cubforge
Cloud based LinkedIn outreach automation with AI written personalisation. Imports prospects from Sales Navigator or CSV, generates a message per prospect from profile and company signals, runs multi step connection and follow up sequences with conditional branching, and manages replies in a unified inbox. Marketed on a safety engine of human like pacing, warm up protocols and account health monitoring, and on cultural and ethnic personalisation as its stated differentiator. Single published plan at 19 US dollars per month per LinkedIn account. Operated from Ahmedabad, India.
Capability Axes
The vendor settles this axis itself in its own comparison table. Ranged against Expandi, LinkedHelper and Dux-Soup, it marks AI personalisation as the row those three lack while they carry sequences, safety limits and analytics, which is a published demonstration that a complete and saleable product in this category survives removal of the model.
What remains here after the model is exactly that: prospect import from Sales Navigator or CSV, multi step connection and follow up sequences, daily limit management and campaign analytics. The models write the message and adapt the tone, which is a strong differentiator inside an existing category rather than the thing that makes the category possible.
The published loop runs from launch to booked meeting without a described human checkpoint. Step three of the vendor's own three step model is headed Launch and Auto-Pilot, campaigns are described as sending connection requests, follow ups and tracking replies automatically, and the pipeline is said to run twenty four hours a day even while the operator sleeps.
Every control named is a throttle rather than an oversight mechanism: smart daily limits, human like pacing, warm up protocols and an account health score, all of which govern how fast messages leave rather than whether any given message should. A review step, an approval gate, a withholding guardrail and any audit trail of what the model wrote and sent are absent from the pages read.
Provider, model family, version and inference location go unnamed. The description of the mechanism stops at analysing a prospect's profile, company news and growth signals to craft the message. The gap that matters most sits under the marketed differentiator: cultural and ethnic personalisation is sold as a capability no competitor offers, and the method by which the system determines a recipient's cultural or ethnic context, the inputs it uses and its error rate are all undescribed. Getting that inference wrong produces a message that misidentifies the person it is addressed to, and nothing published addresses how often that happens.
The proof surface does not survive being read against itself, and four checkable conflicts sit on the vendor's own pages. The customer count is given as more than 10,000 active teams in the hero, the statistics band and a line reading measured across 10,000 or more active teams, while the footer of every page reads trusted by 2,400 or more sales teams.
A headline average reply rate of 47 percent sits on the same page as a return calculator whose stated assumptions are 30 percent acceptance and 25 percent reply. A trust badge reads 4.9 out of 5 on G2, and the G2 entry located for this vendor records no reviews.
A logo wall headed trusted by revenue teams at leading companies carries Stripe, HubSpot, Notion, Vercel, Shopify, Linear, Figma, Calendly, Datadog, Intercom, Segment and Deel with no case study, named person or attribution behind any of them. Six further testimonials are attributed to job titles and company archetypes with no names, and the one named testimonial that appears twice on the site is labelled a verified pilot user.
Safety appears throughout the site and always means avoiding account restriction rather than meeting any legal obligation, which is the pattern this band was written for in social selling tools. No regulation is named on any page read, and the surface is not small: unsolicited connection requests and messages at a marketed rate above 200 a day, sent into 36 stated countries including European markets where an unsolicited commercial approach engages both a lawful basis question and the platform's own rules. A consent position, a suppression mechanism, an opt out route and a data subject request path are all absent from the outreach product.
A privacy policy, a cookie policy and a security page are published and footer linked, the security page claims GDPR and CCPA compliance, commits to breach notification within 72 hours, and states privacy by design with data minimisation and automatic purging on a retention policy. The finding sits in the product rather than the policies.
Cultural and ethnic personalisation is marketed as the differentiator no competitor offers, and it is listed in the feature set separately from location based targeting, so the vendor is describing something other than geography. Racial and ethnic origin is special category data under the GDPR the same page claims compliance with, and a lawful basis, an impact assessment, a source for the inference and any subject notification are absent from every page read. Recorded as observed on the published feature description.
Prospect data enters through the operator's own Sales Navigator seat or a CSV upload, which is a lighter posture than harvesting and places the sourcing decision with the buyer. Held at the middle of the band rather than higher because the platform then derives new information about those individuals, analysing profile content, company news and growth signals and inferring a cultural or ethnic context to shape the message, with no statement of what is retained, for how long, or on what basis. The people profiled this way have no notification, lookup or removal route described anywhere on the vendor's surface.
Four elements compound and all of them are the vendor's own marketing. The architecture is server side and sold as such: cloud based, runs 24/7, no browser needed, listed as an advantage over three named rivals, and the security page confirms that LinkedIn session cookies are encrypted and stored by the vendor, so the platform holds the live authenticated session.
The evasion is stated in the product FAQ, which says the system mimics natural activity to keep the account in good standing, alongside human like behaviour patterns and a safety engine whose comparison row reads auto-adjusts to avoid restrictions. The marketed volume is above 200 messages a day, far beyond any published platform allowance.
And the only acknowledgement of the platform anywhere is the safety framing itself, with no conformance position, no reference to the platform's automation policy and no statement of who carries the risk when an account is restricted. The account that gets restricted belongs to the operator.
The training question goes unanswered while the platform accumulates an unusual corpus: prospect profiles, generated messages, reply text and the inferred cultural context attached to named individuals, across a stated 500,000 messages a day. A statement on whether that material trains or improves models serving other accounts appears nowhere.
Held at the middle of the band because two real stewardship commitments are published on the security page, automatic data purging based on retention policies and processing in memory without unnecessary persistence, neither of which is quantified but both of which are more than most vendors at this price state.
Undetectability is sold as a feature, which is the test for this band. The FAQ states that the system mimics natural activity, the comparison table sells a safety engine that auto-adjusts to avoid restrictions, and the transformation section contrasts about five manual messages a day against more than 200 automated ones while promising a unique message per prospect.
A recipient receiving one of those has no available signal to distinguish it from a message a person wrote, and that is the intended effect rather than a side effect. The cultural and ethnic personalisation feature deepens it: the recipient is addressed in a register selected from an inference about their background that they never disclosed. Article 50 goes unmentioned across a stated 36 countries. Recorded in fairness: messages send from the operator's own account under their own name, and nothing impersonates a named human or uses a synthetic voice.
A real integration surface for a product at this price. Named CRM sync into HubSpot, Salesforce and Pipedrive described as two way and in real time with custom field mapping and activity timeline logging, plus Zapier reaching a stated 5,000 further applications, Slack notifications, Google Sheets, webhooks and CSV export. The supporting furniture is better than the category norm: a published changelog, a status page, a documentation site and an API page all sit in the footer navigation.
Off the top of the band because the API surface was not verified as documented endpoints rather than a marketing page, no developer portal or agent facing endpoint was located, and the sync claims carry no rate, object coverage or conflict handling detail.
The residency question goes unanswered on every page read. Hosting is described only as enterprise grade cloud with isolated network architecture and private subnets, and backups are said to be encrypted and stored in geographically distributed locations, which states that data moves between jurisdictions without naming any of them.
Provider, region, storage location and sub processor list are all absent, on an Indian operated platform holding live session credentials and prospect records for customers across a stated 36 countries.
The control set is enumerated more fully than most vendors at this size manage: TLS 1.3 in transit and AES-256 at rest, encrypted backups, hardware security module key management, multi factor authentication, bcrypt password hashing, session timeout, role based access control, a web application firewall, DDoS mitigation, vulnerability scanning and penetration testing, OWASP practices, automated security testing in the pipeline, dependency monitoring, and a responsible disclosure programme with a 48 hour acknowledgement commitment.
Against that sits a contradiction the vendor publishes itself. The homepage displays a trust badge reading SOC 2 Type II, and section six of the security page states that SOC 2 Type II certification is in progress. The only completed attestation described anywhere belongs to the cloud host rather than to this vendor, which is the same attribution gap seen elsewhere in the index. No auditor, report route, audit period or trust centre exists. The custody position is stated plainly and is worth reading beside the platform terms row: LinkedIn session cookies are encrypted and stored by the vendor, and the LinkedIn password is not.
One published plan at 19 US dollars a month or 190 a year, with the unit stated plainly as one LinkedIn account, and a promise page that answers the three questions this axis exists to test: no feature gates with every capability unlocked from day one, no per seat surprises, and no usage limits, overage charges or add on upsells. A seven day trial runs with no card, cancellation is self service, and a 30 day money back guarantee is published.
The vendor also prints its rivals' entry prices beside its own, naming Expandi at 99, LinkedHelper at 15 to 79 and Dux-Soup at 11 to 55. Two observations recorded and not enough to move the grade: a custom plan for enterprise volume is routed to a contact form with no figure, and the return calculator on the homepage assumes a 495 dollar monthly investment, which reconciles with the published price only by multiplying accounts, so the flat price is per connected account rather than per organisation.
The practical routes out are real and they sit in the integration list rather than in any commitment: CSV export, Google Sheets, webhooks and two way CRM sync into HubSpot, Salesforce or Pipedrive, so contacts, replies and meetings land continuously in a system the customer already owns. The commercial exit is clean, with self service cancellation and a 30 day refund. What is missing is the contractual half.
A post termination retention period, a deletion timeline, a deletion artefact and any statement of what happens to stored session credentials on cancellation are absent, and the automatic purging described on the security page is tied to a retention policy that is never published.
The axis maps onto platform messaging rather than email here, since the product sends no mail. The published discipline is genuine as far as it goes: warm up protocols, smart daily limits that adjust automatically, human like pacing and a real time account health score shown as a dial with a daily limit counter. It runs in one direction only.
The stated target is more than 200 messages a day, so the pacing exists to sustain volume rather than to constrain it, and the questions a buyer needs answered are untouched: what the limits actually are, what the health score is calculated from, what the platform does when a score degrades, and what recovery looks like once an account is restricted.
Two segments are corroborated by product design rather than asserted. Agencies get multi client workspace isolation, reusable playbooks and white label reporting, and recruiters get candidate matching, InMail and connection sequences and stated applicant tracking integration, both of which are build decisions rather than page copy. The claim around them is the problem.
Eight audience labels run from solo founders to enterprise sales floors with no headcount band, no size distribution and no ceiling, so the positioning reaches for the entire market, and the two customer counts published on the same site, more than 10,000 active teams and more than 2,400 sales teams, leave a reader unable to size the base at all.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.