Executive Summary
Clearbit (now HubSpot-owned) is a B2B data enrichment and identity resolution provider detected on 39 sites with a 64.7% pre-consent tracking rate. Despite claiming SOC2, GDPR, and CCPA compliance, their own website loads 11 third-party vendors before consent including advertising pixels (Meta, Google, LinkedIn) and identity resolution tools (RB2B, Mutiny). Their privacy policy explicitly states they sell personal information and do not honor GPC/DNT signals, creating material contradictions with compliance certifications. The gap between disclosed subprocessors and observed vendors represents significant undisclosed data sharing.
Revenue Threat Profile
4 COLLAPSE VECTORSHow this vendor creates financial exposure. Each score (0-100) reflects observed runtime behavior and documented business practices.
CAC Subsidization
Clearbit corrupts measurement by enabling cross-site identity resolution. Their Reveal product deanonymizes website visitors, meaning site owners lose control over who knows their traffic patterns. When Clearbit enriches a lead, that same data may be sold to competitors through their data broker relationships, poisoning the accuracy of first-party attribution.
Signal Corruption
As an explicit data seller, Clearbit represents direct demand signal leakage. When a company uses Clearbit enrichment, their prospect list composition becomes visible to Clearbit and potentially their customers. The 16+ undisclosed advertising vendors on clearbit.com (Meta, Google, LinkedIn, Twitter pixels) mean visitor intent signals are shared with ad networks.
Legal Tail Risk
Clearbit creates attack surface through extensive third-party JavaScript loading. With 11 vendors firing pre-consent and identity resolution capabilities, any compromise of Clearbit or their vendors exposes client visitor data. The presence of RB2B (another identity vendor) on Clearbit own site suggests layered deanonymization creating amplified exposure.
GTM Attack Surface
Six BTI-X codes triggered (X01, X02, X05, X07, X08, X09) represent material consent and compliance liability. The explicit statement that GPC is not honored contradicts CCPA compliance claims. SOC2/GDPR certifications are undermined by 64.7% pre-consent tracking. Companies using Clearbit inherit this compliance gap through their subprocessor relationship.
