Customer Discovery Engine

How do we find your customers?

This page is an architecture note, not a marketing promise. Where the data comes from, what we never collect, how we verify it and which legal basis we rely on — with what we do today clearly separated from what is still on the roadmap.

Public corporate data only
No purchased lists
Data stays in your tenant
Absolute right to opt out
In One Sentence

What we do — and what we don't

We do not sell data and we do not stockpile it. We find and verify the corporate contact details companies publish themselves so that they can receive trade enquiries — inside the customer's own account, for the customer's own query, at the moment it is asked. Records stay in their tenant; the right to opt out is absolute.

We sell discovery capability, not a data product

ihracatAI does not sell a database. No list is transferred, copied or repackaged. Every search runs at the moment it is asked, for that user's own question, and the result is written only to that user's own space.

Corporate, public, commercial data only

Every record we collect is information a company published deliberately for its commercial activity: role addresses on its own domain such as info@, sales@ or export@, plus official company records. Individual data is out of scope by design.

Purpose alignment is the heart of the argument

When an exporter puts export@company.com on its website, it does so precisely to receive trade enquiries. The purpose of publication and our purpose of use align — and that alignment is what the legal basis rests on.

The right message to the right counterpart

Our goal is not to send more email; it is to remove the irrelevant company from the list. Sector and role exclusions plus a relevance threshold exist to find the right counterpart, not to fill an inbox.

A Three-Layer Engine

Where does the data come from?

Three independent layers. We state the real maturity of each one — an architecture note that hides where a capability actually stands is worth nothing.

Live in our own operation

Layer 1 — Open Web Discovery

We ran this engine on ourselves first: ihracatAI's own customers are found by it today. Bringing it into the product is in progress.

Map and business-directory search lists companies in the target sector
The company's own website is visited; contact, about and corporate pages are read
Only generic role addresses on the company's own domain are taken (info@, sales@, export@)
Manufacturer / importer signals are derived from the company name and site content; retail and micro-traders are filtered out
A uniqueness record prevents the same address from ever being approached twice
Live today

Layer 2 — Licensed Business Data Provider

The product's main engine today. The decision-maker's role and corporate email address are retrieved from a licensed business data provider, one record at a time.

Search results come back masked; contact details are resolved only if the user chooses to open that specific record
Data is not stockpiled in bulk, not resold and not transferred to third parties
Each user's quota is allocated to them; nobody can reach a record another user opened
The provider's own verification status is carried through as-is — we do not mint our own label on top of it
Phone number reveal is switched off across the product
Live today

Layer 3 — AI Relevance Layer

A raw list is not a value. This layer decides which of the companies found could realistically buy your product.

Your product description is translated into target sectors, decision-maker roles and countries
Service sectors that never import physical goods are removed by a deterministic exclusion list
Roles with no purchasing authority (HR, marketing, legal) are filtered out
Every company receives a 0-100 relevance score with a one-sentence rationale
Companies below the threshold never enter the list at all

The layers are not backups of one another but complements: open web brings breadth, licensed data brings the decision-maker, AI brings relevance.

Hard Limits

What we never collect

A data architecture is judged less by what it gathers than by what it refuses to. The following are structural constraints, not product preferences.

Personal mobile phone numbers
Personal email addresses (gmail, hotmail and other free providers)
Any consumer-facing (B2C) personal data
Special category personal data (health, belief, political opinion, biometrics)
Content behind login walls or paywalls
Areas a site owner has disallowed via robots.txt
Purchased, rented or breach-sourced ready-made lists
Profile scraping that would violate a social network's terms of service

Phone number reveal is disabled across the product and at the central gateway — it cannot be switched on by changing a setting.

Verification Pipeline

How do we verify this data?

The industry habit is to make the verification pipeline look longer than it is. We list the steps that genuinely run today separately from the ones we are still building.

Running today

01

Source filter

Only corporate addresses on the company's own domain are accepted; free email providers and personal addresses are excluded from the outset.

02

Format and placeholder cleaning

Invalid formats, example domains and provider placeholder values are stripped before anything reaches your list.

03

Provider verification status

The business data provider's own verification state is carried through per record and shown on the results screen. Searches request verified records first; when the filter is relaxed because nothing came back, those records are not labelled 'verified'.

04

Relevance verification

Deterministic sector and seniority exclusion lists work alongside an AI relevance score; companies below the threshold are dropped. A company that cannot be scored is never given a fabricated score — no score means no badge.

05

Duplicate and history checks

The same company or person will not reappear across searches; records you have already opened or hidden are filtered out, and no record is ever charged twice.

06

Post-send feedback loop

Undeliverable addresses and auto-replies are detected and separated; they are excluded from success reporting and never enter the auto-reply loop.

On the roadmap

Live mail server verification

The existence and response of the domain's mail server will be tested independently before sending.

Catch-all domain detection

Domains that accept every address will be flagged and presented at a separate confidence level.

Dual-source consensus

Records confirmed by two independent sources will be assigned a higher confidence level.

Provenance record

For each record we will store and display where the data came from and when — for auditability and for source-disclosure obligations alike.

An honest note: no platform in B2B data can guarantee total accuracy — people change jobs, companies retire domains. So instead of hiding the verification state of a record, we show it to you.

Legal Framework

What do we rely on?

Cold outreach law differs by country. Rather than leaning on a single justification, we rely on the framework of the target market itself.

JurisdictionBasisWhat it means
European UnionGDPR Art. 6(1)(f) + Recital 47Direct marketing may be carried out under legitimate interest. A written legitimate interest assessment covering purpose, necessity and balancing is maintained.
United KingdomPECR — corporate subscriber exemptionThe prior consent requirement for electronic marketing applies to individual subscribers; it does not apply to corporate subscribers (company addresses).
United StatesCAN-SPAMNo prior consent required; sender identity, a valid physical address and a working opt-out mechanism are mandatory.
TürkiyeLaw No. 6563, Art. 6(2)Commercial electronic messages sent to the electronic contact addresses of merchants and tradespeople do not require prior consent. The recipient's right to refuse always stands, and no message may be sent after refusal.
TürkiyeKVKK — corporate data and purpose alignmentOnly role addresses published for a company's commercial activity are processed; individual, special category and consumer data are out of scope. Disclosure and source-notification duties are observed.
Strict regimes (Germany, Canada)UWG §7 / CASLThese jurisdictions require prior consent for cold commercial email. A country-level rules engine will close these markets by default — on the roadmap.

Purpose alignment: the heart of the argument

When an exporter publishes export@company.com on its website, it does so not to conceal the address but precisely to receive commercial approaches. The purpose of publication and our purpose of use align. That alignment is what both the legitimate interest balancing test and the purpose compatibility test rest on — and it is exactly why personal addresses, mobile numbers and consumer data are architecturally out of scope.

This page is for information only and does not constitute legal advice. Commercial communication rules vary across target markets; we advise our users to seek local counsel for their own target countries.

Right to Opt Out

What happens when a company says no?

For us the right to opt out is not a compliance checkbox but an operating condition. A second message to a company that already said no is commercially pointless too.

Working today

One-click opt-out on every email

Every first-touch email carries the standard headers (List-Unsubscribe, RFC 8058) that power your own email client's unsubscribe button, plus a visible opt-out link in the body. No account, no reply, no request needed.

Permanent, platform-wide suppression

Once an address opts out it is suppressed permanently across the whole platform, regardless of sending brand or account. The suppression list cannot be read or deleted by any user.

Source disclosure inside the email

Every first-touch email states in one line that the contact detail is a corporate address published on your own website or in public commercial records.

Automatic recognition of refusal

You do not even need to click the link: incoming replies are classified by AI, and a reply meaning 'do not contact me again' writes the address straight to the suppression list.

Separation of undeliverable addresses

Bounced and auto-responding addresses are detected and flagged; they are excluded from the auto-reply loop and from reporting.

Volume caps and pacing limits

No recipient is ever blasted. Working hours, a mandatory wait between sends and a daily ceiling are enforced by the system.

Suppression list infrastructure

The platform maintains a persistent blocklist table holding manual refusals, complaints and invalid addresses.

On the roadmap

Country-level rules engine

In jurisdictions requiring prior consent, cold outreach will be disabled by default; users will only be able to message their own consented lists.

Complaint feedback loops

Subscribing to major mailbox providers' feedback loops so that addresses marking a message as spam are suppressed automatically.

Data Ownership

Whose data is it, and where does it live?

The customer you find is your commercial asset. Our architecture treats that as a technical constraint, not a promise.

Per-account isolation

Your search history and the records you open are protected by row-level security at the database layer. No user can see another user's records.

Server-side masking

Information restricted by your plan is never sent to the browser at all — it is masked on the server and cannot be revealed with developer tools.

Deployment on your own server

Enterprise customers can run the platform on their own isolated server with their own database. In that setup your commercial data never reaches us. It runs this way at a live enterprise customer today.

Bring your own provider licence (roadmap)

On Pro and self-hosted deployments the customer will be able to connect their own business data provider licence. The contract is then directly between the customer and the provider; we step out of the middle, and both the data and the usage logs stay in the customer's own environment.

Sending Discipline

How do we reach out?

A well-intentioned data policy does not survive an undisciplined sending engine. The limits below are system defaults, not optional settings.

Sending window

Local business hours

New address warm-up

Gradual ramp

Between sends

Minutes of spacing

Daily ceiling

Capped per account

Phone calls

Disabled

Bulk blasts

None

Outside business hours the pace drops automatically, and a new sending address cannot reach full capacity on day one. These constraints protect the recipient and the sender's reputation alike.

Auditability

How can you audit the claim?

A compliance story is only worth what an outsider can check. These are the technical and contractual counterparts of everything stated on this page.

Usage records

Every search and every record opened is logged per user. In enterprise deployments those logs live on the customer's own server, so which query ran, when and by whom can be shown after the fact.

The contractual layer

A data processing agreement (DPA), a sub-processor list and a privacy notice are published. Users are contractually bound to comply with the commercial-communication and marketing rules of their target market — that is an article of the subscription agreement, not a recommendation.

Transparency pages

This page is itself audit material: every capability carries its real present status (live / live in our own operation / roadmap) and the distance between claim and code is written down.

Source provenance (roadmap)

For every record we will store and display which address it came from and when. That satisfies GDPR's source-notification duty and Turkish KVKK disclosure practice in a single move.

Roadmap

What comes next

We do not describe things we have not built as if they were live. These are the real items in the development queue.

01

Bringing open web discovery into the product

The map and website discovery engine already running in our own sales operation is being turned into a module users can run directly.

02

Provenance records and audit trail

Where each record came from and when will be stored and shown to the user.

03

Independent email verification layer

Mail server verification, catch-all detection and dual-source consensus, giving a confidence level independent of the provider's label.

04

Country-level compliance rules engine

A rules layer that adjusts sending behaviour automatically according to the target country's commercial communication regime.

05

Trade and exhibition data integrations

Adding public sources such as trade registries, chamber records and exhibition participant lists to the discovery engine.

06

Bring your own provider licence

Letting Pro and self-hosted customers use their own business data licence.

Open Risk Register

What we have not built yet

We publish this section deliberately. A compliance architecture is judged by whether it writes down its own gaps — a story with no gaps is a story that hides them.

GapWhere it stands todayMitigation
No independent email verificationThe verification label comes from the provider; we run no mail-server (MX/SMTP) check of our own.An independent verification layer — on the roadmap.
No country-level rules engineIn consent-first regimes (Germany, Canada) no automatic restriction is enforced by the platform.The rules engine is on the roadmap; until then the user is bound by the subscription agreement.
Open web discovery is not in the productLayer 1 runs only in our own sales operation and is not yet exposed to users.Productisation is under way — the first item on the roadmap.
Single-provider dependencyLayer 2 rests on one licensed business data provider today.Productising Layer 1 and the bring-your-own-licence model structurally reduce the dependency.

Gaps we closed: in August 2026 the codebase was audited against the claims on this page and two inconsistencies were fixed. The fabricated 'natural-looking' match score generated when AI scoring failed was removed, and the verification label — previously stamped unconditionally — is now derived from the provider's per-record field. One-click opt-out and platform-wide permanent suppression also left this register: they are live.

FAQ

Direct questions, direct answers

The questions investors and enterprise customers ask most — without the varnish.

No. What is sold is software and automation capability, not data. The user asks their own question and the result is written to their own account. No dataset is transferred, copied or repackaged for sale. On our roadmap, enterprise customers connect their own business data provider licence — in that model the contract sits directly between the customer and the provider, and we step out of the middle entirely.

A corporate address a company publishes on its own website, on a contact page anyone can view, is by definition public commercial information — and it is published precisely so that commercial approaches can be made. We take only information of that nature, from pages requiring no login, in areas the site owner permits. Personal addresses, mobile numbers and gated areas are architecturally out of scope.

We rely on the framework of the target market rather than a single justification. In the EU, GDPR's legitimate interest ground together with its direct marketing recital, applied with a written balancing assessment. In the UK, corporate subscribers are exempt from the consent requirement. In Türkiye, Law No. 6563 requires no prior consent for commercial electronic messages to merchants and tradespeople. For jurisdictions that do require prior consent, a country-level rules engine is on our roadmap.

Every first-touch email carries a one-click opt-out link and the standard headers that power your email client's own unsubscribe button. Once you opt out, the address is suppressed permanently across the whole platform — no brand and no user can email it again. You do not even have to click: replying 'do not contact me again' is enough, the AI recognises it and writes the address to the list. Undeliverable addresses go to the same list.

You do. Your records are isolated per account and no other user can see them. In enterprise deployments the platform runs on your own isolated server with your own database — in that scenario your commercial data never reaches us at all.

No, because no platform honestly can. People change jobs and companies retire domains. What we do is show the verification state on every record instead of hiding it, and never present an unverified record as a verified one. The same principle governs the match score: we do not manufacture a plausible-looking number for a company that could not be scored — every score you see has a real assessment and a one-sentence rationale behind it. An independent verification layer is on our roadmap.

A data source alone is not a defensible advantage. What is defensible is that the entire path from product description to the right counterpart is automated in one place: discovery, relevance scoring, product-specific offer generation, sending discipline, reply classification and automated response with a price list. The whole chain runs inside a single product.

Yes. ihracatAI's own outbound motion runs on the same discovery and sending discipline. We run the engine in our own sales operation before bringing it into the product — that makes it both our test bed and our accountability test.

We write this dependency into our open risk register: Layer 2 rests on a single licensed business data provider today. We mitigate it in two directions. Layer 1 (open web discovery) is a fully independent source and is already proven in our own sales operation; the moment it ships in the product, single-provider dependency structurally drops. The second direction is letting the customer connect their own business data licence — in that model the contract sits directly between customer and provider, so the risk never concentrates in one place.

Scale magnifies risk in an undisciplined engine. Here the working-hours window, address warm-up, spacing between sends, daily ceiling and relevance threshold are system defaults rather than settings a user can switch off, so they apply automatically as the user base grows. Opt-out and suppression already operate platform-wide. The one remaining gap is the country-level rules engine; once that ships, compliance is enforced at platform level independently of user behaviour.

Start finding your customers today

Describe your product and let us bring you the right counterpart in the right sector. No black box — every step of the process is visible.

WhatsApp'tan yaz