Cirrus Insight
Cirrus Insight, a Cirruspath, Inc. company founded in 2011 and now based in Raleigh, North Carolina, has spent over a decade doing one unglamorous thing: capturing every email, calendar event and task from Gmail and Outlook into Salesforce so the CRM reflects what actually happened. Around that spine sit a Salesforce sidebar that surfaces customer and pipeline records inside the inbox, bi directional sync with configurable capture policies, mappings and retention control for administrators, Smart Scheduler for logic based lead routing to the right rep's calendar, personal and team scheduling, Email Blast for one to many templated sends using Salesforce merge fields, and attachment and link tracking.
The company is now repositioning that decade of captured relationship data as the foundation for an agentic layer, arguing that AI is only as good as the history it can learn from: Meeting AI generates pre meeting briefs and research, CRM AI queues opportunity hygiene for one tap Salesforce updates, and Conversation Intelligence captures and organizes what was said with live coaching prompts and retrospective coaching for managers.
Sold per seat from 14 to 49 USD per user per month across Salesforce Sync, Pro and Expert tiers plus a custom tier, to over 50,000 customer facing teams including Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor, with concentrations in financial services, higher education, technology and energy.
Capability Axes
Capability grades
17 of 17 axes rated · 10 graded A or B
The vendor settles this itself, and unusually it does so as a boast rather than a concession: AI is inevitable but it is only as good as the history it can learn from, and for over a decade Cirrus has been capturing the relationship data that fuels it. That is a company arguing that its pre AI decade is the moat. The removal test agrees.
Strip the models out and Salesforce Sync, the sidebar, Email Blast, attachment tracking, Smart Scheduler, calendar scheduling and buyer signals all remain, which is the entire historical product and effectively the whole price ladder, since the tiers are built on sync, sidebar and scheduling rather than on agents. Meeting AI, CRM AI and Conversation Intelligence sit on top of that layer, not underneath it.
Oversight is designed into the agentic layer rather than offered as a setting, and the vendor's own description of CRM AI is the cleanest statement of it in the index: a background assistant that queues up opportunity hygiene for one tap Salesforce updates. The agent prepares, the human confirms, and the confirmation is the mechanism rather than an option an administrator may switch off.
The rest of the layer is assistive by construction: Meeting AI produces briefs a person reads, live coaching prompts a person on a call, proposal and ROI drafting drafts. Critically, nothing in the product contacts a prospect on its own initiative; the only outbound is Email Blast, which a human composes and triggers.
Not A because there is no audit trail of what the model proposed against what the human accepted, no guardrail that withholds a bad suggestion rather than queueing it, and no documented policy governing what the background assistant may touch.
The AI features are named and scoped clearly, Meeting AI, CRM AI and Conversation Intelligence, and the data foundation they run on is described at length, but the models themselves are not. No provider, family or version is named anywhere including on the trust page, nothing states where inference runs relative to the customer selected data centre, and no accuracy or error position is published for meeting summaries, conversation capture or the coaching prompts.
That last gap matters more than usual because Conversation Intelligence transcribes and organises what was said in customer meetings and feeds retrospective coaching of employees, so transcription error has consequences for people as well as for forecasts.
Scale and logo quality are real: over 50,000 customer facing teams, with Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor named on the homepage and Logitech, Kaplan and Ecolab reported elsewhere, plus a customer stories library, Salesforce AppExchange partner status and a decade of trading. What holds this at C is a specific and checkable substitution.
The three headline statistics on the homepage sit exactly where product results normally sit and none of them is about Cirrus: 60 percent more meetings booked weekly when using AI tools, 11.5 hours saved on admin per week when using AI sales tools, and two minutes as the average interval between interruptions. Those are category claims about AI sales software in general, presented in the product's own results slot. The one customer quote on the homepage is qualitative. For a vendor with this customer list, the absence of a single named, quantified, method backed outcome is the gap.
Email Blast is described as sending one to many emails with tracking and compliance, and naming compliance as a shipped property is more than most vendors bother with, but nothing published says what it consists of. No unsubscribe handling, suppression list, CAN-SPAM position or consent framework for the product's outbound was located.
What the trust page does cover is the vendor's own marketing rather than the customer's: opt out honoured with unsubscribe links, a transactional carve out, and a statement that certain clients may opt out of marketing on behalf of their end users. The tracking side raises an unaddressed question of its own, since open and link tracking are pixel based and ePrivacy treats that as terminal equipment access, and nothing on the trust page reaches it.
Top of band, and the substance is the best in the index while the execution is not. The instrument is built around a properly worked controller and processor split, with a customisable viewer that filters the policy by topic, by role and by location across the United States, Canada and the EU, which is a privacy interface no other vendor here offers.
Substantively it publishes: a legitimate interest balancing assessment having been conducted; a named DPO channel; a full CCPA notice with 45 day response and authorised agent verification; a Canadian FIPPA section; a FERPA school official section with AB 1584 compliance for education clients; IP address anonymisation by removing the last octet; an explicit statement that no device fingerprinting is used in logs; Do Not Track actually honoured, logging the action while declining to store user agent or IP, which is the first working DNT implementation graded here after CallSine and Boomerang both disclosed they have none; support tickets assigned anonymous IDs with representatives required to delete PII immediately on resolution; a published sub processor list; and repeated statements that data is not sold.
Three copy paste defects keep it off A and they are not typos. The employment section twice refers to career opportunities at Google and improving Google's recruitment process. Stray references to test takers survive from an assessment vendor's template. And the CCPA verifiable request phone channel reads Toll Free xxxxx, an unfilled placeholder standing in for a statutory contact route, in a policy dated 20 July 2026.
The Privacy Shield section is handled correctly rather than as the 9Lenses failure, since it is prefaced in bold by the CJEU invalidation and names SCCs plus supplemental measures as the operative mechanism, though it never mentions the EU US Data Privacy Framework that replaced it.
Determinate by construction and disclosed with unusual specificity. Cirrus ships no purchased contact database and buys no third party data; everything originates in the customer's own mailboxes, calendars and Salesforce org, and the privacy policy states plainly that end user records obtained from a client are the property of that client, under that client's control, processed only on that client's instructions.
It then enumerates exactly what those records may contain, field by field, down to the authentication material. The vendor also states repeatedly and without qualification that it does not sell data to third parties, and confines secondary use to de identified aggregate business analytics.
Not A because no position is taken on the one genuinely contested thing the product does, which is capturing correspondence with third parties, the prospects and customers on the other side of those emails, into a system of record they never interacted with.
Sanctioned access throughout, and the credential position is disclosed rather than inferred, which is what earns the grade. The company is a Salesforce AppExchange partner with the badge on its own site, connects to Gmail, Office 365, Microsoft Teams, Zoom, HubSpot and Zapier through supported integrations, states adherence to the Google API Services User Data Policy including the Limited Use requirements, and does no scraping, social automation or platform evasion of any kind.
The detail worth naming: the enumerated end user record list shows the modern paths hold revocable tokens, Office 365 OAuth token, Gmail OAuth token and Salesforce OAuth token, while the legacy path holds an Exchange username AND an Exchange password. That is credential custody rather than delegated authorisation, and it is on the wrong side of the line this index draws between OAuth and custody.
It is graded generously because the vendor discloses it in a list rather than hiding it, states all such data is encrypted and decryptable only by authorised representatives, and confirms it does not receive or store passwords for the OAuth based services.
Top of band, and the gap is specific rather than general. Two partial answers exist: adherence to the Google API Services User Data Policy including the Limited Use requirements is stated, which imports Google's prohibition on using Workspace data to train generalised models for that data source, and secondary use is otherwise confined to de identified information maintained, used and disclosed in aggregated form only.
Neither is an explicit statement about model training, which is what CallSine wrote down in plain words and earned a higher grade for. The reason this matters here more than for most vendors is the vendor's own pitch: it markets a decade of captured relationship data across more than 50,000 teams as the thing that makes its AI work, which invites the reading that the corpus has value in aggregate, and nothing published says whether models are trained per tenant or across the base. Recorded as a question the marketing raises and the documentation does not answer, not as a finding that data is pooled.
A clean record on impersonation and the worst on surveillance, which is an unusual combination worth stating. Nothing in this product pretends to be a person: no synthetic voice, no agent under a human first name, no manufactured research, no local presence dialling, and the only outbound is composed and sent by a real rep from their own mailbox. Against that, the telemetry aimed at the recipient is the most detailed graded so far.
Buyer Signals tracks and surfaces every touchpoint including opens, link clicks and replies; attachment tracking is marketed as knowing what happens to your attachments after you hit send, which means the sender learns how a document was read after it left; and Conversation Intelligence captures what is said in meetings.
None of it is disclosed to the person on the other end, and nothing published addresses recording notification or consent, which is the position Airspeed took credit for by having its recorder announce itself as a named participant.
Narrow by design and deep where it counts. Salesforce AppExchange partner status is displayed and verifiable, and the integration is object level and bi directional rather than a data push, covering emails, calendar events, tasks, contacts, leads and opportunities with administrator configurable capture policies and field mappings, which is the standard this index looks for.
Around it: Gmail, Outlook, Microsoft Teams, Zoom, HubSpot, Zapier and a Chrome extension, plus a self service hub, two maintained knowledge bases including one for the legacy 2019 interface, and a published sub processor list. Not A because the surface is deliberately confined to one CRM and two mail providers, and because no public API or developer documentation was located, so there is no programmatic extension path for a buyer who wants one.
The first customer selectable data residency in this index, and it is stated plainly: data is stored in data centres requested or chosen by the partnered client, and clients can choose to store data in a centre geographically relevant to their location or in another. Every other A on this axis has been an absolute posture with no choice in it, Ringover committing that nothing leaves France and Bindago putting everything on the buyer's own disk; this is the buyer deciding.
Around it the architecture is named rather than gestured at: built on Microsoft Azure, with controller side data residing exclusively in North America unless specifically noted, a published sub processor list as a downloadable document, and a stated 90 day post termination retention window before production data is deleted. The one gap is that the available regions are not enumerated, so a buyer knows choice exists without knowing the menu.
Top of band, and it does something no other vendor in this index has done: it names both auditors. SOC 2 Type 1 and Type 2 compliance is stated with the auditing firm named, Insight Assurance, and third party penetration testing is attributed to Bishop Fox by name. Apollo named its auditor and took a lower grade only because it routed the report through sales; naming the pen test provider as well is rarer still.
The control set is specific rather than reassuring: 256 bit encryption in transit, transparent data encryption at rest, automated data masking for personally identifiable information, OAuth 2.0 and TLS, least privilege employee access, regular privacy and security training, regular manual and automated audits, data centres themselves ISO 27001 certified and SOC 2 attested, PCI compliant payment processors, and an incident response programme with a stated 72 hour breach notification to clients.
Not A on the bar ActiveCampaign set: there is no self service or even described route to obtain the SOC 2 report, no audit period or date is given, and the Information Security Policies referenced in the text are not published or linked.
Three tiers published with real per seat numbers, Salesforce Sync at 14, Pro at 21 and Expert at 49 USD per user per month, plus priced add ons at Sync+ 4 and Expert+ 9, a 14 day free trial, a self service hub where a buyer can build their own quote, and a custom tier for larger teams. Publishing the add on rate card alongside the tiers is the piece most vendors omit. Two things hold it off the Apollo benchmark.
Implementation is unpriced and third parties report it at 500 to 1,500 USD for smaller buyers and above 5,000 for enterprise. More sharply, the renewal mechanics that actually govern the bill are undisclosed and documented elsewhere: procurement records show a buyer reducing roughly 80 Expert licences being quoted a 12.5 percent uplift on cost per user, with the vendor's representative stating the route to removing the uplift was a two or three year agreement, and another buyer able to hold a flat renewal only by forgoing further discount.
Third party transaction data puts the average annual contract near 15,000 USD against a 49 USD list. A published seat price that says nothing about what happens when you shrink is a partial disclosure.
The first A on this axis in the index, and it is earned contractually rather than architecturally. The commitment is specific and dated: client data is stored and maintained for up to 90 days after termination of the agreement unless the client requests a return of the data, and at the conclusion of that 90 day period all client production data is deleted, with only financial and operational records retained as law requires.
That is a defined window, a defined deletion event and a defined return mechanism, which together are more than any other vendor here publishes; Alta previously held the best position on a self service purge with an emailed confirmation. Retention during the term is also client directed rather than vendor set, with administrators controlling capture policy and retention, and a right to be forgotten and a right to receive data in a structured machine readable format are both published.
The structural point compounds it: because the product's entire output is written continuously into the customer's own Salesforce org, the operative record already sits in a system the buyer owns. Two gaps stop it being unambiguous rather than stopping the grade: no deletion confirmation artefact is offered, and the machine readable portability right is stated under the vendor's controller role, so its application to the processor held client corpus is inferred rather than stated.
Email Blast sends one to many templated messages with Salesforce merge fields from the rep's own connected Gmail or Outlook mailbox, and nothing published addresses warmup, domain authentication, bounce or complaint handling, sending reputation, volume governance or ramp guidance.
What lowers the practical risk relative to the cold outbound tools graded alongside it is the shape of the use case: this is an account executive mailing a bounded list of known contacts from a corporate mailbox, governed by the provider's own send limits, not a sequencer running strangers at scale from rotated domains.
That is a favourable circumstance rather than a discipline, and the vendor does describe the feature as including compliance without saying what that means, so there is something here that could not be verified.
Segmented deliberately in two dimensions and evidenced by the customer list. By role: CRM administrators, account executives, sales operations, sales managers and marketing, each with its own material. By industry: financial services, higher education, technology, and energy and utilities, with the education commitment backed by actual FERPA school official handling and AB 1584 compliance in the privacy policy rather than by a landing page.
Over 50,000 customer facing teams, enterprise names including Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor, and legal coverage published separately for the United States, Canada and the EU. Not A because the addressable market is structurally bounded by a dependency the vendor cannot escape, since the product exists to extend Salesforce, and because no geographic footprint or international presence is claimed beyond the three privacy jurisdictions.
Pricing
What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.
- ›No price is published. There is a quote builder and a trial instead.
- ›The page's description makes a strong claim: full platform access, no tiers and no seat limits, scaling from ten users to over ten thousand. That would be genuinely unusual in this category.
- ›But the page's own help section asks whether you can buy different numbers of seats for different features. That question only makes sense if seats are counted per feature, which is hard to square with no seat limits.
- ›Both of those are the company's own words, so settle which one governs before you ask for a quote. One number covering everything and a matrix of seats per feature are completely different bills.
- ›Also remember this tool sits inside your email and your record system rather than replacing either, so you still pay for both underneath it.
How the price works
What you are charged for, and what makes the bill go up.
Not published as a rate. The pricing page serves no figure in any currency, no tier name, no band, no starting point, no seat minimum and no contract length. A quote builder is published in place of a rate card, alongside a trial and support material.
The commercial position is stated in the page description tag rather than the body: full platform access with no tiers and no seat limits, scaling from ten to more than ten thousand users.
That position is qualified by the vendor's own support content, which raises the question of whether a buyer may purchase different seat counts for different features. Feature by feature seat allocation is difficult to reconcile with an absence of seat limits, and nothing published resolves which arrangement applies.
Seats are the evident unit. No rate per seat, no band, no minimum and no volume breakpoints are published.
The product operates against a specific record system and mailbox platform, so the buyer must separately hold those licenses.
No credible third party estimate was located, so none is recorded.
What the contract says about your data
What the vendor commits to in writing once your data is in the product.
Not established from the pricing page, which served no legal or security links in the retrieved markup. No processing agreement, sub processor listing, certification claim, retention period or residency statement was located, and only the pricing page was followed on this vendor.
The custody question is defined by the platform's position rather than its data volume. This product sits inside the mailbox and synchronizes with the record system, which means it reads the customer's email and calendar and writes activity back. That is a broader permission than most tools in this index hold: a sequencer sends from a mailbox, whereas this reads what is already in one, including correspondence with people who are not prospects at all.
Two questions follow and neither is addressed. What the platform retains from mailbox and calendar content beyond what it synchronizes to the record system, and whether the buyer can constrain which mailbox folders or correspondents are in scope. For a tool whose value is automatic activity capture, the default is likely to be broad, and the buyer's own internal communications are the material most likely to be captured incidentally.
A buyer should also establish the residency position for mailbox content specifically, since email is frequently subject to retention obligations that the record system's own terms do not cover.
Getting started
What it costs and what is included before the product is running.
Not published. No setup fee, onboarding charge, migration rate, professional services rate, seat minimum or contract length was located.
A trial is offered alongside the quote builder, with no stated length, feature scope or card requirement.
The cost structure the buyer can partially infer is the seat model, and it is where the ambiguity sits. The vendor's metadata states there are no seat limits and that a customer may scale from ten to more than ten thousand users. Its own support content asks whether a buyer may purchase different seat counts for different features, which implies feature by feature seat allocation rather than a single organization wide number.
Those two positions produce very different bills. A single unlimited seat arrangement means the platform is bought once for the company. A per feature seat matrix means the buyer is counting users separately for mailbox synchronization, meeting scheduling, templating and any other module, and the total is a sum rather than a figure.
That is the question to settle before requesting a quote, because a buyer who assumes the first and receives the second will find the quote structured in a way they did not anticipate.
One cost sits outside this vendor entirely and should be modeled: the product operates against a specific record system and mailbox platform, so the buyer must already hold licenses for both, and this product's value is contingent on those subscriptions rather than replacing them.
What to watch for
Where this pricing can surprise a buyer who has not read it closely.
A vendor that removes tiers and seat limits as its stated proposition, then publishes no figure at all.
The page description tag states the position plainly: full platform access, no tiers and no seat limits, scaling from ten to more than ten thousand users. That is a coherent and genuinely differentiated commercial stance in a category built on feature gating, and it is the sort of claim a buyer would want to act on.
The page then serves no price. What it offers instead is a quote builder alongside a trial, and it publishes one question in its own frequently asked questions that quietly contradicts the headline: whether a buyer may purchase a different number of seats for different features. That question only exists if features are separable and separately counted, which is difficult to reconcile with no tiers and no seat limits.
So the disclosure has a tension in it. The metadata promises the absence of tiers and seat limits, and the page's own support content implies that seats are counted per feature. Both are the vendor's material. A buyer should establish which governs, because the difference between one number covering everything and a matrix of feature by seat counts is the entire commercial model.
That tension is the finding, and it is a variant of a pattern this index has now recorded repeatedly: the metadata carries the vendor's cleanest commercial statement while the page carries the complexity. In Aimdoc and Bigin the metadata carried the price the body lacked. Here it carries a simplicity claim the body's own questions undercut.
The metering basis is therefore only partially established. Seats are clearly the unit, the vendor claims no limits on them, and its own content suggests they may be counted separately per feature. No rate, band, minimum or contract length is published anywhere.
A quote builder is published rather than a contact form, which is a modest improvement on the pure quote only vendors in this index: a buyer can at least assemble their own configuration before speaking to anyone, even though the resulting figure is not shown on the page.
No dollar figure is recorded in the numeric field. Nothing was served and no third party estimate with sufficient corroboration was located.