BLACKOUT://VENDOR_INTEL/MUTINY
VENDOR_DBINTEL READY
abm
Mutiny

Mutiny

90Hypocrisy
90Revenue Risk

Executive Summary

Mutiny is a Series B ($72M) AI-powered ABM platform (YC S18) that personalizes B2B websites for target accounts. Despite privacy policy claims of using "de-identified and aggregated" data, their own website deploys 39 third-party vendors including aggressive identity resolution services (6sense, Clearbit, IDVisitors, Vector) with 66.7% pre-consent loading. Their subprocessor list discloses only 6 infrastructure vendors while concealing 30+ marketing and tracking vendors. This represents a fundamental gap between privacy marketing and operational reality.

Revenue Threat Profile

4 COLLAPSE VECTORS

How this vendor creates financial exposure. Each score (0-100) reflects observed runtime behavior and documented business practices.

100

CAC Subsidization

critical

Mutiny corrupts measurement by deploying identity resolution vendors (6sense, Clearbit) that enrich visitor data beyond what the visitor consented to. This creates phantom attribution where conversions are credited to enriched profiles rather than actual customer intent, distorting pipeline metrics.

40

Signal Corruption

high

As an ABM platform, Mutiny ingests target account lists and intent signals. The undisclosed identity resolution vendors (6sense, Clearbit, Vector) gain visibility into which companies are being targeted, potentially leaking competitive intelligence about sales priorities to data brokers and competitors.

100

Legal Tail Risk

critical

The 39 third-party vendors create significant attack surface. Each vendor script is a potential injection point. The presence of multiple identity resolution vendors means visitor data flows to numerous third parties, any of which could be compromised. Pre-consent loading (66.7%) means this exposure occurs before visitors can opt out.

0

GTM Attack Surface

low

GDPR and CCPA compliance claims are materially contradicted by 66.7% pre-consent tracking. The privacy policy claim of de-identified/aggregated data is false given identity resolution vendors are active. Subprocessor list omits 30+ vendors - a clear GDPR Article 28 violation for transparency.

Profile: mutinyFirst Seen: 2026-01-04Last Updated: 2026-01-22
Confidence:HIGH

Profile by BLACKOUT Threat Intelligence