LinkedIn & Social Selling
F

Flocurve

Professional network prospecting and outreach sold as a self running development representative. The buyer supplies a website address, the platform reads it to generate an ideal customer profile, searches the network for matching people, monitors a claimed thirty plus buying signals such as funding rounds, role changes, hiring activity and engagement with competitors, then writes and sends connection requests, messages and follow ups until a meeting is booked. Cold electronic mail is included with a monthly allowance of verified addresses.

One published plan at 299 dollars a month covering a single connected account, with a quote only tier that names its own seat price. Seven day trial, no card. Execution of the network actions is delegated to a named third party automation service.

Last VerifiedAugust 20, 2026
Compare Flocurve with other vendors
Founded
Headquarters
Website
flocurve.com
Categories
linkedin-social-selling, ai-sdr-agents, intent-and-signals
Assessment

Capability Axes

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
BB on AI CentralityAI carries a core workflow, with real product surface that is not AI. The vendor is specific about which parts are model driven.
Vendor Published

At the top of the band. There is one plan and its differentiating line items are all model driven: the ideal customer profile is generated by reading the buyer's own website, the signal monitoring decides who is worth contacting, the messages are written per prospect from that context, and lead scoring ranks the result. Nothing in the packaging separates a cheaper mechanical tier from a model tier, because no mechanical tier is offered.

Held off the top for a structural reason the vendor discloses itself: the execution layer that performs the network actions is a commodity automation service supplied by a third party, so what remains after the model is removed is precisely the competitor product this vendor compares itself against.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
CC on Autonomy and Oversight ModelAutonomy is claimed or implied with the oversight model asserted rather than documented. Buyers cannot tell from public sources what runs unsupervised.
Vendor Published

At the bottom of the band. The product is sold on the absence of oversight rather than its presence, with campaigns described as running on autopilot around the clock, follow ups continuing automatically until a meeting appears on the calendar, and the setup framed as sixty seconds from a web address to live outreach. No approval gate, review step, escalation path, audit trail, withholding guardrail or containment mechanism is described anywhere across the pages read.

One contradiction is worth recording because it is internal: the vendor's own comparison writing criticises a competing agent for promising set and forget operation, and claims this platform keeps humans in control, while the homepage sells exactly the promise it criticises.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
BB on AI Disclosure and Model TransparencyMeaningful disclosure of the model stack or the disclosure posture, with one real gap, commonly silence on whether AI authored outreach identifies itself.
Vendor Published

Rare in this category and earned on a specific disclosure: the privacy policy names the model provider outright, states the three jobs it is used for, being profile generation, message generation and lead scoring, and draws a boundary on what is sent to it, describing anonymised lead context of job title, company and industry and stating that network credentials are never transmitted. Naming the provider and the data boundary is more than most vendors here manage.

Held off the top because no model or version is identified, no accuracy, confidence or fallback behaviour is published for the scoring that decides who gets contacted, and the word anonymised carries more weight than it can bear, since a job title plus a named company usually resolves to one person.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
DD on Operational and Outcome EvidenceNo outcome evidence published beyond assertion, on a product sold on its results.
Vendor Published

The product interface shown on the homepage is populated with invented people at invented companies, presented as a live activity feed rather than as an illustration. Named prospects with titles and employers appear alongside quoted replies agreeing to a call and a meeting booked on a specific date, none of which happened.

Around it sit figures with no source and no method: a reply rate, a total leads found, a claimed threefold improvement in replies, a first reply within forty eight hours, and a comparison to template based tools of two to three times better. Against all of that, no named customer, logo, case study or attributed testimonial from a real person appears anywhere across the pages read, and the one review platform listing located carries no reviewer feedback at all. Fabricated telemetry is a heavier version of the invented illustration problem, because it asserts results rather than showing a layout.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

At the bottom of the band. The platform sends connection requests and messages on a professional network and also sends cold electronic mail against an allowance of verified addresses, and across the pages read no consent standard, unsubscribe mechanic, suppression list, sender identification requirement or regulation of any kind is named for any of it.

The asymmetry recurs here as it does elsewhere in this category: the vendor commits to letting its own subscribers unsubscribe from its own product emails, and places no equivalent obligation on the buyer messaging strangers. The published resource library includes a guide to scraping the network the product operates on, which sits oddly beside the absence of any compliance position.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
BB on Data Privacy PostureA real privacy program is visible (DPA available, policy substantive) with a gap on the hard question, commonly lawful basis for enriched or tracked individuals.
Vendor Published

At the bottom of the band and genuinely better than most of this category. Current at March 2026 and unusually specific. Every processor is named with its function, covering authentication and database hosting, payments, the automation execution service, the model provider, two optional systems of record and a messaging platform. Retention is stated with a real number, being removal of personal data within thirty days of account deletion, with session material deleted on disconnect.

Rights are enumerated under both major regimes including portability in a machine readable format, a working contact address is published, and the vendor states it uses essential cookies only with no advertising or analytics trackers and no third party tracking scripts. The extension section describes what is read and adds a list of what is not.

Held at the bottom because no legal basis, transfer mechanism, supervisory authority, officer or processing agreement is offered, no company entity or address appears anywhere on the site, and nothing addresses the leads whose names, titles, employers and enriched addresses are stored without their knowledge.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
CC on Data Licensing and ProvenanceData is described by its size and coverage with its origin unstated. The provenance question is answerable only by asking the vendor.
Vendor Published

No database is purchased or resold and the targets are generated from the buyer's own profile definition, which is the lower exposure side of this axis. Stored lead records are described precisely, covering name, title, company, profile address and an enriched electronic mail address. Two gaps hold the grade. There is no lawful basis, notice, lookup or removal route of any kind for the person whose record is created and messaged.

And there is one conspicuous omission in an otherwise complete supplier list: seven processors are named with their functions, and the supplier of the monthly allowance of verified addresses, which is the only genuinely purchased data in the product, is not among them.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
DD on Platform Terms ExposureThe method visibly violates platform terms (headless automation of a prohibiting platform), or the vendor’s account restriction record is public and unacknowledged.
Vendor Published

The deepest credential custody graded on this axis, and the vendor documents all of it. Beyond the session token, which may be read by the extension or pasted in by hand, the platform stores the browser identifier from the session so that its requests match the operator's fingerprint, and it offers an optional reconnection feature under which it stores the operator's network login address, an encrypted password and the one time password secret key so it can refresh expired sessions unattended.

Holding the second factor seed means the platform can generate the operator's authentication codes at will until that seed is regenerated, which is durable account takeover capability rather than session borrowing. The session token is then passed to a third party automation service that performs the actions.

Purpose is stated plainly in the vendor's own answer to whether accounts get flagged: it mimics human behaviour, randomises timing, and personalises every message to avoid detection patterns. Execution is autonomous with no approval anywhere. The disclosure is exemplary and it does not cure the exposure.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
CC on AI Safety and Data StewardshipSecurity language exists but the training question, the one this axis turns on, is unanswered: a buyer cannot tell whether their pipeline data improves a competitor’s instance.
Vendor Published

At the top of the band on a minimisation posture rather than a commitment. The vendor states that only anonymised lead context reaches the model provider and that credentials never do, which is a real boundary and more than most of this category publishes. What is absent is the commitment itself.

Nothing states whether the provider may retain or train on what is sent, no reference to the provider's own retention terms appears, no tenant boundary is described between customers, and nothing addresses whether the accumulated corpus of messages, replies and outcomes is used to improve the platform's own models.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
DD on Recipient Disclosure and AuthenticityThe product ships fabricated human personas or undisclosed AI interaction by design, or its marketing celebrates evading detection, with no acknowledgement of the disclosure obligations in force.
Vendor Published

The deception here is aimed squarely at the recipient and the vendor names it as a design goal. Answering its own question about whether accounts get flagged, it states that it personalises every message to avoid detection patterns, which reframes personalisation itself as an evasion technique rather than a courtesy.

The marketing says the same thing from the other side, promising outreach that sounds like you rather than a bot and messages that read as though a human spent five minutes researching the prospect. No person approves anything before it sends, timing is randomised so the cadence does not read as machine driven, and the entire selling proposition is that the recipient cannot tell. The transparency provisions of the European artificial intelligence regulation go unmentioned. This is undetectability offered to the buyer as the product benefit, which is what this band exists for.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
CC on Ecosystem and Integration DepthIntegrations are listed as logos. Depth, direction, and limits are not documented anywhere a buyer can read.
Vendor Published

At the top of the band on a small but real integration set: two named systems of record receive lead data as an optional connection, a messaging platform receives notifications, and a browser extension handles the network connection. Electronic mail sending is native rather than delegated to a separate tool. What is absent is everything a technical buyer would check next: no public interface, documentation, webhook surface, marketplace listing or agent endpoint was located anywhere. The homepage comparison table marks connectors as a strength against rivals described as limited, which is a claim the site provides no material to substantiate.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
CC on Deployment Model and Data ResidencyCloud hosted is the whole public answer. Region and residency questions require a sales conversation.
Vendor Published

Four infrastructure and service providers are named with their functions, which establishes roughly where the workload runs even though the vendor never says so directly. No country, region, provider region or residency option is stated for any of it, and no data processing agreement is offered.

The wider gap is corporate rather than technical: no company entity, registration number, address or jurisdiction appears anywhere on the site, and the only route to a human for the quote only tier is a plain electronic mail link. A buyer cannot identify who they would be contracting with, let alone where their material would sit.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
DD on Security Certifications and Trust CenterNo verifiable security posture published for a product that ingests commercial data at scale.
Vendor Published

This vendor stores, by its own account, network session tokens, browser fingerprints, encrypted account passwords and one time password secret keys for its customers' professional network accounts. That is the most sensitive credential material any vendor in this index admits to holding.

Against it, the published security position is four sentences: transport encryption, encrypted database columns, and a reference to industry standard practices for access control, logging and incident response with no standard named. No certification, auditor, report, audit period, trust portal, status page, penetration test or enumerated control set was located, and there is no security page.

Graded on the precedent already applied twice in this category for live session custody with no documented control set, and the credential depth here makes it the clearest instance rather than the most arguable.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
BB on Commercial TransparencyPartial pricing published (entry tiers real, enterprise opaque) or pricing published with load bearing exclusions.
Vendor Published

At the bottom of the band. One published price at 299 dollars a month with the inclusions itemised as actual quantities rather than ticks, covering unlimited leads and campaigns, one connected account, the signal set, scoring, cold electronic mail with a stated monthly allowance of verified addresses, and analytics. A seven day trial with no card, self serve registration, cancel at any time, and the quote only tier is unusually candid in publishing its own additional seat price.

Two things hold it down and the first is checkable in a minute. The vendor's own comparison writing states that this plan covers five connected accounts, while its own pricing section states one, and the inflated figure appears precisely where it makes the cost comparison against a rival look favourable. Separately, no terms of service exist anywhere on the site, so there is no contract to read, no refund position, and no stated rate for exceeding the monthly address allowance.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
CC on Exit and Data PortabilityExport exists as a feature claim while the terms that govern exit, data rights after termination, deletion, and auto renewal mechanics, are not published anywhere a buyer can read.
Vendor Published

At the top of the band on two real commitments. Personal data is removed within thirty days of account deletion, which is a stated outer bound rather than a vague assurance, and session material is deleted when the network account is disconnected. A portability right is granted explicitly in a machine readable format.

What holds it here is that all of it lives in a privacy policy rather than a contract: no terms of service exist on the site at all, so there is no notice period, no cancellation mechanics beyond an assurance that cancelling is possible, and no service commitment. No product level export function is named for leads, campaign configuration, message history or analytics, so the portability route is a manual request by electronic mail.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

The platform sends cold electronic mail against a monthly allowance of verified addresses alongside its network messaging, so the buyer's sending reputation is genuinely at stake here. Across the pages read, nothing describes warmup, sender authentication, domain separation, ramp schedules, bounce or complaint thresholds, blocklist monitoring or placement testing.

On the network side one pacing statement exists and its framing is the finding: sending at a natural pace with randomised timing is presented as a way to avoid detection patterns rather than as protection for the recipient or the account, so the only discipline described is aimed at the platform's enforcement rather than at the health of the channel.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Vendor Published

At the bottom of the band. Six named markets get their own treatment with a specific buyer described in each, running across software, agencies, early stage companies, financial technology, recruiting and manufacturing, and each names the roles it expects to reach.

The worked example on the homepage states roles, industries and a company size band, and the single price point with a named additional seat rate makes the intended buyer legible: a small team or agency without a development representative function.

Held at the bottom because the segmentation is expressed through content pages rather than through the product or the pricing, no headcount band, deal size or geography is stated for the buyer, and no ceiling is published to tell a larger team where this stops being the right purchase.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

GTM Tech Index

An independent reference for evaluating the software revenue teams use to find, win, and keep customers. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 20, 2026
The GTM Tech Index is an editorial reference, not a law firm or a regulator. Compliance postures are assessed from published sources and public records, and nothing on the index is legal advice. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 GTM Tech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746