How we know what a company runs on
runsonwhat lists a tool at a company only when a public record shows it in use. This page explains which records we read, what counts as a match, how often we check again, and what the numbers can and can’t tell you. Last revised 8 October 2026.
What counts as a match
- A company is counted for a tool when at least one direct record names the vendor: a verification record in its DNS, an email record that authorizes the vendor to send for it, a subdomain that points at the vendor, the vendor’s code on its website, or the vendor on its own subprocessor list.
- Weak hints don’t count on their own: a domain in a content security policy, a subdomain that merely carries the tool’s name, or a tool implied by another. They are stored but not listed.
- We skip a company’s own products (stripe.com isn’t listed as a Stripe customer) and records on shared hosting platforms.
- Absent tools are never inferred. If we can’t see a tool, the company simply isn’t on its list.
The records we read
- DNS: TXT verification tokens, SPF includes, MX, NS, DMARC, CAA, a fixed list of DKIM selectors, and where subdomains point (CNAME). Rechecked every week.
- Certificate transparency logs: every public certificate names the hosts it covers, which reveals subdomains such as help., status. and careers., when they first appeared, and vendors that give each customer its own host.
- Website code: the homepage, its response headers and cookies, the scripts it loads, its own JavaScript bundles, its Google Tag Manager container and Segment settings, ads.txt and OpenID configuration. Rescanned about monthly by our crawler, which obeys robots.txt.
- A real-browser crawl: HTTP Archive’s monthly Chrome crawl of about 11 million homepages shows tags that only load while the page runs.
- Subprocessor lists: a company’s own subprocessor or DPA page, when its homepage links to it.
- Job boards: open roles from public Greenhouse, Lever, Ashby, Workable and Recruitee boards, for hiring numbers. A job posting alone never makes a company a tool’s customer.
We track 1400+ tools. Each has its own fingerprints (the exact records and code that identify it), and a new tool is added only after its fingerprint is confirmed on a real company.
Starts, stops and adoption dates
- A company’s first check is a baseline: tools found then aren’t counted as new.
- A start is a tool found on a later check that the previous check, done the same way, didn’t find. A stop is the reverse, and only for a tool the previous check confirmed. Changing how we check a company never shows up as a start or a stop.
- “Since” dates come from the first certificate of the host that proves the tool (for example the help center that points at the vendor), never earlier than the year the vendor was founded. Without such a certificate we show when we first saw it.
What the numbers can’t tell you
- Counts are lower bounds. Tools used only on servers (most AI model APIs, internal software, tools inside other tools) leave no public record, and some companies block our crawler.
- A match shows a tool is set up, not how much it’s used or what the company pays.
- Companies we haven’t checked yet aren’t counted, so compare tools by their counts here, not against market-size estimates.
- Industry, size and country come from public company profiles and may be missing or out of date for a share of companies.
How to cite runsonwhat
Cite the tool, category or company page the number came from, with the month: “According to runsonwhat (October 2026), N companies show public evidence of HubSpot.” Counts change daily, so use the page’s current number. Every tool, category and company page also has a Markdown copy at the same address plus .md, and the summary dataset is at /data/tool-counts.csv (CC BY 4.0).
Corrections and removal
If a match is wrong, or you want your company removed, email hello@runsonwhat.com. See data and removal.