All Vendors
abm
6sense

6sense

Texas-registered data broker capturing "one trillion signals daily" while displaying "Security & Privacy By Design" trust badges. 69% pre-consent tracking rate across 42+ third-party vendors on their own website. Explicitly acknowledges selling personal information while holding SOC 2 Type 2 (all 5 TSCs including Privacy) and TRUSTe-validated GDPR compliance.

150 IOCs60 detections70% pre-consent38 sites
90
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what 6sense discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

60 detections across 38 sites70% pre-consent activity3 critical disclosure gaps
CRITICAL

Consent Bypass

69% pre-consent tracking rate detected across monitored sites

GDPR Art 7ePrivacy Art 5(3)
CRITICAL

Compliance Claim Mismatch

Pre-consent tracking behavior contradicts GDPR consent requirements

GDPR Art 6GDPR Art 7
CRITICAL

Vendor Disclosure

42+ vendors detected on site with limited disclosure in privacy policy

GDPR Art 13GDPR Art 14
CRITICAL

Pre-Consent Activity

6sense was observed loading and executing before user consent was obtained on 70% of sites where it was detected.

GDPRePrivacy
HIGH

Data Selling

Acknowledged data selling activity as registered Texas data broker

CCPATexas Data Broker Act
Disclosure Gaps

Claims vs. Observed Behavior

6 gaps
3 CRIT3 HIGH
Classified:BTI-X01BTI-X02BTI-X04BTI-X05BTI-X08BTI-X10BTI-X12

Compliance Claim Mismatch

GDPR Art 6 · GDPR Art 7CRITICAL
They Claim

GDPR compliant with TRUSTe validation

Observed Behavior

Pre-consent tracking behavior contradicts GDPR consent requirements

TRUSTe badge displayed while 69% pre-consent rate observed

Vendor Disclosure

GDPR Art 13 · GDPR Art 14CRITICAL
They Claim

Privacy policy vendor disclosure

Observed Behavior

42+ vendors detected on site with limited disclosure in privacy policy

Runtime scan detected 42+ third-party vendors

Data Selling

CCPA · Texas Data Broker ActHIGH
They Claim

SOC 2 Privacy Trust Service Criteria

Observed Behavior

Acknowledged data selling activity as registered Texas data broker

Texas data broker registration confirms data sale practices

Disclosure Gap

HIGH
They Claim

Trust center compliance badges

Observed Behavior

Registered as data broker in Texas despite privacy-first positioning

Texas data broker registry listing

CMP Failure

ePrivacy Art 5(3)HIGH
They Claim

Ketch CMP deployed for consent management

Observed Behavior

Ketch CMP fires pre-consent alongside other vendors

Runtime detection shows CMP loading pre-consent

Customer Impact

What This Means For You

If 6sense powers your ABM targeting, your intent data is sourced from a Texas-registered data broker that explicitly acknowledges selling personal information including identifiers, commercial information, and employment data. Under CCPA §1798.140, you may bear shared liability for intelligence derived from data sale operations. The 69% pre-consent rate on 6sense.com means their own Ketch CMP fires before consent, calling into question whether their "one trillion daily signals" have valid consent provenance. Under GDPR Art 5(1)(a), you must ensure lawful basis for processing — 6sense's data broker registration and pre-consent behavior make consent chain verification impossible. Their SOC 2 Privacy TSC certification exists alongside acknowledged data selling, creating a paradox your compliance team must reconcile.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use 6sense

  • Request explicit written clarification on how GDPR compliance is maintained while operating as a registered data broker that sells personal information
  • Review your privacy policy to ensure 6sense's data broker status and intent data sourcing are adequately disclosed to your prospects
  • Audit your subprocessor documentation — 42+ vendors on 6sense.com are not adequately disclosed in their privacy policy
  • Assess whether competitor access to the same 6sense subscriber ecosystem creates strategic risk for your ABM campaigns
  • Document legitimate interest basis for 6sense intent data — their data broker model may not support consent-based processing claims

If You're Evaluating 6sense

  • Note their Texas data broker registration alongside 'Security & Privacy By Design' marketing — reconcile this contradiction before procurement
  • Request SOC 2 report including Privacy TSC and verify how it addresses their acknowledged data selling practices
  • Ask specifically how your target account research signals are isolated from other 6sense subscribers including potential competitors
  • Consider privacy-respecting ABM alternatives that do not operate as registered data brokers (Bombora for aggregate intent, G2 for declared intent)
  • Require contractual data isolation and prohibition on selling data derived from your account activity before signing

Negotiation Leverage

  • Data broker status acknowledgment: 6sense is a registered Texas data broker that explicitly sells personal information. Require contractual prohibition on selling data derived from your account activity, with quarterly audit rights to verify compliance.
  • Consent chain verification: 69% pre-consent rate on their own site plus 'one trillion daily signals' from web, mobile, and exchanges. Require documented consent provenance for all intent data provided to your organization under GDPR Art 5(1)(a).
  • Signal isolation: Multi-tenant intent data model means your target account research may inform competitor campaigns. Require contractual data isolation ensuring your account lists and engagement signals are never used to enrich other subscribers' targeting.
  • Privacy TSC reconciliation: SOC 2 with Privacy TSC alongside acknowledged data selling requires explanation. Request the SOC 2 report and verify how the Privacy TSC addresses their data broker operations.
  • CMP remediation evidence: Their Ketch CMP fires pre-consent on 6sense.com. Require documented evidence of consent architecture remediation with independent audit verification before trusting compliance claims.
Runtime Detections

Runtime Detections

9 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C09Consent Bypass

Ignoring CMP signals

BTI-C10Fingerprinting

Device identification

BTI-C13Persistence Mechanisms

Long-lived identifiers

BTI-C14Identity Resolution

PII deanonymization

BTI-C15Tag Manager

Container/loader (neutral)

IOC Manifest

IOC Manifest

145 INDICATORS

Indicators of compromise across 6 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*content.6sense.com/js/forms2/js/forms2.js*
Tracking script
TRACK
*6sense.com/wp-includes/js/dist/vendor/react.js*
Tracking script
TRACK
*6sense.com/wp-content/plugins/embed-lottie-player-pro/build/view.js*
Tracking script
TRACK
*6sense.com/wp-includes/js/wp-util.js*
Tracking script
TRACK
*6sense.com/wp-includes/js/underscore.js*
Tracking script
TRACK
*6sense.com/wp-content/themes/6Sense-*/dist/assets/main_js.js*
Tracking script
TRACK
*6sense.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*6sense.com/wp-includes/js/dist/vendor/react-dom.js*
Tracking script
TRACK
*6sense.com/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*6sense.com/wp-content/plugins/embed-lottie-player-pro//public/js/lottie-interactivity.js*
Tracking script
TRACK
*6sense.com/wp-content/themes/6Sense-*/assets/js/mkto-form-custom.js*
Tracking script
TRACK
*6sense.com/wp-content/plugins/embed-lottie-player-pro//public/js/dotlottie-player.js*
Tracking script
TRACK
*6sense.com/pntd/*
Tracking script
TRACK
*content.6sense.com/index.php/form/getForm*
Tracking script
TRACK
6sense.com
Tracking script
TRACK
6sc.co
Tracking script
TRACK
eps.6sc.co
Tracking script
TRACK
v.eps.6sc.co
Tracking script
TRACK
b.6sc.co
Tracking script
TRACK
content.6sense.com/js/forms2/js/forms2.min.js
Auto-extracted from scan
TRACK
6sense.com/pntd/
Auto-extracted from scan
TRACK
6sense.com/wp-content/themes/6Sense-2025/dist/assets/main_js.js
Auto-extracted from scan
TRACK
6sense.com/wp-includes/js/dist/vendor/react.min.js
Auto-extracted from scan
TRACK
6sense.com/wp-includes/js/dist/vendor/react-dom.min.js
Auto-extracted from scan
TRACK
6sense.com/wp-content/plugins/embed-lottie-player-pro/build/view.js
Auto-extracted from scan
TRACK
6sense.com/wp-includes/js/underscore.min.js
Auto-extracted from scan
TRACK
6sense.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
6sense.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
6sense.com/wp-includes/js/wp-util.min.js
Auto-extracted from scan
TRACK
6sense.com/wp-content/plugins/embed-lottie-player-pro//public/js/dotlottie-player.js
Auto-extracted from scan
TRACK
6sense.com/wp-content/plugins/embed-lottie-player-pro//public/js/lottie-interactivity.min.js
Auto-extracted from scan
TRACK
6sense.com/wp-content/themes/6Sense-2025/assets/js/mkto-form-custom.js
Auto-extracted from scan
TRACK
content.6sense.com/index.php/form/getForm
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

6sense sits at the center of the B2B intent data ecosystem. They collect signals from web-based and mobile networks, exchanges, aggregators and publishers then syndicate this data to Subscribers. The company has major integrations with Salesforce, HubSpot, Marketo, and other marketing platforms. Their Signalverse claims to capture one trillion signals daily. Customers deploying 6sense tags connect their visitor data to this ecosystem.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

150 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details