All Vendors
deanon
Userpilot

Userpilot

Trust Center lists 2 subprocessors (AWS, Cloudflare). Runtime scans detect 22 third-party vendors including data brokers Brightdata, Dstillery, and Intentdata. 7 vendors fire before consent despite SOC2/GDPR compliance claims.

95 IOCs1 detections1 sites
90
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Userpilot discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

1 detection across 1 site2 critical disclosure gaps
CRITICAL

Subprocessor Disclosure

22 additional vendors detected on userpilot.com including data brokers

GDPR Art 28GDPR Art 13
CRITICAL

Data Broker Presence

Brightdata, Dstillery, Intentdata (data brokers) detected on site

CCPA 1798.115GDPR Art 6
HIGH

Pre-Consent Tracking

7 vendors including identity resolution load before any consent mechanism

GDPR Art 6ePrivacy Directive Art 5(3)
HIGH

Privacy-First Marketing

Identity resolution vendors (Clay, Vector) identify visitors by PII

FTC Act Section 5
HIGH

Undisclosed Party

Not in privacy policy

Disclosure Gaps

Claims vs. Observed Behavior

5 gaps
2 CRIT2 HIGH1 MED
Classified:BTI-X01BTI-X02BTI-X04BTI-X05BTI-X09BTI-X12

Subprocessor Disclosure

GDPR Art 28 · GDPR Art 13CRITICAL
They Claim

Only AWS and Cloudflare listed as subprocessors

Observed Behavior

22 additional vendors detected on userpilot.com including data brokers

Runtime scan 2026-01-23

Data Broker Presence

CCPA 1798.115 · GDPR Art 6CRITICAL
They Claim

Will never sell/use data for Third Parties without consent

Observed Behavior

Brightdata, Dstillery, Intentdata (data brokers) detected on site

Runtime detection of known data broker scripts

Privacy-First Marketing

FTC Act Section 5HIGH
They Claim

Privacy-first Session Replay tool

Observed Behavior

Identity resolution vendors (Clay, Vector) identify visitors by PII

Homepage marketing vs runtime detection

Security Documentation Access

MEDIUM
They Claim

SOC2 Type II certified

Observed Behavior

Report not publicly available, requires request access

Trust Center shows gated access button

Customer Impact

What This Means For You

If Userpilot's SDK is deployed in your application, their operational practices reveal how they handle data environments. Their own website runs 22 undisclosed vendors — 11x more than their Trust Center discloses. Under GDPR Art 28, you are required to verify subprocessor chains, but Userpilot's disclosure of only AWS and Cloudflare while running Clay, Vector, Brightdata, and Dstillery makes this impossible. Seven vendors loading pre-consent on their marketing site, including identity resolution tools that de-anonymize prospects during evaluation, suggests consent-first architecture is not a priority. The presence of known data brokers (Brightdata, Dstillery, Intentdata) on their site creates questions about where visitor data ultimately flows.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Userpilot

  • Audit your consent implementation — Userpilot's own site loads 7 vendors pre-consent, verify their SDK does not replicate this pattern in your application
  • Review their Data Processing Agreement against GDPR Art 28 — the gap between 2 disclosed and 22 detected subprocessors is a material red flag
  • Request their SOC2 Type II report and verify scope explicitly covers the SDK deployed in your application, not just their marketing infrastructure
  • Monitor network requests from Userpilot's SDK in your application to ensure no undisclosed third-party data flows to data brokers
  • Update your privacy policy if Userpilot's SDK creates data flows to any of their 22 detected vendor partners

If You're Evaluating Userpilot

  • Discount privacy-first marketing claims — their own site contradicts this positioning with 22 undisclosed vendors and 3 data brokers
  • Ask specifically about Clay and Vector usage and whether visitor identification data from their website feeds into sales outreach targeting
  • Require pre-contract runtime scan of your test environment with Userpilot SDK installed to verify actual third-party loading behavior
  • Compare against alternatives with verifiable subprocessor transparency (Pendo, WalkMe, Appcues) that do not run data brokers on their sites
  • Negotiate right-to-audit clause allowing you to scan your application network behavior with Userpilot SDK active

Negotiation Leverage

  • Subprocessor audit clause: Userpilot's Trust Center lists 2 subprocessors while 22 vendors are detected at runtime. Require quarterly runtime audit rights and contractual obligation to disclose all third-party code executing on their properties.
  • SDK isolation guarantee: As a product analytics platform embedded in your application, require contractual guarantee that Userpilot's SDK does not load any third-party vendors into your users' browsers without explicit documentation and approval.
  • Data broker prohibition: Brightdata, Dstillery, and Intentdata detected on userpilot.com are known data brokers. Require contractual commitment that no data broker relationships exist within their SDK supply chain.
  • Consent architecture SLA: 7 pre-consent vendors on their own site suggests consent-last engineering culture. Require documented consent-first initialization proof for their SDK with liquidated damages for violations.
  • Identity resolution disclosure: Clay and Vector perform visitor identification on userpilot.com. Require written disclosure of whether prospect identification data from their website feeds into sales targeting.
Runtime Detections

Runtime Detections

6 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C10Fingerprinting

Device identification

BTI-C14Identity Resolution

PII deanonymization

BTI-C15Tag Manager

Container/loader (neutral)

IOC Manifest

IOC Manifest

95 INDICATORS

Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*userpilot.com/wp-content/plugins/plausible-analytics/assets/dist/js/plausible-form-submit-integration.js*
Tracking script
TRACK
*userpilot.com/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*userpilot.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*userpilot.com/wp-content/themes/userpilot-inc/js/navigation.js*
Tracking script
TRACK
*userpilot.com/wp-content/themes/userpilot-inc/js/main.js*
Tracking script
TRACK
*userpilot.com/wp-includes/js/dist/dom-ready.js*
Tracking script
TRACK
*userpilot.com/wp-content/themes/userpilot-inc/inc/megamenu/megamenu.js*
Tracking script
TRACK
*userpilot.com/wp-content/plugins/q2w3-fixed-widget/js/frontend.js*
Tracking script
TRACK
*userpilot.com/wp-includes/js/dist/hooks.js*
Tracking script
TRACK
*userpilot.com/wp-includes/js/dist/i18n.js*
Tracking script
TRACK
*userpilot.com/wp-includes/js/dist/a11y.js*
Tracking script
TRACK
*userpilot.com/wp-content/plugins/gravityforms/js/jquery.json.js*
Tracking script
TRACK
*userpilot.com/wp-content/plugins/gravityforms/js/gravityforms.js*
Tracking script
TRACK
*userpilot.com/wp-content/plugins/gravityforms/js/placeholders.jquery.js*
Tracking script
TRACK
*userpilot.com/wp-content/plugins/gravityforms/assets/js/dist/utils.js*
Tracking script
TRACK
*userpilot.com/wp-content/plugins/gravityforms/assets/js/dist/vendor-theme.js*
Tracking script
TRACK
*userpilot.com/wp-content/plugins/gravityforms/assets/js/dist/scripts-theme.js*
Tracking script
TRACK
website-assets.userpilot.com
Tracking script
TRACK
userpilot.com/wp-content/plugins/plausible-analytics/assets/dist/js/plausible-form-submit-integration.js
Auto-extracted from scan
TRACK
userpilot.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/themes/userpilot-inc/js/navigation.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/themes/userpilot-inc/js/main.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/themes/userpilot-inc/inc/megamenu/megamenu.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/plugins/q2w3-fixed-widget/js/frontend.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-includes/js/dist/dom-ready.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-includes/js/dist/hooks.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-includes/js/dist/i18n.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-includes/js/dist/a11y.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/plugins/gravityforms/js/jquery.json.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/plugins/gravityforms/js/gravityforms.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/plugins/gravityforms/js/placeholders.jquery.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/plugins/gravityforms/assets/js/dist/utils.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/plugins/gravityforms/assets/js/dist/vendor-theme.min.js
Auto-extracted from scan
TRACK
userpilot.com/wp-content/plugins/gravityforms/assets/js/dist/scripts-theme.min.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Userpilot occupies a sensitive position in the SaaS ecosystem as a product analytics and user onboarding platform. They are embedded in customer applications via JavaScript SDK, gaining visibility into end-user behavior within customer products. On their own website, they deploy a complex vendor stack: GTM orchestrates 22+ vendors including identity resolution (Clay, Vector), data brokers (Brightdata, Dstillery, Intentdata), and ad platforms (Google Ads, LinkedIn Ads, Bing Ads). This vendor density suggests aggressive lead generation and retargeting. Notably, many vendors that would detect as hostile on customer sites are running on Userpilot's own domain. Their SDK integrates with Segment, Amplitude, Mixpanel, and HubSpot, creating data flows into customer analytics stacks.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

95 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details