Data & Enrichment
N

Neuron

Business contact data supplied through a browser extension rather than a fixed database, from a Waterloo company trading as Planleaf and formerly called Prospect. Work email addresses are assembled as real time permutations and then tested against mail infrastructure before they are handed over, mobile numbers are matched on multiple attributes and confirmed with telecom providers, and every paid tier is unlimited, so the credit arithmetic that governs most of this category is absent here.

A natural language layer called Autopilot turns a sentence into a filtered prospect search, and its published filter dictionary reaches degree of connection, profile viewers, post engagement, company page followers and saved searches, all surfaces available only to an authenticated professional network session.

The compliance posture is the thing a buyer should read twice: three marketing pages present certification and regulatory alignment as settled, while the privacy policy leans on a Canadian carve out that places business contact details outside the definition of personal information, and the user agreement requires the customer to obtain every relevant permission and to indemnify the vendor against any claim from any person in the data.

Last VerifiedAugust 21, 2026
Compare Neuron with other vendors
Founded
2014
Headquarters
Waterloo, Ontario, Canada
Website
neuron.com
Categories
data-and-enrichment, sales-engagement, intent-and-signals
Assessment

Capability Axes

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

Strip the model layer and the business survives almost whole. The permutation engine that assembles work email addresses, the mail infrastructure checks that test them, the multiple attribute matching and telecom confirmation behind mobile numbers, the extension, the four connectors and the unlimited export path all sit below any model and none of them depend on one.

What disappears is Autopilot, a natural language front end onto filters that the vendor itself publishes as a filter dictionary, so the fallback is a filter interface rather than a sentence box. Worth recording that this vendor is unusually restrained for the category.

The homepage never claims artificial intelligence at all, the strongest language anywhere is an intelligent sidekick and active learning applied to verification technique, and this axis reserves its lowest band for a marketed claim that fails the removal test rather than for a competent product that declines to make one.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
CC on Autonomy and Oversight ModelAutonomy is claimed or implied with the oversight model asserted rather than documented. Buyers cannot tell from public sources what runs unsupervised.
Vendor Published

The product returns a list and a person decides what to do with it, which is the conservative end of this category and keeps the row clear of the lower bands. The published control surface stops there. Autopilot accepts an instruction in plain language and resolves it into a query across roughly thirty filter families with no stated review step, confidence signal, result provenance or audit record.

The workflow surface goes further than the buyer might expect and states that the system automatically learns the buyer's ideal customer profile by analysing their prospecting activity, then serves curated leads and dynamically scored profiles from it. Who can inspect that scoring, correct it, or switch it off goes unaddressed.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
CC on AI Disclosure and Model TransparencyThe product is described as AI powered with the stack, the disclosure behavior, and the scoring logic all unstated.
Vendor Published

Autopilot is sold as a natural language interface and given its own published prompt cheat sheet, so the feature is documented at the level of what a buyer types into it. The model behind it is undocumented at every other level. Provider, family, version, hosting arrangement, boundary and processing terms are absent from every read surface, and the two laboratory products carried in the navigation, Vantage and StackScanner, are unexplained anywhere on the site.

The verification engine carries the same silence. Active learning is named as the mechanism by which data quality improves over time, and what learns, on what inputs, and where it runs are all left open.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
CC on Operational and Outcome EvidenceOutcome claims are headline percentages with no stated basis, or customer logos standing in for results.
Vendor Published

Six named and recognisable customers carry the page, Algolia, Glassdoor, NextRoll, ON24, PagerDuty and Ripple, beside a stated deployment range of one to more than a hundred users. Every performance claim around them is unattributed and unmethodised: near zero bounce rates, fifteen or more verification techniques, ten or more attributes behind a mobile match, highest connect rates. The sharp point belongs to the vendor's own product description.

It states that the product integrates with the buyer's outbound tools to deliver detailed bounce and connect rate reports, which means the instrumentation to prove the central claim of this business exists and runs for every customer, and not one figure from it is published. A single dated bounce rate with a denominator would move this row further than another logo.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

An acceptable use clause exists inside the user agreement and it carries real content, prohibiting harassing, abusive, libelous, illegal and deceptive messages, deceptive impersonation, and activity that violates any third party privacy right. That is more than several vendors in this alphabetical block publish. Past it the surface is bare in the way that matters most for what this product supplies.

Electronic marketing statutes go unnamed, consent is never positioned, and suppression, complaint handling and recipient removal are absent for a product whose entire output is work email addresses and direct mobile numbers for cold approach. The conspicuous gap is jurisdictional.

This is an Ontario company that selects Ontario courts as its exclusive forum and sells outbound contact data, and the Canadian anti spam legislation governing commercial electronic messages, one of the strictest consent regimes anywhere and carrying penalties in the millions, appears on no page and in no document read for this build.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
CC on Data Privacy PostureA standard privacy policy exists and answers none of the questions this product category specifically raises.
Vendor Published

A policy exists, names the governing statute plainly, identifies the operating entity as Planleaf, gives a privacy officer two addresses, and offers access, correction and destruction on request. Those are real and several vendors here have less. The problem is scope and it is the finding of this build.

The policy reproduces the Canadian carve out under which, in a business context, personal information excludes the name, job title, business address and business telephone number of an employee in an organisation. Applied to this vendor that definition places the entire output of the product outside the document that governs it.

Three marketing surfaces meanwhile present alignment with the European regulation and compliance with the Californian statute as settled, and neither regime recognises the carve out: a work address is personal data in Europe, and the Californian business to business exemption lapsed at the start of 2023. Also missing throughout: any retention period, any subprocessor list, any transfer mechanism for a Canadian entity processing in an Oregon data centre, any processing addendum, and any revision date.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
BB on Data Licensing and ProvenanceProvenance is substantively described but incompletely: sourcing classes named without the legal footing, or indemnification unstated.
Vendor Published

The vendor answers the question most of this category dodges, and answers it mechanically. Email addresses are assembled as permutations and verified in real time against mail infrastructure rather than served from a stored file, which the marketing states outright as a design choice and repeats as a differentiator.

Phone numbers are attributed to supplier categories by name: mapping providers, public phone number listings, corporate websites and telecom providers, with a second confirmation step through telecom partners. Coverage is stated across four named regions, and the vendor draws an explicit scope line, supplying corporate contact data and declining to supply personal contact data. The disclosure stops short of the top band in three places.

Supplying partners go unnamed, the underlying process is described as a secret sauce and left there, and no licence, consent record or lawful basis is offered for either the permutation method or the telecom sourcing.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
CC on Platform Terms ExposureThe vendor is silent on method while the product’s function implies platform automation. Restriction risk is real and unpriced.
Vendor Published

The exposure is a browser extension and the vendor's own filter dictionary establishes how far it reaches. Autopilot resolves searches on degree of connection, profile viewers, who liked or commented on the buyer's posts, company page followers and saved searches. Those are session gated surfaces inside an authenticated professional network account, visible to the account holder and to nobody else. The legal documents describe something considerably narrower.

Both the user agreement and the privacy policy characterise the service as abstracting publicly posted contact information from supported websites, and neither document ever names a supported website. Where a conformance position would sit, the agreement puts an allocation instead, making the customer responsible for reading and abiding by the terms of any third party site reached through the service, and giving the application store usage rules priority wherever this agreement is looser.

Stating the allocation openly is better than silence, and it remains the buyer who holds the account that gets restricted. The good half is real: four official native integrations with partner applications that the security page says carry an annual security and compliance review.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
CC on AI Safety and Data StewardshipSecurity language exists but the training question, the one this axis turns on, is unanswered: a buyer cannot tell whether their pipeline data improves a competitor’s instance.
Vendor Published

Three affirmative statements sit on the security page and they deserve credit. Data from the customer's sales stack is treated as transient and used only for necessary business logic, only the minimum permissions needed are requested against the connected systems, and sharing runs to approved subprocessors with nothing sold or shared past them. Set against that are two open questions the vendor raises itself.

The workflow surface states that the system learns the buyer's ideal customer profile from their prospecting activity, and the data surface states that verification improves through active learning, and whether either form of learning stays inside the account it came from is unaddressed. The second question is contractual and a buyer is unlikely to find it.

The user agreement takes a perpetual, worldwide, sublicensable and transferable licence over anything a user submits, for any purpose whatsoever, carving out only personal information subject to the privacy policy, and that policy defines an employee's name, title, business address and business telephone out of personal information. The carve out and the definition do not meet.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
CC on Recipient Disclosure and AuthenticityNothing published on whether recipients are told they are dealing with software. For a product whose AI talks to prospects, silence here is now a regulatory posture, not a style choice.
Vendor Published

One genuine route exists for a person who is in the data and is not a customer. The privacy policy commits that where a third party notifies the vendor directly, or through a user, about how they wish their personal information handled, the vendor will comply with those instructions. That is more than most of this category offers and it holds the row clear of the bottom band. It is also entirely passive: the person must already know they are in the data, locate the policy and write in.

Notification at the point of collection, a self service lookup and an opt out link are all absent, and those are the bar the two data vendors already graded in this index set. Two mechanics deserve naming here. Addresses are generated by permutation and then probed against the recipient's own mail infrastructure, so a prospect's mail server is contacted by verification machinery before any person writes to them.

And profile viewers and post engagers are enumerable as targeting filters, so someone who looked at a page or liked a post can be resolved into a prospect record with no indication that the engagement made them findable.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
BB on Ecosystem and Integration DepthSolid primary CRM integration documented, with depth unstated at the edges (sync direction, custom objects, failure behavior).
Vendor Published

Four named connectors, and the selection is worth more than the count suggests: the system of record, a spreadsheet destination for teams without one, and both of the sequencers a buyer at this size already licenses rather than a replacement for them. Field mappings are configurable, single sign on is offered through two providers on every tier including the free one, seat management and analytics exist as administrative surfaces, and a maintained help centre sits behind all of it.

The security page adds that the native integrations are official partner arrangements subject to an annual security and compliance review, which is a statement about how the attachments are maintained rather than a logo grid. Held off the top band on breadth and documentation.

Four connectors is a short list against the ten and twenty published by larger vendors here, a programmatic interface is referenced only in a page description with no endpoints or developer documentation located, and webhooks, a protocol server and a marketplace listing are all absent.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
BB on Deployment Model and Data ResidencyThe deployment model is clear and residency options are partially specified.
Vendor Published

A named region, stated plainly and without needing to be asked twice. Infrastructure runs on one cloud provider with a primary location in Oregon in the United States, across multiple availability zones for redundancy. A residency posture with no options in it, disclosed clearly, beats silence, and that is what sets the band. Two qualifications belong in any comparison.

The same answer adds that other regions of the provider are tapped as needed, which reopens what the primary location closed and leaves a buyer nothing firm to plan against. And the corporate flow goes entirely unaddressed: this is a Canadian entity, incorporated and litigated in Ontario by its own choice of forum, processing in a United States data centre, and the privacy policy names no transfer mechanism for that movement at all.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
BB on Security Certifications and Trust CenterCertifications named and plausible with a gap: no trust center, stale dates, or asserted without enumeration.
Vendor Published

One of the better security pages in this alphabetical block, and it enumerates rather than asserts. The service organisation control report is named with its type, which is the distinction this band turns on, and it sits beside regulatory alignment badges and a control set laid out in three layers. Application covers real time monitoring, vulnerability scanning and a secure development lifecycle.

Infrastructure covers the cloud provider, multiple regions, firewalls, access controls and modern encryption. Operations covers internal access control, single sign on, automated device management and staff training. Encryption in transit and at rest is stated, least privilege is stated for the integration permissions, a vulnerability reporting route is published rather than hidden, and the vendor commits to completing customer security questionnaires during the sales cycle.

Held off the top band by what a buyer still cannot see. The report comes by emailing support rather than through a trust centre or a self service portal, audit date, period and auditor are absent everywhere, no penetration test attestation is offered, the subprocessors are referenced and never listed, and no status page was located.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
BB on Commercial TransparencyPartial pricing published (entry tiers real, enterprise opaque) or pricing published with load bearing exclusions.
Vendor Published

The published path is clean and it renders server side, which is rarer in this index than it should be. Three tiers carry a full feature comparison across all of them, and the paid entry point carries a number and a unit, seventy nine dollars per user per month, with a monthly and yearly toggle.

The model itself removes the arithmetic that makes most of this category unpredictable: paid tiers are unlimited on emails, mobile numbers and exports, so there are no credits to price, no reveals of different sizes drawing on one pool, and no rollover question to answer. Payment methods and tax treatment are both stated. Held off the top band by where the ladder stops.

The top tier is quote only and requires an annual contract with annual billing, and it is no courtesy tier: mainline numbers, account based prospecting, analytics, success tracking, custom field mappings and seat management all sit behind it, which is the administrative equipment any team of the size this vendor advertises will need. A custom service level agreement is disclosed as a paid add on with no figure attached. A buyer of one seat can budget exactly. A buyer of forty cannot.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
BB on Exit and Data PortabilityReal export capability documented, with a material exit question unstated in public terms, commonly post termination rights to licensed or enriched records.
Vendor Published

The architecture answers this axis better than a clause could, and the vendor states that architecture in two separate places. Data from the buyer's stack is treated as transient, and the user agreement says plainly that prospect information is provided at the moment of use and is not stored by the vendor.

The asset therefore accumulates inside the buyer's own system of record and spreadsheet from the first day, exports are unlimited and unmetered on every paid tier, and there is no stored credit balance to strand and no proprietary store to extract from at the end. The published half is where it stops.

Post termination data rights, a deletion timeline and a retention period are all absent for the usage, licensing, support and analytics records the vendor does keep by its own account, the deletion route is a manual request to a privacy officer with an archival copy carve out attached, fees are non refundable, and the vendor reserves the right to revoke access at any time with or without cause and without notice.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
BB on Deliverability and Sending DisciplineReal deliverability features documented, with the operating discipline (limits, monitoring, intervention) asserted rather than specified.
Vendor Published

This vendor sends nothing, and for a data supplier the sending discipline question lands squarely on list quality, because a bad list is the fastest route by which a buyer damages their own sending reputation. On that question the disclosure is unusually mechanical.

Every address is tested against mail exchange and mail transfer infrastructure before it is handed over, fifteen or more verification techniques are claimed, verification runs in real time rather than against a stored file so stale addresses are not served from age, mobile numbers pass a second confirmation with telecom providers, and bounce and connect rates flow back through the connected outbound tools so the buyer can see the result of both.

Two things hold it off the top band and both deserve a buyer's attention. Catch all addresses are advertised as a feature under the heading gems, and a catch all domain accepts everything, which is precisely where bounce data stops carrying information and where the near zero bounce claim cannot be tested.

And the unlimited model removes the credit ceiling that quietly governs volume everywhere else in this category, with no warmup ramp, volume guidance, complaint handling or suppression policy offered in its place.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
CC on Segment and Market CoveragePositioning language covers everyone from startup to enterprise, which specifies no one.
Vendor Published

The buyer is sketched rather than drawn. A deployment range is stated, one to more than a hundred users, six named customers stand as proof of it, three tiers ladder from free through to enterprise, and coverage is claimed across four named regions. The vendor also draws one honest line that works as a disqualifier: corporate contact data only, personal contact data declined, which tells a whole class of buyer to look elsewhere before they trial. Under that the coverage half is assertion.

Contact and company volume go unpublished anywhere on the site, which is unusual for a data vendor and removes the single number buyers in this category compare on first. Accuracy and coverage depth by region are unstated while the four regions are claimed as equals, and every named customer is North American. Industry, seniority and team shape are undescribed, and no seat band attaches to any tier.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

GTM Tech Index

An independent reference for evaluating the software revenue teams use to find, win, and keep customers. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 23, 2026
The GTM Tech Index is an editorial reference, not a law firm or a regulator. Compliance postures are assessed from published sources and public records, and nothing on the index is legal advice. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 GTM Tech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746