Intent & Signals
L

Leadfeeder

European business to business website visitor identification and sales intelligence platform. The core product identifies which companies are visiting a customer's website and matches them against company records sourced from official national trade registers, then supports prospecting, advertising campaigns and customer record hygiene through further modules.

The distinguishing asset is European data provenance. Company records originate in official registers including the German commercial register, the Austrian company register, Swiss commercial registries and the United Kingdom companies register, across more than thirty national sources, with per record traceability back to the legal source and a stated commitment that all data is stored and processed on servers within the European Union. That posture is the reason the platform holds its position in German speaking and Nordic markets, and it comes with an acknowledged trade off of thinner personal phone coverage than vendors with a more aggressive collection stance.

Brand history matters for anyone searching. Leadfeeder was founded in Finland in 2012 and merged with the German company intelligence business Echobot in 2022, with the combined company trading as Dealfront from April 2023. On 24 March 2026 the company unified everything back under the Leadfeeder name, the former domain now redirects, and logins moved accordingly. The legal contracting entities were unchanged throughout and remain Dealfront Group GmbH and its subsidiaries. A visitor identification business, WiredMinds, was acquired in March 2025 and is not separately indexed here.

Last VerifiedAugust 30, 2026
Compare Leadfeeder with other vendors
Founded
2012
Headquarters
Germany
Categories
intent-and-signals, data-and-enrichment
Assessment

Capability Axes

Capability grades

17 of 17 axes rated · 9 graded A or B

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

A matching and records business with an AI layer added recently on top. The core operation is resolving a website visitor's network address to an organisation and joining that organisation to a record sourced from an official register, which is deterministic lookup against authoritative data rather than inference, and it is what the product has done since 2012.

Register sourced company records, financial filings, ownership structures and industry classifications are retrieved rather than predicted. The vendor does market AI capabilities and maintains a dedicated page describing how they work, and enrichment and scoring layers use modelling, but stripping all of it leaves visitor identification, the register database, the browser extension and the customer record hygiene module intact and saleable.

That is the incumbent pattern rather than the model native one, and the accurate reading is that the data acquisition is the asset and the modelling assists it. Ask which capabilities stop working entirely without the AI layer, and whether any AI features carry separate cost.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
CC on Autonomy and Oversight ModelAutonomy is claimed or implied with the oversight model asserted rather than documented. Buyers cannot tell from public sources what runs unsupervised.
Vendor Published

Automation is triggered rather than agentic, and the boundary around it is not published. Workflows fire when a company matching defined criteria visits the site, pushing records into a customer record platform or notifying a team, which is rule based execution the customer configures rather than a system exercising judgement. The advertising module runs campaigns against identified audiences, which spends budget automatically once configured.

Neither contacts an individual directly on the vendor's own initiative. What is unaddressed is the surrounding governance: nothing published states what an administrator can constrain, whether spend on the campaign module carries a ceiling the operator sets, or what review applies to the AI features the vendor separately documents. The scope limits the exposure rather than the vendor's controls doing so. Ask what caps apply to automated campaign spend, and what an administrator can disable across the AI features.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
CC on AI Disclosure and Model TransparencyThe product is described as AI powered with the stack, the disclosure behavior, and the scoring logic all unstated.
Vendor Published

A dedicated disclosure page exists and its contents were not reachable on this pass. The vendor publishes a page specifically covering how its AI features work, what data they process, how privacy is protected and how compliance with the European artificial intelligence regulation is ensured.

Maintaining a standing document that addresses that regulation by name is uncommon in this index and indicates the questions have been answered somewhere in writing, particularly for a vendor whose entire position rests on European regulatory posture.

What could not be established on the routes taken is any of the substance: no model provider, family or version is named in the material reached, no model card was located, and no accuracy figure appears for the visitor to company matching that the product depends on. That last gap matters because a mis-resolved visitor attributes one organisation's browsing to another, and every downstream action inherits the error.

This grade records what a buyer could establish on this pass rather than asserting the disclosure is absent. Ask for the AI features documentation, which models process customer data, and the measured accuracy of visitor to company resolution.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
CC on Operational and Outcome EvidenceOutcome claims are headline percentages with no stated basis, or customer logos standing in for results.
Third Party Estimated

Scale is well evidenced and performance is not. More than fifteen thousand business customers are reported, including several recognisable software companies named on the vendor's own pages, and the customer base concentrates visibly in the European markets the product targets, which corroborates the positioning rather than merely asserting it. Independent review coverage is extensive across the visitor identification category.

What is absent is measurement of the thing the product does: no published match rate for visitor to company resolution, no coverage figure by country, no accuracy measure for register sourced records, and no study showing pipeline or conversion effect across a stated customer population and period. For a product whose value is entirely a function of how many visitors it can identify and how accurately, the match rate is the foundational number and it does not appear. Ask for the identification match rate by country, the accuracy of register sourced records, and conversion effect measured against a stated population.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

The platform identifies and advertises rather than sending, which narrows this axis without emptying it. No email sequencer or dialer operates here, so consent capture, suppression and unsubscribe handling execute in whatever systems a customer uses downstream.

The advertising module places campaigns against identified audiences, where the applicable rules are the advertising industry's rather than the direct messaging statutes, and nothing published describes what conformance position governs that activation. The identification layer itself resolves to organisations rather than individuals, which limits what a customer receives to act on and is a real structural mitigation.

What is missing is the handoff statement: nothing describes what obligations the vendor considers to transfer to a customer that combines visitor identification with contact data and begins outreach, which for a vendor whose entire differentiation is compliance posture is a conspicuous omission. Ask what the vendor's stated position is on using visitor identification as a basis for outreach, and what governs the advertising module's audience activation.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
AA on Data Privacy PostureGDPR and CCPA posture documented with specifics: lawful basis stated, DSR handling described, DPA published and signable, subprocessors listed.
Vendor Published

Certification, contract and a named accountable person, with the documents published rather than described. The privacy information management standard is certified alongside the information security standard, which is the specific certification covering how privacy is managed rather than only how data is secured.

A processing agreement is published, and a second version incorporating the European standard contractual clauses is published separately for customers interacting with the vendor's United States entity, so the transfer question is answered with a document rather than a paragraph. A group data protection officer is named as an individual, identified as also holding the information security management role, and carrying a recognised European privacy practitioner credential.

Registration as a data broker in the United States is disclosed on the vendor's own privacy pages together with the rights of United States residents and how to exercise them, which is a disclosure many vendors in this category make only where a regulator compels it. A consolidated legal kit and a privacy contact address are published. Two limits are worth stating.

No published request metrics or response times were located, where the comparable records at this grade publish counts and median response times. And no notification practice is described for individuals whose details enter the contact database, which is the disclosure a peer vendor in this index does publish. Ask for request volumes and response times, and what notice reaches individuals added to the contact layer.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
AA on Data Licensing and ProvenanceThe vendor states where its data comes from, under what license or legal theory, and stands behind it contractually. Sources are classed (licensed, contributed, public record) and the answer survives scrutiny.
Vendor Published

Provenance is traceable to the individual record and the sources are named institutions rather than categories. Company data originates in official national trade registers, with the German commercial register, the Austrian company register, Swiss commercial registries and the United Kingdom companies register all identified by name across more than thirty national sources, and the vendor states that each record carries traceability back to its public legal source.

That is a stronger claim than any aggregate description of sourcing, because it means a buyer challenged on where a record came from can answer for that record rather than for the corpus. The layering is described rather than blurred: registers form the foundation, public web data enriches, and directory records cross reference.

The lawful basis is stated as legitimate interest and the vendor's own framing is that this is built into the data model rather than added afterward, which is consistent with sourcing from records that are already public by law. The honest limits belong on the record.

Register sourcing covers company and officer information, so the personal contact layer rests on the enrichment tier rather than on the registers, and independent analysis notes the resulting trade off of thinner personal phone coverage than vendors collecting more aggressively. No indemnification position was located. Ask which sources supply the personal contact layer as distinct from the register sourced company layer, and whether provenance is indemnified.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Third Party Estimated

The core asset is sourced from public legal records, which removes the exposure this axis usually measures. Register data is published by statute and gathered from official sources rather than extracted from a platform whose terms could be withdrawn, so the largest part of the corpus carries no platform dependency at all.

Around it sit conventional integrations into named customer record platforms and a published interface, with the prior generation retained as a legacy interface after the rebrand, which is orderly rather than disruptive. Two components hold it below the top band because their method is not described.

A browser extension is offered free and independent analysis describes it being used for prospecting on a professional network, and nothing published states what it collects or under whose terms it operates, which is precisely the pattern the grading convention treats cautiously. And independent analysis describes the register foundation as enriched with web scraped signals, without the vendor describing what is scraped or from where. Ask what the browser extension collects and under which platform terms, and what the web enrichment layer scrapes.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
CC on AI Safety and Data StewardshipSecurity language exists but the training question, the one this axis turns on, is unanswered: a buyer cannot tell whether their pipeline data improves a competitor’s instance.
Vendor Published

The governing documents exist and their contents were not reachable. A dedicated page addresses the AI features and their compliance with the European artificial intelligence regulation, and the privacy information management certification covers how personal data is handled across the organisation, so the framework is in place.

What could not be established on this pass is the specific position: whether customer data or visitor records train or tune any model, which providers process material when AI features run, what retention applies to model inputs and outputs, and whether anything crosses a tenant boundary. The corpus is less sensitive than several vendors in this cohort, since the register foundation is public record and identification resolves to organisations, which limits the exposure inherently.

No independently audited management standard for artificial intelligence is claimed, where two vendors in this index hold one and publish the certificate. Ask whether customer or visitor data trains or tunes any model, which providers process it, and what retention applies.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
BB on Recipient Disclosure and AuthenticityDisclosure is available and documented but not the default, or the persona and personalization posture is substantively addressed with one real gap, commonly silence on the Article 50 obligations that took effect in August 2026.
Vendor Published

The default resolves to a company rather than a person, and the rights route for individuals is published where a regulator can check it. Visitor identification returns the organisation behind the traffic rather than naming the individual browsing, which is a design choice that keeps most of the platform's operation outside the person level identification that competitors in this lane market as a headline capability.

Where individuals do appear, they largely appear as company officers whose details already sit in public legal registers, so the person has a materially different relationship to the data than someone profiled from behavioural observation.

On the disclosure side the vendor publishes its United States data broker registration alongside a statement of what personal information it collects, the rights of United States residents, and how to exercise them, which is an active disclosure rather than a buried notice.

Held below the top band because the enrichment tier does hold personal contact details sourced beyond the registers, and no notification practice is described for those individuals, where a peer vendor in this index states that it notifies people of their inclusion within the statutory window. Ask what notice reaches individuals in the contact layer who were not sourced from public registers.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
BB on Ecosystem and Integration DepthSolid primary CRM integration documented, with depth unstated at the edges (sync direction, custom objects, failure behavior).
Vendor Published

A multi module platform with integration treated as the delivery mechanism rather than an accessory. Named connectors reach the major customer record platforms, a published interface is maintained with the previous generation retained as a legacy version so existing integrations did not break at the rebrand, and a free browser extension surfaces company profiles, contact details and customer record data inside whatever tab the user is working in.

A separate module handles ongoing customer record hygiene, deduplicating, flagging stale entries and enriching on a schedule within the same European hosted infrastructure, which is a genuine architectural claim rather than a connector count. Workflow triggers fire on visits from high intent companies.

Held below the top band on verification and gating: no interface documentation, authentication model or rate limits were reached on this pass, no integration inventory was counted, and the modules are separately licensed so the integration surface a buyer receives depends on which parts of the platform they bought. Ask for the interface documentation and which modules are included at the tier quoted.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
BB on Deployment Model and Data ResidencyThe deployment model is clear and residency options are partially specified.
Vendor Published

An absolute residency commitment, without the architecture around it. The vendor makes a named promise that all data is stored and processed on servers within the European Union, applying across both the sales intelligence and visitor identification products and to data generated by customers within the platform.

That is a guarantee rather than an option, and it is the strongest form the answer can take for a European buyer, because there is no configuration to get wrong and no region to elect. Independent analysis treats it as the platform's defining procurement advantage over vendors headquartered elsewhere. Held below the top band because the commitment stands alone.

No specific country or data centre region within the Union is named, no tenancy or isolation model is described, no recovery time or recovery point objective is published, and no deployment options beyond the hosted service are offered. The record already holding the top band on this axis earned it with deployment optionality and two levels of tenant isolation including physical separation, which is a different and more detailed answer than a single jurisdictional guarantee. Ask which member states host the infrastructure, what the tenancy model is, and what the recovery objectives are.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
AA on Security Certifications and Trust CenterA live trust center with enumerated, current certifications (SOC 2 Type II and peers), audit recency visible, and security practices documented beyond the badge.
Vendor Published

The artifacts a security reviewer actually asks for are published as files rather than released on request. A downloadable security kit contains the certificate files themselves for both the information security standard in its 2022 revision and the privacy information management standard, alongside the vendor's own information security policy, an overview of its bug bounty programme and a detailed question set.

Publishing the information security policy openly is notably more forthcoming than the norm, and one vendor already in this index releases the equivalent document only by screenshare. Separately the vendor has completed the cloud industry consensus assessment questionnaire, stated at two hundred and sixty one questions, and publishes the completed submission file, which is the artifact enterprise procurement teams send and rarely receive back without a confidentiality agreement.

A bug bounty programme runs and an accountable security manager is named. The ceiling and one honest caveat. No service organisation control report is claimed, which is a market fit choice for a European vendor whose buyers ask for the international standards rather than the American attestation, and no penetration test report or subprocessor list was located.

The certificate files were not opened on this pass, so the certifying body and validity periods are unverified here even though publishing the files is what earns the grade. Ask for the current certificate validity dates and the certifying body, and whether a penetration test summary and subprocessor list are available.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
BB on Commercial TransparencyPartial pricing published (entry tiers real, enterprise opaque) or pricing published with load bearing exclusions.
Vendor Published

One half of the platform is priced properly and the other half is quote only, which the vendor itself operates as a deliberate split. Published for the visitor identification line: a free tier that is permanent rather than a trial, showing the most recent hundred identified companies with a week of history, then three paid tiers at seventy nine, three hundred and sixty nine and five hundred and ninety nine euros per month on annual billing, with monthly rates published separately at one hundred and thirteen and five hundred and twenty seven for the lower two and the top tier annual only.

A fourteen day trial requires no card. That is real disclosure in both billing cycles with a genuine free entry path. The sales intelligence side, covering the company database, the browser extension and the customer record hygiene module, carries no published price at all and is quoted, so a buyer wanting the register sourced data that differentiates this vendor cannot budget it. Independent review roundups flag that split consistently.

A further gate matters for the priced line: contact level capabilities sit two tiers above the entry plan, so the seventy nine euro rate buys company identification rather than the ability to act on it. Ask for the sales intelligence pricing, and which tier is required for contact level access.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
CC on Exit and Data PortabilityExport exists as a feature claim while the terms that govern exit, data rights after termination, deletion, and auto renewal mechanics, are not published anywhere a buyer can read.
Vendor Published

Nothing published addresses leaving. No statement of export scope or format was located, nothing describes whether identified visitor history, enriched company records, audience definitions and campaign performance data leave with a departing customer, and no retention period, deletion timeline or notice term appears. Two exposures are specific here.

Register sourced company records were licensed rather than owned, so what a customer may lawfully retain and continue using after termination is a real question and one this vendor is better placed than most to answer given its provenance work. And the customer record hygiene module writes enriched values directly into the customer's own system throughout the term, so enriched data will already sit outside the platform at termination with no published statement about what happens to it.

The recent brand transition confirmed that contracts and entities carried over unchanged, which is reassuring about continuity and silent about exit. Ask what licence attaches to enriched and register sourced records after termination, what exports and in what format, and the deletion timeline.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

No sending infrastructure exists. The platform identifies visitors, supplies company and contact data and runs advertising campaigns, and where a customer sends email or calls a prospect that happens in systems the customer operates on their own domains and estate. There is no pooled sending, no shared reputation and none of the warmup, rotation or bounce machinery this axis normally examines.

The nearest analogue is the advertising module, where the equivalent questions are inventory quality, viewability and invalid traffic filtering, and nothing published addresses any of them. On the data side the contribution to a customer's own deliverability is the accuracy of supplied contact details, and no verification method or freshness window is published for that layer, which is the variable that decides bounce rates downstream. Ask what verification applies to contact records and how recently they are reverified, and what invalid traffic filtering applies to the advertising module.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Third Party Estimated

The served market is stated narrowly and the vendor accepts the trade off that comes with it. Positioning is explicitly European, with depth concentrated in German speaking, Nordic, Benelux and United Kingdom markets, and the register sourcing that produces that depth is the same choice that limits reach elsewhere.

Independent analysis is consistent that this is the correct choice for teams selling into Europe with a compliance requirement, and the wrong one for global reach, and the vendor does not contest that framing. More than fifteen thousand customers are reported including several recognisable software businesses.

The commercial ladder covers the range genuinely, from a permanent free tier through three published paid tiers to a custom enterprise arrangement, so the smallest buyer is served by product rather than by trial. Held below the top band because the boundary the vendor states is geographic while the boundary that bites is capability: the entry tiers identify companies without providing contact level access, so a small team buying at the published rate gets a narrower product than the platform description implies, and no statement addresses that. Ask what the smallest deployment is that includes contact level access and register sourced company data.

Commercial

Pricing

What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.

What it costs
Vendor Published
79 euros per month, Discover tier, billed annually
In short
  • Leadfeeder publishes prices for half of what it sells and not the other half.
  • The website visitor part has real prices. There is a free version that never expires, showing the last hundred companies that visited you. Then plans at seventy nine, three hundred and sixty nine and five hundred and ninety nine euros a month if you pay yearly. Paying monthly costs more, and the biggest plan is yearly only. You can trial it for fourteen days without a card.
  • The other half, which is the European company database that makes this tool distinctive, has no published price at all. You have to ask.
  • One thing to check before buying the cheapest plan: it tells you which companies visited, not who to contact. Getting actual people's details means moving up two tiers.
  • Note that prices are in euros, not dollars.

How the price works

What you are charged for, and what makes the bill go up.

Dual track. The visitor identification line is published per month across a free tier and three paid tiers, in euros, with separate annual and monthly rates and the top tier on annual billing only. The sales intelligence line, covering the register sourced company database, the browser extension and the customer record hygiene module, is quoted rather than published. Contact level access is gated two tiers above the entry paid plan. Modules are separately licensed rather than bundled, so a buyer's total depends on which parts of the platform they take.

What the contract says about your data

What the vendor commits to in writing once your data is in the product.

A data processing agreement is published, with a second version incorporating the European standard contractual clauses published separately for customers contracting with the vendor's United States entity. The privacy information management standard and the information security standard are both certified, with the certificate files published as downloadable artifacts alongside the vendor's own information security policy and a completed cloud industry consensus assessment questionnaire stated at two hundred and sixty one questions.

A group data protection officer is named as an individual, holding a recognised European privacy practitioner credential and also serving as information security manager. The vendor commits that all data is stored and processed on servers within the European Union. Registration as a data broker in the United States is disclosed with the rights of United States residents and how to exercise them. A consolidated legal kit and a bug bounty programme are published. Not located: a subprocessor list, a penetration test summary, published request metrics, or a stated retention period.

Getting started

What it costs and what is included before the product is running.

Not published. No onboarding, implementation or professional services fee appears for the self serve visitor identification tiers, which are purchasable without a sales conversation and include a free tier and a card free trial. Sales intelligence and customer record hygiene deployments are quoted and no services schedule was located. The March 2026 brand transition explicitly required no re-signing, no contract change and no action from existing customers, and billing descriptors, invoices and tax registration were stated to be unchanged, so no migration cost attached to it.

What to watch for

Where this pricing can surprise a buyer who has not read it closely.

A deliberate split, with one product line properly priced and the other entirely quoted. Published for the visitor identification line as of August 2026: a permanent free tier showing the most recent one hundred identified companies with seven days of history, then three paid tiers at seventy nine, three hundred and sixty nine and five hundred and ninety nine euros per month on annual billing. Monthly rates are published separately for the lower two at one hundred and thirteen and five hundred and twenty seven euros, with the top tier available on annual billing only. A fourteen day trial requires no payment card.

Publishing both billing cycles and a genuinely permanent free tier is better disclosure than most vendors in this index manage. The sales intelligence side, covering the register sourced company database, the browser extension and the customer record hygiene module, carries no published price and is quoted, and independent review roundups flag that split consistently.

A gate within the priced line matters as much as the split: contact level capabilities sit two tiers above the entry plan, so the seventy nine euro rate buys company identification without the ability to reach anyone. entryPriceUsd left blank deliberately: the published rates are in euros rather than dollars, and recording a converted figure would introduce a rate and a conversion date the vendor never published. The euro figures are recorded in entryPriceDisplay and pricingBasis instead. Flagging this as a convention question, since the field is named in dollars and this is the first vendor in the project publishing only in another currency.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.