Lead Generation
Ocean.io
Provenance unknown Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Ocean.io ApS · ocean.io
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Ocean.io is a lookalike engine: it learns an ICP from your closed-won CRM deals, ranks every company in your market against it with fit scores and reasons, and pushes ranked accounts to Salesforce, HubSpot, Clay, rep queues, or agents. Its clear strength is CRM sync and export — the top score in the table at a flat 4 — though even there judges report no public information on field mapping, deduplication, or post-cancellation data terms. The weaknesses sit underneath the workflow: data coverage with no record counts, DACH figures, verification, or refresh cadence, and data provenance behind an unexplained 'Built with GDPR in mind' claim. Judges genuinely split on visitor identification, sovereignty, and prospecting compliance: the rationales point to the same evidence — no tracking or consent documentation, a San Francisco contracting entity against vendor Ocean.io ApS, no sovereignty attributes on record, working list-building with no outreach-legality guidance — and weigh it differently. Public pricing stops at 'Start for free', a free trial, and an 'API Pricing' heading.
Speaks for it
- Ranked accounts push directly to Salesforce, HubSpot, and Clay, with an advertised API and delivery into rep queues or agents
- Connects to your CRM and clusters closed-won deals into segments to learn the ICP behind the rankings
- Fit scores with the reason shown and match filtering so only companies that fit make the list, plus research questions answered from companies' own websites as filterable columns
- Change signals — raised funding in the last 90 days, new leadership hired, sales team growth, headcount growth — add timing cues to ranked accounts
- Buying-committee roles per deal over the last 6 quarters, and pipeline revenue projected from your own segment win rates and deal values
Held against it
- No public information on record counts, DACH or per-country coverage, verification methods, or a refresh cadence (data coverage 1)
- The claim of data 'handled securely and in full compliance with EU privacy law' is unexplained, with no public information on source categories, legal basis, or an opt-out route for listed people (data provenance 0–1)
- No public information on identifying companies behind website visits, tracking scripts, or a consent position (visitor identification 0–1)
- No public information on suppression or do-not-contact lists, do-not-call screening, or cold-outreach guidance for Germany and other EU markets (prospecting compliance 1–2)
- The contracting entity shown is Ocean Global, Inc. of San Francisco against vendor Ocean.io ApS, with no sovereignty attributes on record and no public information on hosting, subprocessors, or transfer basis (sovereignty 0–1)
Best for
- You run Salesforce, HubSpot, or Clay and want fit-ranked lookalike accounts pushed directly into existing rep workflows
- You have enough closed-won deals in your CRM for the ICP learning to work from, and you trust your own win data over a third-party database
- You sequence outreach by timing signals — funding, leadership changes, headcount growth — on companies that already fit
- You want ranked company-level accounts for ABM rather than verified person-level contact data
Avoid if
- Your compliance review needs a documented legal basis, source categories, or an opt-out route for the people in the database before contracting (data provenance 0–1)
- You need published coverage numbers or a verification and refresh method for Germany, Austria, and Switzerland to justify the purchase (data coverage 1)
- Your procurement must see hosting location, subprocessors, or a transfer basis in writing — ask the vendor: the public pages we read do not show it
- You need website-visitor identification or third-party intent data rather than lookalike ranking built from your own closed-won deals (visitor identification 0–1)
The scores
Coverage, accuracy & freshness
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
The captured page sells lookalike ranking — every company in your market scored against your closed-won — but I found no public information on record counts, per-country or DACH coverage, emails, direct dials, or any verification and refresh cadence. For a team measured on connect rate rather than list size, nothing here evidences that reachable contact data even sits behind the ranked accounts. Change signals like funding in the last 90 days show event recency, not record freshness. 1
The RevOps Manager
Ocean.io claims to rank every company in the market against your won-deal profile and surfaces change signals like funding and headcount growth, but I found no public information on record counts, country or DACH coverage, verification method, or refresh cadence. Nothing here lets me hold the data quality to account. 1
The Data Protection Officer
The captured pages promise to rank "every company in your market" against a learned profile, but give no database size, no country or DACH breakdown, no verification method and no refresh cadence — accuracy rests entirely on assertion. I found no public information on coverage methodology, firmographic sourcing, or any guarantee backing the numbers. 1
The ABM Marketer
The pages claim Ocean.io ranks every company in my market against my ICP, and timing signals like raised funding in the last 90 days hint at freshness, but I found no public information on record counts, DACH or EU coverage, verification methods, or a refresh cadence — so the accuracy of the ranked universe is unverifiable from outside. 1
The DACH Sales Director
The pitch says Ocean.io ranks "every company in your market", but we found no public information on how much of that market is actually covered — no record counts, nothing stated for Germany, Austria or Switzerland, and no verification method or refresh cadence. For a Mittelstand-heavy patch where firms barely show up in US-built databases, change signals like funding and new leadership are the only nod to currency, with nothing documented behind them. 1
The Skeptic
We found no public information on record counts, per-country or DACH coverage, a verification method, or a re-verification cadence; the only time-bound data points are the change-signal windows such as 'Raised funding in the last 90 days', which is a trigger window rather than a documented refresh schedule. 1
Data sources & lawful basis
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
"GDPR Built with GDPR in mind" and SOC 2 Type II are the only compliance statements, and neither says where the contact and company data comes from or on what legal basis it is processed. I found no public information on legitimate interest, a privacy notice for the people in the database, or any route for them to object and get removed. 1
The RevOps Manager
The only statement on the pages is that the product was built with GDPR in mind and handles data in full compliance with EU privacy law — an assertion with nothing behind it. I found no public information on where contact data comes from, the legal basis for processing it, or how a listed person could find and object to their record. 1
The Data Protection Officer
"Built with GDPR in mind… in full compliance with EU privacy law" is exactly the unexplained compliance assertion I cannot accept: the pages name no source category, no legitimate-interest basis or balancing, no Art. 14 notification of the people in the database, and no route for a listed person to find, object to, or remove their record. The moment a list is exported the customer becomes controller, and nothing public tells them what they inherit. 1
The ABM Marketer
The only lawful-basis statement is "GDPR Built with GDPR in mind... in full compliance with EU privacy law", and I found no public information on where the contact data comes from, on any legitimate-interest reasoning, or on a route for a listed person to find, object to, or remove their record. 1
The DACH Sales Director
The only basis offered is "Built with GDPR in mind" and "full compliance with EU privacy law" — an assertion with no explanation behind it. We found no public information on where the contact data comes from, on legitimate interest as a legal basis, or on how someone listed in the database could object or have their record removed. 1
The Skeptic
The pages assert data is 'handled securely and in full compliance with EU privacy law' with no explanation behind it; we found no public information on source categories, the legal basis for processing, an Article 14 notice to the people in the database, or a self-service opt-out. A trust center is linked but its contents are not captured. 1
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
The only website capability described is researching target companies' own sites to answer questions as filterable columns, which is the opposite direction from identifying visitors to my site. I found no public information on visitor identification, intent signals, a tracking script, or how it behaves around consent. 1
The RevOps Manager
The product ranks lookalike accounts from the closed-won deals sitting in your CRM, not from website traffic, and I found no public information on visitor identification, intent data, tracking scripts, or any consent position. 1
The Data Protection Officer
The pages describe change signals such as funding and headcount growth as timing cues, but we found no public information on identifying companies behind website visits, no description of any tracking script, and no stated position on consent under the German cookie rule. I cannot judge a tracking practice the vendor does not document, and nothing here evidences person- or company-level visitor identification at all. 1
The ABM Marketer
I found no public information on identifying companies behind website visits, no tracking-script or consent position, and no third-party intent data with a named source; the closest thing is change signals like new leadership or sales team growth, which are company events, not buying intent I can trace. 1
The DACH Sales Director
We found no public information on identifying companies behind website visits or on third-party intent data; the story on the page is lookalike ranking from your own closed-won CRM deals. There is likewise no public information on any tracking script or on how it behaves with and without consent. 1
The Skeptic
We found no public information on identifying companies behind website visits — nothing on how any tracking would work, match rates, or a position on TDDDG consent. The closest signals are company-level change triggers such as 'New leadership hired', but no source for intent data is named. 1
Prospecting workflow & outreach rules
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
Fit filters with match thresholds, timing signals like raised funding and new leadership, and buying-committee roles per deal are genuinely useful list-building and timing help for my reps. But the pages describe nothing about contact records, a suppression or do-not-contact list, or what the buyer may lawfully send in Germany and other EU markets — I found no public information on outreach rules or compliance handling of any kind. 1
The RevOps Manager
Fit-scored filters, change signals and ranked lists delivered into rep queues are a real prospecting workflow, but I found no public information on suppression or do-not-contact handling, country-aware outreach rules, or what the buyer may lawfully do with the contacts once the list lands in a queue. 1
The Data Protection Officer
Fit scoring, threshold filters and delivery of ranked accounts into rep queues and CRMs exist, but the pages say nothing about what a buyer may lawfully do with the resulting contacts — no cold-outreach guidance for the main EU markets, no do-not-contact or suppression list, no country-aware flagging of German contacts, and no opt-out handling. The legal risk sits entirely with the customer. 1
The ABM Marketer
Fit scoring with reasons shown, filterable research columns, and ranked accounts delivered to rep queues are all evidenced, but I found no public information on suppression or do-not-contact handling, do-not-call checks, or outreach guidance for Germany and other EU markets — nothing that helps me stay inside UWG §7 once the list is built. 1
The DACH Sales Director
Fit-scored lists, change triggers such as "Raised funding in the last 90 days" and "New leadership hired", and ranked accounts pushed to Salesforce, HubSpot or Clay make a real prospecting workflow. But we found no public information on what the buyer may lawfully do with those contacts — nothing on suppression or do-not-contact handling, on country-aware flags for German contacts, or on guidance for cold outreach rules in any market. 1
The Skeptic
The product builds company-level lists, scores and filters matches by fit threshold, alerts on change signals, and delivers ranked accounts to systems or rep queues. We found no public information on suppression or do-not-contact lists, screening phone numbers against national registers, or guidance on cold-outreach rules in the main EU markets. 1
CRM sync, enrichment & export
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
The loop is the right shape for my team: it connects to the CRM, learns the ICP from closed-won deals, and pushes ranked accounts to Salesforce, HubSpot, Clay, rep queues or agents, with an API advertised under its own pricing heading. What the pages do not describe is field mapping, deduplication, enrichment of existing records, API limits, or what happens to exported data and access when the subscription ends. 1
The RevOps Manager
Direct push to Salesforce, HubSpot and Clay plus a CRM connection that clusters closed-won deals is a decent plumbing start, and an API with its own pricing section exists. But I found no public information on field mapping, deduplication, re-enrichment of existing records, or what happens to pushed records and the buyer's access to them when the subscription ends — the exit terms are the first thing I read and they aren't there. 1
The Data Protection Officer
A direct push to Salesforce, HubSpot and Clay plus an advertised API is more than a bare export, and the CRM is read to cluster closed-won deals — but we found no public information on field mapping, deduplication, API limits or credit costs, or on what happens to exported records and the buyer's access after cancellation. As controller of every exported record, the buyer needs those exit terms in writing before signing. 1
The ABM Marketer
The CRM story is real: Ocean.io connects to my CRM, clusters closed-won deals, pushes ranked accounts directly to Salesforce, HubSpot, and Clay, and mentions an API under pricing — but I found no public information on field mapping, deduplication, scheduled re-enrichment, API limits, or what happens to my exported data and access after cancellation. 1
The DACH Sales Director
A direct push to Salesforce, HubSpot and Clay plus an API is more than a bare export, and the CRM connection is what feeds the ICP learning in the first place. We found no public information on field mapping, deduplication, enrichment of existing CRM records, API limits, or whether exported data may be kept after cancellation. 1
The Skeptic
Direct push to Salesforce, HubSpot, and Clay, a CRM connection that ingests closed-won deals to learn the ICP, and an API offering go beyond a single one-way push. We found no public information on field mapping, deduplication, enrichment of existing records, API limits, or what data may be kept after cancellation. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
The contracting entity shown on the page is Ocean Global, Inc. at a San Francisco address, and hosting, infrastructure, and subprocessors are all unnamed — a GDPR-minded badge and SOC 2 say nothing about where EU personal data sits or under what transfer basis. I found no public information on EU hosting, an EU representative, or the data partners behind the company universe, though the vendor itself is listed as a Danish company. 1
The RevOps Manager
The captured page names Ocean Global, Inc. of San Francisco as the legal entity while the vendor carries a Danish company name, and I found no public information on hosting location, subprocessors, or any transfer basis. A GDPR-minded statement and a SOC 2 audit are the entire footing on display, with no European evidence behind them. 1
The Data Protection Officer
The contracting entity shown is Ocean Global, Inc. of San Francisco while the vendor is named as a Danish company; hosting is unstated, no subprocessor or data-partner list is published, and no transfer basis appears anywhere. The "GDPR built with GDPR in mind" line is a claim, not a safeguard, and the independently sourced record carries no sovereignty attributes. 1
The ABM Marketer
The captured page names Ocean Global, Inc. at a San Francisco address as the legal entity, and I found no public information on hosting location, a subprocessor or data-partner list, or a transfer basis for EU residents' data; SOC 2 Type II and the GDPR statement speak to security posture, not to where the data sits or who processes it. 1
The DACH Sales Director
The contracting entity named on the site is Ocean Global, Inc. of San Francisco, and the sovereignty review has nothing on record for hosting, controller or subprocessors. We found no public information on where EU personal data is held or on any transfer basis, so there is nothing here I could put in front of a German customer's data-protection officer. 1
The Skeptic
The contracting entity shown on the captured page is Ocean Global, Inc. at 28 Geary Street, San Francisco — a US entity — and the sovereignty record carries no attributes at all; we found no public information on hosting location, subprocessors, or a transfer basis for EU residents' data. The claim of being 'Built with GDPR in mind' says nothing about where the data sits. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
Starting for free, a free trial, and an API pricing heading are the full extent of public pricing on the captured page. I found no public information on paid tier prices, credits per data type, seat costs, credit expiry, or minimum terms, so a real annual invoice is not computable from what is published. 1
The RevOps Manager
The public price signals amount to a free starting tier, a free trial, and an API pricing section. I found no public information on tier prices, seat costs, credit allowances or credit expiry, so a buyer cannot compute the annual cost from what is shown. 1
The Data Protection Officer
"Start for free", a free trial and an "API Pricing" label are the only pricing signals captured; no tier prices, credit costs, seat fees, credit expiry or VAT treatment are public, so the annual invoice is not computable. A buyer also cannot see from these pages what contact data they would be paying to export — which is where my controller questions would begin. 1
The ABM Marketer
Public pricing information amounts to "Start for free", a free trial, and an "API Pricing" heading — I found no public information on tier prices, credit allowances, seat costs, or expiry, so I cannot compute a real annual invoice from what is published. 1
The DACH Sales Director
The only price signals are "Start for free" and a free trial; we found no public information on tier prices, credit allowances, credit expiry, seat costs or what the API costs. A buyer cannot compute an annual invoice from anything on the captured pages. 1
The Skeptic
The only pricing signals are 'Start for free', a free trial, and an 'API Pricing' heading; we found no public information on tier prices, credit allowances or what a credit buys, seat costs, or credit expiry. The invoice is not computable from the captured pages. 1
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (ocean.io, ocean.io/privacy). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (2)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.