All Vendors
abm
Demandbase

Demandbase

92.2% pre-consent tracking rate across 64 detections despite SOC2 Type II and ISO 27001 certifications. Discloses 18 subprocessors while 30+ vendors operate on demandbase.com including undisclosed ad tech (Criteo, MetaPixel, RubiconProject) enabling cross-site tracking beyond stated ABM scope.

101 IOCs65 detections92% pre-consent58 sites
90
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Demandbase discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

65 detections across 58 sites92% pre-consent activity1 critical disclosure gap
CRITICAL

Pre-Consent Tracking

92.2% of page loads fire tracking before consent collection

GDPR Art 6GDPR Art 7ePrivacy Directive
CRITICAL

Pre-Consent Activity

Demandbase was observed loading and executing before user consent was obtained on 92% of sites where it was detected.

GDPRePrivacy
HIGH

Subprocessor Disclosure Gap

30+ additional vendors detected at runtime on demandbase.com

GDPR Art 28CCPA transparency requirements
HIGH

DNT Non-Compliance

Confirmed - no DNT respect while claiming compliance certifications

CCPA opt-out requirementsCalOPPA
HIGH

Undisclosed Party

Not in privacy policy

Disclosure Gaps

Claims vs. Observed Behavior

4 gaps
1 CRIT2 HIGH1 MED
Classified:BTI-X01BTI-X02BTI-X05BTI-X06BTI-X08

Subprocessor Disclosure Gap

GDPR Art 28 · CCPA transparency requirementsHIGH
They Claim

18 subprocessors disclosed on official list

Observed Behavior

30+ additional vendors detected at runtime on demandbase.com

Undisclosed: Adroll, Criteo, MetaPixel, RubiconProject, Reddit, HockeyStack, RB2B, etc.

DNT Non-Compliance

CCPA opt-out requirements · CalOPPAHIGH
They Claim

Privacy notice explicitly states does not honor DNT

Observed Behavior

Confirmed - no DNT respect while claiming compliance certifications

Privacy policy quote: Demandbase does not respond to DNT signals

Ad Tech Scope Creep

TCF requirements · DAA/NAI self-regulatory principlesMEDIUM
They Claim

ABM Platform for B2B

Observed Behavior

Deploys consumer ad tech (MetaPixel, Criteo, Reddit) for retargeting

Runtime detection of programmatic advertising vendors beyond B2B scope

Customer Impact

What This Means For You

If Demandbase powers your ABM targeting, their tag fires before consent on 92.2% of observed implementations. Under GDPR Art 7, this creates near-certain consent violations for EU traffic. Demandbase discloses 18 subprocessors while 30+ vendors operate at runtime including Criteo, MetaPixel, and RubiconProject — undisclosed ad networks that enable cross-site tracking beyond ABM scope. Your visitors' intent signals flow through LiveRamp (disclosed) and undisclosed programmatic ad ecosystems, meaning a company's buying intent could surface to competitors bidding on the same audiences. Under GDPR Art 28, you cannot verify the full subprocessor chain when 12+ vendors are undisclosed.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Demandbase

  • Audit your CMP configuration — ensure Demandbase tag fires only after consent, given 92.2% pre-consent rate across the industry
  • Review your privacy policy to disclose all vendors Demandbase loads downstream, including undisclosed ad networks (Criteo, MetaPixel, RubiconProject)
  • Request current subprocessor list and compare to runtime scan of your own site to identify undisclosed data flows
  • Consider tag containment — load Demandbase in an isolated iframe to limit the scope of their JavaScript execution
  • Evaluate LiveRamp data flows to understand where your intent signals surface in the programmatic advertising ecosystem

If You're Evaluating Demandbase

  • Request evidence of consent-first implementation from reference customers — 92.2% pre-consent rate suggests this is not the default
  • Ask for complete list of downstream data recipients beyond the 18 disclosed subprocessors — 30+ detected at runtime
  • Clarify the scope of identity resolution capabilities — does it extend beyond company-level to individual identification?
  • Run a runtime scan on reference customer sites to verify claimed consent behavior before procurement
  • Compare the disclosed subprocessor list against actual runtime behavior on demandbase.com before signing

Negotiation Leverage

  • Pre-consent SLA: 92.2% pre-consent rate — one of the highest in our detection network. Require contractual guarantee of 0% pre-consent activity with tag containment via isolated iframe or server-side implementation.
  • Subprocessor reconciliation: 30+ vendors detected versus 18 disclosed, including undisclosed ad networks (Criteo, MetaPixel, RubiconProject). Require complete enumeration of all downstream data recipients with 30-day advance notice before additions.
  • Intent signal isolation: Demandbase aggregates demand signals across customer websites. Require contractual commitment that your account intent data is not used for programmatic advertising or shared with ad networks detected on their site.
  • LiveRamp data flow restriction: LiveRamp (disclosed) enables cross-site identity resolution. Require contractual specification of exactly what visitor data flows to LiveRamp and right to opt out of this data partnership.
  • Consent signal enforcement: Require contractual guarantee that Demandbase's tag respects your CMP signals and ceases all processing when consent is denied, verified by independent audit.
Runtime Detections

Runtime Detections

9 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C02Credential Interception

Form data interception

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C09Consent Bypass

Ignoring CMP signals

BTI-C10Fingerprinting

Device identification

BTI-C14Identity Resolution

PII deanonymization

BTI-C15Tag Manager

Container/loader (neutral)

IOC Manifest

IOC Manifest

84 INDICATORS

Indicators of compromise across 6 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.demandbase.com/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*www.demandbase.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*www.demandbase.com/wp-content/themes/demandbase/assets/dist/js/main.js*
Tracking script
TRACK
*www.demandbase.com/wp-content/themes/demandbase/assets/dist/lib/swiper/swiper-bundle.js*
Tracking script
TRACK
*tag.demandbase.com/*.js*
Tracking script
TRACK
*www.demandbase.com/wp-includes/js/wp-emoji-release.js*
Tracking script
TRACK
*ok.demandbase.com/ping*
Tracking script
TRACK
tag.demandbase.com
Tracking script
TRACK
scripts.demandbase.com
Tracking script
TRACK
www.demandbase.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
www.demandbase.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
www.demandbase.com/wp-content/themes/demandbase/assets/dist/lib/swiper/swiper-bundle.min.js
Auto-extracted from scan
TRACK
www.demandbase.com/wp-content/themes/demandbase/assets/dist/js/main.min.js
Auto-extracted from scan
TRACK
tag.demandbase.com/be33254a43aa5a3a.min.js
Auto-extracted from scan
TRACK
www.demandbase.com/wp-includes/js/wp-emoji-release.min.js
Auto-extracted from scan
TRACK
ok.demandbase.com/ping
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Demandbase operates at the center of B2B go-to-market technology stacks, positioning between CRM systems (Salesforce, HubSpot), marketing automation (Marketo), and advertising platforms. Their tag is typically loaded via Google Tag Manager (detected) and orchestrates data flows to: (1) Their own platform for account identification, (2) LiveRamp for identity graph enrichment, (3) Multiple ad networks for retargeting. Downstream, Demandbase data feeds Salesforce for lead scoring and Marketo for campaign orchestration. The presence of Ketch (consent management) suggests awareness of compliance requirements, though the 92.2% pre-consent rate indicates the CMP may be configured permissively or loads after tracking fires. Notable: Demandbase deploys Cheq (bot detection) while simultaneously running trackers that Cheq would flag as violations on customer sites - a circular dependency that reveals internal inconsistency.
Loads (1)
Loaded By (2)
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

101 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details