All Vendors
tag_manager

PathFactory

PathFactory is a tag_manager vendor with a VRS of 80, flagged for 6 BTI codes including session recording (C07), consent bypass (C09), and tag injection (C15). The platform deploys aggressive visitor intelligence while delivering content experiences, creating moderate signal corruption (25) but severe cost attribution manipulation (90) and full legal tail risk (100).

120 IOCs8 detections75% pre-consent6 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what PathFactory discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

8 detections across 6 sites75% pre-consent activity
CRITICAL

Pre-Consent Activity

PathFactory was observed loading and executing before user consent was obtained on 75% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Revenue teams face three core risks: (1) Marketing attribution becomes distorted by over-crediting content touches, making CAC calculations unreliable and potentially shifting budget toward ineffective content programs. (2) Detailed prospect research behavior becomes visible to PathFactory, revealing which competitors you evaluate and what objections concern you most—intelligence that feeds vendor competitive analysis. (3) Legal exposure from consent bypass and session recording creates GDPR/CCPA liability that DPOs cannot fully mitigate without removing the vendor.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use PathFactory

  • Demand data processing addendum with explicit session recording disclosure
  • Require consent framework integration that blocks tag firing until user acceptance
  • Implement CSP headers to prevent tag injection without security review
  • Configure content analytics to exclude PII and competitive research signals
  • Establish data retention limits for behavioral profiles

If You're Evaluating PathFactory

  • Request technical documentation on consent detection mechanisms
  • Verify whether session recordings are processed in EU for GDPR deployments
  • Test tag behavior in pre-consent state to confirm no data collection occurs
  • Review visitor identity resolution logic for fingerprinting techniques
  • Assess data flows to vendor analytics infrastructure and third-party enrichment

Negotiation Leverage

  • PathFactory deploys 6 high-risk tracking techniques including session recording and consent bypass—demand full technical disclosure of data collection scope and explicit DPA terms covering regulatory liability
  • The platform captures detailed competitive research behavior that reveals your evaluation process to vendor analytics—negotiate contractual limits on secondary use of engagement data for vendor intelligence
  • Tag manager architecture allows runtime tracking modifications without your security review—require change control processes and tag injection approval workflows
  • Content intelligence creates attribution distortion that may shift marketing spend toward ineffective programs—establish baseline measurement methodology and verify attribution logic before deployment
  • Legal tail risk from consent bypass is 100% and cannot be fully mitigated through configuration—evaluate whether content intelligence value justifies regulatory exposure or consider privacy-respecting alternatives
Runtime Detections

Runtime Detections

6 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

Impact: PathFactory can detect analysis environments and alter tracking behavior during security assessments, masking full data collection scope.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Content interaction patterns (scroll velocity, read time, navigation paths) create persistent visitor profiles across sessions.

BTI-C07Session Recording

Full session replay

Impact: Full session replay capability captures all visitor interactions during content consumption, including form fills and page navigation.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Tag manager architecture allows tracking initialization before consent capture, processing visitor data regardless of preferences.

BTI-C10Fingerprinting

Device identification

Impact: Device and browser fingerprinting creates persistent identifiers for visitor recognition across content sessions.

BTI-C15Tag Manager

Container/loader (neutral)

Impact: Dynamic tag injection capability allows runtime modification of tracking scope without code changes or security review.

IOC Manifest

IOC Manifest

120 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*cdn-app.pathfactory.com/libraries/overlay/overlay.js*
Tracking script
TRACK
*cdn-app.pathfactory.com/production/jukebox/current/jukebox.js*
Tracking script
TRACK
*www.pathfactory.com/cdn-cgi/challenge-platform/scripts/jsd/main.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/navbar.CLUOi3YM.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/client.DRCFoS1P.js*
Tracking script
TRACK
*www.pathfactory.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/*/main.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/jsx-runtime.D_zvdyIk.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/path.YQI7Nyfy.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/consts.B2BRXw-v.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/Combination.CV7OmFxI.js*
Tracking script
TRACK
*cdn-app.pathfactory.com/libraries/chatfactory/widget/index.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/index.3HtMLiyt.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/index.DVzEiDzO.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/utils.DY2VeD3N.js*
Tracking script
TRACK
*cdn-app.pathfactory.com/libraries/tracker/3.19.0/sp.lite.js*
Tracking script
TRACK
*cdn-app.pathfactory.com/libraries/tracker/3.19.0/plugin/link-click.js*
Tracking script
TRACK
*cdn-app.pathfactory.com/production/chatfactory/current/static/index.js*
Tracking script
TRACK
*cdn-app.pathfactory.com/libraries/journey/current/journey.js*
Tracking script
TRACK
*www.pathfactory.com/_astro/feature-tabs.D7FHS3DG.js*
Tracking script
TRACK
cdn-app.pathfactory.com
Tracking script
TRACK
cdn-app.pathfactory.com/libraries/overlay/overlay.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/navbar.CLUOi3YM.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/client.DRCFoS1P.js
Auto-extracted from scan
TRACK
www.pathfactory.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
Auto-extracted from scan
TRACK
cdn-app.pathfactory.com/production/jukebox/current/jukebox.js
Auto-extracted from scan
TRACK
www.pathfactory.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/d251aa49a8a3/main.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/jsx-runtime.D_zvdyIk.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/index.DVzEiDzO.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/Combination.CV7OmFxI.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/utils.DY2VeD3N.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/index.3HtMLiyt.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/consts.B2BRXw-v.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/path.YQI7Nyfy.js
Auto-extracted from scan
TRACK
cdn-app.pathfactory.com/libraries/chatfactory/widget/index.js
Auto-extracted from scan
TRACK
cdn-app.pathfactory.com/libraries/tracker/3.19.0/sp.lite.js
Auto-extracted from scan
TRACK
cdn-app.pathfactory.com/libraries/tracker/3.19.0/plugin/link-click.js
Auto-extracted from scan
TRACK
cdn-app.pathfactory.com/production/chatfactory/current/static/index.js
Auto-extracted from scan
TRACK
cdn-app.pathfactory.com/libraries/journey/current/journey.js
Auto-extracted from scan
TRACK
www.pathfactory.com/_astro/feature-tabs.D7FHS3DG.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

PathFactory typically deploys alongside marketing automation platforms (Marketo, Eloqua, HubSpot) and CRM systems (Salesforce). The vendor consumes visitor identity data from these systems while generating engagement scores that flow back into lead scoring models. Integration architecture creates bidirectional data flows where PathFactory enriches prospect records with content intelligence, potentially exposing your pipeline data to vendor analytics infrastructure.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

120 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details