All Vendors
data_enrichment

Hginsights

HG Insights deploys 40 scripts with behavioral biometrics, session recording, and identity resolution capabilities — transforming what is marketed as technology intelligence into a client-side surveillance operation that fires pre-consent on 14% of deployments.

228 IOCs28 detections14% pre-consent26 sites
90
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Hginsights discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

28 detections across 26 sites14% pre-consent activity
MEDIUM

Pre-Consent Activity

Hginsights was observed loading and executing before user consent was obtained on 14% of sites where it was detected.

GDPRePrivacy
HIGH

Pending Analysis

7 BTI behavioral codes detected across 28 instances on 26 sites. Full claims extraction required for gap analysis.

Disclosure Gaps

Claims vs. Observed Behavior

1 gaps
1 HIGH

Pending Analysis

HIGH
They Claim

Claims analysis pending

Observed Behavior

7 BTI behavioral codes detected across 28 instances on 26 sites. Full claims extraction required for gap analysis.

Customer Impact

What This Means For You

If you deploy HG Insights, you are not just adding technology detection to your site — you are installing a 40-script behavioral surveillance infrastructure with identity resolution capabilities. Your visitors' keystroke patterns, mouse movements, and complete browsing sessions are captured and fed into HG Insights' commercial intelligence products. The identity resolution capability means your anonymous visitors are deanonymized and their company affiliations added to a database that your competitors can purchase. Your privacy policy likely describes HG Insights as a "technology intelligence" or "analytics" partner — it is functionally a behavioral data harvester with the ability to identify and profile your visitors for commercial resale.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Hginsights

  • Audit which of the 40 HG Insights scripts load on your pages and verify each serves a legitimate technographic purpose
  • Review your data processing agreement with HG Insights for disclosures about behavioral biometrics, session recording, and identity resolution
  • Verify your CMP correctly manages all HG Insights scripts — the tag manager capability (C15) means new scripts may load dynamically
  • Update your privacy policy to disclose behavioral data collection and identity resolution if you continue using HG Insights

If You're Evaluating Hginsights

  • Assess whether you actually need client-side technology detection or if HG Insights' API-based products would meet your needs without the behavioral capture
  • Request HG Insights' complete data processing documentation covering all 7 detected BTI behavioral capabilities
  • Evaluate alternative technographic providers (BuiltWith, Wappalyzer) with smaller client-side footprints
  • Conduct a DPIA for HG Insights' behavioral biometrics (C06) and identity resolution (C14) capabilities — these likely trigger mandatory assessment requirements

Negotiation Leverage

  • 40 scripts for technology detection is indefensible — standard technographic vendors require 1-3 scripts. Demand technical justification for each script
  • Behavioral biometrics (C06) and session recording (C07) have zero legitimate technographic purpose — demand contractual prohibition on behavioral data collection beyond technology detection
  • Identity resolution (C14) means your visitor data enriches HG Insights' commercial products sold to competitors — demand exclusion of your visitor data from resale products or negotiate data licensing revenue share
  • 7 BTI behavioral codes for a technology intelligence vendor represents the widest gap between stated purpose and observed behavior in this batch — use this disclosure gap as primary negotiation leverage
  • Tag manager capability (C15) means HG Insights can expand its data collection without your knowledge — demand contractual notification requirements for any changes to deployed scripts
Runtime Detections

Runtime Detections

7 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

Impact: Evasion infrastructure means HG Insights can modify behavior during privacy audits, hiding the full scope of its 40-script data collection from compliance assessments.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Keystroke and mouse movement tracking from a technology intelligence vendor has no legitimate technographic purpose. This indicates behavioral profiling capabilities that extend far beyond detecting what technology a company uses.

BTI-C07Session Recording

Full session replay

Impact: Full session replay from a data enrichment vendor means your visitors' complete browsing sessions are captured to feed HG Insights' intelligence products. This transforms your site into a behavioral data collection point for a commercial database.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Pre-consent firing at 14% of deployments means approximately 1 in 7 sites experience unauthorized data collection. With 40 scripts per deployment, each pre-consent load triggers extensive unauthorized behavioral capture.

BTI-C10Fingerprinting

Device identification

Impact: Device fingerprinting creates persistent visitor identification independent of cookies, enabling HG Insights to track and identify visitors across sessions even after they clear their browser data.

BTI-C14Identity Resolution

PII deanonymization

Impact: PII deanonymization from a data enrichment vendor is the most significant finding. HG Insights can resolve your anonymous visitors to real identities and companies, feeding this data into commercial intelligence products available to anyone willing to pay — including your competitors.

BTI-C15Tag Manager

Container/loader (neutral)

Impact: Tag management capabilities mean HG Insights can dynamically load additional tracking scripts, expanding its data collection footprint beyond what was initially deployed or authorized.

IOC Manifest

IOC Manifest

220 INDICATORS

Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*hginsights.com/wp-content/plugins/kmdg-resource-center/dist/js/resources.js*
Tracking script
TRACK
*hginsights.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*hginsights.com/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*hginsights.com/wp-includes/js/imagesloaded.js*
Tracking script
TRACK
*hginsights.com/wp-includes/js/jquery/jquery.masonry.js*
Tracking script
TRACK
*hginsights.com/wp-content/themes/hginsights/src/js/lib/mmenu.js*
Tracking script
TRACK
*hginsights.com/wp-includes/js/masonry.js*
Tracking script
TRACK
*hginsights.com/wp-content/themes/hello-elementor/assets/js/hello-frontend.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/webpack.runtime.js*
Tracking script
TRACK
*hginsights.com/wp-content/themes/hginsights/dist/js/app.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/frontend-modules.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/frontend.js*
Tracking script
TRACK
*hginsights.com/wp-includes/js/jquery/ui/core.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/lib/swiper/v8/swiper.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/kmdg-post-filters/dist/js/select2.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/kmdg-post-filters/dist/js/PostFilters.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.js*
Tracking script
TRACK
*hginsights.com/wp-includes/js/dist/i18n.js*
Tracking script
TRACK
*hginsights.com/wp-includes/js/dist/hooks.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/animate-circle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor-pro/assets/js/frontend.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/elementor.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor-pro/assets/js/elements-handlers.js*
Tracking script
TRACK
*hginsights.com/cdn-cgi/challenge-platform/scripts/jsd/main.js*
Tracking script
TRACK
*hginsights.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/*/main.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/lightbox.*.bundle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/lib/dialog/dialog.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/lib/share-link/share-link.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/shared-frontend-handlers.*.bundle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/text-editor.*.bundle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor-pro/assets/js/nested-carousel.*.bundle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor-pro/assets/js/search-form.*.bundle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/nested-tabs.*.bundle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/nested-accordion.*.bundle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor-pro/assets/js/nav-menu.*.bundle.js*
Tracking script
TRACK
*hginsights.com/wp-content/plugins/elementor/assets/js/nested-title-keyboard-handler.*.bundle.js*
Tracking script
TRACK
*go.hginsights.com/js/forms2/js/forms2.js*
Tracking script
TRACK
hginsights.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/kmdg-resource-center/dist/js/resources.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-includes/js/imagesloaded.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-includes/js/masonry.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-includes/js/jquery/jquery.masonry.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/themes/hginsights/src/js/lib/mmenu.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/themes/hginsights/dist/js/app.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/themes/hello-elementor/assets/js/hello-frontend.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-includes/js/jquery/ui/core.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/frontend.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/lib/swiper/v8/swiper.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/kmdg-post-filters/dist/js/select2.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/kmdg-post-filters/dist/js/PostFilters.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-includes/js/dist/hooks.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-includes/js/dist/i18n.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor-pro/assets/js/elements-handlers.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/animate-circle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/elementor.js
Auto-extracted from scan
TRACK
hginsights.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/lib/dialog/dialog.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/lightbox.d1799e507b570f6b0496.bundle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/lib/share-link/share-link.min.js
Auto-extracted from scan
TRACK
hginsights.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/d251aa49a8a3/main.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/shared-frontend-handlers.03caa53373b56d3bab67.bundle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/text-editor.45609661e409413f1cef.bundle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor-pro/assets/js/search-form.b7065999d77832a1b764.bundle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor-pro/assets/js/nested-carousel.db797a097fdc5532ef4a.bundle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/nested-tabs.a2401356d329f179475e.bundle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/nested-accordion.10705241212f7b6c432b.bundle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor-pro/assets/js/nav-menu.8521a0597c50611efdc6.bundle.min.js
Auto-extracted from scan
TRACK
hginsights.com/wp-content/plugins/elementor/assets/js/nested-title-keyboard-handler.2a67d3cc630e11815acc.bundle.min.js
Auto-extracted from scan
TRACK
go.hginsights.com/js/forms2/js/forms2.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

HG Insights operates in the B2B technology intelligence and data enrichment space, providing technographic data to sales and marketing teams. The company competes with vendors like BuiltWith, Wappalyzer, and SimilarTech for technology detection, but its behavioral capabilities (biometrics, session recording, identity resolution) place it in a different category entirely. HG Insights' data feeds into CRM platforms (Salesforce, HubSpot), ABM tools, and sales intelligence stacks. The tag manager capability (C15) suggests HG Insights can serve as a loader for additional third-party scripts, expanding the data collection surface beyond its own infrastructure.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

228 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details