Data & Enrichment
L

Lusha

Established business contact and company data provider, sold through a browser extension, a filtered web application and a programmatic interface, and consumed on a credit model where an email address, a phone number and a recorded call each draw a different amount from the same pool. The platform has extended beyond contact reveals into filters, recommendations, enrichment, buying signals, email sequences and a conversation intelligence product, so a buyer now purchases data and outreach from one allocation.

Registered as a data broker in California and operating on a legitimate interest basis in Europe, the vendor carries the broadest certification set in this index, including the artificial intelligence management standard none of its three largest competitors publish.

Last VerifiedAugust 20, 2026
Compare Lusha with other vendors
Founded
Headquarters
Boston, MA
Website
www.lusha.com
Categories
data-and-enrichment, sales-engagement, conversation-intelligence
Assessment

Capability Axes

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

Model driven capability sits on top of a mature contact database rather than under it. Enrichment, buying signals and recommendations are marketed additions, and the removal test leaves the original business fully intact: a searchable directory, a browser extension, filtered lists and a credit model. This is the established platform pattern already applied elsewhere in this index and it is not a harsh read, it is what the axis was built to separate.

The one genuinely notable move is organisational rather than architectural, an artificial intelligence management certification that the vendor's own competitive comparison notes its three largest rivals do not hold.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
CC on Autonomy and Oversight ModelAutonomy is claimed or implied with the oversight model asserted rather than documented. Buyers cannot tell from public sources what runs unsupervised.
Vendor Published

Administrative oversight is real and enumerated at the account level: role based access control, audit logs and single sign on are named in the trust centre as in product controls, which is more than most vendors of this size publish. Product level oversight of the model driven surfaces is where it stops.

Whether enrichment, signals or sequence generation propose actions for review, act on their own, or write to connected systems without a check is undescribed, and the vendor's own comparison content raises the question sharply by observing that agents now query this data directly without a person checking each result.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
CC on AI Disclosure and Model TransparencyThe product is described as AI powered with the stack, the disclosure behavior, and the scoring logic all unstated.
Vendor Published

Model, provider, version, hosting location and boundary are unstated across every surface read, and the irony is worth recording plainly: this vendor holds an independently audited artificial intelligence management certification and a separate responsible artificial intelligence certification, and still names no model. Attested governance and disclosed architecture are different things, and only the first is on offer here. The governance credit is taken on the stewardship row where it belongs, and this row records the architecture gap. Naming the models behind enrichment, signals and generated sequences would move it.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
CC on Operational and Outcome EvidenceOutcome claims are headline percentages with no stated basis, or customer logos standing in for results.
Vendor Published

Scale claims are published and specific, more than 300 million verified contacts, and the trust centre advertises a library of case studies and whitepapers. None of that library was read for this build, so this row records what was verified rather than what may exist. What was verified is a scale figure, which is an inventory claim rather than a customer result, and a set of independent audit attestations, which speak to process rather than outcome. A named customer with a measured result and a stated measurement basis would move this row, and the material to do it appears to exist. Flagged for re verification.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

The compliance apparatus here is among the strongest in the index and every part of it governs the data rather than the sending. Legal basis, data subject notification, broker registration, standard contractual clauses and annual independent audit all address collection and processing.

What happens when the customer presses send is a different question and nothing located answers it: no electronic marketing statute is named in connection with the sequence product, and no unsubscribe, suppression, complaint handling or recipient removal mechanism for outbound campaigns was found. That gap matters more here than at a pure data vendor, because this business added a sending product to a data business and the compliance story did not travel with it. The sequence product's own terms were not read and this row is flagged for re verification.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
AA on Data Privacy PostureGDPR and CCPA posture documented with specifics: lawful basis stated, DSR handling described, DPA published and signable, subprocessors listed.
Vendor Published

This is the strongest privacy posture graded in this alphabetical block and one of the strongest in the index. The legal basis is named rather than implied, legitimate interest, and the vendor acts on it: it sends personal information notices to European data subjects under the notification article with an explicit right to opt out, and operates a self serve privacy centre where a person who is not a customer can exercise rights directly.

A pre signed data processing addendum is published with European and United Kingdom standard contractual clauses. Privacy practices are audited annually by an independent third party, two named auditors provide seals, a privacy management certification is held, and a privacy practices white paper is published. Two caveats belong in any comparison and neither reaches the band below. The white paper carries an August 2024 date, so a buyer should confirm nothing material has shifted.

And the vendor's characterisation of a French regulator's position, that it is not itself subject to the European regulation as a controller and complies voluntarily, is the vendor describing a favourable regulatory reading of its own status, which a procurement team should verify rather than accept.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
BB on Data Licensing and ProvenanceProvenance is substantively described but incompletely: sourcing classes named without the legal footing, or indemnification unstated.
Vendor Published

Provenance is disclosed in a legal document rather than a marketing claim, which is the right place for it. The privacy notice states the categories collected, limits them to what appears on a business card or an email signature block, and names two source types, trusted data brokers and publicly available interfaces collecting from publicly available sources. Registration as a data broker in California is a matter of public record, and the legitimate interest basis is stated openly.

Two things hold it off the top band. Not one supplying broker is named, so the buyer inherits a supply chain they cannot inspect. And the vendor's own marketing contradicts its own privacy notice: comparison content published on the vendor's site claims data is verified at the source rather than aggregated from third parties, while the privacy notice states plainly that it is sourced from data brokers. When a vendor's legal document and its marketing disagree about where the data comes from, the legal document is the one to believe and the disagreement is the finding.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
CC on Platform Terms ExposureThe vendor is silent on method while the product’s function implies platform automation. Restriction risk is real and unpriced.
Vendor Published

The browser extension is the exposure and it is the classic shape this axis was written for: contact details surfaced while a user browses a professional network profile. The vendor states no conformance position with that platform anywhere in the material read, and the tension is worth naming precisely.

This company has built one of the most elaborate data compliance apparatuses in the category, covering statutes, auditors, certifications and data subject rights, and none of it addresses the terms of the platform its extension operates alongside. The two questions are genuinely separate and only one is answered. No rotation, proxy, rental or evasion mechanism appears anywhere, which is what keeps this at the middle band rather than lower.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
BB on AI Safety and Data StewardshipTraining use is addressed substantively with a real gap, commonly a default in rather than default out posture, or retention terms unstated.
Vendor Published

Governance here is attested rather than asserted, which is rare and earns the band. The vendor holds the artificial intelligence management systems standard, which its own competitive comparison notes none of its three largest rivals publish, and separately a responsible artificial intelligence certification audited across governance, privacy and accountability pillars.

Both are independent third party audits rather than a paragraph of marketing, and both are the kind of commitment a procurement team can actually ask to see. The specific question this axis turns on is still unanswered: whether customer data, contact data or campaign content is used to train or tune models, and whether anything learned in one account can reach another, is not stated anywhere read. A plain training statement alongside the certifications would take this to the top band.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
BB on Recipient Disclosure and AuthenticityDisclosure is available and documented but not the default, or the persona and personalization posture is substantively addressed with one real gap, commonly silence on the Article 50 obligations that took effect in August 2026.
Vendor Published

For a data vendor the question is whether the person being sold knows, and this vendor answers it better than almost anything in the category. Personal information notices go to European data subjects under the notification article, carrying the right to opt out, and a self serve privacy centre lets any individual find and act on their own record without being a customer.

That is a real mechanism rather than a policy sentence, and it sets the bar for this category alongside the one other data vendor in this index that emails individuals when their details enter its directory. Two gaps keep it off the top band. The notification mechanism is described for European and United Kingdom data subjects and no equivalent proactive notice is documented elsewhere, so most of the contact base is covered by a rights process rather than a notice. And the vendor now generates outreach as well as supplying data, with no position located on the European obligation to disclose artificial authorship to the recipient.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
BB on Ecosystem and Integration DepthSolid primary CRM integration documented, with depth unstated at the edges (sync direction, custom objects, failure behavior).
Vendor Published

The integration surface is genuine and layered: named connectors into the two major customer relationship platforms, a programmatic interface and webhooks available from the second paid tier rather than reserved for enterprise, a browser extension that is the product's most used entry point, and connectors documented in a maintained help centre. What holds it off the top band is a gate that lands on the thing buyers actually need.

Full two way synchronisation with those same two platforms sits on the custom priced enterprise tier, so a mid market team on a published plan gets a one directional connection and reconciles the rest themselves. The vendor's own content discusses agents querying this data directly through an emerging protocol, but that is written as an observation about the market and no server of the vendor's own was located, so it is recorded as unverified rather than credited.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
BB on Deployment Model and Data ResidencyThe deployment model is clear and residency options are partially specified.
Third Party Estimated

Two processing jurisdictions are on the record, the United States and Israel, with a transfer mechanism stated as standard contractual clauses, and a published sub processor list is offered as part of the vendor's evaluation materials. A residency posture with named countries and a named transfer mechanism beats silence and beats a consent clause that names nowhere, which is why this sits above several vendors graded earlier in this session.

Off the top band on two counts: no customer choice of processing region is documented anywhere, and the second jurisdiction was established from a third party trust profile citing the vendor rather than from a plainly published residency page, which is why this row carries a third party source basis.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
AA on Security Certifications and Trust CenterA live trust center with enumerated, current certifications (SOC 2 Type II and peers), audit recency visible, and security practices documented beyond the badge.
Vendor Published

This is the broadest certification set in the index. A public trust centre enumerates an audited service organisation control report plus the international standards for information security, cloud security, cloud privacy, privacy information management, privacy by design and artificial intelligence management, alongside a cloud security registry listing.

In product controls are enumerated individually rather than asserted as a category: single sign on, role based access control, audit logs, authenticated programmatic access, redundant high availability infrastructure, a public status page and a stated incident communication practice. Evaluation materials are packaged for procurement and include penetration test summaries and a sub processor list, not just the certificates.

One qualification belongs in the note rather than the band: full certification reports are supplied on request rather than served directly, which is ordinary practice and is the only thing separating this from the very top of the range.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
CC on Commercial TransparencyA pricing page exists and communicates structure without numbers, or numbers so qualified they do not budget anything.
Third Party Estimated

Prices are published, which keeps this out of the bottom band, and that is where the good news ends. The vendor's own public materials disagree with each other on plan structure, credit allocation, seat model and feature entitlement, and the disagreement is not subtle.

Independent reviews published within months of each other report the free tier at five, forty, fifty and one hundred credits; the entry paid tier between roughly 22 and 70 dollars a user a month; a phone reveal at one, five or ten credits; and the seat model as per user in some accounts and per plan with seats included in others. Rollover is variously reported as monthly, annual and non existent.

At least one review states directly that the vendor's own pricing page and its vendor supplied listing on a major review site show different plan names at different price points. Three structural points a buyer should carry regardless of which numbers turn out to be current. A phone number costs several times an email address from the same pool, so a phone first motion drains an allocation many times faster.

The conversation intelligence product draws from that same pool per recorded call, so call recording competes directly with contact reveals. And full two way synchronisation with the major customer relationship platforms is gated to the custom priced tier. Published numbers that a buyer cannot reconcile produce false confidence, which is a different failure from opacity and in one respect a worse one.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
CC on Exit and Data PortabilityExport exists as a feature claim while the terms that govern exit, data rights after termination, deletion, and auto renewal mechanics, are not published anywhere a buyer can read.
Third Party Estimated

Export exists as a real function, list export from the second tier upward and connector based movement into the major customer relationship platforms, and the data processing addendum governs what happens to records processed on a customer's behalf. Two adverse terms sit against that and both bear on exit economics rather than data movement.

Unused credits are widely reported not to survive the billing period, with no refund and no carry forward, so an allocation bought and not spent is simply lost, and the reporting on whether this operates monthly or annually conflicts. And the richest export path, full two way synchronisation, is the one gated to the custom priced tier, so the buyers with the most accumulated data have the least native way to move it unless they are on an enterprise contract. Post termination rights over lists built inside the product, retention periods and deletion timelines for the customer's own workspace were not located.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

A sequence product exists and the sending discipline around it is undocumented in everything read. Warmup guidance, daily or hourly sending limits, complaint rate thresholds, bounce handling, authentication requirements for a connected mailbox, blocklist monitoring and any stated response to a deteriorating sender reputation are all absent from the material located.

The omission is more consequential than it would be at a pure sending tool, because the same platform supplies the list and the sending mechanism, so a buyer can move from a filtered search to a live campaign without ever encountering a volume or quality gate. The sequence product's own documentation was not read and this row is flagged for re verification.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Vendor Published

The ladder has real structure and it is published: a permanent free tier through four paid steps to a custom priced enterprise plan, with seat counts and credit bands attached at each step and volume sliders on the upper tiers, so a buyer can locate themselves on it.

Inventory is quantified at more than 300 million verified contacts and the vendor publishes competitive comparisons that position it explicitly against the three largest providers in its category, including where it trails them. That last point is a disclosure against interest and it is credited here. Coverage detail is the gap.

Regional breakdown of the database, industry concentration and any stated ceiling are not published, and independent reviews consistently report that data accuracy varies by region and contact type, which is the single variable that most determines the real cost per usable contact and which the vendor does not address anywhere located.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

GTM Tech Index

An independent reference for evaluating the software revenue teams use to find, win, and keep customers. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 20, 2026
The GTM Tech Index is an editorial reference, not a law firm or a regulator. Compliance postures are assessed from published sources and public records, and nothing on the index is legal advice. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 GTM Tech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746