Revenue Intelligence & Forecasting
C

Cirrus Insight

Cirrus Insight, a Cirruspath, Inc. company founded in 2011 and now based in Raleigh, North Carolina, has spent over a decade doing one unglamorous thing: capturing every email, calendar event and task from Gmail and Outlook into Salesforce so the CRM reflects what actually happened. Around that spine sit a Salesforce sidebar that surfaces customer and pipeline records inside the inbox, bi directional sync with configurable capture policies, mappings and retention control for administrators, Smart Scheduler for logic based lead routing to the right rep's calendar, personal and team scheduling, Email Blast for one to many templated sends using Salesforce merge fields, and attachment and link tracking.

The company is now repositioning that decade of captured relationship data as the foundation for an agentic layer, arguing that AI is only as good as the history it can learn from: Meeting AI generates pre meeting briefs and research, CRM AI queues opportunity hygiene for one tap Salesforce updates, and Conversation Intelligence captures and organises what was said with live coaching prompts and retrospective coaching for managers.

Sold per seat from 14 to 49 USD per user per month across Salesforce Sync, Pro and Expert tiers plus a custom tier, to over 50,000 customer facing teams including Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor, with concentrations in financial services, higher education, technology and energy.

Founded
2011
Headquarters
Raleigh, NC, US
Categories
revenue-intelligence, sales-engagement, conversation-intelligence
Assessment

Capability Axes

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

The vendor settles this itself, and unusually it does so as a boast rather than a concession: AI is inevitable but it is only as good as the history it can learn from, and for over a decade Cirrus has been capturing the relationship data that fuels it. That is a company arguing that its pre AI decade is the moat. The removal test agrees.

Strip the models out and Salesforce Sync, the sidebar, Email Blast, attachment tracking, Smart Scheduler, calendar scheduling and buyer signals all remain, which is the entire historical product and effectively the whole price ladder, since the tiers are built on sync, sidebar and scheduling rather than on agents. Meeting AI, CRM AI and Conversation Intelligence sit on top of that layer, not underneath it.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
BB on Autonomy and Oversight ModelThe human in the loop posture is described substantively (draft versus auto send, approval flows) but the failure containment story is incomplete.
Vendor Published

Oversight is designed into the agentic layer rather than offered as a setting, and the vendor's own description of CRM AI is the cleanest statement of it in the index: a background assistant that queues up opportunity hygiene for one tap Salesforce updates. The agent prepares, the human confirms, and the confirmation is the mechanism rather than an option an administrator may switch off.

The rest of the layer is assistive by construction: Meeting AI produces briefs a person reads, live coaching prompts a person on a call, proposal and ROI drafting drafts. Critically, nothing in the product contacts a prospect on its own initiative; the only outbound is Email Blast, which a human composes and triggers.

Not A because there is no audit trail of what the model proposed against what the human accepted, no guardrail that withholds a bad suggestion rather than queueing it, and no documented policy governing what the background assistant may touch.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
CC on AI Disclosure and Model TransparencyThe product is described as AI powered with the stack, the disclosure behavior, and the scoring logic all unstated.
Vendor Published

The AI features are named and scoped clearly, Meeting AI, CRM AI and Conversation Intelligence, and the data foundation they run on is described at length, but the models themselves are not. No provider, family or version is named anywhere including on the trust page, nothing states where inference runs relative to the customer selected data centre, and no accuracy or error position is published for meeting summaries, conversation capture or the coaching prompts.

That last gap matters more than usual because Conversation Intelligence transcribes and organises what was said in customer meetings and feeds retrospective coaching of employees, so transcription error has consequences for people as well as for forecasts.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
CC on Operational and Outcome EvidenceOutcome claims are headline percentages with no stated basis, or customer logos standing in for results.
Vendor Published

Scale and logo quality are real: over 50,000 customer facing teams, with Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor named on the homepage and Logitech, Kaplan and Ecolab reported elsewhere, plus a customer stories library, Salesforce AppExchange partner status and a decade of trading. What holds this at C is a specific and checkable substitution.

The three headline statistics on the homepage sit exactly where product results normally sit and none of them is about Cirrus: 60 percent more meetings booked weekly when using AI tools, 11.5 hours saved on admin per week when using AI sales tools, and two minutes as the average interval between interruptions. Those are category claims about AI sales software in general, presented in the product's own results slot. The one customer quote on the homepage is qualitative. For a vendor with this customer list, the absence of a single named, quantified, method backed outcome is the gap.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

Email Blast is described as sending one to many emails with tracking and compliance, and naming compliance as a shipped property is more than most vendors bother with, but nothing published says what it consists of. No unsubscribe handling, suppression list, CAN-SPAM position or consent framework for the product's outbound was located.

What the trust page does cover is the vendor's own marketing rather than the customer's: opt out honoured with unsubscribe links, a transactional carve out, and a statement that certain clients may opt out of marketing on behalf of their end users. The tracking side raises an unaddressed question of its own, since open and link tracking are pixel based and ePrivacy treats that as terminal equipment access, and nothing on the trust page reaches it.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
BB on Data Privacy PostureA real privacy program is visible (DPA available, policy substantive) with a gap on the hard question, commonly lawful basis for enriched or tracked individuals.
Vendor Published

Top of band, and the substance is the best in the index while the execution is not. The instrument is built around a properly worked controller and processor split, with a customisable viewer that filters the policy by topic, by role and by location across the United States, Canada and the EU, which is a privacy interface no other vendor here offers.

Substantively it publishes: a legitimate interest balancing assessment having been conducted; a named DPO channel; a full CCPA notice with 45 day response and authorised agent verification; a Canadian FIPPA section; a FERPA school official section with AB 1584 compliance for education clients; IP address anonymisation by removing the last octet; an explicit statement that no device fingerprinting is used in logs; Do Not Track actually honoured, logging the action while declining to store user agent or IP, which is the first working DNT implementation graded here after CallSine and Boomerang both disclosed they have none; support tickets assigned anonymous IDs with representatives required to delete PII immediately on resolution; a published sub processor list; and repeated statements that data is not sold.

Three copy paste defects keep it off A and they are not typos. The employment section twice refers to career opportunities at Google and improving Google's recruitment process. Stray references to test takers survive from an assessment vendor's template. And the CCPA verifiable request phone channel reads Toll Free xxxxx, an unfilled placeholder standing in for a statutory contact route, in a policy dated 20 July 2026.

The Privacy Shield section is handled correctly rather than as the 9Lenses failure, since it is prefaced in bold by the CJEU invalidation and names SCCs plus supplemental measures as the operative mechanism, though it never mentions the EU US Data Privacy Framework that replaced it.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
BB on Data Licensing and ProvenanceProvenance is substantively described but incompletely: sourcing classes named without the legal footing, or indemnification unstated.
Vendor Published

Determinate by construction and disclosed with unusual specificity. Cirrus ships no purchased contact database and buys no third party data; everything originates in the customer's own mailboxes, calendars and Salesforce org, and the privacy policy states plainly that end user records obtained from a client are the property of that client, under that client's control, processed only on that client's instructions.

It then enumerates exactly what those records may contain, field by field, down to the authentication material. The vendor also states repeatedly and without qualification that it does not sell data to third parties, and confines secondary use to de identified aggregate business analytics.

Not A because no position is taken on the one genuinely contested thing the product does, which is capturing correspondence with third parties, the prospects and customers on the other side of those emails, into a system of record they never interacted with.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Vendor Published

Sanctioned access throughout, and the credential position is disclosed rather than inferred, which is what earns the grade. The company is a Salesforce AppExchange partner with the badge on its own site, connects to Gmail, Office 365, Microsoft Teams, Zoom, HubSpot and Zapier through supported integrations, states adherence to the Google API Services User Data Policy including the Limited Use requirements, and does no scraping, social automation or platform evasion of any kind.

The detail worth naming: the enumerated end user record list shows the modern paths hold revocable tokens, Office 365 OAuth token, Gmail OAuth token and Salesforce OAuth token, while the legacy path holds an Exchange username AND an Exchange password. That is credential custody rather than delegated authorisation, and it is on the wrong side of the line this index draws between OAuth and custody.

It is graded generously because the vendor discloses it in a list rather than hiding it, states all such data is encrypted and decryptable only by authorised representatives, and confirms it does not receive or store passwords for the OAuth based services.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
CC on AI Safety and Data StewardshipSecurity language exists but the training question, the one this axis turns on, is unanswered: a buyer cannot tell whether their pipeline data improves a competitor’s instance.
Vendor Published

Top of band, and the gap is specific rather than general. Two partial answers exist: adherence to the Google API Services User Data Policy including the Limited Use requirements is stated, which imports Google's prohibition on using Workspace data to train generalised models for that data source, and secondary use is otherwise confined to de identified information maintained, used and disclosed in aggregated form only.

Neither is an explicit statement about model training, which is what CallSine wrote down in plain words and earned a higher grade for. The reason this matters here more than for most vendors is the vendor's own pitch: it markets a decade of captured relationship data across more than 50,000 teams as the thing that makes its AI work, which invites the reading that the corpus has value in aggregate, and nothing published says whether models are trained per tenant or across the base. Recorded as a question the marketing raises and the documentation does not answer, not as a finding that data is pooled.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
CC on Recipient Disclosure and AuthenticityNothing published on whether recipients are told they are dealing with software. For a product whose AI talks to prospects, silence here is now a regulatory posture, not a style choice.
Vendor Published

A clean record on impersonation and the worst on surveillance, which is an unusual combination worth stating. Nothing in this product pretends to be a person: no synthetic voice, no agent under a human first name, no manufactured research, no local presence dialling, and the only outbound is composed and sent by a real rep from their own mailbox. Against that, the telemetry aimed at the recipient is the most detailed graded so far.

Buyer Signals tracks and surfaces every touchpoint including opens, link clicks and replies; attachment tracking is marketed as knowing what happens to your attachments after you hit send, which means the sender learns how a document was read after it left; and Conversation Intelligence captures what is said in meetings.

None of it is disclosed to the person on the other end, and nothing published addresses recording notification or consent, which is the position Airspeed took credit for by having its recorder announce itself as a named participant.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
BB on Ecosystem and Integration DepthSolid primary CRM integration documented, with depth unstated at the edges (sync direction, custom objects, failure behavior).
Vendor Published

Narrow by design and deep where it counts. Salesforce AppExchange partner status is displayed and verifiable, and the integration is object level and bi directional rather than a data push, covering emails, calendar events, tasks, contacts, leads and opportunities with administrator configurable capture policies and field mappings, which is the standard this index looks for.

Around it: Gmail, Outlook, Microsoft Teams, Zoom, HubSpot, Zapier and a Chrome extension, plus a self service hub, two maintained knowledge bases including one for the legacy 2019 interface, and a published sub processor list. Not A because the surface is deliberately confined to one CRM and two mail providers, and because no public API or developer documentation was located, so there is no programmatic extension path for a buyer who wants one.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
AA on Deployment Model and Data ResidencyHosting, regions, and residency options documented: where data lives, what EU customers can choose, and what is single tenant versus shared.
Vendor Published

The first customer selectable data residency in this index, and it is stated plainly: data is stored in data centres requested or chosen by the partnered client, and clients can choose to store data in a centre geographically relevant to their location or in another. Every other A on this axis has been an absolute posture with no choice in it, Ringover committing that nothing leaves France and Bindago putting everything on the buyer's own disk; this is the buyer deciding.

Around it the architecture is named rather than gestured at: built on Microsoft Azure, with controller side data residing exclusively in North America unless specifically noted, a published sub processor list as a downloadable document, and a stated 90 day post termination retention window before production data is deleted. The one gap is that the available regions are not enumerated, so a buyer knows choice exists without knowing the menu.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
BB on Security Certifications and Trust CenterCertifications named and plausible with a gap: no trust center, stale dates, or asserted without enumeration.
Vendor Published

Top of band, and it does something no other vendor in this index has done: it names both auditors. SOC 2 Type 1 and Type 2 compliance is stated with the auditing firm named, Insight Assurance, and third party penetration testing is attributed to Bishop Fox by name. Apollo named its auditor and took a lower grade only because it routed the report through sales; naming the pen test provider as well is rarer still.

The control set is specific rather than reassuring: 256 bit encryption in transit, transparent data encryption at rest, automated data masking for personally identifiable information, OAuth 2.0 and TLS, least privilege employee access, regular privacy and security training, regular manual and automated audits, data centres themselves ISO 27001 certified and SOC 2 attested, PCI compliant payment processors, and an incident response programme with a stated 72 hour breach notification to clients.

Not A on the bar ActiveCampaign set: there is no self service or even described route to obtain the SOC 2 report, no audit period or date is given, and the Information Security Policies referenced in the text are not published or linked.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
BB on Commercial TransparencyPartial pricing published (entry tiers real, enterprise opaque) or pricing published with load bearing exclusions.
Third Party Estimated

Three tiers published with real per seat numbers, Salesforce Sync at 14, Pro at 21 and Expert at 49 USD per user per month, plus priced add ons at Sync+ 4 and Expert+ 9, a 14 day free trial, a self service hub where a buyer can build their own quote, and a custom tier for larger teams. Publishing the add on rate card alongside the tiers is the piece most vendors omit. Two things hold it off the Apollo benchmark.

Implementation is unpriced and third parties report it at 500 to 1,500 USD for smaller buyers and above 5,000 for enterprise. More sharply, the renewal mechanics that actually govern the bill are undisclosed and documented elsewhere: procurement records show a buyer reducing roughly 80 Expert licences being quoted a 12.5 percent uplift on cost per user, with the vendor's representative stating the route to removing the uplift was a two or three year agreement, and another buyer able to hold a flat renewal only by forgoing further discount.

Third party transaction data puts the average annual contract near 15,000 USD against a 49 USD list. A published seat price that says nothing about what happens when you shrink is a partial disclosure.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
AA on Exit and Data PortabilityOffboarding is documented before signature: full export paths for customer created and engagement data, post termination rights to delivered data stated in public terms, deletion commitments with timelines, and renewal notice terms a buyer can plan around.
Vendor Published

The first A on this axis in the index, and it is earned contractually rather than architecturally. The commitment is specific and dated: client data is stored and maintained for up to 90 days after termination of the agreement unless the client requests a return of the data, and at the conclusion of that 90 day period all client production data is deleted, with only financial and operational records retained as law requires.

That is a defined window, a defined deletion event and a defined return mechanism, which together are more than any other vendor here publishes; Alta previously held the best position on a self service purge with an emailed confirmation. Retention during the term is also client directed rather than vendor set, with administrators controlling capture policy and retention, and a right to be forgotten and a right to receive data in a structured machine readable format are both published.

The structural point compounds it: because the product's entire output is written continuously into the customer's own Salesforce org, the operative record already sits in a system the buyer owns. Two gaps stop it being unambiguous rather than stopping the grade: no deletion confirmation artefact is offered, and the machine readable portability right is stated under the vendor's controller role, so its application to the processor held client corpus is inferred rather than stated.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

Email Blast sends one to many templated messages with Salesforce merge fields from the rep's own connected Gmail or Outlook mailbox, and nothing published addresses warmup, domain authentication, bounce or complaint handling, sending reputation, volume governance or ramp guidance.

What lowers the practical risk relative to the cold outbound tools graded alongside it is the shape of the use case: this is an account executive mailing a bounded list of known contacts from a corporate mailbox, governed by the provider's own send limits, not a sequencer running strangers at scale from rotated domains.

That is a favourable circumstance rather than a discipline, and the vendor does describe the feature as including compliance without saying what that means, so there is something here that could not be verified.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Vendor Published

Segmented deliberately in two dimensions and evidenced by the customer list. By role: CRM administrators, account executives, sales operations, sales managers and marketing, each with its own material. By industry: financial services, higher education, technology, and energy and utilities, with the education commitment backed by actual FERPA school official handling and AB 1584 compliance in the privacy policy rather than by a landing page.

Over 50,000 customer facing teams, enterprise names including Walmart, Discover, Equitable, Samsung, Tableau and Tripadvisor, and legal coverage published separately for the United States, Canada and the EU. Not A because the addressable market is structurally bounded by a dependency the vendor cannot escape, since the product exists to extend Salesforce, and because no geographic footprint or international presence is claimed beyond the three privacy jurisdictions.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

GTM Tech Index

An independent reference for evaluating the software revenue teams use to find, win, and keep customers. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 19, 2026
The GTM Tech Index is an editorial reference, not a law firm or a regulator. Compliance postures are assessed from published sources and public records, and nothing on the index is legal advice. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 GTM Tech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746