Data & Enrichment
G

GTM Workspace by ZoomInfo

GTM Workspace is ZoomInfo's unified account command centre for revenue teams, and the product the company positions as the execution layer sitting above its data. It combines records from the customer's own system of record with ZoomInfo's verified company and contact profiles, organisational charts, buying intent signals, buying group maps, website visitor identification and activity timelines into a single continuously refreshed view of every account, then applies agents that research accounts, monitor signals, draft follow ups, update fields and surface next best actions.

It sits alongside ZoomInfo Copilot, the seller facing agent it evolved from, and GTM Studio, the campaign orchestration surface built for revenue operations. ZoomInfo Technologies was founded in 2007, is headquartered in Vancouver, Washington, is listed on the Nasdaq exchange under the ticker GTM, employs more than 3,000 people and reports more than 35,000 customers. The wider platform spans the contact and company database, account based marketing and advertising, recruiting, data as a service, conversation intelligence and website chat. Pricing is published as six enumerated packages plus a credit consumption model, with no figures attached to any of it.

Founded
2007
Headquarters
Vancouver, WA, United States
Categories
data-and-enrichment, intent-and-signals, revenue-intelligence
Assessment

Capability Axes

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

Remove every model and what remains is the largest and most commercially established business contact database in this market, with search, filtering, export, browser extension, mobile application and enrichment into the customer's system of record.

That is a complete and saleable product, it is what the company sold for most of its eighteen years, and the vendor's own package ladder says so plainly: the entry tier is described as contact and company profiles with search and exporting, and the model driven capabilities are what a buyer moves up the ladder to acquire. The workspace product itself is an assembly and prioritisation layer over that data rather than a thing the data could not exist without. This is the established platform pattern applied to the largest vendor in the index, and the removal test separates it the same way it separates every other incumbent here.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
CC on Autonomy and Oversight ModelAutonomy is claimed or implied with the oversight model asserted rather than documented. Buyers cannot tell from public sources what runs unsupervised.
Vendor Published

The published framing is assistive rather than autonomous and that is what keeps this off the floor. Agents are described as surfacing next best actions, prioritising accounts, prepping meetings, assembling deal briefs, generating talking points and email openers, and prompting timely outreach, which places a person at the point of every outward action.

Two capabilities do act without a person: fields in the customer's system of record are updated automatically, and activity and reminders are logged automatically. Beyond that nothing is described. No approval gate, no confidence threshold on a prioritisation decision, no statement of what an agent may not do, no escalation path by risk, and no action level audit trail is shown to a buyer before purchase.

For a platform whose agents write into the customer's system of record across tens of thousands of accounts, the absence of a published governance mechanism is the notable gap rather than the absence of a published capability.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
CC on AI Disclosure and Model TransparencyThe product is described as AI powered with the stack, the disclosure behavior, and the scoring logic all unstated.
Vendor Published

The techniques are named generically and the substance stops there. The company states that it applies natural language processing, machine learning and data science to a multi layered real time verification process, and that models recommend next best actions, detect intent and personalise messages. No model provider is identified, no model or version is named, no inference location is stated, and no terms govern what is sent to any model.

The sharpest way to put it is that the company maintains a page whose entire purpose is telling external systems authoritative facts about itself, and that page does not say which systems it runs on. Adjacent artefacts do exist and are worth the buyer's time: a public engineering blog and a dedicated page describing data sources and verification. Neither answers the model question.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
AA on Operational and Outcome EvidenceMeasured outcomes published with their basis: sample, timeframe, and metric definitions stated, so a buyer can tell a measurement from a marketing number.
Vendor Published

The evidence base is the deepest in this index and most of it is verifiable outside the vendor's own control. The company is publicly listed, so its customer numbers, revenue and growth are filed and auditable rather than asserted. One review platform carries a rating of 4.5 out of 5 across more than 9,300 reviews, an order of magnitude larger than any other sample in this corpus.

Customer results are attributed to named individuals with job titles at named employers, including a sales development representative at Adobe crediting 43 percent of quota to a single connection, a seller at Amazon Web Services reporting pipeline growth of four times, MongoDB reporting sales cycles cut 30 percent alongside 25 percent revenue growth, and Capital One attributing a quarter of an annual quota to one intent signal. Case studies carry figures and named executives.

Recorded as defects rather than disqualifiers: no figure carries a method, period, baseline or sample; the customer count is given as more than 35,000 in one place and more than 30,000 in another on the same page; and the answer to whether the product is worth its price rests on a review platform award from autumn 2020, cited on a live 2026 page.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

The split here is unusually clean and it is the finding. On the rights of the person in the database, this vendor is the most developed in the index, with a functioning removal route, a sale and sharing opt out, automatic honouring of browser opt out preference signals, and a stated legal basis. On the rules governing the outreach that the database exists to produce, nothing is published at all.

The platform ships intelligent dialling, automated outreach workflows and generated email, and no sending or calling regulation is named anywhere: no commercial email statute, no consent standard, no do not call obligation attached to the dialling feature, no unsubscribe handling and no suppression process. A company that leads this index on what a person may demand of the record says nothing about the rules governing the call or the email that record is sold to enable. Some of the sending surface is routed to a named partner platform, which moves part of the obligation without discharging it.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
AA on Data Privacy PostureGDPR and CCPA posture documented with specifics: lawful basis stated, DSR handling described, DPA published and signable, subprocessors listed.
Vendor Published

This is the strongest data subject apparatus in the index and it is operational rather than declarative. A dedicated request subdomain carries four separate verified workflows: removal and deletion, an access request that returns a report of what is held, correction through claiming and updating a personal profile, and company record correction. Requesting removal also operates as an opt out of sale and sharing where the jurisdiction provides one.

Browser opt out preference signals are honoured automatically for site visitors. The legal basis is stated as legitimate interest rather than left implicit, the right to complain to a supervisory authority is set out for European, United Kingdom and Swiss individuals, and a named privacy address is published alongside the automated flows.

Most distinctive, and located nowhere else in this corpus: covered persons under New Jersey's Daniel's Law, the Oklahoma judicial security statute and comparable state laws protecting judicial and public officials are given a dedicated address for expedited non disclosure.

The honest qualifications, and they matter: none of this is consent, and the proactive notice is hedged twice over, applying only where the company already holds an email address and stating only that a person may receive it.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
AA on Data Licensing and ProvenanceThe vendor states where its data comes from, under what license or legal theory, and stands behind it contractually. Sources are classed (licensed, contributed, public record) and the answer survives scrutiny.
Vendor Published

Provenance is disclosed at two levels and both are unusual. At company level the vendor names four distinct source classes rather than gesturing at public sources: collection from across the web using its own technologies, specialist third party providers, community contributors, and an employed research team.

A dedicated data transparency page and a separate page describing the community contribution programme both sit in the site footer, so the contributed inventory model is named as a programme rather than buried in a policy clause. At individual level the published personal information notice enumerates the fields a European style notice requires, and it explicitly includes where the information was obtained, which is per subject provenance disclosed to the subject.

Alongside it sits a self serve report of everything held about a person. Held at the top band because the combination of a source taxonomy, a transparency page, a named contribution programme and a per subject sourcing disclosure is more than any other data vendor here publishes.

What is still absent, and should be re verified on the data sources page: individual suppliers are not named, the collection method is not described technically, and the terms a community contributor accepts when their address book becomes inventory are not summarised where a buyer would see them.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Vendor Published

The buyer does not carry the exposure here, which is the question this axis exists to ask. Data collection risk sits with the vendor, since the company gathers from the web using its own technologies under its own name rather than operating from a customer's credentials. Every integration named runs on official interfaces into systems of record, marketing platforms, warehouses and cloud providers, and the newer agent surfaces are formal partnerships.

There is no rotation of accounts, no automation of actions from a buyer's social profile, and no marketing that frames evasion of a platform's limits as a feature, so the failure modes that produce the low grades on this axis are absent. Two things hold it off the top band. No conformance position is published for the web collection method itself, on a company whose data estate has been the subject of sustained public argument.

And the community contribution programme means a customer's own employees can supply their address books as inventory, which creates an obligation running from that customer to its own contacts, and nothing in the public material frames that as a decision the customer's administrator should make deliberately.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
CC on AI Safety and Data StewardshipSecurity language exists but the training question, the one this axis turns on, is unanswered: a buyer cannot tell whether their pipeline data improves a competitor’s instance.
Vendor Published

The published position is assertion without mechanism. The company states that its data and model operations are governed by strict privacy standards with continuous monitoring and transparency, and that it adheres to the major privacy regimes. Nothing states whether customer data trains any model, whether analysis crosses tenants, whether there is a contractual retention position with any third party model provider, or what a customer may exclude from processing.

The corpus this question applies to is very large: a conversation intelligence product that records calls, a website chat product, agents that read the customer's own system of record, and a contact database assembled across tens of thousands of customers. The vendor has demonstrated on the privacy side that it will write precise, operational commitments when it chooses to, which makes the silence here a choice rather than an oversight. Several peers in this index now publish a plain sentence on the training question and one holds an audited management standard for it.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
BB on Recipient Disclosure and AuthenticityDisclosure is available and documented but not the default, or the persona and personalization posture is substantively addressed with one real gap, commonly silence on the Article 50 obligations that took effect in August 2026.
Vendor Published

On the disclosure half this is the best position any data vendor in the index holds, and it exceeds the previous benchmark. The person in the database can look themselves up in a public directory, request a report of what is held, claim and correct the record, or have it removed, all through verified self serve flows, and a personal information notice may reach them proactively where an email address is held.

Nothing in the product manufactures an identity: no synthetic voice, no invented persona, no assumed local presence. What holds it off the top band is the surveillance half, which is extensive and invisible to its subject. Buying intent, website visitor identification, job change and champion movement tracking, hiring activity, engagement history and relationship strength are assembled into an account timeline, and no notice reaches the individual whose promotion or site visit triggered an alert.

Generated outreach carries no stated position on the European transparency obligations that took effect in August 2026. Recorded as observed: website visitor identification is described as company level on the vendor's own information page while third party product descriptions reference person level visits, and those are materially different claims.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
AA on Ecosystem and Integration DepthDeep, documented, bidirectional integration with the systems of record: named CRM objects and sync behavior, a public API with real docs, and a marketplace presence that matches the claims.
Vendor Published

This is the deepest ecosystem surface in the index and it is the furthest ahead on the agent era question specifically. Conventional depth first: a marketplace on its own subdomain, an enterprise interface product, named connectors across the major systems of record and marketing automation platforms, a browser extension, a mobile application, alerting into the major team messaging tools, webhooks, and formal cloud partnerships delivering data shares into the leading warehouse and analytics platforms.

Then the part almost nobody else has built. Support for the emerging protocol that lets external agents query a vendor directly is sold as a named product in the top level navigation rather than shipped as a feature, a dedicated integration places the vendor's data inside a major consumer assistant as a named solution, a separate developer domain exists for building against the platform, and release notes record native connectors into a large cloud provider's agentic workspace and into a coding agent. A public status page and a public engineering blog sit alongside. Where most vendors here have one protocol server, this vendor has built a distribution strategy around being queryable.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
CC on Deployment Model and Data ResidencyCloud hosted is the whole public answer. Region and residency questions require a sales conversation.
Vendor Published

Where customer data is processed and stored is not stated on the public product surface. No region, data centre, residency commitment or residency option was located, and the only geography published is the company's own headquarters. The cloud platforms named on the data delivery pages are destinations a customer can have data pushed into rather than a statement about where the platform itself runs, and naming them should not be mistaken for a residency position.

This matters more than it would for a smaller vendor because the platform holds personal data on individuals across many jurisdictions and sells into European and United Kingdom markets where the transfer question is the first one a procurement team asks. The trust centre was not read in full on this pass and is the place to re verify before treating the absence as settled.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
BB on Security Certifications and Trust CenterCertifications named and plausible with a gap: no trust center, stale dates, or asserted without enumeration.
Vendor Published

A service organisation control report at type two is named with its type, which is the distinction that separates a real disclosure from a bare assertion and which several vendors in this index fail. A trust centre sits on the vendor's own domain, a public status page is linked in the site footer, and a public engineering blog exists.

Against that, the same page that names one certification also claims numerous security and privacy certifications without enumerating them, which is exactly the pattern that has held other vendors down: a buyer cannot rely on a count. No audit period, no auditor, no certificate or report access route, no penetration test statement, no vulnerability disclosure programme and no list of the other parties that process customer data were located on the pages read.

The security section of the trust centre was not read on this pass, and for a vendor of this scale it very likely carries more than has been credited here, so re verify there before relying on this row.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
DD on Commercial TransparencyBook a demo is the entire commercial disclosure. In a category this competitive, silence on price is a choice, and this grade records it.
Vendor Published

This is the most thoroughly documented pricing page in the index that contains no price, and the volume of genuine structural disclosure is what makes it remarkable rather than what rescues it. Published: six named packages across sales and marketing with their features fully enumerated, included credit allowances on two of them at 75,000 and 150,000, intent topic counts of 25, 100 and unlimited, advertising network limits, and a substantial explanation of the consumption model.

A credit is consumed on export of a company or contact profile, from the platform, the browser extension, or any interface call from any integration. Credits are explicitly not fungible, since deeper intelligence costs more per record than basic firmographics. Pre packaged integrations carry a base cost to install and require a minimum purchase of bulk credits, which is a rare admission of a mandatory cost. Intent is priced on keyword volume and account universe.

And there is not one currency figure anywhere: no seat rate, no credit rate, no package price, no floor, no range. The page headed with pricing and plans resolves to a form. The standing rule in this index is that publishing the meter without the rate is the bottom band, and this is that rule at the largest scale it has been applied to. Recorded as observed: the question of whether the product is worth its price is answered with case study percentages and a review platform award from 2020.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
CC on Exit and Data PortabilityExport exists as a feature claim while the terms that govern exit, data rights after termination, deletion, and auto renewal mechanics, are not published anywhere a buyer can read.
Vendor Published

Export is a first class product function rather than an afterthought, and the data as a service line goes further by delivering records into the customer's own warehouse and analytics platforms through interfaces, webhooks and cloud data shares, which is a genuine portability position for the customer's own environment. The complications are two.

Export of the vendor's records is metered, so retrieving data costs credits and the volume a customer can take is governed by what they bought rather than by what they hold. And nothing at all is published about the end of the relationship: no post termination retention period, no deletion timeline, no deletion confirmation, no statement of what happens to saved lists, workflows, engagement history or recorded conversations, and no statement of whether licensed records must be purged from the customer's warehouse when the licence lapses. That last question is the one a data licence makes urgent and the public surface does not reach it. Terms of use are published and were not read on this pass.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

The platform generates email, runs automated outreach workflows and ships intelligent dialling, so the axis applies, and no control is named against any of it. No sender authentication standards, no warm up, no volume pacing, no bounce or complaint handling, no blocklist monitoring and no placement measurement were located.

On the voice side, dialling at scale puts the customer's calling number at risk of carrier spam labelling and no caller reputation, attestation or number rotation position is published. One structural observation belongs here rather than as a criticism: the sales automation solution routes to a named partner platform rather than to a first party sending product, so a substantial share of the sending discipline question now sits with that partner. That transfers the obligation without discharging it, and a buyer evaluating the combination has to grade two vendors rather than one.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Vendor Published

Segmentation is done by buyer function and by depth of access rather than by company size, and at that it is precise. Three product families address distinct buyers, covering sellers, marketers and recruiters, and six packages beneath them are enumerated feature by feature so a buyer can see exactly what separates one from the next. A separate enterprise solutions track exists.

Published customer evidence spans the full range from the largest technology companies in the world down to a video production firm and a small advisory practice, which corroborates the breadth rather than merely claiming it. Held off the top band on the size question, where the vendor states it serves enterprise organisations, rapidly growing start ups and small businesses all at once, publishes no headcount band, no minimum and no ceiling, and gives a smaller buyer nothing to test themselves against. That is the claim the whole market pattern, and the counter example in this index remains the vendor that publishes the point at which a customer should leave for a bigger product.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

GTM Tech Index

An independent reference for evaluating the software revenue teams use to find, win, and keep customers. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 20, 2026
The GTM Tech Index is an editorial reference, not a law firm or a regulator. Compliance postures are assessed from published sources and public records, and nothing on the index is legal advice. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 GTM Tech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746