anVendor

A unique way to see subscriptions of any company

Visit Website
August 26, 2026 I found a way to detect which SaaS subscriptions any company has

I'm a solo founder. My background is engineering and product; I'm picking up the marketing and sales side as I go.

A while back I found an approach to working out which SaaS subscriptions a company actually holds. I went looking for anyone doing it the same way and didn't find anything - though that may just mean I didn't look hard enough. Either way, I'd rather not describe the mechanism yet.

I know "I can't tell you how it works" is a weak thing to post here, so let me at least say what it isn't: no browser extension, no SDK, no tracking script, and nothing that touches private or password-protected systems. It works from public information, and from the vendor's side of the relationship rather than the customer's.

That last difference is why it sees things the existing tools don't. To be fair to them, each is good at what it was built for:

  • Site analysis (BuiltWith, Wappalyzer) reads a company's public website - scripts, tags, headers, DNS. Genuinely excellent for analytics, ad tech and CDNs. It just can't see anything behind a login.

  • Job ads (TheirStack) mine vacancies for tool names. That's a real signal about where a company is heading - but it's hiring intent, not billing, and nobody posts a job ad about their document suite.

  • Modelled data (HG Insights, Enlyft, 6sense) estimates from firmographics and comparable companies. The right tool for sizing a market. At the level of one company it's a statement about companies like that one.

All three infer from the outside. Mine looks for evidence of the account itself, which is why it reaches what people log into every morning - CRM, HR, design, documents, ticketing, code hosting. For most companies that's the larger part of the software budget.

Where I am now. It works. Give it any company domain and it comes back with the subscriptions that company holds. The company side isn't the constraint - any domain works.

The constraint is the other side: it can only detect the ~700 services I've built coverage for. If a company pays for something outside that list, I don't see it, and the result is quietly incomplete rather than wrong. Every service I add makes every future lookup better, so the list is the thing worth getting right.

What I'm building next. The reverse lookup: enter a competitor's product and get back the companies paying for it, with roughly what each one spends. Their customer list is your prospect list. That runs on the same engine, pointed the other way.

What I'd like from you. I picked the first 700 services myself, which means I picked them based on what I could think of.

So: which service would you want this to cover?

Your competitor, the tool you sell against, or just something you're curious whether a company pays for. Leave it in the comments or just search for it in anVendor.com

1 Comment

  1. 2

    The 700-service constraint is probably an interesting signal in itself. The question isn’t just which services people want covered, but which missing coverage actually changes whether they’d use the product at all.

About

I found a way to verify what a company actually subscribes to. And I created a lead generation tool that uses this.