All Vendors
marketing_automation
ActiveCampaign

ActiveCampaign

Core value is "Start with trust" while explicitly admitting to selling identifiers and network activity to data enrichment providers. 73.1% pre-consent tracking rate across 20+ vendors on their own website. No SOC2 or ISO certifications visible despite serving 170+ countries.

102 IOCs27 detections74% pre-consent21 sites
90
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what ActiveCampaign discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

27 detections across 21 sites74% pre-consent activity1 critical disclosure gap
CRITICAL

Consent Bypass

73.1% pre-consent tracking rate detected across monitored sites

GDPR Art 7ePrivacy Art 5(3)
CRITICAL

Pre-Consent Activity

ActiveCampaign was observed loading and executing before user consent was obtained on 74% of sites where it was detected.

GDPRePrivacy
HIGH

Data Selling

Explicit data selling acknowledged in privacy documentation

CCPA
HIGH

CMP Failure

OneTrust CMP fires pre-consent alongside tracking vendors

ePrivacy Art 5(3)
HIGH

Vendor Disclosure

20+ vendors detected on site with limited disclosure

GDPR Art 13GDPR Art 14
Disclosure Gaps

Claims vs. Observed Behavior

6 gaps
1 CRIT3 HIGH2 MED
Classified:BTI-X01BTI-X04BTI-X05BTI-X08BTI-X10

Data Selling

CCPAHIGH
They Claim

Start with trust company value

Observed Behavior

Explicit data selling acknowledged in privacy documentation

Privacy policy discloses data sale practices

CMP Failure

ePrivacy Art 5(3)HIGH
They Claim

OneTrust CMP deployed for consent management

Observed Behavior

OneTrust CMP fires pre-consent alongside tracking vendors

Runtime detection shows CMP loading pre-consent

Vendor Disclosure

GDPR Art 13 · GDPR Art 14HIGH
They Claim

Privacy policy vendor disclosure

Observed Behavior

20+ vendors detected on site with limited disclosure

Runtime scan detected 20+ third-party vendors vs limited privacy policy list

Certification Gap

MEDIUM
They Claim

Enterprise marketing platform

Observed Behavior

No SOC2 or ISO 27001 certifications unlike competitors

No compliance certifications listed on trust center

Session Recording Disclosure

MEDIUM
They Claim

Privacy-respecting analytics

Observed Behavior

Session replay tools deployed without clear disclosure to users

Session replay detected on site without prominent user notice

Customer Impact

What This Means For You

If ActiveCampaign processes your marketing automation, your subscriber engagement data enters a circular data ecosystem. ActiveCampaign explicitly admits to selling identifiers and network activity to data enrichment providers — meaning your audience engagement patterns become inventory available to competitors. Under GDPR Art 28 and CCPA §1798.140, you bear responsibility for disclosing these downstream data flows to your subscribers. ActiveCampaign displays no SOC2 or ISO security certifications despite processing 4 billion+ weekly interactions, leaving you without independent verification of their security posture. Their 73.1% pre-consent rate on their own site suggests consent-first architecture is not operationally prioritized.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use ActiveCampaign

  • Request explicit written clarification on how GDPR compliance is achieved with 73.1% pre-consent tracking on their own properties
  • Review what happens to your subscriber engagement data — their privacy policy admits selling identifiers to data enrichment providers
  • Demand SOC2 Type II report or explanation for why none exists despite processing 4 billion weekly interactions across 170+ countries
  • Audit whether your subscriber data enters the data enrichment ecosystem where competitors may purchase engagement insights
  • Consider alternatives that do not participate in data broker networks if data sale is incompatible with your privacy commitments

If You're Evaluating ActiveCampaign

  • Note the gap between 'Start with trust' messaging and explicit data sale admissions in their privacy policy
  • Request SOC2 Type II and ISO 27001 certifications — ActiveCampaign does not appear to hold either despite enterprise scale
  • Ask specifically how subscriber data is isolated from their data enrichment provider relationships
  • Compare against alternatives like Mailchimp, Customer.io, or Klaviyo that do not admit to selling subscriber data
  • Require contractual data sale prohibition before signing — their default terms allow selling your audience intelligence

Negotiation Leverage

  • Data sale prohibition: ActiveCampaign explicitly admits selling identifiers and network activity to data enrichment providers. Require contractual prohibition on selling, sharing, or enriching data derived from your subscriber interactions, with quarterly audit rights.
  • Security certification requirement: ActiveCampaign displays no SOC2 or ISO certifications despite processing 4 billion weekly interactions. Require SOC2 Type II certification as a contract condition or negotiate significant liability indemnification.
  • Pre-consent SLA: 73.1% pre-consent tracking on their own website contradicts GDPR-friendly claims. Require contractual guarantee that their SDK and tracking code respects your CMP signals with zero pre-consent data processing.
  • Data enrichment opt-out: ActiveCampaign both buys from and sells to data enrichment providers. Require written confirmation that your account data is excluded from all enrichment partnerships and data marketplace activity.
  • Subprocessor transparency: 20+ vendors detected on activecampaign.com with limited disclosure. Require complete subprocessor list with 30-day advance notice before additions affecting your data processing.
Runtime Detections

Runtime Detections

8 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C09Consent Bypass

Ignoring CMP signals

BTI-C10Fingerprinting

Device identification

BTI-C14Identity Resolution

PII deanonymization

BTI-C15Tag Manager

Container/loader (neutral)

IOC Manifest

IOC Manifest

93 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.activecampaign.com/wp-content/themes/activecampaign/assets/js/ehawk-talon-6-init.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/site-D33staw0.js*
Tracking script
TRACK
*www.activecampaign.com/dist/scripts/ehawk-talon-6-init.js*
Tracking script
TRACK
*www.activecampaign.com/cdn-cgi/challenge-platform/scripts/jsd/main.js*
Tracking script
TRACK
*www.activecampaign.com/wp-content/themes/activecampaign/assets/js/ehawk-talon-6.js*
Tracking script
TRACK
*www.activecampaign.com/_track.php*
Tracking script
TRACK
*try.activecampaign.com/pr/js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/navigation-BR2nwwwd.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/DropdownGroup-CZc0EjAP.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/QuoteCardCarousel-CFy53MSm.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/FreeTrialModal-Cm2oZj1P.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/MediaQueries-DefP1YF7.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/PromptCardCarousel-aZnr2I_B.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/FreeTrialForm-BDiB1r5t.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/Accordion-Bqq5ekF0.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/Modal-MBUdlBwJ.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/Card-DmGTY9gn.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/svg-drRkrG95.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/AmbientVideo--ltUpe9Y.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/FullWidthScrollingSlides-D0iG5PuO.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/formatting-rsiiYB3c.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/Widgets-zpX4-aK4.js*
Tracking script
TRACK
*www.activecampaign.com/dist/assets/isEmail-D4GNX9_Y.js*
Tracking script
TRACK
*www.activecampaign.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/*/main.js*
Tracking script
TRACK
*www.activecampaign.com/dist/scripts/EHawkTalon6.js*
Tracking script
TRACK
trackcmp.net
Tracking script
TRACK
www.activecampaign.com/dist/assets/site-D33staw0.js
Auto-extracted from scan
TRACK
www.activecampaign.com/wp-content/themes/activecampaign/assets/js/ehawk-talon-6-init.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/scripts/ehawk-talon-6-init.js
Auto-extracted from scan
TRACK
try.activecampaign.com/pr/js
Auto-extracted from scan
TRACK
www.activecampaign.com/_track.php
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/PromptCardCarousel-aZnr2I_B.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/navigation-BR2nwwwd.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/AmbientVideo--ltUpe9Y.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/svg-drRkrG95.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/formatting-rsiiYB3c.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/MediaQueries-DefP1YF7.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/QuoteCardCarousel-CFy53MSm.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/FreeTrialForm-BDiB1r5t.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/isEmail-D4GNX9_Y.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/FreeTrialModal-Cm2oZj1P.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/Modal-MBUdlBwJ.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/DropdownGroup-CZc0EjAP.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/FullWidthScrollingSlides-D0iG5PuO.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/Accordion-Bqq5ekF0.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/Card-DmGTY9gn.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/assets/Widgets-zpX4-aK4.js
Auto-extracted from scan
TRACK
www.activecampaign.com/wp-content/themes/activecampaign/assets/js/ehawk-talon-6.js
Auto-extracted from scan
TRACK
www.activecampaign.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
Auto-extracted from scan
TRACK
www.activecampaign.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/7f3d2ee44814/main.js
Auto-extracted from scan
TRACK
www.activecampaign.com/dist/scripts/EHawkTalon6.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

ActiveCampaign integrates with 1000+ apps including Salesforce, Shopify, Facebook, Google Ads, and notably Clay (another VRS 90 vendor). They both buy data FROM and sell data TO data enrichment providers, creating a circular data ecosystem. Their 4 billion weekly interactions represent massive data flow across this network.
Loaded By (2)
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

102 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details