Data & Enrichment
C

Clay

Data enrichment and go to market workflow platform built on a spreadsheet interface. A user creates tables of companies or contacts and builds enrichment sequences against a marketplace of more than one hundred and fifty data providers, with waterfall enrichment as the defining capability: the same field is queried against several providers in sequence until one returns a result, which produces materially higher match rates than any single source. An AI research agent runs open ended research per row, and a built in email sequencer sends from the same tables.

The platform is bought as an orchestration layer rather than a list. Independent testing reports email match rates near seventy eight percent on a waterfall against roughly forty two percent from single source tools, and the same testing reports a four to six week learning curve, which is the consistent trade off in the review evidence: the most capable tool in the category, operated rather than consumed, and generally staffed with someone whose job is building the workflows.

Pricing was restructured on 11 March 2026, splitting billing into data credits for marketplace lookups and actions for platform orchestration, cutting marketplace data rates and moving customer record synchronisation and interface access down from the retired top self serve tier. Founded 2017 in New York. Reported customers include several large artificial intelligence and software companies.

Last VerifiedAugust 30, 2026
Compare Clay with other vendors
Founded
2017
Headquarters
New York, New York, United States
Website
www.clay.com
Categories
data-and-enrichment, ai-sdr-agents
Assessment

Capability Axes

Capability grades

17 of 17 axes rated · 9 graded A or B

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

The core product is orchestration and the AI sits alongside it rather than underneath it. Waterfall enrichment, which is what the platform is bought for, is sequencing logic against a provider marketplace: query one source, and on a miss fall through to the next. That is routing rather than inference, and it works identically with every model switched off.

The research agent that reads pages and answers open questions per row is genuine model dependency and is a first class capability rather than a wrapper, and the sequencer generates message copy. But strip both and the tables, the waterfalls, the conditional logic and the integrations all still run, which is the majority of what the review evidence describes teams doing. The company dates to 2017 and the spreadsheet orchestration model predates its AI features. Ask which capabilities stop entirely without the research agent, and what share of a typical workflow's cost is model calls rather than data lookups.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
CC on Autonomy and Oversight ModelAutonomy is claimed or implied with the oversight model asserted rather than documented. Buyers cannot tell from public sources what runs unsupervised.
Vendor Published

Spend is bounded architecturally and behaviour is not described. Every operation consumes a metered credit or action from a finite monthly allocation, so a workflow that misbehaves exhausts a budget rather than running indefinitely, and the ceiling is visible to the operator before it is hit. That is a real constraint arising from how the product is built rather than from a policy.

What is absent is everything above it: no published statement describes what the research agent may do while investigating a row, whether it is bounded in the pages it will fetch or the actions it will take, what happens when it returns a confidently wrong answer into a field that then drives downstream branching, or whether any approval gate exists before generated content enters a sending sequence.

Workflows are built by the customer, so the blast radius is largely whatever the customer designed, which places responsibility rather than removing risk. Ask what bounds the research agent per row, and whether generated copy can enter a sequence without human review.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
BB on AI Disclosure and Model TransparencyMeaningful disclosure of the model stack or the disclosure posture, with one real gap, commonly silence on whether AI authored outreach identifies itself.
Vendor Published

Model providers are named and the subprocessor list covering them is published as its own artifact. The documentation names a major provider's model family directly and describes others as leading providers, and a full list of artificial intelligence subprocessors is maintained on the trust site rather than referenced in passing.

Alongside it the vendor states that its model providers carry contractual obligations never to train on customer data and to hold their own security certifications, which is a supply chain commitment rather than a claim about the vendor's own systems. Publishing an AI subprocessor list separately from a general subprocessor list is uncommon and directly useful, because for this product the model layer and the data layer are different third party estates.

Two gaps hold it below the top band: no model version or evaluation is published, and no accuracy or error rate is stated for research agent output, which matters because that output lands in fields that drive branching logic and message copy. Ask which model versions are in use and what evaluation covers research agent output before it enters a workflow.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
BB on Operational and Outcome EvidenceReal outcome evidence published, with named customers and numbers, but the measurement basis is incomplete: population, period, or definition unstated.
Third Party Estimated

A measured performance figure exists in public with a stated method, which is rare on this axis and rarer still in this category. An independent reviewer ran a thirty day test across a two thousand contact list and reported email match rates near seventy eight percent through a multi provider waterfall against roughly forty two percent from single source tools.

The population, the duration and the comparison basis are all stated, and the reviewer sells a competing product, so the finding runs against their commercial interest, which strengthens rather than weakens it. Separate independent modelling puts a five step workflow at roughly seven data credits and five actions per record, which lets a buyer estimate unit economics from outside.

The vendor's own contribution is thinner: a claim of more than one hundred thousand teams and a named customer list including several large artificial intelligence and software companies, with no published study of its own. Match rate also depends entirely on the provider mix a customer configures, so the figure describes a good configuration rather than the platform. Ask for match rates by provider combination, and for the vendor's own measured accuracy on its default waterfalls.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

The platform now sends, and the obligations that come with sending are not addressed. A built in email sequencer runs campaigns directly from enrichment tables with generated personalisation, which means contacts sourced from a marketplace of third party providers can move to outbound delivery without leaving the product.

That is the compliance surface, and nothing published describes what governs it: no statement on suppression list handling, no unsubscribe mechanics, no bounce or complaint policy, and nothing on whether a contact who has objected to one customer's outreach is suppressed anywhere else. The absence is more consequential here than for a pure enrichment tool, because the enrichment step and the send step share a table and the person in that row never gave either party permission directly. Ask how suppression and unsubscribe state is maintained in the sequencer, and what prevents a purchased record from being sequenced without a lawful basis.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
CC on Data Privacy PostureA standard privacy policy exists and answers none of the questions this product category specifically raises.
Vendor Published

Roles and deletion are stated plainly and the instruments behind them are not published. The documentation states that the vendor acts as a processor while the customer remains the controller, that customer data is primarily processed in the United States, that only the customer and authorised workspace users can reach it, and that deleting a workspace removes all data after thirty days.

A stated deletion window and a named processing location are both more than most vendors in this category offer. Against that, the processing agreement is available only by emailing a security address rather than published, no transfer framework certification was located, and no general subprocessor list covering the data providers was found, only the artificial intelligence one.

That last gap is the load bearing one for this product: the marketplace routes customer queries to more than a hundred and fifty third parties, and which of those are processors, under what terms, is the question a privacy review would ask first. Ask for the processing agreement, the full subprocessor list covering data providers, and the transfer mechanism for European customer data.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
BB on Data Licensing and ProvenanceProvenance is substantively described but incompletely: sourcing classes named without the legal footing, or indemnification unstated.
Vendor Published

Field level attribution to a named provider, which almost nothing else in this category offers. Because the marketplace is the product, a customer building a waterfall selects providers by name and sees the credit price of each, so at the point of use they know which company supplied a given email address or phone number and what it cost.

That is more provenance visibility than an aggregated database can structurally provide, since a conventional data vendor returns a record without saying where inside its corpus the field came from. The vendor also states that it negotiates volume terms with partners and passes rates through, which describes a licensed reseller relationship rather than an undisclosed one.

What is missing sits one layer down and is not the vendor's to answer easily: nothing describes how any individual provider collected its data, under what lawful basis, or whether European records in the marketplace rest on consent or legitimate interest, and no indemnification position is stated. So a buyer can trace a field to a company and no further. Ask whether provenance is indemnified, and what diligence the marketplace applies to a provider's own collection basis before listing it.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Vendor Published

Integration runs through official routes and the vendor's structural position keeps most platform risk at arm's length. More than eighty named partner integrations are published including customer record platforms, sequencers and model providers, with interface access and webhook automation offered as tier gated features rather than through unofficial means.

Because enrichment is executed by marketplace providers rather than by the vendor scraping directly, the collection exposure sits with those providers under their own terms, which is a genuine architectural distinction rather than a technicality. Nothing resembling credential storage or headless automation appears on the surface. Two things hold it below the top band. No stated conformance position against any specific platform's terms was located.

And the arm's length position cuts both ways: a customer whose waterfall includes a provider operating against a platform's rules inherits that exposure through the vendor without any published statement of what the marketplace screens for. Ask what a provider must demonstrate about its collection method to be listed, and whether any named platform conformance commitment exists.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
BB on AI Safety and Data StewardshipTraining use is addressed substantively with a real gap, commonly a default in rather than default out posture, or retention terms unstated.
Vendor Published

The training commitment is pushed onto the supply chain contractually rather than asserted about the vendor's own systems. The documentation states that model providers carry contractual obligations never to train on customer data, that campaign and prospect data is processed only to generate that customer's content, and that it is neither used for training nor shared with other customers.

Locating the commitment in the provider contracts is the right place for it, because on this architecture the customer's data leaves for a third party model on nearly every AI operation, and a promise about the vendor's own behaviour would not reach that. The artificial intelligence subprocessor list is published so a buyer can see who those providers are.

Held below the top band on instrument tier and on a distinction the vendor draws itself: the commitments sit in product documentation rather than a published agreement, and the management standard for artificial intelligence is stated as planned rather than held, where the two vendors at the top of this axis hold it and publish the certificate. Ask whether the provider training restrictions are reflected in the customer's own agreement, and what the timeline is for the management standard.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
CC on Recipient Disclosure and AuthenticityNothing published on whether recipients are told they are dealing with software. For a product whose AI talks to prospects, silence here is now a regulatory posture, not a style choice.
Vendor Published

Generated copy reaches a stranger under a seller's name and nothing addresses the fact. The sequencer composes personalised messages from enriched fields and research agent output, then sends them from the customer's identity to a person whose details were purchased from a marketplace moments earlier. That recipient has no relationship with either party and no way to know that the message referencing their company was assembled by a model reading their web presence.

Nothing published states a position on disclosing machine authorship, offers a setting to mark generated copy, or describes what the recipient is told. This lands mid band rather than lower because the vendor does not market the concealment as a feature, the send is initiated by a human operating a workflow they built, and the volume is bounded by metered credits rather than unlimited. Ask what the vendor's position is on disclosing AI authorship in sequencer output, and what a recipient asking how they were contacted would be told.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
BB on Ecosystem and Integration DepthSolid primary CRM integration documented, with depth unstated at the edges (sync direction, custom objects, failure behavior).
Vendor Published

Two distinct ecosystems rather than one, and public documentation covering both. The data side carries more than one hundred and fifty marketplace providers a customer composes directly. The software side carries more than eighty partner integrations spanning customer record platforms, sequencers and model providers, plus interface access, webhook automation and customer record synchronisation.

A public documentation site is maintained with real operational depth, including plans and billing mechanics, credit consumption guidance and security notes per feature, which is genuinely useful reference material rather than marketing. Two limits.

Customer record synchronisation and interface access are gated to the middle tier rather than available across the range, so the integration depth a buyer gets depends on what they pay, and the review evidence identifies that gate as a common reason teams upgrade. And reported provider counts differ across sources between roughly seventy five and one hundred and fifty, so the marketplace size is not firmly established. Ask which integrations are gated to which tier, and for the current verified provider count.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
CC on Deployment Model and Data ResidencyCloud hosted is the whole public answer. Region and residency questions require a sales conversation.
Vendor Published

The processing location is named specifically, which is more than most manage, and there is only one of it. The documentation states that customer data is primarily processed in the United States and names the cloud provider and region directly rather than describing a multi region estate in the abstract. Naming a region is a real disclosure and a buyer can act on it.

What follows from it is the limitation: no European or United Kingdom residency option is described anywhere, no tenancy model is stated, and no recovery time or recovery point objective is published. For a European customer enriching European contacts through a marketplace of third party providers, single region United States processing with no stated alternative is a material constraint rather than a detail, and the word primarily is doing unexplained work about where the rest goes. Ask whether European data residency is available, what primarily excludes, and what the recovery objectives are.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
BB on Security Certifications and Trust CenterCertifications named and plausible with a gap: no trust center, stale dates, or asserted without enumeration.
Vendor Published

A live trust site carrying real certifications, with the documents themselves on request. The vendor holds a service organisation control type two report, completed and announced in September 2024, and the trust site lists the international information security standard alongside it, together with the artificial intelligence subprocessor list and security questionnaire responses. A dedicated security contact address is published and the processing agreement is obtainable through it.

Documentation of security posture also appears inside the product documentation per feature rather than only on a central page, which means a buyer evaluating one capability finds the relevant control notes where they are working. Held below the top band because no certificate or report is published openly, no audit period or auditor is named on the public face, and the management standard for artificial intelligence is stated as planned rather than held.

One caution recorded rather than graded: at least two unrelated companies operating under the same name publish their own certification claims, including a separate personal relationship product and a human resources platform, and their announcements surface readily in search against this vendor's name. Only material from this vendor's own domains was used. Ask for the report with its audit period and auditor.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
BB on Commercial TransparencyPartial pricing published (entry tiers real, enterprise opaque) or pricing published with load bearing exclusions.
Vendor Published

The first vendor in this expansion cohort to publish real prices, and the disclosure is substantial. Four tiers are published with figures: a permanent free tier at one hundred data credits and five hundred actions monthly, two self serve tiers at one hundred and eighty five and four hundred and ninety five dollars monthly with stated credit and action allowances, and a custom enterprise tier.

Unit economics are published too, with data credits starting at five cents each, rollover rules stated as up to twice the monthly allowance on self serve and fifteen percent of prior year purchases on enterprise, and documentation mapping each tier to a monthly record volume so a buyer can self select. The vendor also published its internal pricing memo alongside the March 2026 restructure, which is unusual and creditable.

Three things keep it off the top band and they are the ones that decide the real bill. Customer record synchronisation and interface access are gated to the middle tier, so a feature gate rather than volume sets the entry point for most teams. Top up credits above the allowance are reported at a markup over the plan rate.

And the pricing page states its own prices two different ways, with the annual plan cards reading one hundred and sixty seven and four hundred and forty six dollars while the frequently asked questions lower on the same page describe the tiers as starting at one hundred and eighty five and four hundred and ninety five, with both cards also carrying lower slider floors. Ask which figure on the page governs, what the top up rate is, and the credit cost of your own intended waterfall.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
CC on Exit and Data PortabilityExport exists as a feature claim while the terms that govern exit, data rights after termination, deletion, and auto renewal mechanics, are not published anywhere a buyer can read.
Vendor Published

A deletion timeline is committed and the export question is unanswered. The documentation states that deleting a workspace removes all data after thirty days, which is a specific and checkable commitment, and that the customer can delete data at any time. That covers getting data destroyed. It does not cover getting it out.

Nothing published states what a departing customer can export or in what format, whether enriched records leave with the account, or what happens to the workflow logic itself, which on this platform is the accumulated asset: a mature deployment holds waterfall configurations, conditional branching and prompt design built over months by someone the review evidence says takes four to six weeks to become competent.

Whether that configuration is portable, or whether it is only reproducible by rebuilding it, is not addressed. A further wrinkle specific to the marketplace model is that enriched fields were licensed from third parties, and no statement describes what a customer may retain and use after the subscription ends. Ask what exports and in what format, whether workflow configuration is portable, and what licence attaches to enriched records after termination.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

Sending is a recent addition and none of the discipline around it is described. The built in sequencer sends campaigns from enrichment tables, which makes this a sending product rather than a pure data tool, and the axis applies in full.

Nothing published addresses the questions it applies: whether mail leaves from vendor infrastructure or the customer's own connected mailboxes, who configures authentication records, whether warmup exists, what bounce or complaint thresholds trigger intervention, or how one customer's sending behaviour is isolated from another's on shared infrastructure.

The risk profile is specific and elevated here, because the contacts being sequenced were purchased through a waterfall moments earlier and the review evidence reports that stale input lists commonly produce miss rates of twenty to thirty percent, which is exactly the profile that generates bounces. Ask which infrastructure sends, whether mailbox warmup is provided, and what bounce rate triggers a stop.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Third Party Estimated

Fit is stated by volume rather than by company size, which is both unusual and more useful. The documentation maps each tier to a monthly record throughput, naming under one thousand records for the entry tier, one thousand to ten thousand for the middle tier and above ten thousand for enterprise, so a buyer self selects on the measure that actually drives their bill rather than on headcount.

A free tier means the smallest possible user is served rather than turned away, and the range runs continuously from there to custom enterprise contracts reported around thirty thousand dollars annually. Reported reach of more than one hundred thousand teams and named references among large artificial intelligence and software companies support the upper end.

The honest limit is one the vendor does not state and the independent evidence does: the platform assumes technical capability, with a four to six week learning curve reported and teams commonly assigning a dedicated operator, so the real constraint on fit is skills rather than volume or budget, and nothing on the vendor's surface says so. Ask what a team without a dedicated operator should expect for time to first working waterfall.

Commercial

Pricing

What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.

What it costs
Vendor Published
185 US dollars per month, Launch tier
$185 lowest published figure
In short
  • Clay actually tells you what it costs, which most tools in this index do not. There is a free version, then two paid plans at one hundred and eighty five and four hundred and ninety five dollars a month, and a custom price for big companies.
  • You pay in two separate currencies. Data credits buy the actual information, starting around five cents each. Actions pay for the work the platform does running your steps. Both run down separately.
  • The monthly price is not the whole bill. What you really spend depends on how many contacts you look up and how many providers you check for each one, and looking up one person across several providers can cost a dozen credits or more.
  • Two things to check before you buy. Connecting it to your customer database only works on the more expensive plan. And the pricing page shows two different sets of numbers depending on where you look on it, so ask which one applies to you.

How the price works

What you are charged for, and what makes the bill go up.

Subscription with dual metered consumption. Four tiers: a permanent free tier at one hundred data credits and five hundred actions monthly with unlimited seats, a Launch tier at one hundred and eighty five dollars monthly carrying two thousand five hundred data credits and fifteen thousand actions, a Growth tier at four hundred and ninety five dollars monthly carrying six thousand data credits and forty thousand actions plus customer record synchronisation, interface access, webhook automation and web intent, and a custom enterprise tier reported to start around thirty thousand dollars annually. Annual billing is discounted roughly ten percent.

Data credits purchase marketplace data at rates from five cents, actions meter platform orchestration including workflow steps, model calls, interface requests and record synchronisation. Unused data credits roll over up to twice the monthly allowance on self serve tiers and up to fifteen percent of prior year purchases on enterprise at equal or higher renewal. Legacy tiers retired for new customers on 11 March 2026 with existing customers grandfathered indefinitely.

What the contract says about your data

What the vendor commits to in writing once your data is in the product.

A signed data processing agreement is available by emailing a published security address rather than being published. The vendor states it acts as a processor with the customer as controller, that customer data is primarily processed in the United States on a named cloud provider and region, and that workspace deletion removes all data after thirty days. An artificial intelligence subprocessor list is published on the trust site, and model providers are stated to carry contractual obligations never to train on customer data. No general subprocessor list covering the data marketplace providers was located, and no transfer framework certification was found.

Getting started

What it costs and what is included before the product is running.

None charged. The platform is self serve with no published onboarding or implementation fee at any self serve tier. The real adoption cost is internal rather than invoiced: independent testing reports a four to six week learning curve, teams commonly assign a dedicated operator, and third party implementation partners exist and charge separately. Enterprise customers are described as building custom plans with an assigned engineer from the vendor, with no fee stated for that support.

What to watch for

Where this pricing can surprise a buyer who has not read it closely.

The best commercial disclosure in this expansion cohort and the first that is not quote only. Four tiers are published with figures, unit economics are stated at the credit level, rollover rules are published, and the vendor released its internal pricing memo alongside the March 2026 restructure. Three qualifications matter for a buyer.

First, the vendor's own pricing page states its prices two different ways: on the annual view the plan cards read one hundred and sixty seven and four hundred and forty six dollars monthly while the frequently asked questions further down the same page describe the tiers as starting at one hundred and eighty five and four hundred and ninety five, and both cards additionally carry lower slider floors reported at fifty four and one hundred and eighty five dollars because the cards are adjustable rather than fixed. Second, sources disagree on whether failed lookups consume credits.

The vendor's March 2026 announcement is reported as eliminating charges for enrichments returning no result, while several independent reviewers writing after that date state that failed lookups still consume credits and that miss rates of twenty to thirty percent on stale lists are a real budget factor. That conflict was not resolved on this pass and a buyer should settle it directly, because on a multi provider waterfall it materially changes cost per record.

Third, top up credits purchased above the plan allowance are reported at a markup over the plan rate, variously given as thirty and fifty percent. entryPriceUsd is recorded at 185, the published monthly rate of the lowest paid tier per the vendor's own frequently asked questions, not zero for the free tier and not the annual or slider floor figures, consistent with the convention that the field carries the lowest recurring paid rate.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.