All Vendors
sales_engagement

Salesloft

Sales engagement platform with comprehensive session recording and cross-domain tracking. Maximum CAC subsidization and legal tail risk scores indicate severe competitive intelligence leakage.

123 IOCs32 detections56% pre-consent21 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Salesloft discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

32 detections across 21 sites56% pre-consent activity
CRITICAL

Pre-Consent Activity

Salesloft was observed loading and executing before user consent was obtained on 56% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Your sales team's most effective email templates, call timing patterns, and engagement sequences train SalesLoft models used by competitors. If your SDRs achieve 25% meeting conversion, competitors access same playbook insights through shared ML models. Meanwhile, 40%+ of privacy-conscious prospects block tracking, making your pipeline metrics systematically biased.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Salesloft

  • Legal review of wiretap compliance - session recording requires two-party consent in CA/FL/PA and 9 other states
  • Audit cross-domain tracking scope - verify tracking does not extend beyond owned properties
  • Request model training opt-out - your pipeline data should not optimize competitor campaigns
  • Implement consent-first tracking architecture or accept strict liability for all historical data

If You're Evaluating Salesloft

  • Sales engagement platforms with data isolation (Apollo.io, Instantly.ai)
  • First-party email tracking with no cross-customer model training
  • On-premise sales automation with complete data sovereignty

Negotiation Leverage

  • Perfect CAC subsidization score (100) means your pipeline is training competitor models - demand data segregation guarantees
  • Perfect legal tail risk score (100) indicates multiple violation categories - DPA must include unlimited indemnification
  • Session recording creates wiretap liability beyond GDPR - verify compliance in all two-party consent states
  • Behavioral biometrics require Article 9 consent - audit existing consent mechanism for lawful basis
  • Platform value derives from cross-customer intelligence - pricing should reflect your contribution to shared models
Runtime Detections

Runtime Detections

6 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Typing patterns and interaction timing constitute biometric data under GDPR Article 9, requiring explicit consent and DPO notification.

BTI-C07Session Recording

Full session replay

Impact: Recording sales interactions without disclosure violates wiretap laws in 12 US states (two-party consent). Creates criminal liability beyond civil GDPR fines.

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Tracking begins at page load before any consent mechanism. Every visitor interaction creates unlawful processing under GDPR Article 6.

BTI-C10Fingerprinting

Device identification

IOC Manifest

IOC Manifest

96 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.salesloft.com/scripts/drift-facade.js*
Tracking script
TRACK
*www.salesloft.com/scripts/vidyard-tracking.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/chunks/webpack-*.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/chunks/framework-*.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/chunks/pages/index-*.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/v8wakRIJRXk4tZpXUBVb_/_ssgManifest.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/chunks/511-*.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/chunks/*-*.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/chunks/main-*.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/v8wakRIJRXk4tZpXUBVb_/_buildManifest.js*
Tracking script
TRACK
*www.salesloft.com/_next/static/chunks/pages/_app-*.js*
Tracking script
TRACK
*scout-cdn.salesloft.com/sl.js*
Tracking script
TRACK
*pages.salesloft.com/js/forms2/js/forms2.js*
Tracking script
TRACK
*pages.salesloft.com/rs/432-WAJ-793/images/salesloft-formsplus-core-1.0.8.js*
Tracking script
TRACK
*pages.salesloft.com/rs/432-WAJ-793/images/salesloft-simpledto-2.0.4.js*
Tracking script
TRACK
scout-cdn.salesloft.com
Tracking script
TRACK
www.salesloft.com/scripts
Tracking script
TRACK
www.salesloft.com/scripts/drift-facade.js
Auto-extracted from scan
TRACK
www.salesloft.com/scripts/vidyard-tracking.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/webpack-b2afb039e16ba9ad.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/framework-840cff9d6bb95703.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/main-299a53fb56d14482.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/pages/_app-d6dcf9c957475483.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/1664-5384bf8fb9963953.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/5512-8b6dddd6ee763b8d.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/511-e91a8a960f650952.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/7426-db1b788f425108ca.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/3669-f49a050741555d2d.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/chunks/pages/index-57a75cee1df6e1f2.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/v8wakRIJRXk4tZpXUBVb_/_buildManifest.js
Auto-extracted from scan
TRACK
www.salesloft.com/_next/static/v8wakRIJRXk4tZpXUBVb_/_ssgManifest.js
Auto-extracted from scan
TRACK
scout-cdn.salesloft.com/sl.js
Auto-extracted from scan
TRACK
pages.salesloft.com/js/forms2/js/forms2.min.js
Auto-extracted from scan
TRACK
pages.salesloft.com/rs/432-WAJ-793/images/salesloft-formsplus-core-1.0.8.js
Auto-extracted from scan
TRACK
pages.salesloft.com/rs/432-WAJ-793/images/salesloft-simpledto-2.0.4.js
Auto-extracted from scan
TRACK
pages.salesloft.com/js/stripmkttok.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Integrates with Salesforce, Outreach, Gmail/Outlook. Shares engagement model training data across customer base. Requires email tracking pixels and web tracking deployment.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

123 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details