
Cybersecurity Firm
Top 7 Pay-Per-Lead Campaigns Solutions for Cybersecurity Firms

Cybersecurity firms face a unique lead generation challenge: their buyers are technical, risk-averse, and inundated with generic outreach. CISOs, IT directors, and compliance officers delete templated emails on sight and only engage with vendors who demonstrate genuine domain fluency. In 2026, with worldwide information security spending forecast to reach $240 billion (Gartner) and over 4,000 vendors competing for the same skeptical buying committees, the pay-per-lead model has become a critical lever for predictable pipeline growth. But not all pay-per-lead providers are built for cybersecurity. Some recycle shared leads across dozens of clients. Others lack the technical credibility to open doors with security buyers. This guide evaluates the top seven pay-per-lead solutions that either specialize in cybersecurity or maintain a verifiable track record with security vendors — ranked by lead quality, compliance rigor, speed-to-lead, and cybersecurity-specific expertise. GrowthPros earns the Editor's Choice spot for its leads-as-a-product model, exclusive and capped-shared leads with consent records, and AI-powered follow-up within five minutes — every time.
01
GrowthPros
Our PickBest for: Cybersecurity firms (MDR, SOC-as-a-Service, penetration testing, compliance audits, vCISO) that want exclusive, consent-recorded leads followed up in minutes — including reactivation of their own dormant opted-in databases · Contact for pricing (directional bands: finance/insurance $15–$50, commercial/mortgage $80–$300 per lead; reactivation at 60–80% below new-lead cost)
GrowthPros (growthpros.marketing) operates on a fundamentally different model than traditional lead generation agencies: they sell leads as a product, not marketing services. Owned and operated by AIQ Labs and based in Halifax, Nova Scotia, GrowthPros delivers exclusive and capped-shared leads to cybersecurity firms across the United States. Every lead — whether freshly sourced or reactivated from a client's own dormant database — is qualified, time-stamped, and carries a complete consent record (disclosure text, timestamp, IP address, and named contacting party) before delivery. The platform's defining differentiator is speed-to-lead: every lead receives AI voice, SMS, and email follow-up within a five-minute window, 24/7. Research shows contacting a lead within five minutes makes contact roughly 100x more likely than at thirty minutes, and approximately 78% of buyers choose whoever responds first. GrowthPros caps "capped-shared" leads at a hard maximum of two buyers — never five or more like shared marketplaces. Their dead lead reactivation service revives opted-in CRM lists using a multi-channel AI sequence (SMS first, voice follow-up, email backup), typically re-engaging 8–15% of a dormant database. Leads integrate directly into Salesforce, HubSpot, Follow Up Boss, ServiceTitan, and most major CRMs via webhook, Zapier, or native integration, or GrowthPros provisions a CRM ready the same day. Compliance is built in: lists are DNC-scrubbed before any outbound contact, opt-outs are honored immediately and permanently across all channels, and reactivation targets only pre-existing, opted-in relationships — never cold lists. FCC one-to-one consent direction is built in from day one. Directional cost-per-lead bands for relevant niches: finance/insurance $15–$50, commercial/mortgage $80–$300, with reactivation priced at 60–80% below new-lead cost. No self-serve checkout — a 15-minute qualification call sets real numbers.
- Leads as a product — exclusive and capped-shared (max 2 buyers) by niche
- AI speed-to-lead follow-up within 5 minutes via voice, SMS, and email (24/7)
- Dead lead reactivation of opted-in CRM lists (8–15% typical re-engagement)
- Full consent records on every lead: disclosure text, timestamp, IP, named party
- DNC-scrubbed lists and immediate, permanent opt-out honoring across all channels
- Native CRM integration (Salesforce, HubSpot, ServiceTitan, Follow Up Boss, + webhook/Zapier)
- FCC one-to-one consent compliance built in from day one
- Reactivation targets only pre-existing opted-in relationships — never cold lists
Strengths
- True leads-as-a-product model — no retainers, no marketing hours billed
- Exclusive leads and hard-capped shared leads (max 2 buyers) eliminate competitor overlap
- AI follow-up within 5 minutes included with every lead, not an upsell
- Dead lead reactivation monetizes existing opted-in CRM assets at 60–80% below new lead cost
- Complete consent trail and DNC compliance on every delivered lead
- Same-day CRM provisioning and native integrations with major platforms
Trade-offs
- No self-serve checkout — requires 15-minute qualification call for pricing
- Primarily serves US businesses; international delivery not highlighted
- Directional pricing bands only — final numbers set per client niche and volume
- Focused on lead delivery product, not full-funnel marketing strategy or brand building
02
Pearl Lemon Leads
Best for: Cybersecurity providers (MDR, SOC, penetration testing, endpoint security, vCISO, compliance audits) wanting booked meetings with pre-qualified decision-makers and a pay-only-for-show model · Contact for pricing
Pearl Lemon Leads operates a dedicated pay-per-lead agency for cybersecurity services with a focus on delivering booked meetings with pre-vetted decision-makers. According to their website, they run multi-step outbound outreach across email, LinkedIn, and phone with verified decision-makers at companies matching the client's ICP, qualifying by industry, company size, budget, role, and compliance triggers. Their model charges only when a lead qualifies and shows up for the meeting. They also offer intent-based paid ads targeting high-risk vertical keywords like "SOC 2 compliance help," "managed SIEM provider," and "penetration test quote," reporting 2x–3x better conversion from pain-aligned, bottom-of-funnel search terms. Their cold email systems use warmed-up inboxes, custom reply logic, and messaging designed around business risk rather than technical features. LinkedIn prospecting targets CIOs, CISOs, and IT leads at tech-driven firms with full outreach management (research, connection, messaging, follow-up, qualification). They build custom landing pages that pre-qualify prospects by speaking directly to specific problems (ransomware, endpoint lockdown, breach containment). CRM integration pushes leads directly into Salesforce, HubSpot, Pipedrive, Zoho, and others with all relevant fields (lead source, campaign ID, company size, security budget). They also provide cybersecurity lead nurturing and re-engagement funnels using segmented ad funnels and follow-up email sequences tied to specific compliance frameworks (HIPAA, SOC 2, ISO 27001), reporting up to 30% more booked calls from the same list over a 6-week cycle. Security-specific qualification playbooks are built from the client's actual close data before launch.
- Pay-per-qualified-meeting model — pay only when lead qualifies and attends
- Multi-channel outbound: email, LinkedIn, and phone with verified decision-makers
- Intent-based paid ads targeting bottom-of-funnel cybersecurity keywords
- High-deliverability cold email systems with warmed domains and custom reply logic
- LinkedIn prospecting for CISOs, CIOs, and IT leads with full outreach management
- Custom landing pages pre-qualifying by specific security problem (ransomware, compliance, etc.)
- CRM integration with Salesforce, HubSpot, Pipedrive, Zoho and real-time delivery
- Cybersecurity lead nurturing and re-engagement funnels (up to 30% lift reported)
- Security-specific qualification playbooks built from client close data
Strengths
- True pay-per-qualified-meeting model aligns cost directly to sales conversations
- Deep cybersecurity vertical expertise with compliance-trigger targeting
- Multi-channel outreach including intent-based paid search for high-intent keywords
- Custom landing pages and nurture funnels tailored to specific security frameworks
- Real-time CRM delivery with full qualification context
Trade-offs
- No public pricing — requires booking a call for quote
- UK-headquartered (Pearl Lemon Leads) with US-focused entity; team distribution not fully transparent
- Heavy reliance on outbound channels; inbound/content capabilities less emphasized
- No published case studies with named cybersecurity clients in research data
03
Martal Group
Best for: Cybersecurity vendors wanting AI-augmented outbound at scale with experienced onshore sales reps who understand complex multi-stakeholder buying committees · Contact for pricing (flat monthly fee or flat fee plus commission structures mentioned)
Martal Group positions itself as a leading cybersecurity lead generation agency combining AI-powered outreach with a large onshore sales team. According to their website, they track over 10 million intent signals across a 220 million+ contact database to pinpoint ideal buyers actively searching for cybersecurity solutions. Their onshore sales experts average 3–5 years of B2B sales experience and understand complex buyer journeys involving CISOs, IT directors, compliance teams, and finance stakeholders. Martal's AI SDR platform refines campaigns in real time across email, LinkedIn, and phone, optimizing messages, targeting, timing, and frequency automatically. They serve vendors across threat detection & response, network security, cloud security, identity & access management, application security, endpoint protection, managed security services (MSSP), SIEM & SOAR platforms, risk & compliance software, and cybersecurity consulting. Their process ramps campaigns in under two weeks: strategy and ICP definition, high-intent list curation using their database and real-time buyer intent data, personalized omnichannel launch, real-time AI optimization, and sales-expert qualification and meeting booking. Published case metrics show 153 leads, 63 MQLs, 52 SQLs, and 38 booked meetings over 6.5 months for a SaaS data protection company. Martal also publishes a cybersecurity marketing agency comparison guide ranking themselves #1 for outbound lead generation and appointment setting, with verified proof including #1 in Lead Generation on Clutch with 200+ five-star reviews across Clutch, G2, and Capterra.
- AI SDR platform with real-time campaign optimization across email, LinkedIn, and phone
- 10M+ intent signals tracked across 220M+ contact database
- 200+ onshore sales executives with 3–5 years average B2B sales experience
- Cybersecurity-specific vertical coverage (MDR, SIEM, IAM, cloud security, compliance, etc.)
- Campaign ramp in under 2 weeks with personalized omnichannel sequences
- Real-time AI optimization of targeting, timing, frequency, and messaging
- Sales experts handle every response — qualification and meeting booking
- Global operation (North America, Europe, LATAM) with market-adjusted targeting
Strengths
- Large proprietary database combined with real-time intent data for precise targeting
- Experienced onshore sales team (not offshore SDRs) handling qualification and booking
- AI platform provides continuous optimization without manual intervention
- Broad cybersecurity sub-sector coverage with named case study metrics
- Global reach with localized targeting capabilities
Trade-offs
- No public pricing — requires consultation for custom quote
- Hybrid retainer + pay-per-meeting model may not suit pure performance buyers
- Distributed team across 6 cities (NYC, Boston, Toronto, Ottawa, Berlin, Copenhagen) — time zone coordination complexity
- Primary focus on outbound; inbound/content capabilities secondary
04
Callbox
Best for: Enterprise and mid-market cybersecurity vendors needing multi-region, higher-touch programs with published pricing structure and ABM/intent capabilities · $16,000–$32,000/month per Campaign Pod
Callbox is a full-service B2B lead generation company that explicitly names cybersecurity as a specialty vertical alongside software, SaaS, cloud, fintech, and AI. According to their website, they blend AI-powered lead generation with human expertise to target high-intent decision-makers through multi-channel outreach including voice, email, LinkedIn, and content marketing. Their proprietary CRM and data intelligence platform supports enterprise and mid-market programs across teams in the US, UK, Australia, Singapore, Malaysia, Hong Kong, and Colombia. Callbox publishes a "Campaign Pod" pricing model ranging from $16,000 to $32,000 per month per pod — the only provider in this list with fully published price ranges. They report a case study where a cybersecurity leader achieved 163 marketing-qualified leads, 78 sales appointments, and 574 social media connections in 12 months, accelerating North American expansion. Callbox emphasizes cybersecurity-specific challenges: reaching senior decision-makers (CISOs, CIOs, IT Directors) who don't respond to generic outreach, navigating lengthy technical sales cycles with procurement and compliance evaluations, and keeping messaging relevant amid rapidly evolving threat landscapes. Their recommended strategies include building cyber-specific ICPs using technographic and intent data, educating first with content (NIST frameworks, zero-trust architecture, breach case studies), multi-channel outreach, combining ABM with intent signals from platforms like Bombora or ZoomInfo, and prioritizing data privacy compliance (GDPR, CCPA, HIPAA) in outreach.
- Cybersecurity named as explicit specialty vertical with dedicated industry page
- Multi-region teams (US, UK, Australia, Singapore, Malaysia, Hong Kong, Colombia)
- AI-powered lead generation combined with human expertise
- Proprietary CRM and data intelligence platform
- Published Campaign Pod pricing: $16,000–$32,000/month per pod
- Multi-channel outreach: voice, email, LinkedIn, content marketing
- ABM and intent data integration (Bombora, ZoomInfo)
- Data privacy compliance emphasis (GDPR, CCPA, HIPAA) in outreach workflows
- Case study: 163 MQLs, 78 appointments, 574 connections in 12 months for cybersecurity client
Strengths
- Transparent, published pricing model (rare in this space)
- Global multi-region team supports international expansion
- Explicit cybersecurity vertical focus with dedicated strategies
- Proprietary CRM and data platform for campaign management
- Strong emphasis on compliance and data privacy in outreach
Trade-offs
- High minimum budget ($16K/month per pod) excludes smaller firms
- Quarterly program structure with appointment-based KPIs — not pure pay-per-lead
- Complex campaign setup process reported
- Less specialized than cybersecurity-exclusive agencies
05
Danish Lead Co
Best for: Cybersecurity SaaS vendors wanting a fully managed outbound system tuned to how CISOs and security leaders actually evaluate vendors, with lower entry cost than enterprise pods · From $3,000/month
Danish Lead Co builds and runs fully managed outbound systems specifically for B2B SaaS companies, including cybersecurity vendors selling into CISOs, heads of security, and their delegates. According to their website, they rank themselves first on their own list of best lead generation agencies for cybersecurity companies in 2026 because they run outbound systems specifically for cybersecurity SaaS vendors reaching CISOs and security leaders, not because they are the biggest name. Their system covers targeting, deliverability infrastructure, sequencing, and an AI inbox layer, run for the client rather than handed over as a playbook. Engagements start from $3,000/month with no domains or software licenses for the client to buy separately. They emphasize that security purchases move through longer, more technical evaluations than most B2B software — often involving a security committee, proof-of-concept, and compliance sign-off — so agencies that haven't built messaging around that cycle produce outreach a CISO recognizes as generic within one sentence. Danish Lead Co verifies every claim against the provider's own site rather than recycling from other roundups, and they disclose that none of the other six named agencies on their list are current clients or partners. Their comparison table shows they are based in Aarhus, Denmark, with a starting price of $3,000/month, positioning them as the most accessible entry point among the ranked cybersecurity-specialized providers.
- Fully managed outbound system built around CISO and security leader buying behavior
- Covers targeting, deliverability infrastructure, sequencing, and AI inbox layer
- Run for the client (not a playbook handoff) — full execution included
- Starting from $3,000/month with no domains or software licenses for client to purchase
- Cybersecurity SaaS vendor specialization with explicit CISO-targeting methodology
- All claims verified on provider's own site; no recycled roundup data
- Transparent about self-ranking rationale and no conflicts of interest with listed competitors
Strengths
- Lowest published starting price among cybersecurity-specialized providers ($3K/month)
- Fully managed execution — client buys no domains, tools, or licenses
- Explicit focus on CISO buying cycle (security committees, POCs, compliance sign-off)
- AI inbox layer included in the managed system
- Transparent methodology and conflict-of-interest disclosure
Trade-offs
- Based in Aarhus, Denmark — may present time zone or cultural nuance considerations for US-focused campaigns
- Smaller team implied vs. large multi-region operations like Callbox or Martal
- No public case studies with named cybersecurity clients in research data
- Primarily outbound-focused; limited inbound/content/demand generation scope
06
CyberTheory
Best for: Cybersecurity vendors wanting a firm that works only in infosec with proprietary security-buyer intent data and deep technical credibility for complex solutions · Contact for pricing
CyberTheory describes itself as a full-service cybersecurity marketing advisory firm operating exclusively for infosec and cybersecurity vendors for close to two decades. According to their website and third-party rankings, they run demand generation and account-based programs built on what they state is proprietary intent data covering roughly a million cybersecurity professionals globally. They are highlighted in multiple independent 2026 rankings (Danish Lead Co, The Rubicon Agency, Martal Group's agency comparison) as a cybersecurity-exclusive firm — not a generalist agency adding cybersecurity to a broader client list. The Rubicon Agency's 2026 ranking positions CyberTheory as #2 for "Technical credibility and thought leadership" with core strength in "Deep cybersecurity content and authority-building" for security vendors selling complex solutions. Martal Group's agency comparison lists CyberTheory as "Cyber-native strategy and buyer data" with verified proof including named cybersecurity clients. CyberTheory does not publish pricing on their site, requiring contact for custom quotes. Their exclusive focus on the cybersecurity vertical means their entire methodology, content, and data infrastructure are built around security buyer behavior, compliance frameworks, and technical evaluation cycles — a significant differentiator from generalist B2B agencies that treat CISOs like any other buyer persona.
- Exclusive focus on infosec/cybersecurity vendors for nearly 20 years
- Proprietary intent data covering ~1 million cybersecurity professionals globally
- Demand generation and account-based programs built for security buying cycles
- Recognized as cybersecurity-exclusive by multiple independent 2026 rankings
- Technical credibility and thought leadership as core strength (per Rubicon Agency)
- Cyber-native strategy and buyer data focus (per Martal Group comparison)
- Full-service advisory model (strategy + execution) not just lead delivery
Strengths
- True cybersecurity-exclusive focus — no generalist dilution
- Proprietary intent data specific to security professionals (1M+ coverage claimed)
- Two decades of sector-specific experience informs messaging and targeting
- Recognized by multiple independent 2026 agency rankings as a top specialist
- Advisory + execution model addresses strategy gaps, not just lead volume
Trade-offs
- No public pricing — requires custom engagement scoping
- No published per-lead or per-meeting pricing model — likely retainer-based
- New York-based only; no multi-region team mentioned
- Less transparent about specific lead delivery mechanics (CPL, CPA, exclusivity)
07
Sopro
Best for: Cybersecurity vendors wanting a provider with named, checkable security clients and multichannel outreach capability across US and UK markets · Contact for pricing
Sopro runs multichannel lead generation combining email, LinkedIn, and phone outreach on verified contact data, with a dedicated cybersecurity page that names actual clients including ITC, Reliance Cyber, TrustLayer, and Qualys. According to their website and third-party verification (Danish Lead Co's 2026 ranking), the firm is headquartered in Miami Beach, Florida, with an additional office in Brighton, UK. Sopro positions itself as a provider with a "proven, named track record of security clients across multichannel outreach" rather than a general "we serve tech" claim. Danish Lead Co's comparison table lists Sopro as best for "Vendors wanting a proven, named track record of security clients across multichannel outreach" with a starting price of "Contact for pricing." Their multichannel approach across email, LinkedIn, and phone aligns with cybersecurity buyer expectations for multi-touch engagement across channels. The named client references (ITC, Reliance Cyber, TrustLayer, Qualys) provide verifiable proof of cybersecurity sector experience that many generalist agencies lack. However, Sopro does not publish pricing, lead exclusivity terms, or specific cybersecurity qualification frameworks on their public-facing materials reviewed in the research.
- Multichannel lead generation: email, LinkedIn, and phone on verified contact data
- Dedicated cybersecurity page with named clients (ITC, Reliance Cyber, TrustLayer, Qualys)
- Dual headquarters: Miami Beach, FL (US) and Brighton, UK
- Verified track record with security clients per independent 2026 ranking (Danish Lead Co)
- Multichannel outreach aligns with cybersecurity buyer multi-touch expectations
Strengths
- Named cybersecurity clients provide verifiable sector proof
- US and UK presence supports transatlantic campaigns
- Multichannel approach (email, LinkedIn, phone) covers key security buyer touchpoints
- Dedicated cybersecurity page signals vertical commitment
- Recognized in independent 2026 ranking for proven security track record
Trade-offs
- No public pricing or pricing model transparency
- No published lead exclusivity, replacement terms, or qualification criteria
- Limited public detail on cybersecurity-specific qualification frameworks
- No case study metrics (MQLs, SQLs, meetings) published in research data
Choosing the right pay-per-lead partner for your cybersecurity firm comes down to matching the model to your sales motion. If you need exclusive, consent-recorded leads followed up in minutes — including reactivating the opted-in database you already paid for — GrowthPros's leads-as-a-product model is purpose-built for that. If you prefer a pay-per-meeting model with deep cybersecurity vertical expertise and custom landing pages, Pearl Lemon Leads delivers booked appointments with pre-vetted decision-makers. For AI-augmented outbound at scale with experienced onshore reps, Martal Group combines intent data with a 200+ person sales team. Enterprise firms needing multi-region campaigns with published pricing should evaluate Callbox's Campaign Pod model. Cybersecurity SaaS vendors wanting a fully managed outbound system tuned to CISO buying behavior at a lower entry point will find Danish Lead Co's $3K/month starting price compelling. For exclusive cybersecurity focus with proprietary security-buyer intent data, CyberTheory's two-decade specialization stands out. And if named client references are your primary trust signal, Sopro's listed clients (ITC, Reliance Cyber, TrustLayer, Qualys) offer verifiable proof. Whichever you choose, vet them on lead exclusivity, consent compliance, speed-to-lead, and whether they truly understand the CISO buying cycle — or just claim to. Ready to see what exclusive leads followed up in five minutes look like for your pipeline? Book a 15-minute qualification call with GrowthPros — no commitment, honest about fit, and you'll walk away with real numbers for your niche.
This guide is general information, not legal or financial advice. Rankings reflect stated criteria at time of writing.
Questions
Asked and answered plainly.
GrowthPros sells leads as a product, not marketing services. Every lead is exclusive or capped-shared (max 2 buyers), qualified, time-stamped, and carries a complete consent record (disclosure text, timestamp, IP, named contacting party). AI follow-up via voice, SMS, and email happens within 5 minutes, 24/7 — included with every lead, not an upsell. They also reactivate your own dormant opted-in CRM lists (typically 8–15% re-engagement) at 60–80% below new lead cost. Leads integrate natively into Salesforce, HubSpot, ServiceTitan, and most CRMs, or they provision a CRM same-day. No self-serve checkout — a 15-minute qualification call sets real numbers for your niche.
Pay-per-lead models vary: some charge per qualified lead (CPL), others per booked meeting (CPA), and some use hybrid retainer + performance models. GrowthPros uses directional cost-per-lead bands (e.g., finance/insurance $15–$50, commercial/mortgage $80–$300) with reactivation at 60–80% below new-lead cost. Callbox publishes Campaign Pod pricing at $16,000–$32,000/month. Danish Lead Co starts at $3,000/month for a fully managed outbound system. Pearl Lemon Leads, Martal Group, CyberTheory, and Sopro require custom quotes. Always clarify what "qualified" means, replacement terms for bad leads, and exclusivity before signing.
Cybersecurity buyers (CISOs, CIOs, IT Directors) are highly skeptical and receive dozens of vendor pitches weekly. If your lead is shared with 3–5 competitors — common in shared marketplaces — you're racing to build trust with the same prospect who's already talking to rivals. GrowthPros caps shared leads at a hard maximum of two buyers and offers exclusive leads that go to only you. Pearl Lemon Leads and Martal Group also emphasize qualified, non-shared meetings. Always ask: how many other buyers receive this same lead?
At minimum: GDPR, CCPA, CAN-SPAM, and FCC one-to-one consent rules. GrowthPros builds FCC one-to-one consent in from day one, DNC-scrubs all lists before outbound contact, honors opt-outs immediately and permanently across SMS, voice, and email, and only reactivates pre-existing opted-in relationships — never cold lists. Every lead carries a consent record. Pearl Lemon Leads mentions GDPR/CCPA/HIPAA compliance in outreach. Callbox emphasizes data privacy compliance in workflows. Verify the provider's consent documentation, DNC process, and opt-out handling before engaging.
Research shows contacting a lead within 5 minutes makes contact roughly 100x more likely than at 30 minutes, and ~78% of buyers choose whoever responds first. GrowthPros guarantees AI voice, SMS, and email follow-up within 5 minutes, 24/7, included with every lead. Most agencies hand off leads to your CRM for your team to follow up — which often takes hours or days. If speed-to-lead matters, confirm the provider's follow-up SLA and whether it's automated or manual.
Yes. GrowthPros specializes in dead lead reactivation: upload your opted-in dormant CRM list, and their multi-channel AI sequence (SMS first, voice follow-up, email backup) re-engages and qualifies contacts, pushing them back into your CRM. Typically 8–15% of a dormant database re-engages, at 60–80% below new-lead cost. Pearl Lemon Leads also offers lead nurturing and re-engagement funnels reporting up to 30% more booked calls from the same list over 6 weeks. This is often the highest-ROI pay-per-lead investment because you've already paid for the initial acquisition.
Ask: (1) What is your lead exclusivity policy — max buyers per lead? (2) What consent records come with each lead? (3) How do you DNC-scrub and handle opt-outs? (4) What is your speed-to-lead SLA for follow-up? (5) Do you offer dead lead reactivation for my existing CRM? (6) What are your replacement terms for unqualified leads? (7) Can you share named cybersecurity client references or case metrics? (8) What is the true all-in cost per qualified meeting (including any retainers)? (9) How do you qualify for CISO/IT Director access vs. lower-level contacts? (10) What CRM integrations are native vs. webhook-only?