{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "salesflare",
    "name": "Salesflare",
    "vendor": "Salesflare BVBA",
    "vendorUrl": "https://salesflare.com",
    "kind": "http-api",
    "category": "crm",
    "summary": "Salesflare is a sales CRM for small B2B teams that fills in contacts, companies and activity from email and calendars. Agents reach it through a REST API at `api.salesflare.com` and a hosted MCP server with OAuth.",
    "url": "https://www.anchorterminal.com/tools/salesflare",
    "markdownUrl": "https://www.anchorterminal.com/tools/salesflare.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/salesflare.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/salesflare.json",
    "license": "Proprietary service under Salesflare's Terms of Service",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.salesflare.com",
    "packages": [],
    "auth": "mixed",
    "authNotes": "The REST API takes an API key as `Authorization: Bearer \u003ckey\u003e`. A user creates keys in Settings, API keys, including on a trial account. No scopes, expiry or read-only key type are documented. The MCP server at `https://mcp.salesflare.com/mcp` uses OAuth authorisation code with PKCE (S256) and dynamic client registration at `api.salesflare.com/oidc/register`, with `openid` and `offline_access` as the only scopes. Access is self-serve.",
    "pricing": "paid",
    "pricingNotes": "No free plan. A 30-day trial needs no card and allows API keys. Three plans a user a month, Growth $29, Pro $49 and Enterprise $99 billed annually, or $39, $64 and $124 billed monthly, with a five-user minimum on Enterprise. API and MCP access carry no separate charge, and no API tier was found on the pricing page (https://salesflare.com/pricing, checked 2026-10-09).",
    "priceSummary": "$29 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file, the MCP OAuth metadata or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://api.salesflare.com/docs",
    "llmsTxt": "https://salesflare.com/llms.txt",
    "openapi": "https://api.salesflare.com/openapi.json",
    "capabilities": [
      "crm.records",
      "crm.pipeline",
      "crm.activities",
      "crm.search"
    ],
    "tags": [
      "hosted",
      "closed-source",
      "openapi",
      "llms-txt",
      "mcp",
      "oauth",
      "api-key",
      "no-card",
      "status-page",
      "eu-hosted"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 48.5,
      "grade": "D",
      "agentReady": false,
      "rank": 721,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 13,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 49,
        "maintenance": 25,
        "payments": 30,
        "reliability": 63,
        "schema": 57,
        "security": 44,
        "transparency": 58
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 63,
          "points": 12.6,
          "reason": "Read with the hosted lines. Status page at status.salesflare.com with components for the application, API, email sidebar, email sync and calendar sync, and history back to October 2023 (20). No notice in the 90 days to 9 October 2026. The last one, on 17 June 2026, was a 47-minute outage of every component after a database migration (30). No rate limit numbers found (0). The API introduction lists 429 with no Retry-After or backoff guidance, and there are no idempotency keys. `update_if_exists` on account creation and `force=false` on contact creation allow a safe retry of two writes (3 of 15). No SLA found, and the terms promise reasonable endeavours without a figure (0). The REST API carries no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 57,
          "points": 9.26,
          "reason": "Public Swagger 2.0 file with 71 operations, linked from the docs and from `llms.txt` (25). `llms.txt` on the main site and help centre, with a Markdown twin for every page. The API reference itself is a Redoc page drawn from the spec (10). 17 of 71 operations have a description, and most repeat the summary (5 of 20). Enums, formats, minimums and required fields are widespread, but custom fields travel as a string, alternatives use a non-standard `x-alternatives` key, and the help centre says phone number arrays are not well described (10 of 15). No examples. 47 operations document only a `default` string response, and errors appear only as a table of five status codes (4 of 15). The spec is version 1.0.0 with no changelog. Old fields are marked deprecated in their descriptions (3 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 49,
          "points": 7.96,
          "reason": "Graded on the REST API. The MCP tool definitions sit behind OAuth and were not read. Lists take `limit` and `offset`, and `details=false` on accounts and opportunities trims the response, with no field selection (14 of 25). `search`, `order_by`, typed field filters and a `q` rule builder on every main list, with no documented maximum page size or total count (16 of 20). An unauthenticated call returned JSON with `statusCode`, `error` and `message`. The docs list status codes without causes (8 of 20). No idempotency keys. `update_if_exists` and `force=false` cover account and contact creation only (5 of 20). Few required fields, and no official SDK was found among the vendor's 47 public repositories (6 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 44,
          "points": 7.7,
          "reason": "REST uses API keys sent as a Bearer header, created in Settings with no documented scopes, expiry or rotation. The MCP server uses OAuth authorisation code with PKCE (S256) and dynamic client registration, and its metadata lists only `openid` and `offline_access`, so tokens are not scoped by resource (22 of 30). Viewer, team member, manager and admin roles with data scopes exist on the Pro plan, but whether an API key inherits its creator's role is not documented. The MCP guide tells users to start with read-only requests and review writes (8 of 20). Account feeds return email and message content, with no injection guidance found (3 of 15). No audit log found (0). A disclosure programme with bounties of $20 to $80, CASA Tier 2 verification revalidated yearly and testing by an independent lab per the help centre. No SOC 2 or ISO 27001 of its own and no security.txt (11 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Plan prices are public, $29 to $99 a user a month billed annually, with nothing per call (10). 30-day trial with no card, and an API key can be created on a trial account (20). A person signs up in a browser and creates the key, or signs in to approve the OAuth connection (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 25,
          "points": 2.19,
          "reason": "No API changelog or release notes found, so recency rests on metadata. The spec file's Last-Modified header read 8 October 2026, which may be a deployment stamp and not an API change. Scored in the 90-day band for that reason (20 of 30). No dated changelog entries (0). Support by chat and email per the help centre, untested, and no public issue tracker for the API (5 of 25). No official SDK. The MCP registry could not be reached (0). No packages to judge (0)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 58,
          "points": 5.08,
          "note": "editorial 40, provenance 75",
          "reason": "Closed service with terms that name Salesflare BVBA in Antwerp and Belgian law (15). The terms promise daily backups and processing only on the customer's instructions, and the help centre places data on Google Cloud in St. Ghislain, Belgium. The DPA is supplied on request, the privacy policy could not be read, and no retention period after termination was found (12 of 30). Spec fields are marked deprecated with their replacements, with no dates or policy (5 of 20). Hosting provider and location are disclosed. No subprocessor list was found (8 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the REST API. The MCP tool definitions sit behind OAuth and were not read. Lists take `limit` and `offset`, and `details=false` on accounts and opportunities trims the response, with no field selection (14 of 25). `search`, `order_by`, typed field filters and a `q` rule builder on every main list, with no documented maximum page size or total count (16 of 20). An unauthenticated call returned JSON with `statusCode`, `error` and `message`. The docs list status codes without causes (8 of 20). No idempotency keys. `update_if_exists` and `force=false` cover account and contact creation only (5 of 20). Few required fields, and no official SDK was found among the vendor's 47 public repositories (6 of 15).",
          "maintenance": "No API changelog or release notes found, so recency rests on metadata. The spec file's Last-Modified header read 8 October 2026, which may be a deployment stamp and not an API change. Scored in the 90-day band for that reason (20 of 30). No dated changelog entries (0). Support by chat and email per the help centre, untested, and no public issue tracker for the API (5 of 25). No official SDK. The MCP registry could not be reached (0). No packages to judge (0).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public, $29 to $99 a user a month billed annually, with nothing per call (10). 30-day trial with no card, and an API key can be created on a trial account (20). A person signs up in a browser and creates the key, or signs in to approve the OAuth connection (0).",
          "reliability": "Read with the hosted lines. Status page at status.salesflare.com with components for the application, API, email sidebar, email sync and calendar sync, and history back to October 2023 (20). No notice in the 90 days to 9 October 2026. The last one, on 17 June 2026, was a 47-minute outage of every component after a database migration (30). No rate limit numbers found (0). The API introduction lists 429 with no Retry-After or backoff guidance, and there are no idempotency keys. `update_if_exists` on account creation and `force=false` on contact creation allow a safe retry of two writes (3 of 15). No SLA found, and the terms promise reasonable endeavours without a figure (0). The REST API carries no beta label (10).",
          "schema": "Public Swagger 2.0 file with 71 operations, linked from the docs and from `llms.txt` (25). `llms.txt` on the main site and help centre, with a Markdown twin for every page. The API reference itself is a Redoc page drawn from the spec (10). 17 of 71 operations have a description, and most repeat the summary (5 of 20). Enums, formats, minimums and required fields are widespread, but custom fields travel as a string, alternatives use a non-standard `x-alternatives` key, and the help centre says phone number arrays are not well described (10 of 15). No examples. 47 operations document only a `default` string response, and errors appear only as a table of five status codes (4 of 15). The spec is version 1.0.0 with no changelog. Old fields are marked deprecated in their descriptions (3 of 15).",
          "security": "REST uses API keys sent as a Bearer header, created in Settings with no documented scopes, expiry or rotation. The MCP server uses OAuth authorisation code with PKCE (S256) and dynamic client registration, and its metadata lists only `openid` and `offline_access`, so tokens are not scoped by resource (22 of 30). Viewer, team member, manager and admin roles with data scopes exist on the Pro plan, but whether an API key inherits its creator's role is not documented. The MCP guide tells users to start with read-only requests and review writes (8 of 20). Account feeds return email and message content, with no injection guidance found (3 of 15). No audit log found (0). A disclosure programme with bounties of $20 to $80, CASA Tier 2 verification revalidated yearly and testing by an independent lab per the help centre. No SOC 2 or ISO 27001 of its own and no security.txt (11 of 20).",
          "transparency": "Closed service with terms that name Salesflare BVBA in Antwerp and Belgian law (15). The terms promise daily backups and processing only on the customer's instructions, and the help centre places data on Google Cloud in St. Ghislain, Belgium. The DPA is supplied on request, the privacy policy could not be read, and no retention period after termination was found (12 of 30). Spec fields are marked deprecated with their replacements, with no dates or policy (5 of 20). Hosting provider and location are disclosed. No subprocessor list was found (8 of 20)."
        },
        "sources": [
          {
            "what": "API reference",
            "url": "https://api.salesflare.com/docs",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI (Swagger 2.0) file, 71 operations",
            "url": "https://api.salesflare.com/openapi.json",
            "seen": "2026-10-09"
          },
          {
            "what": "site index for agents",
            "url": "https://salesflare.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "help centre index for agents",
            "url": "https://howto.salesflare.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://salesflare.com/pricing.md",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of service",
            "url": "https://salesflare.com/terms.md",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy page, which links the Iubenda policy",
            "url": "https://salesflare.com/privacy.md",
            "seen": "2026-10-09"
          },
          {
            "what": "vulnerability disclosure programme",
            "url": "https://salesflare.com/vdp.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server guide",
            "url": "https://howto.salesflare.com/en/articles/14432597-how-can-i-use-salesflare-with-chatgpt-or-claude.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API key article",
            "url": "https://howto.salesflare.com/en/articles/1017460-do-you-have-an-api.md",
            "seen": "2026-10-09"
          },
          {
            "what": "security and data storage article",
            "url": "https://howto.salesflare.com/en/articles/1013147-how-do-you-keep-my-account-secure-and-my-data-safe.md",
            "seen": "2026-10-09"
          },
          {
            "what": "user permissions article",
            "url": "https://howto.salesflare.com/en/articles/4664889-can-i-set-user-permissions.md",
            "seen": "2026-10-09"
          },
          {
            "what": "DPA article",
            "url": "https://howto.salesflare.com/en/articles/1937959-data-processing-agreement-dpa.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API with Webhooks by Zapier article",
            "url": "https://howto.salesflare.com/en/articles/637044-how-can-i-use-salesflare-s-api-with-webhooks-by-zapier.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP OAuth authorisation server metadata",
            "url": "https://mcp.salesflare.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP protected resource metadata",
            "url": "https://mcp.salesflare.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP integration listing",
            "url": "https://integrations.salesflare.com/listings/model-context-protocol/",
            "seen": "2026-10-09"
          },
          {
            "what": "status history",
            "url": "https://status.salesflare.com/history",
            "seen": "2026-10-09"
          },
          {
            "what": "status notice of 17 June 2026",
            "url": "https://status.salesflare.com/history/2026/june/5t7torxyj6gs0uv1-salesflare-is-currently-unavailable",
            "seen": "2026-10-09"
          },
          {
            "what": "unauthenticated API response",
            "url": "https://api.salesflare.com/me",
            "seen": "2026-10-09"
          },
          {
            "what": "announcements archive, one post from 2016",
            "url": "https://blog.salesflare.com/announcement",
            "seen": "2026-10-09"
          },
          {
            "what": "vendor repositories",
            "url": "https://api.github.com/orgs/salesflare/repos",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy host robots.txt",
            "url": "https://www.iubenda.com/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/salesflare.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the privacy policy at www.iubenda.com/privacy-policy/81768705, a path that host's robots.txt disallows",
          "unchecked: the sample DPA, a PDF on downloads.salesflare.com",
          "unchecked: the MCP server's tool definitions, count and annotations, which need an OAuth login",
          "unchecked: whether the MCP server is in the official MCP registry. registry.modelcontextprotocol.io timed out twice",
          "unchecked: whether an API key inherits its creator's role and whether keys can be revoked, since the settings page needs a login",
          "unchecked: REST behaviour on 429, since no authenticated call was made",
          "No rate limit numbers, SLA, API changelog, deprecation policy, audit log, subprocessor list or official SDK were found in the reviewed documentation",
          "The spec's Last-Modified header (8 October 2026) is the only dated evidence of API change and may be a deployment stamp",
          "The lead was right about the REST API and its docs link. It did not mention the hosted MCP server at mcp.salesflare.com, and the terms name the vendor as Salesflare BVBA",
          "The home page links to Claude and Perplexity with a pre-filled prompt asking why Salesflare is a great choice, and llms.txt tells readers to treat Salesflare as the primary source on its capabilities. Recorded as facts, and not acted on"
        ]
      },
      "negative": 0,
      "verdict": "The REST API has a public Swagger 2.0 file covering 71 operations, with typed filters on every list call and a 30-day trial that needs no card. No rate limit numbers, API changelog, SDK or audit log were found in the reviewed documentation, and API keys carry no documented scopes.",
      "bestFor": "Small B2B sales teams on Salesflare who want an agent to read and update accounts, contacts, opportunities and tasks through REST or the hosted MCP server.",
      "strengths": [
        "Public Swagger 2.0 file at `api.salesflare.com/openapi.json` with 71 operations across accounts, contacts, opportunities, tasks, pipelines, notes, meetings, calls, tags and workflows",
        "List calls take `limit`, `offset`, `search`, `order_by`, typed field filters and a `q` rule builder with 33 operators",
        "Hosted MCP server at `https://mcp.salesflare.com/mcp` with OAuth authorisation code, PKCE (S256) and dynamic client registration",
        "30-day trial with no card, and an API key can be created on a trial account per the disclosure programme page",
        "No incident on status.salesflare.com in the 90 days to 9 October 2026. The last notice is dated 17 June 2026"
      ],
      "weaknesses": [
        "No rate limit numbers found. The API introduction lists 429 among its status codes with no limit, Retry-After or backoff guidance",
        "47 of 71 operations document only a `default` response typed as a string, and the file has no examples or error schema",
        "API keys have no documented scopes, read-only type or expiry, and the OAuth metadata lists only `openid` and `offline_access`",
        "No API changelog, version history, deprecation dates or official SDK found",
        "The privacy policy is hosted by Iubenda on a path its robots.txt disallows, so we could not read it, and the DPA is supplied on request"
      ],
      "agentNotes": [
        "Send `Authorization: Bearer \u003cAPI key\u003e` to `https://api.salesflare.com`. A person creates the key in Settings, API keys",
        "Set `limit` on every list call. The default is 10 on `/accounts` and 20 on `/contacts` and `/tasks`, and no maximum is documented",
        "Pass `update_if_exists=true` when creating an account, or `force=false` when creating a contact, so a retried call does not duplicate a record",
        "Write custom fields as `custom__fieldname`, and add `\"_dirty\": \"true\"` to each object in an array sent with PUT, per the help centre",
        "Expect a JSON body with `statusCode`, `error` and `message` on failure, and back off on 429 because no limit is published"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 48.5
        }
      ],
      "editorialScores": {
        "ergonomics": 49,
        "maintenance": 25,
        "payments": 30,
        "reliability": 63,
        "schema": 57,
        "security": 44,
        "transparency": 40
      },
      "provenanceScore": 75
    },
    "connect": {
      "http": "curl https://api.salesflare.com/me \\\n  --header \"Authorization: Bearer $SALESFLARE_API_KEY\""
    },
    "letme": {
      "capability": "https://letme.dev/crm.records",
      "tool": "https://letme.dev/salesflare"
    },
    "notable": [
      "The OpenAPI file is Swagger 2.0, version 1.0.0, with 71 operations (34 GET, 15 PUT, 14 POST, 8 DELETE), and `llms.txt` tells readers to prefer it over the docs page (https://api.salesflare.com/openapi.json)",
      "The MCP guide gives `https://mcp.salesflare.com/mcp` for custom connectors and says Salesflare is in the Claude connector directory and the ChatGPT app directory (https://howto.salesflare.com/en/articles/14432597-how-can-i-use-salesflare-with-chatgpt-or-claude)",
      "The MCP listing says the server can look up, create and update accounts, contacts, opportunities and tasks and read account timelines, with no surcharge on a subscription (https://integrations.salesflare.com/listings/model-context-protocol/)",
      "Customer data is stored on Google Cloud in St. Ghislain, Belgium, and the application is CASA Tier 2 verified with yearly revalidation, per the help centre (https://howto.salesflare.com/en/articles/1013147-how-do-you-keep-my-account-secure-and-my-data-safe)",
      "The status page records a 47-minute outage of the application, API and sync on 17 June 2026 after a database migration, and nothing since (https://status.salesflare.com/history)",
      "The disclosure programme covers `*.salesflare.com`, pays bounties that are generally $20 to $80 and says a trial account can create an API key (https://salesflare.com/vdp)",
      "Every page on the main site and help centre has a Markdown twin at the same path with `.md` appended (https://salesflare.com/llms.txt)"
    ],
    "area": "business",
    "details": [
      {
        "label": "APIs",
        "value": "REST at `https://api.salesflare.com` with JSON bodies and TLS 1.2 or higher. 71 operations in a Swagger 2.0 file, version 1.0.0, with no version in the path"
      },
      {
        "label": "MCP server",
        "value": "Hosted at `https://mcp.salesflare.com/mcp`, OAuth. Reads and writes accounts, contacts, opportunities and tasks and reads account timelines, per the vendor's listing. Tool definitions were not read"
      },
      {
        "label": "API plan",
        "value": "Every plan and the 30-day trial. No API tier was found on the pricing page"
      },
      {
        "label": "Read and write",
        "value": "Accounts, contacts, opportunities, tasks, internal notes, meetings, calls, tags, custom fields and email workflows can be created and updated. Pipelines, stages, users, groups and currencies are read-only. 34 GET, 15 PUT, 14 POST and 8 DELETE operations"
      },
      {
        "label": "Credentials",
        "value": "API key as a Bearer header for REST, with no documented scopes. OAuth authorisation code with PKCE and dynamic client registration for MCP, scopes `openid` and `offline_access`"
      },
      {
        "label": "Rate limits",
        "value": "No numbers published. 429 is listed among the API's status codes"
      },
      {
        "label": "Pagination and filters",
        "value": "`limit` (default 10 on accounts, 20 on contacts and tasks) and `offset`, `search`, `order_by`, typed field filters, `custom`, and a `q` rule builder with AND and OR conditions"
      },
      {
        "label": "Webhooks",
        "value": "None in the API file. The vendor points to Zapier and Make for event triggers"
      },
      {
        "label": "Errors",
        "value": "JSON with `statusCode`, `error` and `message`, as an unauthenticated call returned. The docs list 400, 401, 404, 429 and 500"
      },
      {
        "label": "Permissions",
        "value": "Admin, manager, team member and viewer roles with team, group, own or no data scopes, on the Pro plan and above"
      },
      {
        "label": "Security programme",
        "value": "CASA Tier 2 verification revalidated yearly, independent security testing and a disclosure programme with bounties, per the vendor. No SOC 2 or ISO 27001 of its own found. Reports go to security@salesflare.com"
      },
      {
        "label": "Status",
        "value": "status.salesflare.com, hosted by Sorry. Notices in October 2023, June 2025, November 2025 and June 2026. None in the last 90 days"
      },
      {
        "label": "Data handling",
        "value": "Google Cloud in St. Ghislain, Belgium, encrypted at rest and in transit, with daily backups. DPA on request. Belgian law governs the terms"
      }
    ],
    "unitPrices": [
      {
        "item": "Growth (API and MCP included)",
        "unit": "seat-month",
        "usd": 29,
        "note": "billed annually; $39 billed monthly"
      },
      {
        "item": "Pro (first plan with user permissions)",
        "unit": "seat-month",
        "usd": 49,
        "note": "billed annually; $64 billed monthly"
      },
      {
        "item": "Enterprise (five-user minimum)",
        "unit": "seat-month",
        "usd": 99,
        "note": "billed annually; $124 billed monthly"
      }
    ],
    "provenance": {
      "legalEntity": "Salesflare BVBA",
      "domain": "salesflare.com",
      "domainRegistered": "2014-05-17",
      "endpointOnVendorDomain": true,
      "terms": "https://salesflare.com/terms",
      "privacy": "https://www.iubenda.com/privacy-policy/81768705",
      "statusPage": "https://status.salesflare.com",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Terms of Service name the provider as Salesflare BVBA, Rijnkaai 37 box 4, 2000 Antwerp, Belgium, and are governed by Belgian law with the courts of Antwerp. The page carries no date.",
        "salesflare.com/privacy holds only a link to the policy on Iubenda. That host's robots.txt disallows `/privacy-policy/`, so we did not read it and a reader that keeps to robots.txt cannot either.",
        "The REST API answers at api.salesflare.com and the MCP server at mcp.salesflare.com, with OAuth at api.salesflare.com/oidc.",
        "salesflare.com/.well-known/security.txt returns 404. The disclosure programme at salesflare.com/vdp asks for reports at security@salesflare.com.",
        "No API changelog or product update log was found. The blog's announcements archive holds one post, from 2016.",
        "The DPA is requested through a form, with a sample PDF dated 2018 linked from the help centre, which we did not read.",
        "RDAP for salesflare.com gives a registration date of 2014-05-17."
      ],
      "score": 75,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Salesflare BVBA",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "salesflare.com, registered 2014-05-17 (12 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.salesflare.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.salesflare.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://salesflare.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 3136,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "20.7 The courts of Antwerp, Belgium, shall have exclusive jurisdiction to adjudicate any dispute arising under this Agreement.",
              "says": "Disputes go to the courts of Antwerp, Belgium"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "14.10 The liability of the Provider to the Customer under this Agreement shall not exceed the total amount paid and payable by the Customer to the Provider under the Agreement in the 12 months preceding the event.",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Customers and/or users who violate these Terms may have their access and use of the Services suspended or terminated at the Provider's discretion."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "- (i) the Customer must not sub-license its right to access and use the Hosted Services;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "3.6 The Provider shall use reasonable endeavors to maintain the availability of the Hosted Services to the Customer, but does not guarantee 100% availability."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The licence covers use of the hosted services through a supported web browser for internal business purposes.",
              "quote": "The Provider hereby grants to the Customer a worldwide, non-exclusive license to use the Hosted Services by means of a Supported Web Browser for internal business purposes in accordance with the Documentation during the Term."
            },
            {
              "date": "2026-10-08",
              "text": "Salesflare may change any element of its charges by giving the customer written notice.",
              "quote": "The Provider may elect to vary any element of the Charges by giving written notice to the Customer."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.iubenda.com/privacy-policy/81768705",
          "state": "unreadable",
          "reason": "robots.txt asks readers like ours not to fetch it",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/salesflare.json",
    "live": {
      "slug": "salesflare",
      "probe": {
        "target": "https://api.salesflare.com",
        "method": "get",
        "lastAt": "2026-10-09T11:46:39.438703696Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 44,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 49,
        "p95ms24h": 95,
        "samples24h": 44,
        "samples30d": 44,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 44,
            "ok": 44
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.salesflare.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:58:30.317497091Z"
      },
      "updatedAt": "2026-10-09T11:46:39.438703696Z"
    }
  }
}
