Lusha
Established business contact and company data provider, sold through a browser extension, a filtered web application and a programmatic interface, and consumed on a credit model where an email address, a phone number and a recorded call each draw a different amount from the same pool. The platform has extended beyond contact reveals into filters, recommendations, enrichment, buying signals, email sequences and a conversation intelligence product, so a buyer now purchases data and outreach from one allocation.
Registered as a data broker in California and operating on a legitimate interest basis in Europe, the vendor carries the broadest certification set in this index, including the artificial intelligence management standard none of its three largest competitors publish.
Capability Axes
Model driven capability sits on top of a mature contact database rather than under it. Enrichment, buying signals and recommendations are marketed additions, and the removal test leaves the original business fully intact: a searchable directory, a browser extension, filtered lists and a credit model. This is the established platform pattern already applied elsewhere in this index and it is not a harsh read, it is what the axis was built to separate.
The one genuinely notable move is organisational rather than architectural, an artificial intelligence management certification that the vendor's own competitive comparison notes its three largest rivals do not hold.
Administrative oversight is real and enumerated at the account level: role based access control, audit logs and single sign on are named in the trust centre as in product controls, which is more than most vendors of this size publish. Product level oversight of the model driven surfaces is where it stops.
Whether enrichment, signals or sequence generation propose actions for review, act on their own, or write to connected systems without a check is undescribed, and the vendor's own comparison content raises the question sharply by observing that agents now query this data directly without a person checking each result.
Model, provider, version, hosting location and boundary are unstated across every surface read, and the irony is worth recording plainly: this vendor holds an independently audited artificial intelligence management certification and a separate responsible artificial intelligence certification, and still names no model. Attested governance and disclosed architecture are different things, and only the first is on offer here. The governance credit is taken on the stewardship row where it belongs, and this row records the architecture gap. Naming the models behind enrichment, signals and generated sequences would move it.
Scale claims are published and specific, more than 300 million verified contacts, and the trust centre advertises a library of case studies and whitepapers. None of that library was read for this build, so this row records what was verified rather than what may exist. What was verified is a scale figure, which is an inventory claim rather than a customer result, and a set of independent audit attestations, which speak to process rather than outcome. A named customer with a measured result and a stated measurement basis would move this row, and the material to do it appears to exist. Flagged for re verification.
The compliance apparatus here is among the strongest in the index and every part of it governs the data rather than the sending. Legal basis, data subject notification, broker registration, standard contractual clauses and annual independent audit all address collection and processing.
What happens when the customer presses send is a different question and nothing located answers it: no electronic marketing statute is named in connection with the sequence product, and no unsubscribe, suppression, complaint handling or recipient removal mechanism for outbound campaigns was found. That gap matters more here than at a pure data vendor, because this business added a sending product to a data business and the compliance story did not travel with it. The sequence product's own terms were not read and this row is flagged for re verification.
This is the strongest privacy posture graded in this alphabetical block and one of the strongest in the index. The legal basis is named rather than implied, legitimate interest, and the vendor acts on it: it sends personal information notices to European data subjects under the notification article with an explicit right to opt out, and operates a self serve privacy centre where a person who is not a customer can exercise rights directly.
A pre signed data processing addendum is published with European and United Kingdom standard contractual clauses. Privacy practices are audited annually by an independent third party, two named auditors provide seals, a privacy management certification is held, and a privacy practices white paper is published. Two caveats belong in any comparison and neither reaches the band below. The white paper carries an August 2024 date, so a buyer should confirm nothing material has shifted.
And the vendor's characterisation of a French regulator's position, that it is not itself subject to the European regulation as a controller and complies voluntarily, is the vendor describing a favourable regulatory reading of its own status, which a procurement team should verify rather than accept.
Provenance is disclosed in a legal document rather than a marketing claim, which is the right place for it. The privacy notice states the categories collected, limits them to what appears on a business card or an email signature block, and names two source types, trusted data brokers and publicly available interfaces collecting from publicly available sources. Registration as a data broker in California is a matter of public record, and the legitimate interest basis is stated openly.
Two things hold it off the top band. Not one supplying broker is named, so the buyer inherits a supply chain they cannot inspect. And the vendor's own marketing contradicts its own privacy notice: comparison content published on the vendor's site claims data is verified at the source rather than aggregated from third parties, while the privacy notice states plainly that it is sourced from data brokers. When a vendor's legal document and its marketing disagree about where the data comes from, the legal document is the one to believe and the disagreement is the finding.
The browser extension is the exposure and it is the classic shape this axis was written for: contact details surfaced while a user browses a professional network profile. The vendor states no conformance position with that platform anywhere in the material read, and the tension is worth naming precisely.
This company has built one of the most elaborate data compliance apparatuses in the category, covering statutes, auditors, certifications and data subject rights, and none of it addresses the terms of the platform its extension operates alongside. The two questions are genuinely separate and only one is answered. No rotation, proxy, rental or evasion mechanism appears anywhere, which is what keeps this at the middle band rather than lower.
Governance here is attested rather than asserted, which is rare and earns the band. The vendor holds the artificial intelligence management systems standard, which its own competitive comparison notes none of its three largest rivals publish, and separately a responsible artificial intelligence certification audited across governance, privacy and accountability pillars.
Both are independent third party audits rather than a paragraph of marketing, and both are the kind of commitment a procurement team can actually ask to see. The specific question this axis turns on is still unanswered: whether customer data, contact data or campaign content is used to train or tune models, and whether anything learned in one account can reach another, is not stated anywhere read. A plain training statement alongside the certifications would take this to the top band.
For a data vendor the question is whether the person being sold knows, and this vendor answers it better than almost anything in the category. Personal information notices go to European data subjects under the notification article, carrying the right to opt out, and a self serve privacy centre lets any individual find and act on their own record without being a customer.
That is a real mechanism rather than a policy sentence, and it sets the bar for this category alongside the one other data vendor in this index that emails individuals when their details enter its directory. Two gaps keep it off the top band. The notification mechanism is described for European and United Kingdom data subjects and no equivalent proactive notice is documented elsewhere, so most of the contact base is covered by a rights process rather than a notice. And the vendor now generates outreach as well as supplying data, with no position located on the European obligation to disclose artificial authorship to the recipient.
The integration surface is genuine and layered: named connectors into the two major customer relationship platforms, a programmatic interface and webhooks available from the second paid tier rather than reserved for enterprise, a browser extension that is the product's most used entry point, and connectors documented in a maintained help centre. What holds it off the top band is a gate that lands on the thing buyers actually need.
Full two way synchronisation with those same two platforms sits on the custom priced enterprise tier, so a mid market team on a published plan gets a one directional connection and reconciles the rest themselves. The vendor's own content discusses agents querying this data directly through an emerging protocol, but that is written as an observation about the market and no server of the vendor's own was located, so it is recorded as unverified rather than credited.
Two processing jurisdictions are on the record, the United States and Israel, with a transfer mechanism stated as standard contractual clauses, and a published sub processor list is offered as part of the vendor's evaluation materials. A residency posture with named countries and a named transfer mechanism beats silence and beats a consent clause that names nowhere, which is why this sits above several vendors graded earlier in this session.
Off the top band on two counts: no customer choice of processing region is documented anywhere, and the second jurisdiction was established from a third party trust profile citing the vendor rather than from a plainly published residency page, which is why this row carries a third party source basis.
This is the broadest certification set in the index. A public trust centre enumerates an audited service organisation control report plus the international standards for information security, cloud security, cloud privacy, privacy information management, privacy by design and artificial intelligence management, alongside a cloud security registry listing.
In product controls are enumerated individually rather than asserted as a category: single sign on, role based access control, audit logs, authenticated programmatic access, redundant high availability infrastructure, a public status page and a stated incident communication practice. Evaluation materials are packaged for procurement and include penetration test summaries and a sub processor list, not just the certificates.
One qualification belongs in the note rather than the band: full certification reports are supplied on request rather than served directly, which is ordinary practice and is the only thing separating this from the very top of the range.
Prices are published, which keeps this out of the bottom band, and that is where the good news ends. The vendor's own public materials disagree with each other on plan structure, credit allocation, seat model and feature entitlement, and the disagreement is not subtle.
Independent reviews published within months of each other report the free tier at five, forty, fifty and one hundred credits; the entry paid tier between roughly 22 and 70 dollars a user a month; a phone reveal at one, five or ten credits; and the seat model as per user in some accounts and per plan with seats included in others. Rollover is variously reported as monthly, annual and non existent.
At least one review states directly that the vendor's own pricing page and its vendor supplied listing on a major review site show different plan names at different price points. Three structural points a buyer should carry regardless of which numbers turn out to be current. A phone number costs several times an email address from the same pool, so a phone first motion drains an allocation many times faster.
The conversation intelligence product draws from that same pool per recorded call, so call recording competes directly with contact reveals. And full two way synchronisation with the major customer relationship platforms is gated to the custom priced tier. Published numbers that a buyer cannot reconcile produce false confidence, which is a different failure from opacity and in one respect a worse one.
Export exists as a real function, list export from the second tier upward and connector based movement into the major customer relationship platforms, and the data processing addendum governs what happens to records processed on a customer's behalf. Two adverse terms sit against that and both bear on exit economics rather than data movement.
Unused credits are widely reported not to survive the billing period, with no refund and no carry forward, so an allocation bought and not spent is simply lost, and the reporting on whether this operates monthly or annually conflicts. And the richest export path, full two way synchronisation, is the one gated to the custom priced tier, so the buyers with the most accumulated data have the least native way to move it unless they are on an enterprise contract. Post termination rights over lists built inside the product, retention periods and deletion timelines for the customer's own workspace were not located.
A sequence product exists and the sending discipline around it is undocumented in everything read. Warmup guidance, daily or hourly sending limits, complaint rate thresholds, bounce handling, authentication requirements for a connected mailbox, blocklist monitoring and any stated response to a deteriorating sender reputation are all absent from the material located.
The omission is more consequential than it would be at a pure sending tool, because the same platform supplies the list and the sending mechanism, so a buyer can move from a filtered search to a live campaign without ever encountering a volume or quality gate. The sequence product's own documentation was not read and this row is flagged for re verification.
The ladder has real structure and it is published: a permanent free tier through four paid steps to a custom priced enterprise plan, with seat counts and credit bands attached at each step and volume sliders on the upper tiers, so a buyer can locate themselves on it.
Inventory is quantified at more than 300 million verified contacts and the vendor publishes competitive comparisons that position it explicitly against the three largest providers in its category, including where it trails them. That last point is a disclosure against interest and it is credited here. Coverage detail is the gap.
Regional breakdown of the database, industry concentration and any stated ceiling are not published, and independent reviews consistently report that data accuracy varies by region and contact type, which is the single variable that most determines the real cost per usable contact and which the vendor does not address anywhere located.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.