Nutshell
Ann Arbor customer relationship platform trading since 2009 and now owned by the digital marketing firm WebFX, sold to small and mid market business to business teams as the affordable alternative to the enterprise systems it names in its own comparison pages. Five tiers run from thirteen to seventy nine dollars per user per month with no seat minimum or maximum, and around the pipeline sit paid add ons for email marketing, two way messaging, prospecting against a two hundred million contact database, website visitor identification, contact enrichment, and quotes and invoices.
The model layer is metered rather than bundled: each tier carries a monthly allowance of what the vendor calls outcomes, meaning call summaries, lead research and scoring and campaign generation, with lighter assists unlimited. The disclosure profile is the mirror image of most of this session. Price and security are published to a depth almost nothing else here matches, with every add on priced on a sliding scale and a security page enumerating controls across five areas alongside two independent assessments and a published responsible disclosure process. The privacy policy, the processing addendum and the terms all exist, are properly signposted, and were not read for this build, so several rows below record a flag rather than a finding.
Capability Axes
The established platform pattern, applied as the convention requires rather than as a harsh read. This business has sold a working customer relationship platform since 2009, and removing the model layer leaves contacts, pipelines, reporting, forecasting, email and calendar sync, automation, forms, landing pages and a mobile application entirely intact. One tension is worth recording because it points the other way and may eventually move this row.
The vendor markets itself as the leading platform of its kind for artificial intelligence, and more tellingly the model allowance is the principal thing separating one tier from the next: ten outcomes at the entry tier rising to a hundred and fifty at the top, with an hours saved figure printed beside each.
A platform that increasingly prices on the model layer while the underlying product would survive its removal is exactly the transitional case this axis was built to catch, and today the removal test still decides it.
Account level oversight exists and is enumerated, and product level oversight of the model surfaces is undescribed, which is the split already recorded against Lusha in this index. On the account side an audit log and changelog appear as named tier features, single sign on with directory synchronisation is available, and lead assignment rules and stage goals give administrators real control over routing. Two qualifications keep the row here.
Both of those oversight artefacts are gated: the audit log arrives only at the fourth tier and identity federation only at the fifth, so the ability to see who changed what is a paid upgrade rather than a property of the platform. And the layer that actually acts has no published oversight model at all.
The vendor operates a marketplace of agents described as accelerating revenue driving tasks inside the platform, and no approval step, escalation threshold, containment rule, confidence signal or record of what an agent did appears on any page read.
Two model provider marks sit in the site footer on every page, alongside the parent company and the security badge, and both link through to the company page. That is more of a signal than most vendors in this index give, and it stops short of disclosure. A logo among partner and award marks establishes a relationship without stating which product surface uses which provider, what data reaches them, on what terms, or whether anything is retained.
Model family, version and inference region appear nowhere on the pages read. What the vendor does document well is the shape of its own metering: outcomes are defined as features delivering a measurable result drawing on a shared monthly allowance, with call and meeting summarisation, lead research and scoring and campaign generation given as examples, while assists are defined as unlimited lightweight helpers.
That is a genuinely clear explanation of how the buyer pays for the model and no explanation of what the model is. The dedicated artificial intelligence page was not read and is the flagged item most likely to move this row.
Three quantified performance claims sit on the pricing page, faster close times of just under fifteen percent, leads won up over thirteen percent and new sales revenue up over twenty six percent, and beside them a link reading about these numbers that leads to a methodology anchor.
Publishing a route to the method is rare enough in this index to earn the band on its own, and around it sit real corroboration: over five thousand companies across fifty countries since 2009, a rating of four point three across more than fourteen hundred reviews on a named platform with the link live, six award badges each linked to the issuing source rather than presented as an image, and a customer story library. Held off the top band on two counts.
The methodology page was not opened for this build, so what backs the three percentages is recorded as a flag rather than a finding. And a second set of numbers carries no route to a method at all: each price tier prints an hours saved per month figure, two, four, eight, twenty and thirty, rising with the tier. That is a quantified benefit claim used as a commercial differentiator, sitting on the page where the buying decision happens, with nothing behind it.
This platform sends at volume through two paid add ons, email campaigns priced per marketing contact and messaging priced per message, and the compliance surface for either was not located on the pages read. No electronic marketing statute is named, no consent position is stated, no acceptable use policy was reached, and the messaging product carries no position on the registration scheme that governs application to person traffic in its home market.
One mechanic deserves recording because it is unusual and it works in the right direction, even though it is a billing definition rather than a compliance stance. A marketing contact is defined as a person holding at least one address who has not unsubscribed and has not bounced from previous outreach, which means unsubscribes and bounces stop being billable. The commercial incentive and list hygiene point the same way, which is rarer than it should be. A support article on European compliance exists and was not read, and it sits at the top of the flagged items for this row.
The surface is complete and properly signposted, and it was not read, so this row records the flag rather than a judgement on the contents. A privacy policy, a data processing addendum, a dedicated European compliance article, a trust centre on its own subdomain and an accessibility statement all appear in the site footer, which is a fuller legal shelf than most of this alphabetical block assembles.
What was verified from the security page is narrower but real: infrastructure sits in one named country, customer records are held in discrete per account silos within a multi tenant architecture, billing details never touch the vendor's own servers, and staff will access an account only with the customer's permission. What a buyer still needs is the part behind the links.
Lawful basis, retention periods, the sub processor list, data subject rights routes and the transfer mechanism for a vendor serving fifty countries from one jurisdiction were none of them established. Reading the policy and the addendum is the highest value check available on this vendor.
This is a customer relationship platform that also sells third party data, and the provenance question lands squarely on three products none of which answers it. Prospecting searches a stated database of over two hundred million contacts. Contact enrichment locates individuals at companies already in the customer's book and reveals their details. And visitor identification pinpoints, in the vendor's own words, the companies and individuals visiting a customer's website.
That last one is the sharpest, because resolving an anonymous visitor to a named person is a different act from matching a company by network address, and it is sold at every tier. Across all three, no supplying source, licensing arrangement, collection method, refresh cadence, accuracy statement or lawful basis appears on any page read. The credit based pricing for the prospecting product is published in full, which means a buyer can price the data precisely and cannot learn where any of it came from.
Infrastructure is the vendor's own on a named cloud provider, and the external attachments are official rather than improvised: listings in a browser extension store and a major software marketplace, native synchronisation with both dominant productivity suites, a documented developer interface, and named connectors across telephony, accounting, documents and messaging. Nothing scrapes, rents an identity, rotates accounts or automates against a professional network.
The item that lifts this above a bare integration count is a completed cloud application security assessment against the requirements of a named industry defence alliance, validating the web application against a published framework with no findings at high or medium exploitation risk. That is a conformance validation with a named external body, which is more than a claim of good behaviour.
Held off the top band because the assessment speaks to security requirements rather than to platform terms generally, and because the visitor identification product raises its own platform question, resolving site traffic to named individuals, on which no position is taken anywhere.
One real stewardship statement was verified and the central question was not reached. The verified part is architectural and sits on the security page: a multi tenant storage design holding each customer's records in discrete silos to isolate them from one another, alongside a commitment that staff access an account only with permission and cannot retrieve a password. Isolation at the storage layer is a genuine answer to one half of the cross client question. The other half is open.
Two model providers are implied by footer marks, the platform runs summarisation, lead scoring, research and campaign generation across the customer's entire contact and conversation record, and whether any of that content reaches a provider for training, or informs suggestions in another account, is addressed nowhere on the pages read. For a system holding a whole company's customer history that is the question a buyer should ask first. The processing addendum and the artificial intelligence page are both unread and both flagged.
Three surfaces here reach a person who is not the customer, and no position was located on any of them. A model driven chatbot is included on every tier and converses with visitors on the customer's website, which is the clearest case the European obligation on systems interacting with people was written for, and nothing states whether it identifies itself as artificial.
Campaign generation writes marketing email that goes out under the customer's name, with no disclosure position attached. And visitor identification resolves an individual who arrived anonymously into a named record without their knowledge, then makes them available to be contacted. Held at this band rather than lower because no identity is manufactured, no sender is substituted and nothing in the marketing celebrates concealment. What would move it is a stated position on any one of the three, and none was found on the pages read.
One of the broader integration surfaces in this index. Developer documentation lives on its own subdomain and is linked publicly from every page, an integration marketplace and a separate agent marketplace both exist, the vendor claims connection to over five thousand applications, and the first party distribution is real rather than asserted: a listing in a browser extension store, a listing in a major software marketplace, mobile applications on both stores, and native synchronisation with both dominant productivity suites.
Named connectors span telephony, accounting, document signature, messaging and advertising. Identity federation with directory synchronisation is supported. Held off the top band by a gate and by an ambiguity a buyer should resolve before signing. Federated sign on and direct query access to the underlying data both sit at the fifth and most expensive tier.
And an independent pricing analysis states that programmatic interface access is reserved for that same tier, while the vendor's own card gates only the direct query access and publishes the developer documentation with no tier caveat visible. Those cannot both be right, and the difference is roughly double the cost for a mid sized team.
Answered directly, in plain words, in a frequently asked question rather than buried: infrastructure is fully located in one named country on one named cloud provider. The provider is identified again on the security page, encryption at rest is stated to run through that provider's controls, replication is continuous across multiple servers with twice daily, weekly and monthly snapshots, and a public status page carries live availability.
A residency posture with no options in it, disclosed clearly, is what this band describes, and this vendor states it more plainly than most of the index. The qualification is scale. This company reports customers in fifty countries and offers a single processing jurisdiction with no regional alternative, and no transfer mechanism for the other forty nine was located on any page read. The processing addendum, which would ordinarily carry that and a sub processor list, was not opened and is flagged.
One of the deepest security disclosures in this index, and the depth is in enumerated specifics rather than badges. A trust centre sits on its own subdomain. An independent service organisation control audit is reported and a second independent assessment is named separately, a cloud application security assessment validated against a named industry defence alliance framework with no findings at high or medium exploitation risk.
Controls are set out across five areas: network, covering firewalls, private networking, conservative security group configuration, brute force protection and a stated patching practice with a worked example; storage, with a multi tenant architecture holding each account in a discrete silo; operational, covering full disk encryption on staff machines, a password manager issued on the first day, keycard offices and support access only by customer permission; financial, with card data held by a separate compliant provider and never on the vendor's servers; and credentials, salted and one way hashed with federated sign on available.
Encryption is stated for both transit and rest with the protocol named. A public status page runs live. And a responsible disclosure programme is published in full, with an encrypted reporting channel, an explicit statement that no bounty is paid, a list of six issue classes that will not be accepted, and a public acknowledgements file crediting researchers.
The one thing a buyer should notice: the page title and meta description assert a type two report while the body of the page states only that a successful audit was received, and no audit date, period or auditor appears anywhere. The trust centre contents were not opened, so report currency and any penetration test evidence remain unverified.
The most complete price card in this index. Five tiers each carry a figure, a unit and a monthly and annual option with the exact saving printed against each, and the vendor states there is no seat minimum and no seat maximum, which removes the two most common floors in this category.
Every add on is priced, and priced properly: two suites at a flat monthly and a per user rate, then three usage products published as full sliding scales, twenty three contact bands for email marketing, ten message bands for text, six credit bands for prospecting, and a flat rate for quotes and invoices. A cost calculator sits beside them. A frequently asked question names and denies setup fees, implementation costs and surprise charges specifically rather than in general.
Payment methods are listed including the three that are not accepted. Cancellation is available at any time with changes at the next cycle and no long term contract, and the trial takes no card. Email sending economics are worked through with an example. Two qualifications belong in the note rather than the band.
The model allowance is the real throughput governor and no overage rate is published, so a team that exhausts its outcomes mid month is told only that upgrade options will be clear. And the entry tier's cap of a hundred open leads appears in a frequently asked question rather than on the tier itself.
The asymmetry here is the finding and it is a common one worth naming. Getting in is generously supported and stated repeatedly: data migration assistance is included with every subscription, free onboarding is offered to every customer, and support during the trial is explicit. Getting out is undescribed. No export function, file format, download path, post termination data right, deletion timeline or retention period was located on any page read.
Direct query access to the underlying data exists as a named feature and sits at the fifth and most expensive tier, so the closest thing to a bulk retrieval route is itself a paid upgrade. The terms of service and the processing addendum both exist, are linked from the footer, and were not opened for this build, so this row records a flag rather than an absence. Given how completely this vendor documents its pricing and its security, the silence on offboarding across every marketing surface is conspicuous rather than incidental.
Two published mechanics are real and the rest of the apparatus is missing. The first is a hard volume ceiling stated in plain terms: a customer may send up to eight times their contact allowance each month, worked through with an example, which is an explicit throughput governor of the kind most vendors here leave implicit. The second is the marketing contact definition, which stops billing for anyone who unsubscribes or bounces and so aligns the commercial incentive with list hygiene.
Past those two, the operational surface a sending platform needs was not located: no warmup guidance for a new sender, no shared or dedicated address position, no complaint rate threshold, no bounce handling policy, no authentication guidance for the customer's own domain, and no position on the registration scheme governing text message traffic in its home market, despite messaging being sold as a metered add on.
The coverage half is answered with figures rather than adjectives, which is what separates this from most of the index: over five thousand companies, across fifty countries, since 2009, all three stated together in the site footer on every page.
The buyer is drawn clearly as small to mid market business to business teams, argued through comparison pages naming the two largest platforms in the category directly, and the vendor states no seat minimum and no seat maximum so the ladder genuinely runs from one person upward. Dedicated pages exist for industry fit and for selling motion. Held off the top band by three gaps.
No seat band, headcount range or revenue range attaches to any tier, so a buyer cannot tell which step they belong on without a conversation. No statement exists of who this product would be wrong for. And a claim of fifty countries sits beside a product that independent listings report as English only, with no language or localisation coverage stated anywhere on the pages read.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.