How This Briefing Works
This report opens with key findings, then maps the gaps between what People.ai discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.
Key Findings
Analysis pending. Findings will appear here once intelligence collection is complete.
Claims vs. Observed Behavior
pending
“Awaiting scanner verification”
People.ai's primary data collection occurs through server-side API integrations with email and calendar providers rather than client-side JavaScript on customer websites
What This Means For You
What To Do About It
Role-specific actions based on observed behavior
Recommended Actions for People.ai
- →- Audit People.ai's data access permissions: review exactly which email, calendar, and communication platform integrations are active and what content-level access is granted. - Evaluate Sensitive Content Filtering effectiveness: request documentation on how the NLP filtering works, what percentage of content is flagged, and whether filtered content is retained or deleted. - Assess data portability: determine what activity data can be exported in standard formats and what remains locked in People.ai's proprietary models. - Review employee notification and consent: ensure sales reps are fully informed about the scope of communication monitoring and have provided appropriate consent per jurisdiction. - Request contractual data isolation: confirm that your organization's activity data is not used for cross-customer model training or aggregate intelligence products.
Negotiation Leverage
- →People.ai's leverage comes from activity capture dependency -- once an organization's CRM hygiene relies on automated logging, removing People.ai creates a data vacuum. Negotiate data portability rights upfront: ensure all captured activity data (emails, meetings, calls, contacts) can be exported in standard formats. Demand explicit contractual language prohibiting use of your activity data for cross-customer model training or aggregate products. The Sensitive Content Filtering claim should be tested: request an audit of what personal content was captured, how it was processed, and what retention policies apply. Push for employee-level opt-out capabilities where jurisdictions require it. People.ai's valuation has faced scrutiny -- use competitive alternatives (Clari, Gong, native Salesforce Einstein) as leverage in pricing negotiations. Total cost should include the organizational risk of centralizing all sales communication data with a single vendor.
IOC Manifest
Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.
No indicators in this category
Ecosystem & Supply Chain
Evidence Artifacts
Artifacts collected during analysis, available with evidence-tier access.
Complete network capture with all requests and responses
21 detection signatures across scripts, domains, cookies, and network endpoints