How This Briefing Works
This report opens with key findings, then maps the gaps between what ConvertKit discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.
Key Findings
Analysis pending. Findings will appear here once intelligence collection is complete.
Claims vs. Observed Behavior
Pending Analysis
“Claims extraction pending”
CDT analysis needed for tracking pixel and behavioral scoring assessment
What This Means For You
What To Do About It
Role-specific actions based on observed behavior
If You Use ConvertKit
- →monitor for future scanner detections
If You're Evaluating ConvertKit
- →recon investigation for web tracking and behavioral scoring patterns
Negotiation Leverage
- →Baseline detection only — behavioral analysis pending
- →Marketing automation vendors frequently deploy undisclosed web tracking
- →Review tracking pixel scope and behavioral data retention
IOC Manifest
Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.
Ecosystem & Supply Chain
Evidence Artifacts
Artifacts collected during analysis, available with evidence-tier access.
Complete network capture with all requests and responses
7 detection signatures across scripts, domains, cookies, and network endpoints