Industry and headcount tell you what a company is. The software it runs tells you what it does, what it has already decided to spend money on, and quite often what it is about to replace.
That is a far better filter for most B2B offers, and almost all of it is sitting in public view. This is how to build a prospect list from it.
Why a tech stack beats a firmographic filter
A filter on industry and headcount returns companies that look like your customers. A filter on technology returns companies that have behaved like your customers.
Consider two lists of five hundred companies. The first is mid sized software firms in Britain. The second is mid sized software firms in Britain running a specific help desk product you integrate with.
The second list is better in three ways. Everyone on it has already bought software in your category, so the budget question is settled. Everyone on it has a concrete reason to care about you, because you plug into a thing they use daily. And the first line writes itself, because you know something true and particular about each one.
The four things a stack actually tells you
They have budget in your category
Somebody who runs a paid analytics product has already argued internally for analytics spend and won. That argument is the hardest part of any sale, and it has already happened.
They have a shape you can integrate with
If you build on a specific commerce platform or CRM, the companies running it are the only ones who can buy without a migration. This turns a broad market into a list you can actually work.
They are sometimes unhappy
A company running an incumbent you replace is a switching candidate. They are not all unhappy, but the unhappy ones are all in there, and none of them are in a list built on headcount alone.
They are sometimes mid change
A site carrying two competing analytics scripts is usually a migration in progress. A company that just added a first chat widget has just decided that conversation matters. These are moments, and moments are when people buy.
Where the data is
Technology data is unusually good for prospecting because most of it is served to the browser. It is not scraped from behind a login and it is not inferred.
The front end, which is the richest source
Analytics tags, chat widgets, tag managers, consent tools, payment providers, ecommerce platform, CDN, hosting and front end framework are all visible in the page a company serves to anybody who visits.
The mail exchanger, which tells you the workplace
A domain publishes where its mail goes. That tells you Google or Microsoft, and that single fact often decides whether a company is a fit for an integration.
Job adverts, which describe the back end
The half of the stack you cannot see from outside gets described in detail in engineering job adverts. A company hiring for a specific data warehouse is telling you what it runs, in writing, on its own careers page.
App marketplaces and integration directories
Most major platforms publish customer or partner listings. Those pages are a public list of companies running that platform, which is exactly the list you were trying to build.
Building the list, step by step
Start from the technology, not the firmographics
Work out which one piece of software would most change your pitch if you knew it. Usually it is the incumbent you replace or the platform you integrate with. That single choice does more for list quality than any amount of filtering afterwards.
Get a population of companies first
Detection runs on rows, so you need rows. Pull them from a directory, a marketplace listing, an event exhibitor list, a review site category or your own database of accounts you never worked properly.
Get a website on every row before anything else
Every detection step keys off the domain. Rows without one return nothing, and a row that returns nothing looks exactly like a row that failed a filter. Fill the website column first and check it resolves.
Run detection, then filter, then enrich
This order is the whole economics of the exercise. Detection and filtering cost little. Finding a named person and verifying their address is the expensive part.
A team that finds contacts for four thousand companies and then filters to the six hundred running the right software has paid roughly seven times more than a team that filtered first.
Split the list by what you found
The output is not one list. Companies running your incumbent get a switching message. Companies running your integration partner get a compatibility message. Companies running two competing tools get the migration message. Those are three campaigns and they should never be merged into one.
Reading the combinations
A single tool tells you something. Two tools together often tell you more.
Two analytics platforms at once usually means a migration underway. An enterprise CRM with no marketing automation means a gap somebody has probably noticed. A heavyweight commerce platform on a very small site means someone over bought and may be looking to simplify. A consent tool appearing for the first time means a compliance push, which means budget.
None of these are certainties. They are reasons to write a specific opening line rather than a generic one, which is all a signal ever needs to be.
A worked example
Say you sell a reporting layer that plugs into a specific analytics platform. Your firmographic list would be every ecommerce company above twenty staff, which is tens of thousands of rows and almost no information.
Instead you start with a population. Two thousand ecommerce companies pulled from a marketplace listing and two industry directories. You fill the website column and drop the rows where the domain does not resolve, which is usually a few percent and costs nothing to remove.
Then you detect. Four hundred and ten are running the platform you plug into. Ninety of those are also running a competing reporting tool, which makes them a different conversation. Sixty are running two analytics platforms at once, which means they are migrating and are the most time sensitive group on the list.
You now have three segments and you have not yet spent anything on contact data. Only at this point do you find people and verify addresses, on four hundred and ten rows rather than two thousand.
The saving is real, but the segmentation matters more. The migration group gets contacted this month because the window is open now. The competing tool group gets a comparison. The rest get the straightforward integration pitch. One population, three messages, each of them true.
Where it goes wrong
Detection sees the marketing site, not the product
A company can run one stack on its public website and something entirely different on the application its customers log into. For marketing tooling this does not matter. For anything touching the product, treat front end detection as a hint and confirm from job adverts.
A tag can outlive the contract
Scripts get left behind when a subscription ends. A tag is evidence that a company installed something, not proof it is paying for it today. If your pitch depends on them being a current customer, check a sample by hand before you send.
You mistake ubiquity for a signal
Some tools are on almost every website. Filtering for one of those returns most of the internet and tells you nothing. A useful technology filter is one that a meaningful minority of companies have, not a majority.
You lead with the fact you detected
Opening with a line about having noticed what software somebody runs reads as surveillance rather than research. The detection is for you, to decide who to write to and what to say. It is not the opening line.
What a finished row looks like
A row that is ready to work carries the company and its website, the technologies found, the one that triggered the segment, a named person with a verified address, and a score against your ideal customer profile.
The technology column is doing two jobs there. It decides whether the row survives at all, and it decides which of your three campaigns the row belongs in. Both decisions happen before you have spent anything on contact data.
A note on refreshing
Stacks change, which is the point, and it means a technology list is worth re running rather than building once. A quarterly re run on the same population tells you who added something, who dropped something, and who is mid migration right now.
The change is the signal. A company that has run the same tool for four years is a weaker prospect than one that switched last month, even though a single snapshot shows them identically.
Frequently Asked Questions
How accurate is technology detection?
For anything served to the browser, very accurate, because it is read directly from the page rather than inferred. Accuracy drops for back end systems, which are not visible from outside and have to be confirmed from job adverts or public engineering material.
Is this legal?
Reading what a public website serves to any visitor is ordinary use of published information. The care needed is on the contact data side rather than the technology side, where the usual rules about lawful basis and clear opt out apply.
Can I find companies that stopped using a competitor?
Not from one snapshot, which only shows the present. You get it by running detection on the same population repeatedly and comparing. The company that had the tag in March and does not have it in June is the interesting one.
How many technologies should I filter on?
One to start with, the one that most changes your pitch. Filtering on several at once produces a very small list that feels precise and is usually too narrow to be worth the campaign. Add the second only when the first produces more rows than you can work.
Does this work outside software?
Yes, though the sources shift. For physical industries the equivalent signals are certifications, equipment mentioned in job adverts, and membership of trade bodies. The principle holds: what a company has already invested in predicts what it will buy next.
Buy the list on evidence, not on resemblance
Most prospect lists are built on resemblance. These companies look like the ones we sold to, so perhaps they will buy. It is a reasonable starting point and it is also why so much outbound reads as though it could have been sent to anybody.
A technology filter is built on evidence instead. This company installed a thing, which means somebody there made a decision, spent money and now lives with the consequences. That is a much firmer place to start a conversation, and it is published, checkable and free to read.