DealHub
Agentic quote to revenue platform positioned on governed execution, unifying configure price quote, contract lifecycle management, DealRoom buyer collaboration, subscription management, billing and a revenue intelligence layer aimed at aligning revenue and finance leadership. Core mechanics are guided selling with conditional logic, adaptive pricebooks covering usage based, tiered and fixed models, discount thresholds with automatic approval below and automatic rerouting above, parallel approval workflows, document generation and e signature, and buyer engagement tracking inside the DealRoom. Deep integration into CRM, ERP, tax, payments and e signature systems, with a published API and stated MCP extensibility. Operated by DealHub Ltd.
Capability Axes
The established platform pattern, applied to a decade old quote to revenue system. Remove the models and a complete product remains: rules based quote configuration, adaptive pricebooks, discount thresholds, parallel approval workflows, contract lifecycle management, subscription amendments, invoicing and revenue recognition.
The vendor's own architecture confirms it, since the AI capability sits behind its own page and its own invitation to explore, and the platform comparison lists AI CPQ as one capability row among many rather than as the substrate. Loud AI branding on a system whose logic is deterministic by design lands at the middle of this band, not because the AI is unreal but because the removal test leaves the product standing.
The strongest deal governance architecture graded, and it stops one step short of the thing this axis now most needs. What is published is substantial: discount thresholds with automatic approval below the line and automatic rerouting above it, parallel approval workflows, approval aware pricing, pricing guardrails described as preventing revenue leakage, a deal desk dashboard, real time visibility on where any approval sits, and audit and compliance positioned as ready for public company scrutiny.
Governed execution is the whole thesis. The gap is that every one of those controls governs the human seller. The agentic layer is sold alongside it, and no published statement describes what approves, constrains or records the agents themselves. A vendor this precise about who may approve a discount saying nothing about who approves an agent action is the finding.
Provider, model family, version and inference location go unnamed across the pages read, and the agents are described by what they do rather than by what they are. Held at the top of the band on institutional rather than technical evidence: the vendor holds an ISO 42001 certification for AI management systems and a Cloud Security Alliance STAR AI registry entry, which together evidence an audited governance programme around the AI even though they disclose nothing about the models inside it. No accuracy or error rate is published for any agent output on a platform where a wrong figure becomes a contractual quote.
The deepest customer evidence in the index after Clari, and it is attributed rather than aggregated. Named enterprises appear with named individuals and their titles: a head of deal desk at Intuit, a global CPQ and CRM administrator at HP, a vice president of global deal desk at Braze, a global pricing product manager at The Adecco Group, a revenue operations manager at Zapier, and further named roles at Asure, Trintech and Verbit.
Each case carries a quantified triplet rather than a single number, among them approval cycles cut from days to eight hours, a 48 hour proposal turnaround down from seven days, adoption across more than 200 sellers, a 70 percent reduction in quote to order time and a 90 percent quote accuracy rate. A customer lobby publishes individual studies for Tipalti, Camunda, Digitate, Intellect, Plextrac, Motork, Inkcups and Brock USA. The caveat, and it applies to every vendor at this level: the figures are vendor collected and no methodology accompanies any of them.
The axis barely bites on this product and is graded on what is knowable, per the convention for categories that do not prospect. Nothing here contacts a stranger: the outbound artefacts are proposal links, approval notifications and contract requests sent to people already in a negotiation, and the only sending infrastructure named is a transactional email integration. No outreach regime is named anywhere, which is unsurprising and still recorded.
Worth noting alongside it that the vendor engages a different compliance surface entirely and does so prominently, positioning audit readiness and revenue recognition controls for companies preparing to be publicly scrutinised.
Certification does heavy lifting here and it is the right kind. ISO 27701 for privacy information management is held alongside the security standards, which is a privacy programme audited independently rather than a policy page, and it is the certification the index has previously noted as the one most vendors lack. GDPR and CCPA compliance are claimed with a dedicated GDPR page, and a privacy policy and an enterprise subscription agreement are both published at stable URLs.
Off the top of the band because none of those documents were read this pass, and because a data protection officer contact, a sub processor list and a data subject request route were not located on the surfaces read.
The posture is light because the vendor sells no data. There is no contact database, no enrichment product and no third party sourcing: what the platform holds is the customer's own product catalogue, pricing logic, quotes, contracts and subscription records, plus the CRM data it syncs from a system the customer already owns. Off the top of the band on one feature.
DealStream is listed among the top capabilities and is described elsewhere as collected intent data, and no sourcing, licence or collection method is published for it anywhere on the pages read, which leaves one undisclosed external data input in an otherwise clean architecture.
The exposure this axis measures is largely absent by architecture. The product connects through official, documented integrations with the systems it depends on, publishing individual pages for Salesforce, HubSpot, Microsoft Dynamics, NetSuite, Sage Intacct, QuickBooks, Xero, Priority, Avalara, Stripe, DocuSign, Slack, Gong and an integration platform, alongside its own API.
No browser extension, no credential custody, no scraping, no automated action taken under a user's account on a platform that did not sanction it, and no marketing built on operating around anyone's terms. Off the top of the band on the standard the index applies to everyone: a conformance position is never stated, and depth of platform dependency on the CRM and ERP side is itself a risk nothing published addresses.
The strongest institutional AI governance evidence in the index and the weakest direct answer. ISO 42001, the management system standard for artificial intelligence, is held and published, and a Cloud Security Alliance STAR AI registry entry is linked publicly to the registry rather than asserted. That is an independently audited AI governance programme, and no other vendor graded here holds one.
What it does not do is answer the question this axis asks: whether customer data trains or improves models serving other tenants, and what retention applies to agent inputs and outputs. That statement was not located on the pages read, on a platform holding pricing logic, contract terms and negotiation history for named enterprises. The certification and the security page are the first places to re verify.
The product shape does the work, as it did for the other vendors that reach this band without a policy. Nothing here is synthetic to a counterparty: no agent contacts anyone, no generated persona, no cloned voice, no manufactured research and no invented sender. The buyer arrives in a DealRoom they were invited into by a named person at a company they are already negotiating with, and both identities are real.
Off the top of the band on the surveillance half rather than the impersonation half. Buyer engagement tracking is a marketed capability, so the seller sees which stakeholders opened the proposal and what they looked at, and no published statement says whether the buyer is told that the room reports on them.
Depth across three system classes rather than breadth in one. CRM covers Salesforce, HubSpot and Microsoft Dynamics with individual documented pages. Finance covers NetSuite, Sage Intacct, QuickBooks, Xero and Priority on the ERP side plus Avalara for tax and Stripe for payments, which is the layer almost nothing else in this index reaches. Around them sit DocuSign, Slack, Gong, a transactional email service, single sign on, Google authentication and an integration platform connector.
A documented API, an integration centre, a knowledge base, an academy with admin certification and a partner directory complete it, and the platform capability list names MCP extensibility, making this the ninth vendor in the index building an agent facing surface.
The residency question goes unanswered on the pages read. Hosting provider, processing regions, storage location, sub processor list and any customer selectable region were all absent, and the continuity standard the vendor holds addresses availability rather than location.
This is very likely a false negative rather than a gap: enterprise procurement at the named customers does not approve a system holding contract and pricing data without a residency position, so the material almost certainly exists somewhere the pages read did not reach. Recorded as observed, with the security page as the first place to re verify.
The deepest certification record in the index, ahead of the previous high of six. Eight named attestations sit on the site with the type stated where a type exists: ISO 27001 for information security, ISO 27701 for privacy information management, ISO 22301 for business continuity, ISO 42001 for artificial intelligence management systems, SOC 1 Type II, SOC 2 Type II, GDPR and CCPA. Two of them matter beyond the count.
ISO 42001 is the first AI management system certification recorded in this index. And the Cloud Security Alliance STAR entries, at both the general and the AI level, are hyperlinked to the public registry rather than displayed as badges, so a buyer can verify the claim at source instead of taking it on trust. A dedicated security page and a dedicated GDPR page sit in the footer of every page. Not enough to move it: no audit period, auditor or report access route was located.
A page headed pricing that contains no price, which is the second instance of that exact shape in the index and it arrives from a vendor that is world class on every other disclosure. Read directly, the page publishes two named editions, a capability comparison between them, five customer quotes and a request pricing button. No figure, unit, band, floor or currency appears anywhere, and no minimum or contract length is stated.
The irony is on the page itself, which lists governed execution and audit readiness among its selling points while declining to state what any of it costs. Third party procurement benchmarks put mid market deployments in the region of 60 to 83 US dollars per user per month across three tiers named CPQ plus, CPQ plus CLM, and quote to revenue, none of which match the two edition structure the vendor now publishes, so even the external record and the vendor's own packaging disagree.
One structural advantage and one unread document. The architecture writes continuously into systems the customer already owns, since quotes, contracts, subscription records and billing events sync into the CRM and the ERP, so a departing customer keeps the commercial record in Salesforce or NetSuite without needing the vendor's cooperation. Against that, no export function, post termination retention period, deletion timeline or deletion artefact was located on the pages read.
The enterprise subscription agreement is published at a stable public URL, which is where return and deletion terms belong and is unusual to publish at all, and it went unread this pass. Reading it is the single thing most likely to move this grade.
The axis applies weakly to a product that sends transactional rather than campaign mail. What leaves the platform is proposal links, approval notifications, contract requests and invoices, all to counterparties already in a commercial relationship, and a transactional email service is named among the integrations.
Authentication guidance, bounce handling, suppression and any statement about whose domain those notifications originate from were absent from the pages read, and on a document that carries a price and a signature request, arriving in a junk folder is a commercial failure rather than a marketing one.
The buyer is named precisely and across functions: revenue teams at software and services companies managing complex deals, with sales, revenue operations, finance and legal all called out as participants, which matches a product that spans quoting through revenue recognition. The logo set corroborates rather than contradicts, running from large enterprises through mid market software companies, and the named alternatives place the product in its tier directly.
Off the top of the band because no headcount band, customer count or size distribution appears anywhere, and because a positioning that reaches from mid market software to global enterprise is a claim to two segments without describing either.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.