Marketing Automation
Ortto
Provenance unknown Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Ortto Pty Ltd · www.ortto.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Ortto, a marketing automation platform from Ortto Pty Ltd, shows breadth at the surface and thin evidence beneath it. Its strongest criterion is channel coverage, scoring 4–6: email, SMS, push, live chat, in-app messages, forms and surveys and transactional email are all named, with a customer data platform module behind them, and the range widens because judges weighed that breadth against the absence of public information on shared suppression and cross-channel frequency capping. The weakest showing beyond pricing is consent and profiling at 1–2: GDPR, ISO 27001, HIPAA and SOC 2 appear as certifications and tracking of named people is sold as a branded feature, yet we found no public information on consent records, per-channel consent states or per-contact tracking control. Journey orchestration at 2–3 and lead management at 1–3 rest on a named journey builder with templates and scoring as a single feature word. Sovereignty runs 2–3, with EU hosting one of three listed regions, no stated default, and no EU contracting entity named. Persona-weighted totals span 2.1 to 3.0; a free trial is the only published pricing fact.
Speaks for it
- Email, SMS, push, live chat, in-app messages, forms and surveys and transactional email are all named as channels, with a customer data platform module behind them
- Salesforce and Shopify integrations are named and developer docs are listed among support resources
- Multi-region data hosting is offered across the EU, USA and Australia, so EU residency for storage appears to exist as an option
- GDPR, ISO 27001, HIPAA and SOC 2 compliance is claimed, with 2FA enforcement, SSO and Okta support, user permissions, roles and audit logs
- A journey builder with templates is named as a core platform module
Held against it
- We found no public information on consent records, per-channel consent states, per-contact tracking control or retention, despite tracking of named people being a named feature
- We found no public information on journey branching, waits, entry and exit conditions, or per-contact journey state beyond a named journey builder with templates
- Scoring appears in the feature list as a single word, with no public information on decay, routing, lifecycle stages or per-contact score history
- We found no public information on sync direction, field mapping, deduplication or conflict resolution for the Salesforce and Shopify connectors
- No default hosting region is stated, we found no published subprocessor list, and the contracting entity is presented as Ortto Pty Ltd with no EU entity named
Best for
- You need a broad named channel span — email, SMS, push, in-app messages, live chat — from a single vendor and can probe cross-channel handling during the free trial
- Your stack already includes Salesforce or Shopify and named connectors plus listed developer docs give your engineers a starting point
- You prefer to evaluate hands-on before any commercial conversation, since a free trial signup is offered
Avoid if
- You need documented consent and profiling mechanics — stored consent records, per-channel consent states, per-contact tracking switches — for a DPO sign-off before contract
- You depend on lead scoring you can explain to a lead, since scoring appears in the feature list as a single word
The scores
Journeys & orchestration
Show reasoningHide reasoning
How this is scored
Multi-step automation: triggers, branching, waits, and — the part that decides whether it survives contact with reality — what happens when journeys collide.
0 — Autoresponders on a single trigger; no branching, no waits, no conditions.
3 — Linear sequences with simple conditions, one entry trigger per journey, and no visibility into where a contact currently sits.
5 — A visual builder with branching on attributes and behaviour, waits and goals, entry and exit conditions, and per-contact journey state visible.
8 — Event-driven entry from external systems, frequency capping and suppression across journeys, priority when a contact qualifies for several, versioning of a live journey, and testing against real records.
10 — Orchestration is coherent across the whole programme: one decision layer deciding what a person receives next regardless of which journey wants to send it, holdout groups for measurement, and a journey a colleague can read months later without a diagram.
The Demand Gen Lead
A journey builder and its templates are named, so multi-step journeys exist on paper, but the captured pages say nothing about branching, waits, per-contact journey state, or what happens when two journeys want the same person — which is the part that decides whether automation survives a real quarter. I found no public information on frequency capping, cross-journey suppression, or versioning a live journey. 1
The Sales Ops Manager
A dedicated journey builder with templates is named as a core module, which is more than single-trigger sending, but we found no public information on branching, waits, entry conditions, or what happens when a contact qualifies for several journeys at once. Per-contact journey state is also not shown. 1
The Data Protection Officer
A journey builder is named as a product module and templates are offered for it, but we found no public information on triggers, branching, waits, per-contact journey state, or what happens when a contact qualifies for several journeys. I cannot assess collision handling or suppression from a feature name alone. 1
The Lifecycle Marketer
A journey builder module and its templates are named, but I found no public information on branching, waits, entry and exit conditions, or where a contact currently sits in a journey. What decides survival in reality — frequency capping and suppression when several journeys want the same person — is nowhere shown. 1
The Solution Architect
A journey builder with templates is named as a platform module, which is more than a bare autoresponder, but the captured page shows nothing on branching, waits, entry and exit conditions, or what happens when journeys collide — the collision handling being exactly where these deployments fail. I found no public information on per-contact journey state, frequency capping, or versioning of a live journey. 1
The Skeptic
The captured pages name a journey builder with templates and stop there; I found no public information on triggers, branching, waits, entry and exit conditions, journey collisions, or any view of where a contact currently sits. A named module with templates is all the evidence there is. 1
Lead scoring, routing & lifecycle
Show reasoningHide reasoning
How this is scored
Scoring, qualification and handover to sales — including whether the customer can explain to a lead why the system decided what it decided.
0 — No scoring or lifecycle model; every contact is treated alike.
3 — A single additive score with fixed rules, no decay, no lifecycle stages and no routing.
5 — Configurable scoring on attributes and behaviour with decay, lifecycle stages, and routing to owners or teams with notification.
8 — Multiple scoring models per product or region, negative scoring, account-level scoring alongside contact-level, SLA on follow-up, and score history visible per contact.
10 — Scoring is explainable and accountable: the contribution of each signal visible per record, model changes versioned with their effect on the funnel, routing rules auditable, and predictive scoring — where offered — documented well enough for a DPO to assess it as automated decision-making.
The Demand Gen Lead
Scoring appears as a single feature word and nothing more. I found no public information on lifecycle stages, routing to owners or teams, decay, negative or account-level scoring, or any score history a rep could read back to a lead. 1
The Sales Ops Manager
Scoring is named in the feature list and that is the whole of it: we found no public information on lifecycle stages, score decay, routing to owners or teams, or a per-contact score history a rep could use to explain a decision to a lead. 1
The Data Protection Officer
Scoring appears as a feature name and an AI module exists, and that is the whole of it: we found no public information on decay, lifecycle stages, routing, score history, or per-record signal contributions. Without any documentation of how scores are computed and versioned, I cannot assess the scoring as automated decision-making about individuals. 1
The Lifecycle Marketer
Scoring appears once in a feature list and is never elaborated: I found no public information on configurable rules, decay, lifecycle stages, routing to owners, or score history per contact. A handover to sales I could explain to a lead is not evidenced. 1
The Solution Architect
Scoring appears as a single word in the feature list and nothing more. I found no public information on scoring rules, decay, lifecycle stages, routing, or score history, so I can confirm a score exists but not whether sales could ever explain to a lead why the system decided what it decided. 1
The Skeptic
Scoring appears as a single word in a feature list. I found no public information on how a score is built, decay, lifecycle stages, routing to owners or teams, negative scoring, or per-contact score history — the distance between a checkbox and lead management is precisely what the captured pages do not show. 1
Channels & personalisation
Show reasoningHide reasoning
How this is scored
What the platform can actually send and personalise: email, SMS, push, on-site content, ads audiences — judged on what shares one profile and one suppression list.
0 — Email only.
3 — Email plus one further channel, managed separately with its own list and no shared suppression.
5 — Email, SMS or push and web forms driven from one contact profile, with dynamic content blocks and shared unsubscribe handling.
8 — The above plus on-site personalisation, ad-audience sync to the major networks, cross-channel frequency capping, and content personalised on behaviour rather than only on stored fields.
10 — Channel is a delivery detail: one profile and one consent state across every channel, next-best-channel selection, and personalisation that draws on the full behavioural record without the marketer assembling it by hand.
The Demand Gen Lead
The channel list is genuinely broad — email, SMS, push, in-app messages, live chat, forms and popups, transactional email — and the CDP module plus the omnichannel claim suggest one profile behind them. I found no public information on shared suppression or unsubscribe handling across channels, dynamic content, or ad-audience sync, so this reads as breadth without the cross-channel discipline I would be tested on. 1
The Sales Ops Manager
Email, SMS, push, in-app messages, live chat and forms are all named as channels, and the data platform is pitched as connecting all customer data, which reads as several channels working off one profile. We found no public information on shared unsubscribe and suppression across those channels, dynamic content, or ad-audience sync. 1
The Data Protection Officer
Email, SMS, push notifications, live chat, in-app messages and forms and surveys are all listed alongside a customer data platform and a claim of omnichannel engagement, which suggests several channels drawing on one customer record. We found no public information on shared suppression and unsubscribe handling, cross-channel frequency capping, dynamic content, on-site personalisation, or ad-audience sync. 1
The Lifecycle Marketer
The channel span is real — email, SMS, push, in-app messages, live chat, forms, surveys and transactional email, with a data platform module and an AI omnichannel claim behind them. I found no public information on shared suppression or unsubscribe handling across channels, cross-channel frequency capping, on-site personalisation or ad-audience sync. 1
The Solution Architect
The channel list is unusually broad for a homepage — email, SMS, push, live chat, in-app messages, forms, popups and transactional email — with a CDP module and 'connect all of your customer data' pointing at one profile behind them. I found no public information on shared unsubscribe handling, dynamic content, ad-audience sync or frequency capping, which keeps it well below the top of the scale. 1
The Skeptic
Email, SMS, push, in-app messages, forms and surveys, live chat and transactional email are all named as channels, with a customer data platform alongside — wider than two channels managed separately. But I found no public information on shared suppression or unsubscribe handling across those channels, dynamic content blocks, on-site personalisation or ad-audience sync, so the unifying half of the question rests on a module name. 1
Consent, tracking & profiling
Show reasoningHide reasoning
How this is scored
The platform builds behavioural profiles of named people. Consent capture and proof, tracking that can be limited, retention, and whether automated decisions about individuals are documented and contestable.
0 — Tracking always on and undocumented, single opt-in, no consent record, no retention rule, no way to exclude a person from profiling.
3 — Double opt-in available with a timestamp, cookie tracking that cannot be disabled per contact, and retention described as the customer's problem.
5 — Double opt-in as documented default with a stored consent record including source, per-channel consent states, tracking switchable per contact, and stated retention for inactive records.
8 — Consent reproducible as evidence with the wording versioned, profiling suppressible per person, retention executed per data category, documented handling of access and erasure requests including derived scores, and a cookieless or first-party tracking mode.
10 — Built for the accountability principle: a per-contact history of what was tracked, scored and decided, automated decision-making documented well enough to support an Art. 22 assessment, profiling off by default for anyone who has not consented to it, and deletion that removes derived scores as well as raw events.
The Demand Gen Lead
Tracking is confirmed as a product feature under the Checkmate tracking mark, and GDPR compliance is claimed alongside ISO 27001 and SOC 2 — but a compliance badge is not a consent record. I found no public information on double opt-in, per-channel consent states, retention for profiling data, or a way to exclude a person from profiling. 1
The Sales Ops Manager
GDPR compliance is claimed alongside ISO 27001, HIPAA and SOC 2, and a branded tracking feature is named, but we found no public information on stored consent records, per-channel consent states, disabling tracking per contact, or retention. The consent mechanics a DPO would ask about are not verifiable from the captured page. 1
The Data Protection Officer
The platform tracks named people through a branded tracking feature, yet we found no public information on consent capture, stored consent records with wording versions, per-channel consent states, switching tracking off per contact, retention by data category, or handling of access and erasure requests including derived scores. GDPR, ISO 27001, HIPAA and SOC 2 compliance claims are stated as certifications, which is a posture, not reproducible consent evidence; profiling is not documented as suppressible per person. 1
The Lifecycle Marketer
GDPR, ISO 27001, HIPAA and SOC2 appear as compliance badges and tracking is sold as a branded feature, but I found no public information on consent capture and stored records, per-channel consent states, retention for inactive records, per-contact tracking switches or profiling suppression. For a platform profiling named people, the mechanics are the evidence, not the badges. 1
The Solution Architect
GDPR sits in a certification list alongside ISO 27001 and SOC 2, and Checkmate tracking is a named feature, but that is all the captured page offers on a platform that profiles named people. I found no public information on consent records, per-channel consent states, retention for inactive records, or the ability to suppress profiling for a person. 1
The Skeptic
The evidence is a GDPR compliance claim, a trademarked tracking feature, and reCAPTCHA on forms. I found no public information on consent records or their source, double opt-in defaults, per-channel consent states, per-contact tracking control, retention for inactive records, or handling of access and erasure requests — for a product built on behavioural profiles of named people, that silence is the finding. 1
CRM integration & data model
Show reasoningHide reasoning
How this is scored
The join that decides the implementation: how the platform and the CRM stay in agreement about who a person is, and what happens when they disagree.
0 — CSV import and export; no CRM integration and no identity resolution.
3 — One-way sync into a named CRM on a schedule, with duplicates resolved by hand and no conflict rules.
5 — Bidirectional sync with at least one major CRM, field mapping, deduplication rules, and a sync error log somebody can act on.
8 — Configurable conflict resolution per field, account and contact objects both modelled, custom objects supported, near-real-time sync with retry, and a documented API with rate limits.
10 — One record, two systems, no ambiguity: identity resolution across anonymous and known states, field-level ownership defined per system, replay of failed syncs, and a data model the customer can extend without vendor services.
The Demand Gen Lead
Salesforce and Shopify integrations are named, a CDP module sits at the centre, and developer docs exist, which is more than CSV in and out. I found no public information on sync direction, field mapping, deduplication rules, conflict handling, or a sync error log — the join that decides whether my pipeline reporting holds up. 1
The Sales Ops Manager
A Salesforce integration is named and a customer data platform sits underneath it, but we found no public information on sync direction, field mapping, deduplication rules, per-field conflict resolution, or a sync error log I could act on before the pipeline report is wrong. Developer docs are listed among resources; identity resolution and API limits are not shown. 1
The Data Protection Officer
Named integrations for Salesforce and Shopify plus a customer data platform are confirmed, and developer documentation is listed among support resources, though its contents are not shown. We found no public information on sync direction, field mapping, deduplication, per-field conflict resolution, retry of failed syncs, or identity resolution across anonymous and known states. 1
The Lifecycle Marketer
Salesforce and Shopify connectors are named alongside a no-code integration claim and a data platform module, but I found no public information on sync direction, field mapping, deduplication, conflict rules or a sync error log. Nothing shows what happens when the two systems disagree about who a person is. 1
The Solution Architect
Salesforce and Shopify integrations are named, developer docs exist as a resource, and a CDP module is claimed, but I found no public information on sync direction, field mapping, deduplication rules, conflict resolution, custom objects, or API rate limits — the places implementations actually die. The path from anonymous visitor to known contact, which I look for first, is not documented on this evidence. 1
The Skeptic
Salesforce and Shopify connectors are named and developer documentation exists, which is more than import and export. I found no public information on sync direction, field mapping, deduplication, conflict resolution, account-level modelling or API rate limits — the join that decides the implementation is entirely unevidenced. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where behavioural profiles of named EU residents are processed, who the contracting entity is, and which subprocessors see them. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which given the profiling is heavily.
0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed, behavioural data leaving the EU with no stated basis.
3 — EU data residency for storage while tracking, sending or support access remain non-EU, or the contracting entity sits outside the EU.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — tracking scripts, AI scoring, analytics — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure, EU contracting entity, complete subprocessor list published, and any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: every profile, event and derived score processed in the EU by European subprocessors, certification published, and no transfer requiring a Schrems II argument to survive.
The Demand Gen Lead
EU is listed as one of three hosting regions alongside the USA and Australia, which reads as an option rather than a standard, and the contracting entity is presented as Ortto Pty Ltd with no EU entity named. No subprocessor list or transfer basis appears in the captured pages, and for behavioural profiles of named EU residents I weight that gap heavily. 1
The Sales Ops Manager
EU hosting is offered as one of three regions alongside the USA and Australia, and the contracting entity is an Australian company; we found no public information on subprocessors or the legal basis for any transfers. GDPR and ISO 27001 claims exist, but a region choice paired with a non-EU entity leaves the processing chain unverified. 1
The Data Protection Officer
Multi-region data hosting in the EU, USA and Australia is stated, so EU residency for storage appears to exist, but we found no published subprocessor list and no non-EU processing named with its legal basis. No sovereignty attributes are on record, and a GDPR compliance claim is not a substitute for an evidenced EU contracting and processing chain. 1
The Lifecycle Marketer
Multi-region hosting across the EU, USA and Australia is stated, but I found no public information on where the contracting entity sits, which region holds behavioural profiles by default, or any subprocessor — none are named. For named profiles of EU residents I weigh that silence heavily. 1
The Solution Architect
EU hosting is offered as one of three regions alongside the USA and Australia, and the vendor is registered as Ortto Pty Ltd. I found no public information on an EU contracting entity, a subprocessor list, or the legal basis for behavioural data in the non-EU regions — which, for a platform profiling named EU residents, I weigh heavily. 1
The Skeptic
Hosting regions are listed as EU, USA and Australia with no stated default, no published subprocessor list, no contracting-entity seat beyond the vendor name, and no stated legal basis for processing outside the EU. A GDPR badge sits next to US-centric frameworks, but a certification claim is not a processing location; I found no public information on where tracking, sending or derived scores are handled. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual invoice for their contact base and send volume — including the tier where automation actually begins, overage, and mandatory onboarding — from public pages alone.
0 — No public prices at all; every tier is a sales conversation, and onboarding fees are never mentioned.
3 — A contact-tier headline exists, but the tier where journeys, scoring or CRM sync begin is unstated, as is any mandatory implementation fee.
5 — Contact-tier prices public with billing period and send limits stated, but at least one commonly needed capability sits in an unpriced enterprise tier.
8 — Every tier priced publicly with contact and volume limits, feature boundaries, overage rates, onboarding costs, minimum term and VAT treatment stated.
10 — Complete price computability: annual invoice derivable for a given contact count, send volume and feature set, including overage, additional users and any implementation fee stated outright.
The Demand Gen Lead
The only pricing signal anywhere is a free trial: no tier prices, no billing period, no send or contact limits, and I found no public information on mandatory onboarding. I cannot compute an annual invoice from what is public, so this is a sales conversation end to end. 1
The Sales Ops Manager
The only pricing-related fact captured is a free trial; we found no public information on contact-tier prices, send limits, the tier where automation begins, or onboarding fees. I cannot compute even a rough annual invoice from the captured pages. 1
The Data Protection Officer
A free trial is the only pricing-adjacent fact published; we found no public prices, no contact tiers, no send limits, no billing period, and no mention of onboarding costs. The tier at which journeys, scoring or CRM sync begin cannot be determined from public pages. 1
The Lifecycle Marketer
The only pricing-related item on the captured page is a free-trial sign-up; no tiers, contact or send limits, overage rates or onboarding fees appear. A buyer cannot begin to compute an annual invoice from public pages. 1
The Solution Architect
The only pricing-adjacent fact is a free trial; no tiers, contact prices, send limits, billing periods or onboarding costs appear. A buyer cannot compute any annual invoice from this, so it sits at the bottom of the scale. 1
The Skeptic
The only pricing signal on the captured pages is a free trial; I found no public information on contact tiers, prices, send limits, overage rates, the tier where journeys begin, or any mandatory onboarding fee. A buyer cannot begin to compute an annual invoice from what is public. 1
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 19 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 15 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 13 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 data fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 subprocessors fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (12)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page www.ortto.com Checked 29 Sep 2026 Details →
- 2 Privacy policy — found from the homepage ortto.com Checked 30 Sep 2026 Details →
- 3 Journeys & orchestration — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 4 Journeys & orchestration — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 5 Lead scoring, routing & lifecycle — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 6 Lead scoring, routing & lifecycle — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 7 Channels & personalisation — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 8 Channels & personalisation — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 9 Consent, tracking & profiling — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 10 Consent, tracking & profiling — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 11 CRM integration & data model — found from sitemap ortto.com Checked 1 Oct 2026 Details →
- 12 CRM integration & data model — found from sitemap ortto.com Checked 1 Oct 2026 Details →