All Vendors
data_enrichment

Smarte

Data enrichment platform with comprehensive behavioral profiling and persistent tracking. Perfect CAC subsidization and legal tail risk scores indicate maximum competitive intelligence leakage and privacy violations.

83 IOCs1 detections100% pre-consent1 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Smarte discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

1 detection across 1 site100% pre-consent activity
CRITICAL

Pre-Consent Activity

Smarte was observed loading and executing before user consent was obtained on 100% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Every visitor you enrich trains Smarte behavioral models used by competitors for targeting, suppression, and propensity scoring. Your best prospects become identified targets for competitive campaigns. Perfect CAC subsidization means your visitor intelligence directly optimizes competitor conversion while creating 40%+ signal loss from privacy-conscious users.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Smarte

  • Quantify enrichment coverage - measure signal loss from privacy controls to understand audience bias
  • Request complete data segregation - your visitor profiles should not enrich any other customer datasets
  • Verify consent architecture - all tracking must halt until explicit opt-in
  • Implement first-party enrichment without cross-domain sync or persistent identifiers

If You're Evaluating Smarte

  • CRM enrichment via consented form data (no behavioral tracking)
  • First-party CDP with explicit data sharing controls
  • Server-side visitor intelligence with complete data isolation

Negotiation Leverage

  • Perfect CAC subsidization (100) means every visitor you track trains competitor models - demand complete data segregation or reject vendor
  • Perfect legal tail risk (100) indicates violations across all major privacy frameworks - DPA must include unlimited indemnification
  • Advanced persistence (C13) creates multi-year liability accumulation - confirm retention limits and consent renewal
  • Cross-domain profiling requires GDPR Article 35 DPIA - request documentation or accept compliance gaps
  • Comprehensive BTI coverage (7 codes) reflects platform designed for privacy violation - pricing cannot reflect this risk
  • Platform value derives entirely from shared behavioral intelligence - you are product, not customer
Runtime Detections

Runtime Detections

7 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Interaction patterns and mouse dynamics are biometric identifiers under Article 9, requiring explicit consent and heightened security controls.

BTI-C07Session Recording

Full session replay

BTI-C08Cross-Domain Sync

Identity stitching

Impact: Visitor profiles synchronized across domains constitute large-scale profiling under GDPR Article 35, requiring DPIA and DPO notification.

BTI-C09Consent Bypass

Ignoring CMP signals

BTI-C10Fingerprinting

Device identification

BTI-C13Persistence Mechanisms

Long-lived identifiers

Impact: Advanced persistence mechanisms enable multi-month tracking without consent renewal. Creates unlimited liability accumulation and violates ePrivacy Directive retention limits.

IOC Manifest

IOC Manifest

79 INDICATORS

Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*smarte.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.js*
Tracking script
TRACK
*smarte.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*smarte.com/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*smarte.com/wp-includes/js/dist/dom-ready.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/astra-sites/inc/lib/onboarding/assets/dist/template-preview/main.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/elementor/assets/lib/waypoints/waypoints.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/premium-addons-for-elementor/assets/frontend/min-js/premium-wrapper-link.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/elementor/assets/js/webpack.runtime.js*
Tracking script
TRACK
*smarte.com/wp-content/themes/astra/assets/js/minified/style.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/fluentform/assets/js/form-submission.js*
Tracking script
TRACK
*smarte.com/wp-includes/js/jquery/ui/core.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/popup-maker/assets/js/site.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/elementor/assets/js/frontend.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/elementor/assets/js/frontend-modules.js*
Tracking script
TRACK
*smarte.com/wp-includes/js/wp-emoji-release.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/elementor/assets/js/text-editor.*.bundle.js*
Tracking script
TRACK
*smarte.com/wp-content/plugins/elementor/assets/lib/swiper/v8/swiper.js*
Tracking script
TRACK
smarte.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/themes/astra/assets/js/minified/style.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-includes/js/dist/dom-ready.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/astra-sites/inc/lib/onboarding/assets/dist/template-preview/main.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/fluentform/assets/js/form-submission.js
Auto-extracted from scan
TRACK
smarte.com/wp-includes/js/jquery/ui/core.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/popup-maker/assets/js/site.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/premium-addons-for-elementor/assets/frontend/min-js/premium-wrapper-link.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/elementor/assets/lib/waypoints/waypoints.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/elementor/assets/js/frontend.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-includes/js/wp-emoji-release.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/elementor/assets/lib/swiper/v8/swiper.min.js
Auto-extracted from scan
TRACK
smarte.com/wp-content/plugins/elementor/assets/js/text-editor.2c35aafbe5bf0e127950.bundle.min.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Integrates with CRM, marketing automation, advertising platforms. Shares enrichment data across customer network. Requires pixel deployment across all digital properties.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

83 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details