Competitor technology intelligence that does not rely on fingerprint databases. A real browser walks the site, clicks the paths that matter and fires the forms, and the captured network traffic is read into a current tech stack plus a scored view of how the company goes to market.
Knowing what a competitor runs on is basic marketing homework. It tells you what their team can ship, how fast, and where their funnel actually breaks. The problem is that the answer stopped being visible in the page source.
A React or Webpack build serves you a bundle. The interesting services load later, or only after someone clicks something, or only when a form fires the API behind it. Read the markup and you get the CDN and little else.
The established tools have the same blind spot, and their data lags. Then the rest of the picture lives somewhere else again: DNS records in one tool, subdomains in another, sitemap and SEO posture in a third. Assembling one company's profile meant four tabs and a lot of trust in stale fingerprints.
A React or Webpack build serves you a bundle. The CDN is in there and very little else worth knowing.
no real signalWappalyzer and BuiltWith recognise what they have already catalogued, from a database written before this deploy shipped.
stale by a quarterDNS in one tool, subdomains in a second, sitemap and SEO posture in a third, and none of them share a company record.
4 tabs per companyWhat reaches the team is a partial tool list carrying no read on how the company sells, ships or grows.
unverifiableThree ways to answer this already existed. I used all of them before building anything.
An instant tool list off a fingerprint database, free at the entry tier and already in most marketers' bookmarks.
A fingerprint database recognises what it catalogued last quarter. On React and Next.js builds the interesting services load after the markup, so both come back thin or empty, and the answer stops at the tool list.
RejectedCertainty about exactly what a page shipped, with no vendor between you and the evidence.
The services worth knowing about fire after a click or behind a form submission. It also does not survive contact with a second company, let alone a category.
RejectedA stack already sitting on the account record, at no extra effort for the rep.
Self-reported and undated. A job post asking for Marketo experience is a wish from seven months ago rather than a Marketo deployment.
RejectedAll three describe what a company said or once shipped. The scan had to describe what the site is doing right now, and say so with a timestamp.
A fingerprint database can only recognise what it has seen before. The network a site generates while a real person uses it gives up everything, because every service it depends on has to be called eventually.
So the scan drives a real browser through browserless and records the traffic. A model reads the sitemap first and picks the paths worth walking: the primary calls to action, the pricing flow, the demo request. It fills forms to make the submission APIs fire, and the whole session is captured as a HAR file.
Then several models work over the raw capture, clean the noise out of the requests, and resolve what each endpoint belongs to. The output is current by construction, because it describes what the site did minutes ago rather than what a crawler catalogued last quarter.
A stack list is trivia until you turn it into a read on the company. The CMS, the CRM, the marketing automation and the ad pixels together describe how a business goes to market, so the report scores that directly.
Every claim carries the evidence it came from and a confidence label. Where the crawl was thin, the report says so and states what that leaves unknown, which is the difference between intelligence and a confident guess.
Sales-led or content-led, read from the CRM, the engagement tooling and the pixels actually firing.
Hosting, CDN, DNS and email posture, including the security records most teams leave half-configured.
Sitemap scale and shape: what they publish, in which languages, and which subdomains hold the real library.
Experimentation, analytics and lifecycle tooling, which shows whether anyone is measuring the funnel.
Consent management, monitoring, status pages and the trust signals a large buyer looks for.
Three examples of the translation, all re-runnable by anyone who doubts them. A
js.stripe.com call in the page means subscription billing, so they monetise
recurring. A sitemap holding 40 blog posts and zero comparison pages means a content-first
motion that is thin at the bottom of the funnel, which is an opening. Three frontends on
three subdomains means marketing, app and docs are owned by separate teams, which is the org
chart read off the DNS.
A scan costs time, and the tools worth finding are the ones that cost the most to reach. So depth is a choice made per scan rather than a fixed setting, and the report says which depth produced each finding.
What the site shows the world: DNS and DMARC, subdomains, sitemap, and the front-end, analytics and infrastructure stack. Runs on every scan, including the free tier.
A real browser loads the page and the HAR capture keeps every request it makes. That is where hidden APIs and background third-party calls show up, none of which are in the markup.
Simulated browsing for what only loads after someone acts: chat widgets, checkout scripts, post-click tooling. Adds two to four minutes, and earns it on SPA-heavy sites.
Three rules hold the output honest, and all three cost the product something. Public signals only: no logins, no privileged access, nothing behind a paywall. When Cloudflare blocks the scan or a sitemap is missing, the report flags it and drops confidence to low or medium. Missing data stays missing, so a reader always knows which part was measured.
A rep has more accounts than sequence slots. Qualifying one by hand is a tab-hop through LinkedIn, the homepage and a job post, roughly ten minutes, which is why most reps skip the research and send "just checking in" instead.
So the scan returns a call. There is no 0 to 100 fit score anywhere in the product, because a score pads itself to look useful on every account. The four verdicts are qualify (the stack earns the slot), route (send it to the rep who owns this play), personalize (here is the opener their stack has already given you) and skip. Skip is the one that saves the day: a tool willing to say an account is not worth a touch is a tool you can leave running.
Two systems of record in one stack. Lead with sync and routing pain, because somebody there is already living it.
A subscription commerce motion. Open on retention, lifetime value and churn.
A real data team owns the funnel. Route it to the RevOps or analytics seller.
Identity is a budget line. Hand it to whoever sells security and compliance.
A self-serve developer buyer. Lead with the devtools angle and let them try it.
Nothing to personalise against. Skip it and spend the slot on an account that gave you something to work with.
The reason this beats the enrichment field a team already pays for is freshness. What is serving traffic today at 09:41 is a fact, and the scan timestamps it. Sales, product, content and agency teams each get their own read off the same scan: pre-call recon, a competitor teardown, the GTM gaps a sitemap admits to, and an evidence-backed pitch.
Before interviewing at ThinkingAI I scanned them with it. The report surfaced how their site was operated, what their DNS and subdomains looked like, and where the gaps in that setup were.
I brought a table of findings with a proposed fix beside each one. The hiring manager had not asked for it yet, and it changed the shape of the conversation: we spent the interview on their actual problems rather than on my history. I got the offer.
It does the same job in competitive work. Paired with AdRadar on the campaign side, the two answer different halves of the same question: AdRadar shows what a rival is saying in market, TechSpy shows what they are able to build. Together they show exactly where a gap sits, which competitors are ahead of us technically, and which ones we are already ahead of.
Scans run from whatever already holds the account list, so enrichment happens where the records live.
A new target in the CRM can trigger a scan and write the profile back without anyone opening the product.
An agent can call it mid-task, which is how it ends up inside research that was never about tech stacks to begin with.
Concretely: the Zapier app ships five triggers and nine actions, so a domain can be watched
and a Zap fired the day its tech, subdomains or email records change. The REST API is one
endpoint, POST /api/analyze, with the scan stages as toggles and a bearer key
rate-limited per tier. Teams point it at HubSpot, Salesforce, Pipedrive, Clay, Notion,
Airtable, Sheets and Slack, and the brief lands on the account record before the call.
Ranking a category against the five pillars produces content that is current and checkable, which argues for the method better than any description of it would. Three report types run off the scan: single-company teardowns, head-to-head comparisons, and category rankings.
Every published claim carries its evidence and its confidence, including the uncomfortable ones. A section marked low confidence states the evidence it does have, then states separately what that leaves unknown, which is the part most competitive content quietly skips.
React 19The scan UI and report reader.
TypeScriptEnd to end, including the scan-stage contracts.
TailwindThe design layer.
Gemini 2.5 ProSecond opinion on the pillar scoring, used where the two disagree.
ResendScan-complete and monitoring alerts.
RemotionRenders the report walkthroughs as video.
Browserless is the line item that makes the product work and the one that costs money on every scan, which is why the depth tiers exist and why the free tier stops at the surface layer.
Nine systems shipped, compliance, reporting, intelligence, content.