
Blackout — The Official Blackout Public FAFO Repo.

"You can block the researcher. You can't block the evidence."
On November 25, 2025, ZoomInfo CEO Henry Schuck posted a product demo of GTM Studio on LinkedIn — their AI-powered platform that "identifies person-level website visits."
A security researcher analyzed the GTM Studio landing page and documented extensive pre-consent tracking infrastructure. The findings were posted as a comment on the CEO's LinkedIn post.
Within minutes, the researcher was blocked.
No correction. No clarification. Just silence.
This evidence pack ensures the findings cannot be suppressed.
| Finding | Evidence |
|---|---|
| 50+ tracking requests before consent | Network capture shows tracking fires before consent banner loads |
| Sardine.ai biometrics enabled | enableBiometrics: true in decoded config |
| PerimeterX fingerprinting | Collector fires at request #79 (pre-consent) |
| DNS fingerprinting active | enableDNS: true in Sardine config |
| 118 unique tracking domains | Contacted on single page load |
| Session fingerprinting | Fraud detection API creates session pre-consent |
{
"enableBiometrics": true,
"enableDNS": true,
"partnerId": "zoominfo",
"dBaseDomain": "d.sardine.ai",
"environment": "production"
}
This configuration was decoded from a base64-encoded payload in the collector iframe URL.
Translation:
ZoomInfo markets GTM Studio as a tool to "identify person-level website visits."
Yet on their own landing page for this product, they deploy:
Even the visitor identification vendor doesn't trust their own product for visitor identification.
You're not a privacy lawyer. You're trying to hit pipeline targets. So why should you care?
Every dollar spent on vendors with documented pre-consent tracking is a dollar potentially spent on future legal liability. When class actions emerge in this space, "we didn't know" often isn't accepted as a defense — it can be characterized as negligence.
The question to consider: could this data become actionable in litigation?
Data collected without proper consent may not be legally processable. That could mean:
This is worth evaluating with your legal team.
The people being tracked without consent? They're the same people you're trying to convert. When they find out (and the prevalence of these practices is increasingly public), you may not just lose a deal — you may create an adversary with legal standing.
Every visitor is a potential plaintiff. Every page view is potential evidence.
GDPR Article 26. CCPA 1798.100. Your contracts may say "vendor warrants compliance." Courts have found joint liability regardless. When a vendor's practices become public record, your legal team will ask: "Who approved this vendor?"
That answer is discoverable.
Imagine losing an enterprise deal because the prospect's security team researched your martech stack. Imagine the RFP question: "Do you use vendors with documented pre-consent tracking?"
Your vendor choices are discoverable. Choose accordingly.
Marketing has operated in a "move fast, ask forgiveness" mode for 15 years. That era is ending.
The tracking infrastructure that powered the "growth at all costs" playbook is now:
You can either:
The vendors won't protect you. Your contracts may not protect you. Only your choices will.
zoominfo-gtm-studio/
├── FINDINGS.md # Full technical analysis
├── TIMELINE.md # CEO post → comment → block sequence
├── code/
│ ├── sardine-config.json # Decoded biometrics configuration
│ ├── perimeterx.md # PerimeterX infrastructure details
│ └── tracking-sequence.md # Complete request timeline
├── methodology/
│ └── how-we-tested.md # Reproduction instructions
└── legal/
├── gdpr-analysis.md # EU regulation analysis
├── ccpa-analysis.md # California privacy law analysis
└── cipa-exposure.md # California wiretapping exposure analysis
https://www.zoominfo.com/products/gtm-studiocollector-pxosx7m0dx.px-cloud.net — PerimeterX fingerprinting*.d.sardine.ai/bg.png — Sardine behavioral biometricsgw-app.zoominfo.com/gw/ziapi/fraud-detection — Session fingerprinting
When presented with documented evidence of:
The CEO of a publicly traded company chose to:
ZoomInfo has not responded to requests for comment on these findings.
THIS IS NOT LEGAL ADVICE.
The information contained in this evidence pack is provided for informational and educational purposes only. Nothing herein constitutes legal advice, and no attorney-client relationship is created by accessing, reading, or using this information.
You should consult with a qualified attorney licensed in your jurisdiction before taking any action based on the information presented here. Privacy law is complex, varies by jurisdiction, and is subject to change. What may constitute a violation in one jurisdiction may not apply in another.
Blackout is not a law firm. We are security researchers documenting technical findings. We make no representations or warranties about:
All findings are based on publicly observable behavior at the time of testing. Network captures, decoded configurations, and request timelines represent a point-in-time snapshot. Vendors may modify their practices after publication.
If you believe you have been affected by pre-consent tracking or surveillance practices, consult a privacy attorney or contact your local data protection authority. Do not rely solely on this document to assess your legal rights or remedies.
By accessing this evidence pack, you acknowledge that you have read and understood this disclaimer.
This evidence pack is released in the public interest.
Vendor tracking infrastructure should be transparent and verifiable, not suppressed when documented.
Released by: Blackout Research
Date: November 25, 2025
Free forensic scans. 100 domains. 24 hours.
Find out what YOUR vendors are doing.
"You can block the researcher.
You can't block the evidence."