Lead Generation
Leadboxer
Provenance unknown Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Leadboxer B.V. · www.leadboxer.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Leadboxer B.V. identifies anonymous B2B website visitors at company level, enriches records with firmographics and scores intent. Strongest is visitor identification, scores 7-8: organization-level mapping by default, personal data only after a form submission or email reply, the IP address used for matching but never written to disk, EU tracking starting only after valid consent through a consent management platform. Weakest is data coverage at 1-2: no record counts, country coverage, verification method or refresh cadence. The split is data provenance, scores 1 to 4: judges crediting disclosed first-party collection (own site, email, forms) scored high; those weighing the undocumented source of person-level enrichment and the missing Article 14 notice and opt-out scored low. Sovereignty scored 3-4: the "100% EU-based data hosting" claim sits in promotional copy, the privacy policy is silent on storage location and no subprocessor list is published. Pricing transparency scored 3-4: a free tier, a 14-day trial and a Signal Start plan at € 95 /month are public, but usage-based pricing publishes no unit cost and the pages give different figures ($195 per month and $205/month).
Speaks for it
- Visitor identification scored 7-8, mapping anonymous traffic to organizations by default with names and email addresses appearing only after a form submission or email reply.
- The IP address is used for company matching but never written to disk, with an option that zeroes IPv4 and IPv6 before storage.
- For EU traffic, tracking, identification, enrichment and scoring begin only after valid consent through a consent management platform.
- CRM sync and export scored 4-6, covering two-way sync with Salesforce, HubSpot and Pipedrive plus a documented REST API with full record export.
- Public entry points exist — a free tier, a 14-day trial with no credit card required, and a Signal Start plan at € 95 /month.
Held against it
- Data coverage scored 1-2, with no public record counts, coverage figures by country, verification method or refresh cadence.
- We found no public information on where person-level enrichment data comes from, its legal basis, an Article 14 notice, or a removal route for the people identified.
- The "100% EU-based data hosting" claim appears only in promotional copy, the privacy policy is silent on where data is stored, and we found no public information on subprocessors or a data processing agreement.
- Pricing is usage-based with no published unit of usage, and the captured pages give different starting figures ($195 per month and $205/month).
- The captured pages place the customer as controller, responsible for outreach communication and timely removal of data, and we found no public information on cold-outreach rules or do-not-call checks.
Best for
- You need to see which companies visit your B2B website and get real-time alerts by email, Slack or CRM — the bench's highest scores, 7-8 on visitor identification, sit there.
- You market to EU visitors and want tracking, enrichment and scoring to begin only after valid consent through a consent management platform.
- You work in Salesforce, HubSpot or Pipedrive and want two-way sync plus a documented REST API with full record export.
- You want to test before committing — a free tier and a 14-day trial with no credit card required.
Avoid if
- You need published coverage figures, record counts or a refresh cadence to size a pipeline — ask the vendor: the public pages we read do not show it
- Your compliance review must document where enriched contact details originate and how those people are notified or can opt out — data provenance split 1 to 4 on exactly this gap.
- You require a subprocessor list or contractual hosting terms before signing — sovereignty scored 3-4, with the EU hosting claim in promotional copy only.
- You need a computable fixed annual cost — ask the vendor: the public pages we read do not show it
The scores
Coverage, accuracy & freshness
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
I found no public coverage figures — no record counts, no per-country or DACH numbers, no refresh cadence and no bounce or credit-back terms; the only accuracy practice described is filtering ISP, hosting, telecom, mobile and VPN IP ranges before matching. Enrichment fields like employee count, revenue estimate, industry and job title are listed, but with nothing on how often any of it is re-verified, so I cannot judge what connect rate this data would give my team. 1 4
The RevOps Manager
We found no public coverage figures for the database, no verification method and no refresh cadence; the captured pages list enrichment fields like employee count, revenue estimates and technology usage but say nothing about how many companies or contacts are covered in DACH, the EU or anywhere else. For sizing a pipeline there is nothing to compute against, and accuracy claims are simply absent rather than substantiated. 4 5
The Data Protection Officer
The pages tell me what enrichment returns — industry, company size, location, technology usage — but I found no public information on coverage by country or region, record counts, a verification method or a refresh cadence, and no accuracy or credit-back guarantee. The only accuracy practice described is filtering out ISP, VPN and mobile-network IP addresses before matching. 4 5
The ABM Marketer
Enrichment fields are listed — industry, company size, revenue estimates, technology usage — but I found no public information on coverage figures for any country or region, verification methods, or how often records are refreshed. Working a fixed list of target accounts, I cannot tell from these pages how reliably a DACH visit would match to a named company. 4 5
The DACH Sales Director
The enrichment fields are real — industry, company size, revenue estimates, technology usage — and ISP, VPN and hosting IPs are filtered before matching. But the pages give no record counts, no coverage stated for Germany, Austria or Switzerland, and we found no public information on how often company data is verified or refreshed, so I cannot tell a Mittelstand prospect how many German firms this would actually resolve. 4 5
The Skeptic
The pages describe what enrichment returns — industry, company size, revenue estimates, technology usage — and that ISP, hosting and VPN addresses are filtered out for accuracy, but we found no public information on how many companies or which countries the identification data covers, on a verification method, or on any refresh cadence. "Trusted by 5,000+ teams" is a customer count, not a coverage figure, and no accuracy percentage is even asserted for the matching data. 4 5 1
Data sources & lawful basis
panel disagrees
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
The privacy policy covers Leadboxer's own website — cookies, server logs, tracking pixels, newsletter double opt-in, and data-subject rights to access, portability and erasure — and EU deployments are described as consent-gated before tracking starts. But for the people whose profiles get built I found no public information on where the enrichment contact details come from, the legal basis for holding them, an Article 14 notice, or a self-service removal route; personal details are stated to appear only when a visitor submits a form or replies by email. 2 4 5
The RevOps Manager
The collection channels are described — IP intelligence, form submissions, email tracking — and the privacy policy spells out data-subject rights with deletion supported, but we found no public statement of where the person-level enrichment data (job titles, seniority, professional contact details) comes from, no legitimate-interest balancing and no notice to the people who end up in a customer's records. The controller/processor split puts outreach communication squarely on the customer, which is where I start asking questions the vendor has not answered. 2 4 5
The Data Protection Officer
The privacy policy governs Leadboxer's own website — cookies, server logs, newsletter, tracking pixels — not the people its customers identify and enrich; for the professional contact details, job titles and seniority the product returns, I found no public information on the source, a legitimate-interest basis, an Art. 14 notification, or an objection and removal route for the people in the data. GDPR alignment is asserted in general terms, and the stated controller/processor split leaves the customer carrying the legal basis from the moment a list is exported. 2 4 5
The ABM Marketer
The pages describe the tracking architecture in real detail, but I found no public information on where the enrichment and contact data — job titles, professional contact details — comes from or on what legal basis. No source categories, no notice to the people whose details get enriched, and no opt-out route for them appears; the GDPR discussion covers processing design, not provenance. 2 4 5
The DACH Sales Director
Sources are concrete and disclosed: behavioural data from the customer's own website and email, with names and email addresses appearing only after a form submission or email reply, and a privacy policy setting out access, erasure and portability rights. We found no public information on the lawful basis for processing identified B2B contacts once captured, on any Article 14 notice to those people, or on a self-service route for someone who ends up in a customer's lead database to find and remove themselves. 2 4 5
The Skeptic
Collection is disclosed honestly: a first-party tracker on the customer's own site, form submissions and email links, with names and email addresses appearing only when a visitor submits a form or replies, and explicit consent emphasized for anything person-identifying. What is missing is everything after collection — we found no public information on where the firmographic and company-enrichment data originates, on an Article 14 notice to the people who end up in a customer's lead base, or on a self-service opt-out for them; the published privacy policy describes the vendor's own website and newsletter, not the product's data subjects. 4 5 2
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
Company-level is the stated default, the IP address is used to identify the company but not written to disk, an IP-masking option zeroes IPv4 and IPv6 before storage, and EU traffic is documented to begin tracking, identification, enrichment and scoring only after valid consent through a consent-management platform. Scoring draws on page visits, form submissions and content interest categories, with alerts to email, Slack and CRM. What holds it back: the returning-visitor ID lives in a first-party cookie, no cookieless mode is documented, and I found no public statement naming the German TDDDG or the consent position for it. 3 4 5 7
The RevOps Manager
Company-level mapping is the default, personal details appear only after a form submission or email reply, and EU tracking — including server-side events — begins only after valid CMP consent; the IP address is used for matching but never written to disk, with a masking option on top. First-party intent scoring on page views and content-interest categories feeds alerts into email, Slack or CRM with automated assignment. We found no public information on a cookieless mode or a specific statement on consent duties under Germany's tracking law. 3 4 5 7
The Data Protection Officer
This is close to what I require before a script fires: identification is organization-level by default, names and email addresses only appear on form submission or email reply, EU traffic is connected to a consent management platform so tracking, identification, enrichment and scoring begin only after valid consent, and the IP address is used for matching but not written to disk, with a masking option on top. It stays below the top because the tracker stores a User ID in a first-party cookie with no cookieless mode documented, no third-party intent source is named, and I found no TDDDG-specific statement of the legal position. 3 4 5 7
The ABM Marketer
This is what I buy for: companies identified by default with person-level data appearing only after a form submission, the IP address used for matching but never written to disk with a masking option on top, and EU tracking gated to start only after valid consent through a consent management platform. Alerts land in real time via email, Slack or the CRM with automated assignment to the right owner, and scores draw on page visits and content-interest categories I can trace back through the visit history. I found no public information on a cookieless mode or a named third-party intent source — the intent here is first-party. 1 4 5 7
The DACH Sales Director
This is the vendor's strongest card: anonymous traffic maps to organizations, not people, the IP address is used for company matching but never written to disk — with a masking option that zeroes IPv4 and IPv6 before storage — and EU tracking, enrichment and scoring begin only after valid consent through a consent management platform. One captured page speaks of uncovering both companies and individuals browsing the site while another states personal data enters only via forms and email replies; the detailed pages support the consent-gated reading. Intent scoring runs on named first-party signals — page visits, form submissions, content interest categories — with alerts routed to email, Slack or the CRM, though we found no public information on a cookieless mode or a TDDDG-specific statement. 1 3 4 5 7
The Skeptic
This is the core product and it is documented the way a DPO wants to read it: anonymous traffic maps to organizations by default, personal data appears only after a form submission or email reply, the IP address is used for matching but never written to disk with a masking option on top, and for EU traffic tracking, identification, enrichment and scoring start only after valid consent via a consent management platform, with alerts routed to owners. It stops short of the top because we found no published position naming the German telecom-digital-services consent rule specifically, and the returning-visitor User ID lives in a first-party cookie with no documented cookieless mode. 5 7 4
Prospecting workflow & outreach rules
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
Segments on industry, company size, location and behaviour, saved lead lists with scheduled export, and a visual pipeline with automated assignment by region, size, industry or product interest make the list-building half genuinely usable. The vendor states the customer is the controller and stays responsible for the communication and for removing data from its own systems in time; manual and API-driven deletion with downstream suppression controls exist, but I found no public information on cold-outreach guidance for the main EU markets, country-aware flagging of German contacts, or checks against national do-not-call registers. 3 4 5
The RevOps Manager
Firmographic and behavioural filters, saved lists, segments and account alerts exist, plus manual and API-driven deletion with downstream suppression controls — but the captured pages seat the customer as controller and responsible for outreach communication. We found no public information on per-country outreach rules, checks against do-not-call registers, a shared do-not-contact list, or support for notifying contacts at first touch. 3 4 5
The Data Protection Officer
Segments, saved lead lists, export and alert routing are documented, and manual and API-driven deletion with downstream suppression is stated — but the captured pages place responsibility for communication and removal squarely on the customer as controller. I found no public information on country-aware outreach rules, a do-not-contact list, phone checks against do-not-call registers, or support for the Art. 14 notice at first contact. 3 4 5
The ABM Marketer
Segments, saved lead lists and scheduled exports exist, and manual plus API-driven deletion with downstream suppression is supported, but I found no public information on a do-not-contact list, do-not-call screening, or guidance on cold-outreach rules in the main EU markets. The vendor's own guidance puts responsibility for communications and timely removal squarely on the customer as controller. 3 4 5
The DACH Sales Director
List building is genuinely there — filters on company data and behaviour, saved and schedulable lead lists, automated assignment by region or industry, follow-up sequences, and deletion with downstream suppression controls. But we found no public information on cold-outreach rules in Germany, Austria or Switzerland, no country-aware flagging of German contacts where UWG § 7 requires prior consent, and no do-not-call checking; the captured pages put the customer in the controller seat and responsible for communication. 3 4 5
The Skeptic
Segments and saved lead lists, scheduled export, automated lead assignment and follow-up sequences exist, and manual and API-driven deletion with downstream suppression controls is documented. But the vendor states plainly that the customer is the controller and remains responsible for the communication and for removing data from their own systems, and we found no public information on cold-outreach guidance for the main EU markets, per-country flagging of contacts, or checks against do-not-call registers. 3 5 4
CRM sync, enrichment & export
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
Two-way sync with Salesforce, HubSpot and Pipedrive, enrichment of existing contact records (the HubSpot integration enriches via tracking cookies), and a documented REST API returning JSON with a developer site covering the data model and guides. I found no public information on field mapping, deduplication, API rate limits or per-call costs, or on what a customer may keep after cancellation; the stated model puts removal from the customer's own systems on the customer, which reads as an instruction rather than exit terms. 4 5 6 7
The RevOps Manager
Two-way sync with Salesforce, HubSpot and Pipedrive, a documented REST API, full record export, centralized record history and deletion logging — that is the shape I want in our stack. But we found no public information on field mapping, deduplication, scheduled re-enrichment that updates rather than duplicates, stated API limits, or which data the customer may keep after cancellation — the exit question I always ask first is unanswered. 4 5 6 7
The Data Protection Officer
Two-way sync with Salesforce, HubSpot and Pipedrive, a documented REST API returning enriched data, full record export and API-driven deletion with downstream suppression are all evidenced. But I found no public information on field mapping or deduplication, on API rate limits or per-call costs, and — the question that matters to me — on whether exported data may be kept after cancellation. 3 4 5 6 7
The ABM Marketer
Two-way sync with Salesforce, HubSpot and Pipedrive, enrichment of existing contact records, and a documented REST API with full record export plus deletion and downstream suppression controls get the data to where sales actually works. I found no public information on field mapping, deduplication, API rate limits, or what happens to exported data and my access to it after cancellation. 3 4 5 7
The DACH Sales Director
Two-way sync with Salesforce, HubSpot and Pipedrive, a documented REST API returning JSON with key-based access, full record export, and deletion that propagates downstream with logged record history. We found no public information on field mapping or deduplication, no stated API rate limits or per-call costs, and nothing on whether exported data may be kept — or for how long — after the subscription ends. 4 5 6 7
The Skeptic
Two-way sync with Salesforce, HubSpot and Pipedrive, a HubSpot integration that enriches contact records with firmographic data, and a documented REST API with full record export and unlimited events and properties put this at the solid middle. We found no public information on field mapping or deduplication in the sync, stated API limits or per-call costs, or what the buyer may keep — and for how long — after cancelling. 4 7 5 6
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
The pages claim a GDPR-native architecture, 100% EU-based data hosting and EU-hosted ISO 27001-certified data centers, but those claims appear in a learn article, the privacy policy is silent on storage location, and no hosting provider, data partner or subprocessor list is named; the vendor's own site also integrates Facebook, Google and LinkedIn components. That is an EU-hosting promise without the named infrastructure or subprocessor disclosure I would need before putting EU visitor data in it. 2 5
The RevOps Manager
A Dutch B.V. with repeated EU hosting claims — "100% EU-based data hosting" and ISO 27001-certified EU data centers — but those claims sit in learn/FAQ copy while the privacy policy says nothing about where data is stored. We found no public subprocessor or data-partner list, no named infrastructure and no transfer analysis, so the chain beyond the vendor's own walls is a blank. 2 4 5
The Data Protection Officer
The contracting entity is a Dutch B.V., support hours are CET, and EU hosting is claimed with ISO 27001 data centers — but that claim appears only in a learn article, not in the privacy policy or terms, no provider or data-centre country is named, and the privacy policy is silent on where data is stored. No subprocessor or data-partner list is published, so the chain that sees EU residents' data is invisible, and I found no public information on a data processing agreement covering the records a customer exports. 2 4 5
The ABM Marketer
EU-based hosting is claimed with ISO 27001-certified data centers and EU-resident processing, but the claim sits in promotional material while the privacy policy is silent on where data is stored. I found no public information on the contracting entity's jurisdiction, the named hosting infrastructure, or any subprocessor list — for a tool tracking EU visitors on my site, that gap matters. 2 4 5
The DACH Sales Director
A Dutch entity with a stated controller/processor split and a claim of one hundred percent EU-based hosting in ISO 27001-certified data centers is the right headline for my market. But that residency claim appears only in promotional copy while the privacy policy is silent on where data is stored, and we found no public information on the hosting provider, any subprocessor or data-partner list, or a data-processing agreement, so the promise has nothing contractual behind it. 2 4 5
The Skeptic
EU hosting is claimed — load-balanced, ISO 27001-certified data centres, "100% EU-based data hosting" — but the claim appears in a promotional learn article rather than the privacy policy or terms, no hosting provider or data-centre country is named, and the privacy policy is silent on where data is stored. We found no public information on the contracting entity's jurisdiction or ownership, on a subprocessor or data-partner list, or on a DPA covering exported records. 5 2
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
Public entry points exist: a free tier with basic visitor tracking, IP-to-company matching and API access, a fourteen-day trial without credit card, a Signal Start plan at € 95 /month, and flat-rate plans with the captured pages giving different starting figures of $195 per month and $205/month, plus a custom enterprise plan. Pricing is described as usage-based with no published unit of usage, and I found no public information on seat costs, overage rates, expiry terms or VAT treatment — so the annual invoice for a fixed team size cannot be computed from the public pages. 1 4
The RevOps Manager
Headlines are public — "€ 95 /month Signal Start", a flat-rate plan that "starts at $195 per month", another page saying "starting at $205/month" for U.S. teams, plus a free tier and a 14-day trial without a card — but pricing is described only as usage-based with no unit price, no seat costs, no expiry terms, and enterprise is a sales conversation. The real annual invoice is not computable from these pages. 1 4
The Data Protection Officer
Headline prices are public — a free tier, a fourteen-day trial, a Signal Start plan at € 95 /month, and a flat-rate plan starting at $195 per month — while another captured passage gives pricing plans starting at $205/month, so the pages give different figures for the USD starting price. The model is usage-based with no published unit costs, and I found no public information on seat pricing, credit expiry, API costs or VAT treatment; the enterprise tier is a sales conversation, so the real annual invoice is not computable. 1 4
The ABM Marketer
Headline prices exist — a €95/month Signal Start plan, a flat-rate plan starting at $195 per month, pricing starting at $205/month for U.S. teams, a free tier and a custom enterprise plan — but the model is described as usage-based with no unit prices published. I found no public information on what usage is actually billed, per-seat costs, or term and VAT treatment, so the annual invoice is not computable; the captured pages also give different starting figures. 1 4
The DACH Sales Director
A free tier with named features, a fourteen-day trial without credit card, and public entry points — a Signal Start tier at € 95 /month — are a decent start, though the captured pages give different figures for the paid start ($195 per month for the flat-rate plan in one place, starting at $205/month for U.S. teams in another). The model is usage-based with no stated unit, no seat pricing and no API costs, and Enterprise is a sales conversation, so the real annual invoice still cannot be computed from the public pages. 1 4
The Skeptic
The captured pages give different headline figures — a flat-rate plan starting at $195 per month, plans for U.S. teams starting at $205/month, and a "€ 95 /month" Signal Start — alongside a free tier and a 14-day trial with no credit card required. Pricing is described as usage-based with no public statement of what a unit of usage costs, whether anything expires, seat pricing, or VAT treatment, and the Enterprise and Reseller plans are sales conversations; the invoice cannot be computed from the pages. 4 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 5 Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. The claim appears only in promotional copy (a learn/FAQ article), not in the privacy policy or terms, and no hosting provider or data-center country is named; the privacy policy [S1] is silent on where data is stored.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 6 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 compliance fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 pricing fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
Sources (7)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page www.leadboxer.com Checked 29 Sep 2026 Details →
- 2 Privacy policy — found from the homepage www.leadboxer.com Checked 30 Sep 2026 Details →
- 3 Visitor identification & intent signals — found from sitemap www.leadboxer.com Checked 1 Oct 2026 Details →
- 4 Visitor identification & intent signals — found from sitemap www.leadboxer.com Checked 1 Oct 2026 Details →
- 5 Prospecting workflow & outreach rules — found from sitemap www.leadboxer.com Checked 1 Oct 2026 Details →
- 6 CRM sync, enrichment & export — found from sitemap www.leadboxer.com Checked 1 Oct 2026 Details →
- 7 CRM sync, enrichment & export — found from sitemap developers.leadboxer.com Checked 1 Oct 2026 Details →