AI Systems · TechSpy · Live, public

TechSpy watches what a site actually calls, then reads the company off it

Competitor technology intelligence that does not rely on fingerprint databases. A real browser walks the site, clicks the paths that matter and fires the forms, and the captured network traffic is read into a current tech stack plus a scored view of how the company goes to market.

Read from live trafficcurrent at scan time rather than catalogued
5 scored pillarsGTM, infra, content, growth, enterprise readiness
What the source hides

Modern sites hide their stack, and the tools that read them are behind

Knowing what a competitor runs on is basic marketing homework. It tells you what their team can ship, how fast, and where their funnel actually breaks. The problem is that the answer stopped being visible in the page source.

A React or Webpack build serves you a bundle. The interesting services load later, or only after someone clicks something, or only when a form fires the API behind it. Read the markup and you get the CDN and little else.

The established tools have the same blind spot, and their data lags. Then the rest of the picture lives somewhere else again: DNS records in one tool, subdomains in another, sitemap and SEO posture in a third. Assembling one company's profile meant four tabs and a lot of trust in stale fingerprints.

01 · Look Read the page source

A React or Webpack build serves you a bundle. The CDN is in there and very little else worth knowing.

no real signal
02 · Scan Run a fingerprint tool

Wappalyzer and BuiltWith recognise what they have already catalogued, from a database written before this deploy shipped.

stale by a quarter
03 · Chase Open three more tabs

DNS in one tool, subdomains in a second, sitemap and SEO posture in a third, and none of them share a company record.

4 tabs per company
04 · Guess Call it a profile

What reaches the team is a partial tool list carrying no read on how the company sells, ships or grows.

unverifiable
4 tabs What it took to half-answer one basic question about one competitor, with the interesting half of the stack never appearing in any of them.
The incumbents

Wappalyzer, BuiltWith, and reading it by hand

Three ways to answer this already existed. I used all of them before building anything.

OptionWhat it gaveWhere it brokeVerdict
Wappalyzer and BuiltWith

An instant tool list off a fingerprint database, free at the entry tier and already in most marketers' bookmarks.

A fingerprint database recognises what it catalogued last quarter. On React and Next.js builds the interesting services load after the markup, so both come back thin or empty, and the answer stops at the tool list.

Rejected
Reading the markup by hand

Certainty about exactly what a page shipped, with no vendor between you and the evidence.

The services worth knowing about fire after a click or behind a form submission. It also does not survive contact with a second company, let alone a category.

Rejected
The enrichment field in the CRM

A stack already sitting on the account record, at no extra effort for the rep.

Self-reported and undated. A job post asking for Marketo experience is a wish from seven months ago rather than a Marketo deployment.

Rejected

All three describe what a company said or once shipped. The scan had to describe what the site is doing right now, and say so with a timestamp.

The method

Stop reading the page. Watch what the page does.

A fingerprint database can only recognise what it has seen before. The network a site generates while a real person uses it gives up everything, because every service it depends on has to be called eventually.

So the scan drives a real browser through browserless and records the traffic. A model reads the sitemap first and picks the paths worth walking: the primary calls to action, the pricing flow, the demo request. It fills forms to make the submission APIs fire, and the whole session is captured as a HAR file.

Then several models work over the raw capture, clean the noise out of the requests, and resolve what each endpoint belongs to. The output is current by construction, because it describes what the site did minutes ago rather than what a crawler catalogued last quarter.

The five pillars

One scan, five dimensions, evidence attached

A stack list is trivia until you turn it into a read on the company. The CMS, the CRM, the marketing automation and the ad pixels together describe how a business goes to market, so the report scores that directly.

Every claim carries the evidence it came from and a confidence label. Where the crawl was thin, the report says so and states what that leaves unknown, which is the difference between intelligence and a confident guess.

Go-to-market

Sales-led or content-led, read from the CRM, the engagement tooling and the pixels actually firing.

Infrastructure

Hosting, CDN, DNS and email posture, including the security records most teams leave half-configured.

Content

Sitemap scale and shape: what they publish, in which languages, and which subdomains hold the real library.

Growth

Experimentation, analytics and lifecycle tooling, which shows whether anyone is measuring the funnel.

Enterprise readiness

Consent management, monitoring, status pages and the trust signals a large buyer looks for.

Three examples of the translation, all re-runnable by anyone who doubts them. A js.stripe.com call in the page means subscription billing, so they monetise recurring. A sitemap holding 40 blog posts and zero comparison pages means a content-first motion that is thin at the bottom of the funnel, which is an opening. Three frontends on three subdomains means marketing, app and docs are owned by separate teams, which is the org chart read off the DNS.

How deep it goes

Three depths, because most of the stack never appears in page source

A scan costs time, and the tools worth finding are the ones that cost the most to reach. So depth is a choice made per scan rather than a fixed setting, and the report says which depth produced each finding.

01 Surface · seconds

What the site shows the world: DNS and DMARC, subdomains, sitemap, and the front-end, analytics and infrastructure stack. Runs on every scan, including the free tier.

02 Deep Scan · minutes

A real browser loads the page and the HAR capture keeps every request it makes. That is where hidden APIs and background third-party calls show up, none of which are in the markup.

03 Interact · minutes

Simulated browsing for what only loads after someone acts: chat widgets, checkout scripts, post-click tooling. Adds two to four minutes, and earns it on SPA-heavy sites.

Three rules hold the output honest, and all three cost the product something. Public signals only: no logins, no privileged access, nothing behind a paywall. When Cloudflare blocks the scan or a sitemap is missing, the report flags it and drops confidence to low or medium. Missing data stays missing, so a reader always knows which part was measured.

The output

Four verdicts, and the useful one is "skip"

A rep has more accounts than sequence slots. Qualifying one by hand is a tab-hop through LinkedIn, the homepage and a job post, roughly ten minutes, which is why most reps skip the research and send "just checking in" instead.

So the scan returns a call. There is no 0 to 100 fit score anywhere in the product, because a score pads itself to look useful on every account. The four verdicts are qualify (the stack earns the slot), route (send it to the rep who owns this play), personalize (here is the opener their stack has already given you) and skip. Skip is the one that saves the day: a tool willing to say an account is not worth a touch is a tool you can leave running.

HubSpot and Salesforce together

Two systems of record in one stack. Lead with sync and routing pain, because somebody there is already living it.

Shopify, Klaviyo, Recharge

A subscription commerce motion. Open on retention, lifetime value and churn.

Segment, Snowflake, dbt

A real data team owns the funnel. Route it to the RevOps or analytics seller.

Auth0 or Okta

Identity is a budget line. Hand it to whoever sells security and compliance.

Public API docs and Stripe

A self-serve developer buyer. Lead with the devtools angle and let them try it.

No CRM and no automation

Nothing to personalise against. Skip it and spend the slot on an account that gave you something to work with.

The reason this beats the enrichment field a team already pays for is freshness. What is serving traffic today at 09:41 is a fact, and the scan timestamps it. Sales, product, content and agency teams each get their own read off the same scan: pre-call recon, a competitor teardown, the GTM gaps a sitemap admits to, and an evidence-backed pitch.

What it bought me

I walked into the ThinkingAI interview with their own diagnosis

Before interviewing at ThinkingAI I scanned them with it. The report surfaced how their site was operated, what their DNS and subdomains looked like, and where the gaps in that setup were.

I brought a table of findings with a proposed fix beside each one. The hiring manager had not asked for it yet, and it changed the shape of the conversation: we spent the interview on their actual problems rather than on my history. I got the offer.

It does the same job in competitive work. Paired with AdRadar on the campaign side, the two answer different halves of the same question: AdRadar shows what a rival is saying in market, TechSpy shows what they are able to build. Together they show exactly where a gap sits, which competitors are ahead of us technically, and which ones we are already ahead of.

Getting it into the workflow

An intelligence tool is worth nothing sitting in its own tab

API

Scans run from whatever already holds the account list, so enrichment happens where the records live.

Zapier

A new target in the CRM can trigger a scan and write the profile back without anyone opening the product.

MCP

An agent can call it mid-task, which is how it ends up inside research that was never about tech stacks to begin with.

Concretely: the Zapier app ships five triggers and nine actions, so a domain can be watched and a Zap fired the day its tech, subdomains or email records change. The REST API is one endpoint, POST /api/analyze, with the scan stages as toggles and a bearer key rate-limited per tier. Teams point it at HubSpot, Salesforce, Pipedrive, Clay, Notion, Airtable, Sheets and Slack, and the brief lands on the account record before the call.

The reports

The same pipeline writes the public library

Ranking a category against the five pillars produces content that is current and checkable, which argues for the method better than any description of it would. Three report types run off the scan: single-company teardowns, head-to-head comparisons, and category rankings.

Every published claim carries its evidence and its confidence, including the uncomfortable ones. A section marked low confidence states the evidence it does have, then states separately what that leaves unknown, which is the part most competitive content quietly skips.

techspy.hi-daniel.com/reports
TechSpy company report on RentalReady with a per-technology confidence panel and a written strategy read
TechSpy comparison report placing two vendors side by side with evidence lines and confidence badges
TechSpy report section marked low confidence, listing the evidence found and the implications separately
TechSpy category ranking of streaming video infrastructure vendors with per-pillar bars
What it runs on

A real browser, two model tiers, and a rule that says when it does not know

Application

Next.js logoNext.jsApp Router, server components, and the report pages themselves. React 19 logoReact 19The scan UI and report reader. TypeScript logoTypeScriptEnd to end, including the scan-stage contracts. Tailwind logoTailwindThe design layer.

Scanning

Playwright logoPlaywrightDrives the session. Deep Scan and Interact both run through it. Browserless logoBrowserlessHosted Chrome, so a scan can render a heavy SPA without a local browser. CheerioStatic parsing pass for the surface layer.

Models

DeepSeek v4 Flash logoDeepSeek v4 FlashClassifies every captured request against a service taxonomy. DeepSeek v4 Pro logoDeepSeek v4 ProWrites the five-pillar strategy read and assigns confidence. Gemini 2.5 Pro logoGemini 2.5 ProSecond opinion on the pillar scoring, used where the two disagree.

Data and delivery

Supabase logoSupabaseAccounts, saved scans, and the report history. Resend logoResendScan-complete and monitoring alerts. Stripe logoStripePlan tiers, including the API and Zapier entitlements. Remotion logoRemotionRenders the report walkthroughs as video. Vercel logoVercelHosting and the serverless scan endpoints.

Browserless is the line item that makes the product work and the one that costs money on every scan, which is why the depth tiers exist and why the free tier stops at the surface layer.

Want this kind of tooling on your team?

Nine systems shipped, compliance, reporting, intelligence, content.