Gainsight
Enterprise customer success platform and the category's original vendor. The product tracks customer health, predicts churn, and drives renewal and expansion workflow, built around health scoring, data modeling and automation deep enough that most deployments run a dedicated administrator. It has grown into a six product suite: the flagship success platform, product experience analytics with in application engagement, customer education acquired as Skilljar and Northpass, customer communities acquired as inSided, a mid market edition, and conversation and sentiment agents acquired as Staircase AI. The vendor reports more than three thousand five hundred customers and more than one thousand two hundred employees, with offices in the United States, United Kingdom, Netherlands, Israel and India.
Vista Equity Partners took a majority stake on 30 November 2020 at a reported valuation of one point one billion dollars, and Gainsight has operated as a private equity portfolio company since.
In November 2025 Gainsight was at the centre of a supply chain security incident. Salesforce detected unusual activity through Gainsight published applications, revoked every access and refresh token for those applications, and temporarily removed them from its marketplace. Reporting from the forensic investigation indicated more than two hundred Salesforce instances were potentially affected. Gainsight engaged an external forensic firm and also deactivated its Zendesk, HubSpot and Gong integrations during the investigation. The origin was traced upstream to a separate compromise at another vendor whose product Gainsight itself used, so this was exposure through the integration estate rather than a failure of the Gainsight platform. A buyer should ask what the delegated permission scope of the Salesforce connector is today and what changed after the incident.
Capability Axes
Capability grades
17 of 17 axes rated · 5 graded A or B
An incumbent with a recent and largely acquired AI layer over a product that predates it by fifteen years. The company was founded in 2009 and built its position on health scoring, data modeling and workflow automation, none of which is a model.
The AI now marketed sits on top: sentiment and conversation agents that arrived through the acquisition of a separate company, an assistant layer, and a services business for retention and renewals announced in May 2026 with executives appointed to it in July. Strip all of it and the health scores, rules, playbooks, journeys and renewal workflow keep running, which is what the large installed base is described as configuring and administering.
The scoring itself is rules and data modeling that a customer builds rather than a learned model the vendor supplies. Ask which parts of health scoring are model driven rather than rule driven, and whether the agent products are separately licensed.
Agents that face customers are being sold and the boundary around them is not published. The vendor acquired a conversation and sentiment agent product and in May 2026 launched a services business described as AI native for retention and renewal work, appointing executives to it two months later. That is a move from software that advises an internal team toward systems that act in the retention motion, which is the point at which the category editorial expects autonomy questions to arrive.
Nothing on the public surface states what those agents may do without a human approving it, whether they contact a customer directly, what escalates to a person, or what an administrator can constrain by role. The platform's older automation is rules based and configured by the customer, which is bounded by construction because the customer authors the rule, and that covers most of what is deployed today. Ask what the retention agents can do without human approval, whether any of them communicate with a customer directly, and what the escalation rule is.
A dedicated artificial intelligence document exists and a buyer cannot read it without asking. The trust centre lists an overview covering the vendor's AI alongside its security and privacy documentation, which is more than most of this category maintains and indicates the questions have at least been answered somewhere in writing. It sits behind an access request.
On the open surface no model provider, family or version is named, no model card is published, and no accuracy or validation figure appears for the churn and health predictions that are the product's central claim. That last gap matters more here than the model naming does: a platform selling risk prediction into renewal decisions is asking a customer to act on a score, and nothing published describes how often the score is right. Ask for the artificial intelligence overview document, and for measured predictive accuracy of churn scoring against realised outcomes.
Scale and analyst standing are well evidenced, customer outcome is not. The vendor reports more than three thousand five hundred customers and more than one thousand two hundred employees, and holds leader positions in both major analyst evaluations of the category, which is genuine third party assessment of the vendor.
What is absent is the measurement the category turns on: no published study shows churn reduction or net revenue retention improvement against a stated customer population over a stated period, which for the platform that defined churn prediction is a conspicuous gap.
Independent review analysis pulls the other way on adoption, consistently reporting a steep learning curve, lengthy and resource intensive implementation, and a need for a specialist administrator to configure and maintain the system. That is a cost of ownership finding rather than an outcome finding, but it bears directly on whether the predicted benefit is realised. Ask for retention improvement measured across a stated cohort and period, and for median time from contract to first working health score.
Messaging goes to people who are already customers, which changes what this axis is asking without removing it. Journeys, lifecycle campaigns and in application messages are sent to an existing contractual relationship rather than to cold prospects, so the consent question is largely answered by that relationship and the sending volumes are small beside a marketing platform.
The obligations that survive are real and unaddressed on the public surface: nothing published states whether unsubscribe state is honoured across journeys, whether a customer contact who opts out of lifecycle mail continues to receive in application messaging, or how preferences travel between the success platform and the education and community products that also message the same people.
With six products able to contact the same person, a single suppression view is the thing a buyer would want and no document describes one. Ask whether opt out is honoured across all six products from a single preference record, or per product.
The privacy documentation set is complete in its named contents and gated in its substance. The trust centre enumerates a data processing agreement, a subprocessor list, a data protection impact assessment, a data privacy officer, a breach notification commitment and certificates of destruction, which is the full set a privacy review asks for and considerably more than most vendors name at all.
Naming a data protection impact assessment as a maintained artifact is unusual and indicates the assessment was actually performed rather than promised. The platform aggregates support tickets, product usage telemetry, survey responses, community activity and course completions against identified individuals at customer companies, so the stakes here are high and the documentation appears to match them.
What holds it below the top band is access: every one of those documents requires an approved request, so a buyer cannot confirm the contents, the transfer mechanism or the subprocessor identities before entering a sales conversation, and no transfer framework certification was located on the open surface. Ask for the processing agreement and current subprocessor list, and for the transfer mechanism covering European and Israeli processing given the office footprint.
The platform holds no licensed corpus of its own, which narrows this axis to how customer data moves between products. Everything the system reasons over is supplied by the customer or pulled from the customer's own connected systems, so there is no purchased database, no cooperative and no scraped source to trace.
The provenance question that does apply is internal and unanswered: the suite spans success, product analytics, education, community and conversation intelligence, and nothing published states whether data collected in one product is available to the others by default, whether community activity or course completion feeds the health score, or whether any of it crosses a tenant boundary for benchmarking.
A vendor holding six behavioural signals about the same individual owes a description of how they combine. Ask whether data flows between the six products by default or by election, and whether any cross customer benchmarking uses identified activity.
Integration runs entirely through sanctioned channels. Applications are published on the Salesforce marketplace and connected by delegated authorization that the customer grants and manages inside their own environment, with comparable official connectors to Zendesk, HubSpot and Gong. Nothing on the surface resembles stored credentials, headless browser automation or unsanctioned access.
The November 2025 token compromise is carried in this vendor's description and is not graded here as an event, since it originated at a different supplier whose product Gainsight used. Two aspects of it belong to this vendor and both are gradeable. On scope, the objects reachable through the connector were accounts, contacts, tasks, cases and engagement metadata, which is the working set a customer success platform needs to function, and nothing in the reporting identified permissions beyond that function. The connector used refresh tokens carrying persistent access, which is what made revocation consequential, and that is the standard pattern for background synchronisation rather than a decision particular to this vendor.
On disclosure the response is unusually complete for this index. A customer question set was published on the first day and maintained as a single consolidated post, a status page carried updates, and indicators of compromise were published alongside the platform owner's own. The vendor explained why an indicator set expands during a multi party investigation, so that growth in the list would not be misread as fresh compromise, which is a candid piece of communication aimed at the security reviewers actually reading it. Affected products were named individually and the record was corrected where a product had been disconnected as a precaution rather than affected. Two external forensic firms were engaged, customers were given specific credential rotation instructions, and the platform owner restored the integration on 10 December 2025, stating in its own advisory that the remediation had been independently validated by both firms.
What is missing is the durable artifact. The material lives in community posts and a status page rather than on the trust centre or the security pages, no permanent post incident writeup was located, and no stated scope reduction or customer facing continuity plan for a future revocation is published. Ask what the connector's permission scope is today, whether refresh token lifetime or scope changed as part of remediation, and what the continuity plan is if the connection is revoked again.
The corpus is one of the most sensitive in this index and the stewardship position covering it is behind a request. The platform aggregates, per identified individual at a customer company, support history, product usage telemetry, survey sentiment, community posts and training records, and the conversation agents add recorded customer interactions on top.
Whether any of that material trains or tunes models, whether it stays within a tenant, how long agent processed conversations are retained, and what happens to a departed individual's record are not addressed anywhere on the open surface. An artificial intelligence overview document exists in the trust centre and may answer some of it, but a document a buyer must apply to read cannot be graded as a published commitment.
Compared against the two vendors holding the top band on this axis, both of which hold an independently audited management standard for artificial intelligence, no equivalent certification is claimed here. Ask whether customer data trains or tunes any model, whether agent processed conversations cross a tenant boundary, and what the retention period is.
Communication reaches an existing customer under the sending company's own name, which is where the authenticity question mostly resolves. Journeys, lifecycle mail and in application messages are branded to the customer's business and go to people who already hold a contract with it, so there is no impersonation of a stranger and no cold contact to disclose.
The question moves rather than disappearing, because the vendor now sells conversation and sentiment agents and a services business for retention work. Nothing published states whether an agent generated message to a customer's customer is marked as machine written, whether a recipient interacting with one is told, or what happens when an agent handles a renewal conversation.
The older product is templated automation authored by a human, which is a different thing and covers most of what is live. Ask whether any agent generated communication reaches an end customer, and whether authorship is disclosed when it does.
Genuine bidirectional depth into four major systems, and the depth is the point rather than the count. The Salesforce connector reads and writes rather than exporting, publishing health scores and usage metrics back into the customer record system while pulling account and contact data out, and comparable connectors run to Zendesk, HubSpot and Gong.
Applications are published through the Salesforce marketplace rather than sideloaded, and a public documentation and support site carries product and configuration material per product. The six product suite shares a data layer, so a customer connecting once feeds success, analytics, education and community together, which is a real architectural claim rather than a connector list. Two limits hold it below the top band.
No developer documentation, interface reference or authentication model was reached on the routes taken this pass, so the programmable surface is unverified rather than absent. And the review evidence consistently reports that realising the integration depth requires a specialist administrator, which is a cost attached to the capability. Ask for the interface documentation and the current connector inventory.
Two recovery commitments published as numbers, and no residency answer at all. The trust centre states a recovery time objective of twenty four hours and a recovery point objective of eight hours. Publishing both as figures rather than referring to them in the abstract is uncommon in this index and is a real disclosure, because a buyer can hold a vendor to a number.
It also declares third party dependence openly and maintains network and data flow diagrams, though those require an access request. Against that, no hosting region is named on the open surface, no European or United Kingdom residency election is described, and no tenancy model is stated, while the company operates offices across the United States, United Kingdom, Netherlands, Israel and India, which raises a support access question that nothing published addresses.
For a platform holding the complete post sale history of a customer's entire book of business, where that sits and who can reach it from which country is a first order question. Ask which regions data can be pinned to, and whether support staff outside the region can access production customer data.
A live trust centre with a real certification set, and the documents themselves sit behind a request. Published on the face are certification to the international information security standard in its 2022 revision and a service organisation control type two report, alongside a listed penetration test report, a cloud security alliance consensus questionnaire, a standardised information gathering self assessment, cyber insurance evidence, and named control areas covering access monitoring, code analysis, secure development training, data backups and certificates of destruction.
The recovery objectives are stated as figures on the open page. A separately published support article for the product analytics component names the audit firm, an internationally affiliated accountancy practice, and states the three trust services principles it covered, which is the kind of specificity most vendors omit.
What holds it below the top band is the gating, and one detail sharpens it: the information security policy is marked as available by screenshare only, meaning a buyer may look at it while someone watches but may not retain a copy for their own review file. That is more restrictive than a standard access request. Ask for the current report with its audit period and auditor, and whether the security policy can be released under a confidentiality agreement rather than viewed on a call.
Named tiers with published limits and no price on any of them. The pricing page for the flagship product sets out two editions with defined user and customer record thresholds, so a buyer can see what they would be buying and cannot see what it costs, because every path ends at a request pricing form.
The one genuine exception sits on the product analytics component, which third party sources report offers a free starter tier up to one hundred monthly active users with paid steps above it, and that is a real self serve entry point rather than a demo request. It does not carry the flagship.
Third party procurement data converges more tightly here than for most vendors at this grade, reporting roughly one hundred and fifty dollars per user per month for the lower edition and three hundred for the upper, with a median annual contract near fifty thousand five hundred dollars across nearly three hundred verified purchases. The bill is not the licence.
Implementation is quoted separately at reported ranges from twenty thousand to one hundred and twenty thousand dollars, premium support is reported at eight to twelve percent of contract value and often required at the upper edition, annual escalation is reported at five to ten percent, and the analytics, community and conversation agent products are licensed separately. Ask for the per user rate at each edition, the implementation quote, whether premium support is mandatory, and the escalation cap.
One real exit artifact is named and the scope of what leaves is not described. Certificates of destruction appear in the trust centre listing, which is a genuine end of contract control and more than most vendors name, and data backups are listed as a documented area.
Everything else about departure is absent from the open surface: no statement of export scope or format, nothing on whether health score history, playbook configuration, survey responses, community content and course records come out or stay behind, no deletion timeline, and no renewal or termination notice terms. The exposure is specific and large in this category.
A mature deployment holds years of health history, a configured scoring model built by a specialist administrator, and the accumulated community and training content of the customer's own user base, and the review evidence describing lengthy specialist implementation is also describing how expensive that configuration would be to rebuild. Ask what exports, in what format, whether scoring configuration and historical health trends are included, and what the deletion timeline and notice period are.
The platform sends at modest volume to a known audience, and none of the sending discipline is described. Lifecycle journeys, surveys, in application messages and community notifications reach an existing customer base rather than a purchased list, so the reputational stakes are far lower than for an outbound product and the axis applies in a limited form. What is knowable is thin.
Nothing published states whether mail is sent from vendor infrastructure or the customer's own domain, whether authentication records are the customer's responsibility to configure, what bounce handling exists, or how sending reputation is isolated between tenants on shared infrastructure. Survey and notification traffic across six products to the same recipients is exactly the pattern that generates complaints if unmanaged. Ask which domain sends, who configures authentication, and what bounce and complaint handling applies.
A clearly drawn market with an explicit answer at both ends. The vendor serves a reported three thousand five hundred customers with more than one thousand two hundred employees, and offers a mid market edition alongside the enterprise one, so the smaller buyer is addressed by a named product rather than left to infer that the platform is too heavy for them.
The international footprint is substantive rather than a claim, with offices in the United States, United Kingdom, Netherlands, Israel and India, and the Indian operation is described by independent analysis as several hundred staff giving genuine time zone aligned coverage, which is unusual for a vendor of this size and origin.
Independent review analysis positions the platform as the default choice for business to business software companies above roughly fifty million dollars in recurring revenue with a mature success function, which is a sharper segment statement than the vendor makes itself. That is also the limit: the vendor's own pages do not state where the platform stops fitting, and the same independent analysis reports that lighter deployments struggle with the administrative burden. Ask what the smallest viable deployment looks like in seats and administrator time.
Pricing
What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.
- ›Gainsight does not publish what its main product costs. Its pricing page names two packages and tells you how many people and customer records each one covers, then asks you to fill in a form.
- ›Companies that track real purchases report about one hundred and fifty dollars per person per month for the smaller package and three hundred for the bigger one, with a typical yearly bill around fifty thousand dollars.
- ›The licence is not the whole cost. Setting it up is charged separately and can run from twenty thousand to over one hundred thousand dollars, better support costs extra, and the price usually rises five to ten percent every year.
- ›Most companies also need someone whose job is looking after the system, which is a real cost that never appears in a quote.
- ›One smaller Gainsight product, the one that analyses how people use your software, does have a free version for up to one hundred users a month.
How the price works
What you are charged for, and what makes the bill go up.
Per seat per month for the flagship product, billed annually, across two named editions with published user count and customer record limits but no published rates. Multi year contracts are common and reported to unlock discounts averaging around fifteen percent. Annual escalation is reported at five to ten percent. The product analytics, customer education, customer communities and conversation agent products are licensed separately from the flagship rather than bundled, and the analytics product is metered on monthly active users rather than seats.
What the contract says about your data
What the vendor commits to in writing once your data is in the product.
A data processing agreement, a subprocessor list, a data protection impact assessment and a breach notification commitment are all named in the trust centre, and each requires an approved access request to read. A data privacy officer is named as a maintained role. No transfer framework certification was located on the open surface. Note for a security review: the information security policy is listed as available by screenshare only, meaning it can be viewed on a call but not retained, which is more restrictive than the usual access request and worth raising early.
Getting started
What it costs and what is included before the product is running.
Quoted separately and not published. Third party sources report a wide range depending on deployment complexity and data source count, from roughly twenty thousand dollars to one hundred and twenty thousand dollars, commonly cited as adding twenty to forty percent to the first year total. Premium support is separately reported at eight to twelve percent of contract value and is described as frequently required at the upper edition.
Independent review analysis consistently reports that a dedicated specialist administrator is needed to configure and maintain the platform, which is a recurring internal staffing cost rather than a vendor fee and is not reflected in any quoted figure.
What to watch for
Where this pricing can surprise a buyer who has not read it closely.
The flagship customer success product publishes named editions with defined user and customer record limits and attaches no figure to either, routing every path to a request pricing form. That page resolved on retrieval, so the omission is deliberate rather than a rendering failure. One genuine exception exists and it is not the flagship: third party sources report that the product experience analytics component offers a free starter tier up to one hundred monthly active users with paid steps above it, which is a real self serve entry rather than a demo request, and that was not verified against the vendor page on this pass.
Third party procurement figures converge more tightly here than for most vendors at this grade, which is why they are recorded: roughly one hundred and fifty dollars per user per month for the lower edition and three hundred for the upper, and a median annual contract near fifty thousand five hundred dollars drawn from close to three hundred verified purchases.
A separate benchmark set reports averages near seventy nine thousand dollars for smaller buyers and two hundred and twenty six thousand for enterprise, and reports smaller buyer pricing rising sharply year over year. entryPriceUsd is left blank, consistent with the convention applied to the two preceding builds: the reported per user figures are third party estimates rather than a published rate, and the one genuinely published entry point sits on a separate product whose paid step was not confirmed on a vendor surface.