Conversation Intelligence
G

Gong

Gong created the revenue intelligence category and now sells what it calls a Revenue AI Operating System built on a data layer it calls the Revenue Graph, which connects calls, emails, meetings and records from the customer's system of record. The founding product captures and analyses customer conversations, producing transcripts, summaries, searchable history, coaching signals and deal risk flags. Around it sit a sequencing module, a forecasting module, an enablement module, a warehouse export product, an assistant, and an agent layer that automates follow ups and record updates.

The company reports annual recurring revenue above 500 million dollars, growth above 55 percent year on year for ten consecutive quarters, roughly 584 million dollars raised, and more than 5,000 customers including LinkedIn, Shopify, Snowflake, PayPal, DocuSign, Indeed, Rapid7, HubSpot and ADP. Its compliance surface is the deepest in this index and includes an independently audited artificial intelligence management system certification. Founded 2015. Pricing is not published.

Last VerifiedAugust 20, 2026
Compare Gong with other vendors
Founded
2015
Headquarters
San Francisco, CA, United States
Website
www.gong.io
Categories
conversation-intelligence, revenue-intelligence, sales-engagement
Assessment

Capability Axes

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
BB on AI CentralityAI carries a core workflow, with real product surface that is not AI. The vendor is specific about which parts are model driven.
Vendor Published

This is a genuine middle case and the band exists for it. Strip the model layer and something saleable does remain: a call recorder with storage, a searchable archive and a two way sync into the customer's system of record. That was the 2015 product and it is why this sits below the artificially intelligent native startups graded at the top of this axis. But what survives is emphatically not what the company sells now.

Transcription, summarisation, deal scoring, risk flagging, forecast validation, natural language search across the corpus, coaching signals and the agent layer that updates records and drafts follow ups are all model output, and independent commentary is blunt that recording and transcription are commodities in 2026 shipped by every meeting tool. The differentiating layer is the inference, and the company has renamed itself around it.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
BB on Autonomy and Oversight ModelThe human in the loop posture is described substantively (draft versus auto send, approval flows) but the failure containment story is incomplete.
Vendor Published

An agent layer now acts on the customer's systems, drafting follow ups, updating records in the system of record and executing custom agents at scale, so the autonomy question is live rather than theoretical. The counterweights are substantial and independently verified rather than asserted.

The company holds a certification against the international standard for artificial intelligence management systems, which requires documented governance including defined human oversight, and it publishes that a dedicated governance team works to a stated remit of ethical use, human validation and model oversight. Granular access permissions, configurable retention and auditability across the platform are all published controls.

Off the top band because the public surface describes governance at the programme level rather than the mechanism level: no per action approval architecture is documented for the agents, no description exists of what an agent may not do, and no audit trail of agent actions is shown to a buyer before purchase. The vendor graded highest on this axis publishes engagement rules, guardrails that withhold a violating output, and an action level audit trail.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
BB on AI Disclosure and Model TransparencyMeaningful disclosure of the model stack or the disclosure posture, with one real gap, commonly silence on whether AI authored outreach identifies itself.
Vendor Published

The distinguishing credit is a certification against the international standard for artificial intelligence management systems, published on the vendor's own trust page and backed by independent audit. That is the strongest governance artefact currently available for a model driven product and it is the first instance of it in this index.

Around it sit a dedicated governance team with a published remit, a stated commitment that insights are explainable, an openly disclosed basis that some insight is grounded in patterns observed across aggregated customer usage, published writing on the company's responsible development approach, and an artificial intelligence governance section in the trust centre with downloadable documentation.

Off the top band on the specifics this axis asks for rather than on the programme: no model provider, family or version is named on the public surface, and no accuracy or error rate is published for the deal scoring or the forecast validation, which are the two outputs a revenue leader would act on. A certified management system attests to process, not to how often the score is right.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
AA on Operational and Outcome EvidenceMeasured outcomes published with their basis: sample, timeframe, and metric definitions stated, so a buyer can tell a measurement from a marketing number.
Vendor Published

The evidence base here is the broadest graded in this index and it spans four independent kinds. Corporate performance is published and checkable rather than asserted: annual recurring revenue above 500 million dollars, growth above 55 percent year on year sustained across ten consecutive quarters, and roughly 584 million dollars raised. Named customers run to more than 5,000 and the ones published include LinkedIn, Shopify, Snowflake, PayPal, DocuSign, Indeed, Rapid7, HubSpot and ADP.

Third party review scores are displayed from three separate platforms with the figures shown rather than a badge. Case studies carry named individuals with titles at named companies, and the company runs its own published research function producing dated studies with stated methodology and sample sizes.

Two honest caveats recorded without moving the grade: the outcome percentages most often quoted for this product originate with the vendor, and independent commentary on two of the newer modules, the forecasting and sequencing lines, is markedly cooler than on the founding product.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

The sequencing module sends email to prospects, so the axis applies squarely to one part of the platform, and the vendor's extensive compliance apparatus is aimed almost entirely elsewhere. The certifications, the privacy configurability and the governance programme all address data protection and model governance rather than the duties owed to somebody receiving a sequenced message.

Nothing published states a consent standard, an unsubscribe mechanism, a suppression process or a named sending regulation. The gap is more conspicuous here than for a smaller vendor precisely because the surrounding compliance record is so complete: a company that certifies against five separate international standards has plainly decided this particular obligation sits with the customer, and does not say so.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
AA on Data Privacy PostureGDPR and CCPA posture documented with specifics: lawful basis stated, DSR handling described, DPA published and signable, subprocessors listed.
Vendor Published

This is the strongest privacy record graded in the index and almost all of it is independently attested rather than claimed. Two separate privacy certifications are held, one for privacy information management and one specifically for the protection of personal data in public clouds by a processor, which is the exact role this vendor occupies.

The transfer position is current and verifiable: the company is certified under the European and United States data privacy framework and links to the official government register where that certification can be checked, which is the correct handling of the question that has caught several vendors in this index still citing frameworks invalidated years ago.

On the control side the buyer gets configurable privacy rules by region, by role and by use case, custom retention settings, and custom redaction that lets regulated organisations exclude categories of content from analysis altogether. Health information privacy and the payment card standard are covered. The trust centre carries published answers on retention and on which additional parties process customer data. A published privacy policy sits under all of it.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
BB on Data Licensing and ProvenanceProvenance is substantively described but incompletely: sourcing classes named without the legal footing, or indemnification unstated.
Vendor Published

No contact database is bought, built or resold and the platform supplies no prospects: the corpus is the customer's own conversations, messages and records. What lifts this above a bare pass is a disclosure most vendors in this position simply omit. The company states openly that some of its insight is grounded in patterns observed across aggregated customer usage, and it publishes research derived from that aggregate.

Saying so is more honest than the silence recorded elsewhere in this index where marketing implies a cross customer corpus and documentation never mentions it. Off the top band because the disclosure is not bounded on the public surface: nothing states what is included in the aggregate, whether a customer may decline to contribute, or how the boundary between aggregate pattern analysis and model improvement is drawn. The people recorded on the calls are third parties whose participation rests on the customer's own consent obligations, and no notice or access route for them is described.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Vendor Published

Everything runs on the vendor's own infrastructure and connects outward through sanctioned routes: official meeting platform integrations for capture, a two way system of record sync, a partner and integrations marketplace on its own subdomain, availability in a major cloud provider's own marketplace, and support for the Model Context Protocol so external artificial intelligence systems can be connected under the customer's control.

No credential is borrowed, nothing is scraped and nothing is paced to evade another company's limits. Off the top band because no conformance position is stated in either direction. The product's founding capability depends on recording access granted by third party meeting platforms, and nothing published addresses what happens to a customer's archive or capture if one of those platforms changes its recording or retention rules.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
AA on AI Safety and Data StewardshipThe cross client boundary is answered in writing: whether customer data trains shared models, with opt out or contractual exclusion documented, plus retention and deletion specifics.
Vendor Published

The commitment this axis exists to find is stated plainly on the vendor's own trust page: customer data is never used to train generative models. It is not hedged, not buried and not left to inference, and the trust centre poses the same question as a standing item with published documentation behind it.

Underneath it sits the strongest structural backing available: a certification against the international standard for artificial intelligence management systems, independently audited, plus a dedicated governance team with a published remit covering ethical use, human validation and model oversight. The control surface matches the commitment. Customers can bring their own encryption key, so the vendor holds the data without holding the means to read it unilaterally.

Custom redaction lets regulated organisations remove categories of content before analysis. Retention is configurable. Additional processing parties are addressed as a published question. One tension is recorded without moving the grade, because a buyer should see it: the company also states that insight is grounded in patterns observed across aggregated customer usage, and the boundary between aggregate pattern analysis and model improvement is not drawn on the public surface.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
CC on Recipient Disclosure and AuthenticityNothing published on whether recipients are told they are dealing with software. For a product whose AI talks to prospects, silence here is now a regulatory posture, not a style choice.
Vendor Published

This is the weakest row on an otherwise exceptional compliance record, and the gap is specific. The founding product records conversations in which one side is a customer or prospect who is not the buyer of the software, and the public surface does not state the vendor's own position on telling that person.

What is published is the configurability that a customer would use to comply: privacy rules tunable by region, by role and by use case, which is the mechanism by which differing consent regimes get handled, plus redaction. What was not located is any statement that the recorder announces itself, joins as a named participant, or that consent is captured before capture begins.

The comparison inside this index is direct and it is why this sits in the middle band: a smaller conversation intelligence vendor graded here publishes that its recorder joins as a named participant and announces its presence, answers the consent question directly, and supports consent first workflows. Separately, the sequencing module drafts follow up email with no stated disclosure, and the European transparency obligations that took effect in August 2026 are not mentioned. Re verify at the trust centre, where a stated position may exist.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
AA on Ecosystem and Integration DepthDeep, documented, bidirectional integration with the systems of record: named CRM objects and sync behavior, a public API with real docs, and a marketplace presence that matches the claims.
Vendor Published

The integration surface is deep in every direction a buyer might need and, unusually for a vendor at this price point, it is not monetised. The pricing page states plainly that a customer can integrate their existing technology stack for free, which is the direct inverse of another vendor graded in this same session where every system of record connector is a separately chargeable add on.

Around that sit a partner and integrations marketplace on its own subdomain, a two way sync with the system of record, a warehouse export product that pushes enriched data into the customer's own data platform, availability inside a major cloud provider's marketplace, published multilingual support, and support for the Model Context Protocol so external artificial intelligence systems can be connected under the customer's own controls.

That protocol support is the sixth instance recorded in this index and the first from a vendor of this scale. One caveat carried from independent review commentary rather than the vendor: the sequencing module is criticised by reviewers for a thin interface surface and limited connection to third party dialers, so the depth is not uniform across every product line.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
BB on Deployment Model and Data ResidencyThe deployment model is clear and residency options are partially specified.
Vendor Published

The control set is stronger than the geography disclosure, and the strongest control substantially answers the underlying concern. Customers can bring their own encryption key, which means the organisation retains cryptographic control over its own corpus regardless of where that corpus physically sits, and that is a more meaningful answer than a named region for many buyers.

Alongside it sit configurable privacy rules by region, custom retention settings and redaction, all of which imply and require a multi region architecture. Off the top band because the geography itself was not located on the pages read: no region list, no data centre location, no infrastructure provider and no explicit residency commitment appears on the public product surface, and the trust centre is the stated route to that documentation rather than the site itself. Re verify there before relying on this row for a buyer with a hard residency obligation.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
AA on Security Certifications and Trust CenterA live trust center with enumerated, current certifications (SOC 2 Type II and peers), audit recency visible, and security practices documented beyond the badge.
Vendor Published

This is now the deepest security record in the index. Nine certifications and attestations are published on the vendor's own page with each one named and explained: a service organisation report at type two, the international information security standard at its current 2022 revision, the cloud controls extension, the standard for protecting personal data in public clouds, the privacy management standard, the artificial intelligence management standard, the payment card standard, health information privacy, and a listing in the Cloud Security Alliance registry, plus certification under the European and United States data privacy framework with a link to the official government register.

The infrastructure around them matches: a trust centre on its own subdomain offering downloadable certifications, audit reports and policies rather than gating them behind a sales conversation, a published Office of the Chief Information Security Officer with a direct contact address, a public system status page, a dedicated vulnerability disclosure programme on its own subdomain, and a stated uptime figure.

The control description is specific rather than generic, covering encryption, multi factor authentication, least privilege access, real time monitoring, threat detection and redundancy, and it extends to customer held encryption keys. Worth recording for contrast within this same session: two other vendors here still cite the retired 2013 revision of the information security standard, and this one cites the current revision.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
DD on Commercial TransparencyBook a demo is the entire commercial disclosure. In a category this competitive, silence on price is a choice, and this grade records it.
Third Party Estimated

The pricing page publishes the model and withholds every number, which is the pattern this band exists to record and the sharpest instance of it at this scale. A buyer learns three things: licences are priced per user, a platform fee applies and scales with the number of users supported, and integrations are included at no extra cost. That third disclosure is genuinely useful and is credited on the ecosystem row.

What follows is a form, and the form is gated behind a segmentation step requiring the buyer to declare their team size band before it will even load, so the vendor qualifies the lead before disclosing anything. No rate, band, floor, currency, example or range appears anywhere.

Independent procurement commentary reports a per seat figure in the low thousands of dollars annually, a separate platform fee reported to have risen substantially in 2025, a one time onboarding fee, a usage meter introduced in 2026 for model processing that sits on top of all three, annual or multi year contracts paid in advance with no monthly option and no self serve trial, and early termination charges representing a large share of remaining contract value. Those figures are third party and several of the sources are competitors, so they are recorded as reported rather than adopted. The grade rests on the vendor's own page, not on them.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
CC on Exit and Data PortabilityExport exists as a feature claim while the terms that govern exit, data rights after termination, deletion, and auto renewal mechanics, are not published anywhere a buyer can read.
Vendor Published

Terms and conditions are published and linked from every page and a retention policy is addressed as a standing question in the trust centre, so the governing instruments exist and are reachable. Two real portability mechanisms are published: configurable retention settings that let a customer control how long material is held, and a warehouse export product that pushes enriched data into the customer's own data platform continuously, which means the derived intelligence accumulates outside the vendor by design rather than on request.

What is not established on the vendor's own surface is the termination half: no export format for the underlying conversation archive, no post termination retention window and no deletion timeline was located. Independent procurement commentary reports multi year agreements paid in advance carrying early termination charges representing a large share of the remaining value, which if accurate is a material constraint that the vendor does not publish. Those reports are third party and partly competitor sourced, and are recorded as reported rather than adopted.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

The sequencing module sends email from the customer's own domains, so sender reputation is genuinely at stake, and nothing about protecting it is published. No warmup ramp, bounce handling, complaint rate threshold, sender authentication guidance, throttling policy or reputation monitoring was located, and no position is stated on what happens when a customer's sending degrades.

That silence is the more notable because the platform holds the engagement data that would make such monitoring straightforward to offer. Independent review commentary describes this module as the least developed line in the portfolio and notes limited connection to third party dialers, which is consistent with a sending surface that has not received the same attention as the analytical one.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Vendor Published

Segmentation is published on two dimensions and both are concrete. Nine solution pages address distinct buyers and sectors, covering revenue leadership, revenue operations, sales, customer success, enablement, technology, financial services, healthcare and manufacturing. The pricing form publishes an explicit size ladder in four bands running from one to fifty users up to ten thousand and above, which is an unusually direct statement of the range the company will serve.

Multilingual support has its own page and the named customer list spans several continents and industries. Off the top band on the pattern that has held others here down, and this instance is unusually sharp. Offering a one to fifty band claims the small end of the market, while independent analysis of the actual cost structure concludes the economics only work above roughly fifty representatives with high contract values and rarely work for a ten person team. A vendor graded at the top of this axis elsewhere in this index publishes its own ceiling and tells buyers when to leave. This one publishes a floor it is unlikely to serve well.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

GTM Tech Index

An independent reference for evaluating the software revenue teams use to find, win, and keep customers. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 20, 2026
The GTM Tech Index is an editorial reference, not a law firm or a regulator. Compliance postures are assessed from published sources and public records, and nothing on the index is legal advice. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 GTM Tech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746