Marketing Automation
Customer.io
Provenance unknown Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Customer.io, Inc. · customer.io
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Customer.io — contracting entity Peaberry Software, Inc. — is a marketing automation platform marketed as a customer engagement platform trusted by 9,000+ brands. Channel coverage scored highest at 5-6: email, mobile, in-app, push, SMS and WhatsApp are named on a single platform, with personalisation driven by product usage. Journey orchestration follows at 3-4 on a visual workflow builder and behavioural triggers for onboarding and retention. Lead management is the weakest at 0-2: the captured pages describe churn-risk messaging, and we found no public information on lead scoring, lifecycle stages or handover to sales. Sovereignty scored a flat 1, with no sovereignty attributes on record; consent and profiling sits at 1-2, certifications published but consent mechanics unevidenced. CRM and data spans 2-4: custom objects, a data warehouse and a published API reference appear, but no CRM is named and sync mechanics are undocumented. flagged splits flagged none; the ranges reflect differing weight on behavioural segmentation and data-model substance versus documented lead scoring and CRM sync. Pricing is public only as a 14-day free trial with no credit card required.
Speaks for it
- Six channels — email, mobile, in-app, push, SMS and WhatsApp — are named on a single platform, scoring 5-6 on channel coverage
- Cross-sell and upsell personalisation is described as based on product usage, which judges read as behavioural targeting rather than stored fields
- A visual workflow builder and behavioural triggers for onboarding, activation and retention flows are evidenced, scoring 3-4 on journey orchestration
- Custom objects, data activation, a data warehouse and a published API reference evidence a real data model, scoring 2-4 on CRM and data
- Trial terms are public: a 14-day free trial with no credit card required, cancel anytime
Held against it
- Lead management scored 0-2, with no public information on lead scoring, lifecycle stages, qualification, routing or handover to sales
- Sovereignty scored a flat 1 — no sovereignty attributes are on record, and we found no public information on hosting location, infrastructure or subprocessors
- Consent and profiling scored 1-2: GDPR, CCPA, ISO 27001, AICPA SOC and HIPAA certifications are published, but we found no public information on consent records, double opt-in, per-contact tracking switches or retention rules
- No CRM is named, and we found no public information on bidirectional sync, field mapping, deduplication or conflict resolution
- We found no public information on branching, waits, per-contact journey state or what happens when a contact qualifies for several journeys at once
Best for
- You need lifecycle messaging across many channels — email, mobile, in-app, push, SMS and WhatsApp — on one platform, with personalisation driven by product usage
- Your team runs onboarding, activation and retention journeys triggered by product behaviour rather than hand-built segments
- You have engineering capacity to work with a published API reference, custom objects and a data warehouse
Avoid if
- You need a scored, explainable lead lifecycle with routing and handover to sales — lead management scored 0-2 on this evidence
- You must demonstrate consent mechanics — consent records, double opt-in, per-contact tracking switches — for profiling of named people; consent and profiling scored 1-2
- You require stated data residency or a subprocessor list for behavioural profiles of EU residents — ask the vendor: the public pages we read do not show it
- You need a named CRM integration with documented field mapping, deduplication and conflict resolution before signing — ask the vendor: the public pages we read do not show it
The scores
Journeys & orchestration
Show reasoningHide reasoning
How this is scored
Multi-step automation: triggers, branching, waits, and — the part that decides whether it survives contact with reality — what happens when journeys collide.
0 — Autoresponders on a single trigger; no branching, no waits, no conditions.
3 — Linear sequences with simple conditions, one entry trigger per journey, and no visibility into where a contact currently sits.
5 — A visual builder with branching on attributes and behaviour, waits and goals, entry and exit conditions, and per-contact journey state visible.
8 — Event-driven entry from external systems, frequency capping and suppression across journeys, priority when a contact qualifies for several, versioning of a live journey, and testing against real records.
10 — Orchestration is coherent across the whole programme: one decision layer deciding what a person receives next regardless of which journey wants to send it, holdout groups for measurement, and a journey a colleague can read months later without a diagram.
The Demand Gen Lead
A Visual Workflow Builder with behavioural triggers and welcome flows is named, which is genuine orchestration surface. We found no public information on branching, waits, per-contact journey state, or what happens when a contact qualifies for several journeys — collision handling is where an automation programme survives or dies, and I can't trust it with yesterday's email on this evidence. 1
The Sales Ops Manager
A visual workflow builder and behavioural triggers are named, which puts this past autoresponders, but I found no public information on waits, goals, entry and exit conditions, or per-contact journey state. The part that decides whether it survives contact with reality — what happens when journeys collide — goes entirely undiscussed. 1
The Data Protection Officer
A visual workflow builder is named and behavioural triggers are marketed for activation, onboarding, retention and cross-sell flows, which evidences multi-step automation exists. We found no public information on waits, entry and exit conditions, per-contact journey state, or what happens when journeys collide, so the parts that decide whether orchestration survives contact with reality are unevidenced. 1
The Lifecycle Marketer
A visual workflow builder and behavioural triggers for onboarding, activation and retention flows are named, which clears the single-trigger autoresponder bar. We found no public information on branching, waits, entry and exit conditions, or where a contact currently sits in a journey — and nothing on frequency capping across journeys, priority when several qualify, or holdout groups for measurement. 1
The Solution Architect
A visual workflow builder and behavioral triggers for activation and onboarding flows are named, which is more than single-trigger autoresponders. I found no public information on branching, waits, entry and exit conditions, per-contact journey state, or what happens when a contact qualifies for several journeys at once — the collision handling is what decides whether this survives reality. 1
The Skeptic
The captured page names a Visual Workflow Builder and behavioral triggers for onboarding, activation and retention, which gets it linear conditioned sequences. Beyond that label I found no public information on branching, waits, goals, per-contact journey state, or what happens when a contact qualifies for several journeys at once — the parts that decide whether automation survives contact with reality. 1
Lead scoring, routing & lifecycle
Show reasoningHide reasoning
How this is scored
Scoring, qualification and handover to sales — including whether the customer can explain to a lead why the system decided what it decided.
0 — No scoring or lifecycle model; every contact is treated alike.
3 — A single additive score with fixed rules, no decay, no lifecycle stages and no routing.
5 — Configurable scoring on attributes and behaviour with decay, lifecycle stages, and routing to owners or teams with notification.
8 — Multiple scoring models per product or region, negative scoring, account-level scoring alongside contact-level, SLA on follow-up, and score history visible per contact.
10 — Scoring is explainable and accountable: the contribution of each signal visible per record, model changes versioned with their effect on the funnel, routing rules auditable, and predictive scoring — where offered — documented well enough for a DPO to assess it as automated decision-making.
The Demand Gen Lead
The captured page shows activation and churn-risk messaging, and we found no public information on lead scoring, decay, lifecycle stages, or routing to sales owners with notification. From a demand-gen seat the entire scoring-to-handover path is unevidenced. 1
The Sales Ops Manager
Activation, onboarding and retention use cases plus churn-risk signals show behavioural segmentation of users, but I found no public information on scoring models, lifecycle stages, or routing and handover to sales. Nothing here evidences that a score or its history is visible per record. 1
The Data Protection Officer
Retention messaging that responds to churn-risk signals implies engagement-based targeting, but we found no public information on scoring models, decay, lifecycle stages, or routing to owners and teams. Nothing here documents any decision about a lead, which is itself the finding for a scoring capability. 1
The Lifecycle Marketer
We found no public information on lead scoring, qualification, lifecycle stages, routing to owners, or any handover to sales. The engagement signals mentioned serve retention campaigns, not a scored and explainable decision about a lead. 1
The Solution Architect
The captured pages describe responding to engagement signals and churn risk, which is campaign language rather than lifecycle management. I found no public information on scoring, qualification, routing, handover to sales, or any lifecycle stage model. 1
The Skeptic
I found no public information on lead scoring, decay, lifecycle stages, qualification or routing to sales anywhere in the captured pages. The onboarding and churn-risk use cases are marketing journeys, not a lifecycle model a sales team can hand a lead over against. 1
Channels & personalisation
Show reasoningHide reasoning
How this is scored
What the platform can actually send and personalise: email, SMS, push, on-site content, ads audiences — judged on what shares one profile and one suppression list.
0 — Email only.
3 — Email plus one further channel, managed separately with its own list and no shared suppression.
5 — Email, SMS or push and web forms driven from one contact profile, with dynamic content blocks and shared unsubscribe handling.
8 — The above plus on-site personalisation, ad-audience sync to the major networks, cross-channel frequency capping, and content personalised on behaviour rather than only on stored fields.
10 — Channel is a delivery detail: one profile and one consent state across every channel, next-best-channel selection, and personalisation that draws on the full behavioural record without the marketer assembling it by hand.
The Demand Gen Lead
Six channels are named — email, mobile, in-app, push, SMS, WhatsApp — on a single-platform claim, and cross-sell personalisation is described as based on product usage, which is behaviour rather than stored fields. We found no public information on ad-audience sync, cross-channel frequency capping, or shared suppression across those channels, which holds it below the top band. 1
The Sales Ops Manager
Email, SMS, push, WhatsApp, in-app and mobile marketing are all named on a single platform, and personalisation is described as based on product usage rather than only stored fields. I found no public information on shared suppression lists, cross-channel frequency capping, or ad-audience sync. 1
The Data Protection Officer
Six channels are listed — email, mobile, in-app messages, push, SMS and WhatsApp — on a single platform that personalises cross-sell campaigns on product usage, which is behavioural rather than stored-field personalisation. We found no public information on shared suppression or unsubscribe handling across channels, ad-audience sync, or cross-channel frequency capping, so the one-profile claim rests on marketing copy alone. 1
The Lifecycle Marketer
Six channels are named — email, SMS, push, in-app, mobile and WhatsApp — on a single platform, and cross-sell personalisation is described as based on product usage, which is the behavioural record I want personalisation drawn from rather than hand-assembled fields. We found no public information on shared suppression or unsubscribe handling across channels, dynamic content blocks, ad-audience sync, or cross-channel frequency capping. 1
The Solution Architect
Six channels are listed — email, mobile, in-app, push, SMS, WhatsApp — with personalisation described as based on product usage rather than only stored fields. I found no public information on whether one profile and one suppression list drives all of these channels, or on cross-channel frequency capping. 1
The Skeptic
Six channels are named — email, push, SMS, in-app, WhatsApp, mobile — with personalisation driven by product usage, which clears the multi-channel bar with behaviour-based personalisation to boot. What the pages never show is the part I read for: one profile and one suppression list shared across those channels, ad-audience sync, or cross-channel frequency capping. 1
Consent, tracking & profiling
Show reasoningHide reasoning
How this is scored
The platform builds behavioural profiles of named people. Consent capture and proof, tracking that can be limited, retention, and whether automated decisions about individuals are documented and contestable.
0 — Tracking always on and undocumented, single opt-in, no consent record, no retention rule, no way to exclude a person from profiling.
3 — Double opt-in available with a timestamp, cookie tracking that cannot be disabled per contact, and retention described as the customer's problem.
5 — Double opt-in as documented default with a stored consent record including source, per-channel consent states, tracking switchable per contact, and stated retention for inactive records.
8 — Consent reproducible as evidence with the wording versioned, profiling suppressible per person, retention executed per data category, documented handling of access and erasure requests including derived scores, and a cookieless or first-party tracking mode.
10 — Built for the accountability principle: a per-contact history of what was tracked, scored and decided, automated decision-making documented well enough to support an Art. 22 assessment, profiling off by default for anyone who has not consented to it, and deletion that removes derived scores as well as raw events.
The Demand Gen Lead
GDPR and CCPA appear in a certifications list, but we found no public information on double opt-in defaults, stored consent records with source, per-contact tracking switches, or retention for inactive profiles. For a platform building behavioural profiles of named users via product usage, that silence is itself the finding. 1
The Sales Ops Manager
GDPR, CCPA, ISO 27001, AICPA SOC and HIPAA certifications plus a Trust Center are listed, but I found no public information on consent capture with records, double opt-in defaults, per-contact tracking switches, or retention for profiles of named people. Certification claims are not evidence of consent mechanics. 1
The Data Protection Officer
The platform builds behavioural profiles of named people — behavioural triggers, churn-risk signals, product-usage personalisation — and claims GDPR compliance and a Trust Center, but we found no public information on consent records, double opt-in, per-contact tracking switches, retention rules, or handling of access and erasure requests including derived scores. For a profiling system this silence is decisive: nothing on the captured pages lets a buyer reproduce consent or suppress profiling for a person who never agreed to it. 1
The Lifecycle Marketer
GDPR, CCPA, ISO 27001, AICPA SOC and HIPAA certifications are claimed and a Trust Center is listed, which signals a compliance posture beyond undocumented tracking. Beyond that we found no public information on consent records and their wording, per-channel consent states, tracking switched per contact, retention rules, or how profiling and automated decisions are documented and made contestable. 1
The Solution Architect
GDPR and CCPA appear in a compliance list and a Trust Center is linked, and that is the whole of the accountability picture here. For a platform profiling named people through behavioral triggers, I found no public information on consent records, double opt-in, per-contact tracking switches, retention rules, or suppression of profiling. 1
The Skeptic
GDPR, CCPA, ISO 27001, SOC and HIPAA certifications are published alongside a Trust Center, so compliance is certainly marketed. On the mechanics — double opt-in defaults, stored consent records with source, per-channel consent states, a per-contact tracking switch, retention for inactive records, suppression of profiling — I found no public information. 1
CRM integration & data model
Show reasoningHide reasoning
How this is scored
The join that decides the implementation: how the platform and the CRM stay in agreement about who a person is, and what happens when they disagree.
0 — CSV import and export; no CRM integration and no identity resolution.
3 — One-way sync into a named CRM on a schedule, with duplicates resolved by hand and no conflict rules.
5 — Bidirectional sync with at least one major CRM, field mapping, deduplication rules, and a sync error log somebody can act on.
8 — Configurable conflict resolution per field, account and contact objects both modelled, custom objects supported, near-real-time sync with retry, and a documented API with rate limits.
10 — One record, two systems, no ambiguity: identity resolution across anonymous and known states, field-level ownership defined per system, replay of failed syncs, and a data model the customer can extend without vendor services.
The Demand Gen Lead
Custom objects, anonymous messages, a data warehouse and a documented API reference give this a developer-grade data story on a single-platform claim. We found no public information on sync with a named CRM, bidirectional field mapping, deduplication rules, or conflict resolution — the join that decides the implementation. 1
The Sales Ops Manager
Custom objects, a data warehouse, data activation and a documented API reference give the data model real substance, and anonymous messaging hints at anonymous-to-known handling. But I found no public information naming any CRM integration, field mapping, deduplication or conflict rules, or a sync error log somebody can act on — as the person who inherits every duplicate, that silence decides the score. 1
The Data Protection Officer
Custom objects, a data warehouse, data activation, anonymous messages and a published API reference are evidenced, which shows a real data model rather than CSV exchange. We found no public information on sync with any named CRM, field mapping, deduplication or conflict rules, or identity resolution between anonymous and known states — the join that decides the implementation is entirely unevidenced. 1
The Lifecycle Marketer
Custom objects, a data warehouse, data activation and a published API reference point to a real data model rather than CSV round-trips. We found no public information on a named CRM integration, bidirectional sync, field mapping, deduplication or conflict rules, or identity resolution between anonymous and known visitors — the join that decides the implementation. 1
The Solution Architect
Custom objects and a published API reference are the two things I look for first, and both appear alongside data warehouse and data activation. But I found no public information on any named CRM integration, field mapping, conflict resolution, or API rate limits, and no documented path from anonymous visitor to known contact — anonymous messages are a channel, not identity resolution. 1
The Skeptic
Custom objects, a Data Warehouse connection and a published API reference evidence a real data model, and anonymous messaging hints at identity handling. But no CRM is named anywhere, and there is no public information on bidirectional sync, field mapping, deduplication, conflict resolution or a sync error log — the join that decides the implementation is unevidenced. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where behavioural profiles of named EU residents are processed, who the contracting entity is, and which subprocessors see them. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which given the profiling is heavily.
0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed, behavioural data leaving the EU with no stated basis.
3 — EU data residency for storage while tracking, sending or support access remain non-EU, or the contracting entity sits outside the EU.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — tracking scripts, AI scoring, analytics — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure, EU contracting entity, complete subprocessor list published, and any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: every profile, event and derived score processed in the EU by European subprocessors, certification published, and no transfer requiring a Schrems II argument to survive.
The Demand Gen Lead
The contracting entity is Peaberry Software, Inc. under vendor Customer.io, Inc., with no sovereignty attributes on record; we found no public information on hosting location, subprocessors, or any stated basis for EU behavioural data leaving the EU. Certifications like ISO 27001 and SOC speak to security posture, not to where EU profiles are processed — and given the profiling, I weight that heavily. 1
The Sales Ops Manager
The contracting entity is Peaberry Software, Inc., and no sovereignty attributes are on record: I found no public information on hosting location, EU contracting options, or any subprocessor list. For a platform profiling named EU residents this is close to a blank page, softened only by GDPR and ISO certification claims. 1
The Data Protection Officer
The only contracting entity on record is Peaberry Software, Inc., and no sovereignty attributes exist for this vendor — we found no public information on hosting location, an EU contracting entity, subprocessors, or the legal basis for any transfer. Certifications such as ISO 27001 and GDPR speak to a security and compliance posture, not to where behavioural profiles of EU residents are processed, and given the profiling that gap weighs heavily. 1
The Lifecycle Marketer
No sovereignty information is on record: the contracting entity is shown as Peaberry Software, Inc. with no location stated, and we found no public information on hosting location, infrastructure, or a subprocessor list. For a platform building behavioural profiles of named people, the claimed certifications say nothing about where profiles, events and derived scores are processed. 1
The Solution Architect
The contracting entity is Peaberry Software, Inc., and I found no public information on hosting location, an EU contracting entity, residency claims, or any subprocessor list — certification names are the only compliance signal on the page. For behavioural profiles of EU residents this buyer weighs that absence heavily. 1
The Skeptic
The published legal entity is Peaberry Software, Inc., and the record carries no hosting location, no infrastructure provider and no subprocessor list — I found no public information on where behavioural profiles of EU residents are processed. A GDPR certification is a compliance posture, not a residency claim, and for a platform whose product is profiling named people that silence is nearly the whole score. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual invoice for their contact base and send volume — including the tier where automation actually begins, overage, and mandatory onboarding — from public pages alone.
0 — No public prices at all; every tier is a sales conversation, and onboarding fees are never mentioned.
3 — A contact-tier headline exists, but the tier where journeys, scoring or CRM sync begin is unstated, as is any mandatory implementation fee.
5 — Contact-tier prices public with billing period and send limits stated, but at least one commonly needed capability sits in an unpriced enterprise tier.
8 — Every tier priced publicly with contact and volume limits, feature boundaries, overage rates, onboarding costs, minimum term and VAT treatment stated.
10 — Complete price computability: annual invoice derivable for a given contact count, send volume and feature set, including overage, additional users and any implementation fee stated outright.
The Demand Gen Lead
The only public pricing detail captured is a 14-day free trial with no credit card required. We found no public information on tier prices, contact or send limits, the tier where journeys begin, overage rates, or implementation fees — no buyer can compute an annual invoice from this page. 1
The Sales Ops Manager
Only the trial terms are public — "14-day free trial No credit card required Cancel anytime" — and I found no public information on tier prices, contact or send limits, feature boundaries, or the cost of the hands-on implementation they offer. A buyer cannot begin to compute an annual invoice from this. 1
The Data Protection Officer
Only trial terms are public — fourteen days free, no credit card required — and we found no public information on tier prices, contact or send limits, feature boundaries, overage, or the cost of the hands-on implementation the page itself advertises. A buyer cannot compute any invoice for their contact base from these pages, and the tier where automation begins is unstated. 1
The Lifecycle Marketer
The only public pricing fact is the trial: a 14-day free trial with no credit card required, cancel anytime. We found no public information on tier prices, contact and send limits, where journeys and scoring features begin, overage rates, or any onboarding fee — so an annual invoice is not computable from the captured pages. 1
The Solution Architect
The only pricing fact captured is a 14-day free trial with no credit card required. I found no public information on tier prices, contact or volume limits, where automation begins, or any implementation fee — hands-on implementation is offered with no price attached. 1
The Skeptic
The only pricing fact published is a 14-day free trial with no credit card required. No contact tiers, no prices, no send limits, no overage — and the hands-on implementation the support copy advertises appears with no fee attached, which is exactly the onboarding invoice that arrives after signature. 1
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency, Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 16 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 10 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (12)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page customer.io Checked 29 Sep 2026 Details →
- 2 Security / trust page — found from the homepage customer.io Checked 30 Sep 2026 Details →
- 3 Journeys & orchestration — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
- 4 Journeys & orchestration — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
- 5 Lead scoring, routing & lifecycle — found from sitemap customer.io Checked 1 Oct 2026 Details →
- 6 Lead scoring, routing & lifecycle — found from sitemap customer.io Checked 1 Oct 2026 Details →
- 7 Channels & personalisation — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
- 8 Channels & personalisation — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
- 9 Consent, tracking & profiling — found from sitemap customer.io Checked 1 Oct 2026 Details →
- 10 Consent, tracking & profiling — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
- 11 CRM integration & data model — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
- 12 CRM integration & data model — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →