Selix AI
Selix is an outbound agent that works out of Slack rather than out of its own console, and the company has renamed itself around it.
The operating model is the distinguishing choice. Rather than presenting a dashboard the operator drives, the agent posts into a team messaging channel as it works, explaining what it is researching, what it has found and what it plans to do next. When it reaches missing information or a decision that benefits from human judgement, it asks. When research is complete or a campaign is ready, proposed actions appear for review before anything executes. The vendor describes this in contrast to assistants that wait for context and depend on what is already in the customer record system, positioning Selix as going to find the missing context itself.
The scope it covers is the whole outbound motion. An ideal profile is defined by attributes from titles, company types and locations through to company products and custom record system fields. A signal layer the vendor calls pulse detects non obvious events including champion tracking, fundraising and product fit analysis, drawn from professional network activity, internal messaging and conference announcements. Contacts are pulled from unnamed data providers. Messages are generated per prospect, campaigns launch, and the vendor operates its own sending infrastructure with inbox warming to keep mail out of spam.
Five product areas are published: integration, lead management, representative engagement, messaging and send infrastructure. Two free tools sit alongside, an email grader and a personalised email generator.
Naming and surfaces are split three ways and worth recording. The company is SellScale, Inc. The product is Selix, marketed at selix.ai. The corporate site remains sellscale.com, and the privacy statement additionally names a customer engagement platform at a third subdomain. Company positioning has escalated over time, with current metadata describing the product as a superintelligence whose only goal is to build outbound pipeline.
The company is headquartered in San Jose, California, founded in 2022, and lists angel backing from operators at a number of well known technology companies. Reported customers include several established technology businesses. Note for future readers: the marketing pages render entirely client side and could not be retrieved, so this record rests on the legal documents, the vendor blog and third party reporting.
Capability Axes
The company renamed itself after the agent, which is about as complete a statement of centrality as a vendor can make.
Everything the product does depends on inference. The agent decides which signals matter, researches accounts by going out and finding context rather than reading what is already in the customer record system, builds the target list, writes a message per prospect, plans the campaign and proposes the actions. The vendor describes it as going to find the missing context on its own, pulling from professional network activity, internal messaging and conference announcements, then returning with a plan. Remove the model and there is no list, no research, no message and no plan, only sending infrastructure with nothing to send.
The positioning matches. Current metadata describes the product as a superintelligence whose only goal is to build outbound pipeline, describes the company as growing companies with artificial general intelligence, and titles the product an artificial intelligence go to market engineer. Autonomous outbound end to end is the headline promise.
This is the strongest claim to centrality in the current sweep and the product architecture supports it rather than contradicting it, which is why it sits at the top band rather than being read as marketing inflation.
What the claim is not accompanied by is any disclosure of what performs it, which is recorded separately.
Ask what the agent does when it cannot find context for a target account.
The agent narrates its own reasoning as it works, which is a genuinely unusual oversight design and the best thing about this record.
The mechanism sits in the team messaging channel. As the agent researches, it posts what it is looking at, what it has discovered and what it intends to do next. When it hits missing information or a decision that benefits from human input, it asks rather than guessing. When research finishes or a campaign is ready to launch, the proposed actions surface for review before anything executes.
Two things make that better than a conventional approval gate. The operator sees the intermediate steps rather than only the final artefact, so a wrong assumption is catchable before it propagates into a hundred messages. And placing the whole exchange in a shared channel means oversight is ambient and visible to the team rather than buried in one person's queue.
What holds it below the top band is that none of it is specified. Two passes located no enumeration of which actions require approval and which execute freely, no statement of whether the gate can be disabled or enforced at an administrative level, no permission model governing who may approve, and no audit trail specification. The headline promise of autonomous outbound end to end sits in unresolved tension with a described review step.
Ask which actions execute without approval and whether the gate can be turned off.
A company marketing a superintelligence has no artificial intelligence section in its privacy statement.
The privacy statement is the one substantive document that retrieves in full, and it runs to considerable length covering collection categories, lawful bases, disclosure recipients, international transfers, retention and regional rights. It contains no statement about model use of any kind: no provider, no version, no description of what customer or prospect content is transmitted for inference, no training or retention position from any model provider, and no acknowledgement that the service is built on models at all.
That absence is the finding, because the same company's public metadata describes the product as a superintelligence, describes the company as growing companies with artificial general intelligence, and titles the product an artificial intelligence engineer. The strongest available marketing claim sits alongside the weakest available disclosure, in documents published by the same organisation.
Two further passes across the blog, the legal pages and third party reporting located no model provider, no version, no evaluation, no accuracy figure and no error rate for the research, signal classification or message generation the agent performs.
For a product whose messages reach strangers based on inferred signals about them, a buyer cannot establish whose terms govern the processing or what happens when a signal is wrong.
Ask which model providers process prospect research and message generation.
Named enterprise customers exist in third party reporting and almost nothing is verifiable from the vendor's own retrievable surfaces.
A retrieval limitation shapes this grade and should be stated plainly. The vendor's marketing pages, including its customers page and media page, render entirely client side and returned only metadata across two passes, so what a buyer with a browser would see could not be examined here. This record therefore reflects the legal documents, the vendor blog and third party sources.
What those sources carry: reported customers including a major work operating system company, a corporate spend platform and an expert network, and case study figures of five times faster outreach and 24 hours saved per seller monthly. Named enterprise logos of that calibre are meaningful attribution if accurate.
What is absent: no independent review base of any volume was located, no case study with a stated method, baseline or measurement window, and a competitor review published in early 2025 characterised the product as lacking reviews and social proof, which is self interested but consistent with what two passes found.
One trap deserves recording. The footer carries a strip of well known technology logos under the heading describing backing from leading investors and growth leaders. Those are investors, not customers, and a reader skimming would take them for a client roster.
Ask for a customer reference with reply rate and meeting counts before and after.
The governing transfer framework in the vendor's own policy has been obsolete for roughly three years.
The privacy statement carries a section stating that although the transatlantic privacy frameworks have been ruled invalid, the vendor will continue to protect European data according to their standards while government discussions on replacement mechanisms proceed, and links to a government programme site that no longer operates. A replacement framework has existed since 2023. A vendor running cold outbound into Europe whose own document describes the current transfer regime as a pending discussion has a live gap in the instrument that governs it.
Around that, the outbound specifics are absent. Two passes located no unsubscribe handling or propagation, no suppression list, no consent basis for contacting a prospect surfaced by signal monitoring, no jurisdictional guidance and no acceptable use policy.
The processor position is correctly stated and creates its own problem. The vendor states it has no direct relationship with the individuals whose data its clients supply, and directs anyone seeking access, correction or deletion to the client instead. That is legally orthodox and it means a prospect contacted by this agent has no route to the party that actually generated and sent the message.
Standard contractual clauses are named for transfers, which is the one current mechanism referenced.
Ask how a recipient stops contact and on what basis their data was processed.
The document is thorough and it discloses a sale of personal information.
Under the Californian definition the vendor states that in the preceding twelve months it sold identifiers and contact information, network activity information, and inferences drawn from both, to advertising networks and data analytics providers. Disclosing that is correct practice and most vendors in this index do not, so the transparency deserves credit even as the practice itself is the finding. The vendor separately states it takes no action in response to browser do not track signals, and that it purchases data from lead generation providers and business intelligence platforms and combines it with records it already holds.
What is genuinely good here is the rights apparatus. Lawful bases are enumerated against each processing purpose. European access, rectification, erasure, portability, restriction, objection and consent withdrawal rights are set out. A data subject rights request portal exists. Account closure and correction are self service. Standard contractual clauses are named. The controller and processor split is stated clearly.
What is missing or stale: no subprocessor list, no retention schedule beyond legitimate business purpose, a security section running to two sentences of generalities, a transfer section resting on an obsolete framework, and a copyright notice reading 2024 on a document retrieved in 2026.
Ask for the subprocessor list and the retention schedule for prospect records.
Contacts come from leading data providers and not one of them is named.
The product supplies prospect records to its customers, and the entire account of where they originate is that the platform pulls contacts from leading data providers. Two passes located no supplier name, no licensing arrangement, no interface agreement, no verification step and no accuracy claim for any of it.
The signal layer has the same problem at a higher sensitivity. The vendor describes detecting champion movement, fundraising events and product fit by drawing on professional network activity, internal messaging conversations and conference announcements. That is behavioural observation of named individuals across surfaces the vendor does not own, and no collection method, licence or lawful basis is stated for any of it.
One piece of corroborating evidence comes from the vendor's own privacy statement, which confirms the company purchases data from lead generation providers and business intelligence platforms and combines it with existing records. That establishes buying data as a practice, and leaves open whether the same suppliers feed the customer facing product.
A buyer inherits whatever the collection turns out to be, since the records land in their campaigns and their sending domains carry the consequence.
Ask which providers supply contact records and how professional network signals are obtained.
What is visible is sanctioned and the consequential question cannot be answered from available material.
On the sanctioned side: the agent operates through a team messaging platform, which is that platform's supported integration model and is the product's primary interface rather than a bolt on. Third party sign in through a professional network is described in the privacy statement as a permission based authorisation flow. Sending runs through the vendor's own infrastructure with inbox warming rather than through borrowed accounts. Two passes located no account renting, no undetectability marketing, no browser extension operating a property the vendor does not own and no claim about avoiding enforcement, all of which appeared in other records built this week.
The open question is the signal layer. Detecting champion movement and monitoring professional network activity at the scale implied requires either licensed access or something else, and the vendor states which platforms it observes without stating how. The product pages that might answer this render client side and could not be retrieved across two passes.
The honest position is insufficient evidence rather than a finding either way, which is why this sits mid band rather than lower. A vendor with licensed access would ordinarily say so, and this one does not, but neither does it market the alternative.
Ask whether professional network signal collection runs through a licensed interface.
An agent that researches strangers and writes to them, with one control described and nothing else.
The control is the review gate before execution, credited under the autonomy axis and real. Beyond it the record is empty on both halves of this axis.
On safety: no model is disclosed, so no provider terms, no training position and no retention commitment exist for anything the agent processes. Two passes located no accuracy figure, no evaluation, no error rate and no statement of what happens when the agent asserts something false about a prospect in a message that has already gone out. For a product whose messages are built on inferred signals about named individuals, a wrong signal produces a message that is confidently wrong about a real person's circumstances.
On stewardship: the privacy statement's security section runs to two sentences saying the vendor stresses its standards, regularly re evaluates policies and follows generally accepted standards. Two passes located no encryption specification beyond one sentence about removing encryption before law enforcement disclosure, no access control description, no incident response or breach notification process, no named security contact and no vulnerability disclosure route.
Retention for the client data the agent works on is governed only by agreements with clients.
Ask what evaluation covers signal accuracy before a message is generated from it.
The sender is the customer and the authorship is not disclosed.
On identity the record is clean and worth distinguishing from others built this week. Sending runs through infrastructure the customer controls, under their own sending identity, with warming applied to their own mailboxes. Two passes located no rented accounts, no persona, no synthetic sender, no cloned voice and no undetectability marketing of any kind. The vendor positions explicitly against mass campaigns and for relevance and timing, which is the opposite of the posture that produced the sharpest findings elsewhere in this sweep.
What is not addressed is that the message was written by an agent about research the agent conducted, and nothing describes any disclosure of that to the person receiving it. A prospect reads a message referencing their conference talk or their company's funding round and has no way to know that neither the noticing nor the writing involved a person.
The reply path compounds it. The product promises autonomous outbound end to end and describes the agent asking for a human only when it judges one is needed, which leaves unstated whether a prospect who replies is answered by the agent, and if so whether that is disclosed.
Ask whether a prospect reply is handled by the agent and whether that is disclosed.
One integration is architectural rather than incidental, and the rest could not be established.
The messaging platform integration is the interesting one, because the agent does not merely notify there. It operates there: research narration, questions to the operator and proposed actions for approval all happen inside the channel, which means the integration is the product's primary interface rather than an alerting convenience. Very few vendors in this index treat a third party surface as their main console, and it is a defensible design for a tool whose value depends on a human noticing what it is about to do.
Beyond that, evidence thins. A dedicated integration product page exists in the site navigation but renders client side and returned no content across two passes. Customer record system data is usable as an ideal profile attribute, which implies a connector without naming one. Two free tools are published as separate web surfaces.
Two passes located no interface documentation, no authentication scheme, no webhooks, no model context protocol server and no named connector list, in a sweep where five smaller vendors shipped the last of those.
The retrieval limitation is material here and a buyer with a browser may find more than this record reflects.
Ask for the connector list and whether a public interface exists.
The transfer position is stated and the location is not.
What the privacy statement gives: the vendor is a United States company, its service providers are located in the United States and other countries, and personal information may therefore be transferred to and processed in countries other than the one the individual is in, some of which may have less protective law. Standard contractual clauses are named as one safeguard, alongside transfers to jurisdictions holding an adequacy determination.
That is a transfer disclosure rather than a deployment disclosure, and it is the entirety of what is published. Two passes located no hosting provider, no region, no residency commitment, no region selection option, no tenancy or isolation model, no encryption at rest statement, no backup position and no continuity plan.
The same section leans on a framework that was invalidated and has since been replaced, which means the document describing where data goes is itself out of date on the mechanism governing it.
For a product processing prospect records and behavioural signals about named individuals across multiple jurisdictions, publishing no location at all leaves a buyer's assessment with nothing to assess.
Ask where customer and prospect data is stored and whether any regional option exists.
A badge image in the footer is the whole of the security credential.
The footer carries a graphic whose filename identifies it as a service organisation control badge. It appears without accompanying text, and the page carries no report type distinguishing design from operating effectiveness, no scope, no assessment period, no auditor name, no renewal cadence and no process for requesting the underlying report. A badge is an image, and this is the second record in this sweep whose entire security disclosure is one.
The privacy statement's security section is the only prose on the subject and runs to two sentences: that the vendor stresses its standards, that nobody can guarantee absolute security, that it regularly re evaluates its policies, and that it follows generally accepted standards to protect information in transit and at rest. None of that is actionable.
Two passes located no security page, no trust portal, no international standard certification, no penetration test summary, no vulnerability disclosure route, no named security contact and no subprocessor list. The general support address is the only contact route offered for anything, including privacy rights requests.
A buyer running a supplier security review against a product that holds their prospect data and sends under their domain would find one image.
Ask what report the footer badge refers to, its type, period and how to request it.
The terms of service contain the clearest statement available, and it is that the price will be communicated later.
The governing agreement states that fees to be paid by the customer are set forth in an order or will otherwise be communicated to the customer by the vendor. That is the contractual formulation of no published price, and it is the only pricing language retrievable from any vendor surface.
Two passes located no tier structure, no band, no starting point, no unit of sale, no trial terms, no minimum commitment and no billing frequency on the marketing site, the legal pages or third party directories. An independent pricing analysis published in May 2026 reached the same conclusion, noting that deciding whether the vendor's claimed results justify the cost requires a sales conversation before any comparison is possible.
The absence is more consequential than usual because of what is bundled. The product supplies contact data, generates messages, and operates sending infrastructure with inbox warming, which in every comparable record is priced across at least three separate meters. Whether this vendor charges per seat, per profile, per contact, per send or on consumption cannot be established, so a buyer cannot model cost at any volume.
The vendor does target established teams with mature stacks, which suggests enterprise deal sizes, but suggests is the operative word.
Ask what the unit of sale is and what a typical annual commitment looks like.
Individual rights are well described and business data portability is not addressed at all.
The privacy statement handles the individual well. A registered user may review, update, correct or delete personal information through account settings. Account closure is self service, with the caveat that copies may be retained where law requires or removal is not technically feasible. European users are told explicitly of a right to port personal information to another controller. A data subject rights request portal exists for access and deletion requests, and the vendor commits to responding in accordance with applicable law.
None of that covers what a departing customer actually needs. Two passes located no export mechanism for prospect lists, campaign history, message performance, signal history or the accumulated targeting the agent has learned, no format, no scope statement and no timeline. Retention of client data is governed only by a reference to agreements with clients, so the terms differ per contract and are not visible.
The agent's accumulated understanding of a team's tone, positioning and targeting is the asset that takes longest to build and is the least likely to travel, and nothing addresses whether it can.
Commercially the exit terms are unknown, since no contract length or notice period is published anywhere.
Ask what an export contains and whether the agent's learned targeting travels with it.
Sending infrastructure is a named product area rather than a feature bullet, and the vendor gives away a diagnostic tool.
The structural evidence is good. Send infrastructure appears as one of five published product areas with its own page, alongside integration, lead management, representative engagement and messaging, which means the vendor treats getting mail delivered as a component of the platform rather than an assumption. Inbox warming is described consistently across the vendor's own material and independent reporting as part of what the platform operates, and monitoring inbox health to keep outreach out of spam is stated as an explicit function.
The free email grader is the part that earns the upper band. Publishing a working deliverability diagnostic as an open tool is a contribution to the discipline rather than a claim about it, and it is checkable by anyone without a sales conversation.
A structural throttle operates alongside. Because the agent acts on detected signals rather than working a purchased list, volume is bounded by how often signals fire, which caps sending by construction in the same way the signal first policies recorded elsewhere this week do.
What is missing is specification: no authentication guidance, no bounce policy, no verification step, no per mailbox limits and no measured deliverability data were located, and the infrastructure page did not render.
Ask for the per mailbox daily ceiling and the measured bounce rate across customers.
The vendor tells unsuitable buyers not to buy, in specific terms, which is rare enough to carry the grade.
The published qualification reads that the vendor works with established business to business outbound teams, and that the product is a fit for organisations with formal outbound targets, well defined personas and team familiarity with the sales stack. It then goes further and states that the platform works best with companies that are post product market fit, have a dedicated outbound team and run a mature sales stack. Each of those three is a disqualifier a founder shopping too early would recognise themselves in, and publishing them costs the vendor pipeline.
Roles are named as founders, sales development teams and revenue leaders. Reported customers concentrate in established technology businesses, which corroborates the stated qualification rather than contradicting it.
What is absent keeps it below the top band. No industry vertical is named, no company size band or contract value floor is given, and no geography is stated anywhere despite a transfer section acknowledging processing across multiple jurisdictions. A buyer outside the United States cannot tell whether the contact data, the signal coverage or the sending infrastructure suits their market.
The practical prerequisite also goes unstated: the operating model assumes the team lives in a messaging platform, since that is where the agent works.
Ask which markets the contact data and signal coverage actually reach.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Processing Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published; fees set out in an order or communicated by the vendor
|
Not published on any vendor surface. The terms of service state that fees are set forth in an order or otherwise communicated to the customer by the vendor, which is the contractual formulation of quote on request. No tier structure, band, starting point, unit of sale, billing frequency, minimum commitment or trial term appears on the marketing site, the legal pages or third party directories. The platform bundles contact data supply, model generated messaging and operated sending infrastructure with inbox warming, so at least three commonly metered components sit inside an unpriced package and the metering basis for each is unknown. | No data processing agreement was located. A detailed privacy statement is published covering collection categories, lawful bases, disclosure recipients, retention posture and regional rights, with a data subject rights request portal and standard contractual clauses named for international transfers. The controller and processor split is stated clearly, with the vendor acting as processor for client supplied prospect data and directing individuals to the client for access, correction or deletion. Against that, the statement discloses that the vendor sold identifiers, contact information, network activity data and derived inferences to advertising networks and data analytics providers in the preceding twelve months under the Californian definition, states it takes no action on browser do not track signals, carries no subprocessor list, gives no retention schedule beyond legitimate business purpose, and rests its transfer section on a framework that was invalidated and has since been replaced. A service organisation control badge appears in the site footer with no report type, scope, period, auditor or request process attached. | Not published. No setup fee, onboarding charge, professional services rate, minimum commitment or trial term was located across the marketing site, the legal pages or third party reporting. The vendor operates its own sending infrastructure with inbox warming as part of the platform, which in comparable products carries either a per mailbox charge or a provisioning fee, and neither is disclosed. Two free tools are published as open web surfaces, an email grader and a personalised email generator, which function as evaluation entry points at no cost. The published qualification statement indicates the vendor works with established teams running mature sales stacks, which suggests a sales led motion with negotiated terms rather than self service purchase. | Vendor Published |
The governing agreement contains the clearest pricing statement available from this vendor, and it is that the price will be communicated later. The terms of service state that fees to be paid by the customer are set forth in an order or will otherwise be communicated to the customer by the vendor.
Two passes across the marketing site, the legal pages, the vendor blog and third party directories located no tier structure, no band, no starting figure, no unit of sale, no trial terms, no minimum commitment and no billing frequency. An independent pricing analysis published in May 2026 reached the same conclusion and noted that evaluating the vendor's claimed results against cost requires a sales conversation before any comparison is possible.
The absence matters more here than for a single function tool. This platform bundles contact data supply, model generated messaging and operated sending infrastructure with inbox warming, which across comparable records in this index are priced on at least three separate meters, commonly a seat fee, a credit or contact allowance and a per mailbox charge. Whether this vendor charges per seat, per sending profile, per contact, per send or on consumption cannot be established from any published source, so a buyer cannot model cost at any volume or compare it against an alternative.
No dollar figure is recorded in the numeric field, because no figure traceable to any source exists.
A retrieval limitation applies to this record and should be noted for anyone rechecking it. The vendor's marketing pages, including the product pages and the get started path, render entirely client side and returned only metadata across two passes. A pricing disclosure could exist behind that rendering, though the terms of service language suggests otherwise.
One further caution on company financials. Two aggregators conflict directly: one records a 3.4 million dollar seed round raised in 2022, the other states the company is bootstrapped with no outside funding while also reporting a revenue decline and headcount reduction. The vendor's own site displays investor backing, which contradicts the bootstrapped claim and undermines that source's reliability on the other figures. Neither aggregator's numbers are recorded here.