encryption at rest, automated data masking for personally identifiable information, OAuth 2.0 and TLS, least privilege employee access, regular privacy and security training, regular manual and automated audits, data centres themselves ISO 27001 certified and SOC 2 attested, PCI compliant payment processors, and an incident response programme with a stated 72 hour breach notification to clients.
Not A on the bar ActiveCampaign set: there is no self service or even described route to obtain the SOC 2 report, no audit period or date is given, and the Information Security Policies referenced in the text are not published or linked.
Three tiers published with real per seat numbers, Salesforce Sync at 14, Pro at 21 and Expert at 49 USD per user per month, plus priced add ons at Sync+ 4 and Expert+ 9, a 14 day free trial, a self service hub where a buyer can build their own quote, and a custom tier for larger teams. Publishing the add on rate card alongside the tiers is the piece most vendors omit. Two things hold it off the Apollo benchmark.
Implementation is unpriced and third parties report it at 500 to 1,500 USD for smaller buyers and above 5,000 for enterprise. More sharply, the renewal mechanics that actually govern the bill are undisclosed and documented elsewhere: procurement records show a buyer reducing roughly 80 Expert licences being quoted a 12.5 percent uplift on cost per user, with the vendor's representative stating the route to removing the uplift was a two or three year agreement, and another buyer able to hold a flat renewal only by forgoing further discount.
Third party transaction data puts the average annual contract near 15,000 USD against a 49 USD list. A published seat price that says nothing about what happens when you shrink is a partial disclosure.
The first A on this axis in the index, and it is earned contractually rather than architecturally. The commitment is specific and dated: client data is stored and maintained for up to 90 days after termination of the agreement unless the client requests a return of the data, and at the conclusion of that 90 day period all client production data is deleted, with only financial and operational records retained as law requires.
That is a defined window, a defined deletion event and a defined return mechanism, which together are more than any other vendor here publishes; Alta previously held the best position on a self service purge with an emailed confirmation. Retention during the term is also client directed rather than vendor set, with administrators controlling capture policy and retention, and a right to be forgotten and a right to receive data in a structured machine readable format are both published.
The structural point compounds it: because the product's entire output is written continuously into the customer's own Salesforce org, the operative record already sits in a system the buyer owns. Two gaps stop it being unambiguous rather than stopping the grade: no deletion confirmation artefact is offered, and the machine readable portability right is stated under the vendor's controller role, so its application to the processor held client corpus is inferred rather than stated.
Email Blast sends one to many templated messages with Salesforce merge fields from the rep's own connected Gmail or Outlook mailbox, and nothing published addresses warmup, domain authentication, bounce or complaint handling, sending reputation, volume governance or ramp guidance.
What lowers the practical risk relative to the cold outbound tools graded alongside it is the shape of the use case: this is an account executive mailing a bounded list of known contacts from a corporate mailbox, governed by the provider's own send limits, not a sequencer running strangers at scale from rotated domains.
That is a favourable circumstance rather than a discipline, and the vendor does describe the feature as including compliance without saying what that means, so there is something here that could not be verified.
Segmented deliberately in two dimensions and evidenced by the customer list. By role: CRM administrators, account executives, sales operations, sales managers and marketing, each with its own material. By industry: financial services, higher education, technology, and energy and utilities, with the education commitment backed by actual FERPA school official handling and AB 1584 compliance in the privacy policy rather than by a landing page.
Over 50,000 customer facing teams, enterprise names including Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor, and legal coverage published separately for the United States, Canada and the EU. Not A because the addressable market is structurally bounded by a dependency the vendor cannot escape, since the product exists to extend Salesforce, and because no geographic footprint or international presence is claimed beyond the three privacy jurisdictions.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.