Every competitive intelligence team has a story about the line. Somebody found a competitor's internal deck sitting in a public S3 bucket. Somebody's friend-of-a-friend works there and offered to forward the roadmap. Somebody made a fake email address and booked a demo under a prospect's name. Most of these stories end the same way: "we decided not to use it." A few of them don't end at all — they turn into a lawsuit, a headline, or a career.
The strange part is that the line is almost never where people think it is. The stuff that feels legal is sometimes the riskiest, and the stuff that feels shady is often completely fine. This is a short field guide to where the line actually sits — so you can collect aggressively and still sleep at night.
Most "Gray Area" Is Just Laziness
Half the time someone calls a CI tactic a "gray area," what they mean is "I don't want to do the boring legal version." There is a shocking amount of competitive intelligence sitting out in the open, fully legal, that teams skip because it takes work.
Job postings. Press releases. Pricing pages. Review sites. Conference talks. Patent filings. Earnings transcripts. Marketing emails. Changelogs. Glassdoor, G2, Capterra. Webinar recordings. Even the language in a competitor's terms of service. All public. All fair game. You can read it, log it, and build strategy on it, and no lawyer will look up from their coffee.
The teams that drift into the actual gray area are usually trying to shortcut the collection step. They want the roadmap now, not the roadmap inferred from three months of hiring signals. So they stretch. The shortcut is where the trouble lives.
The Legal Line, Actually
Here's the version that holds up, then the caveats. In the US, the core rules are the Economic Espionage Act, the Defend Trade Secrets Act, and a stack of state law — plus whatever your employment agreements and NDAs say. The short version:
- Public information is fair game. If it's published, posted, or otherwise out in the world, collecting it is legal.
- Trade secrets are off-limits. The definition is specific: information that has economic value from not being known, and that the owner made reasonable efforts to keep secret. A public pricing page isn't a trade secret. A customer list locked behind a password-protected portal is.
- You can't acquire trade secrets by "improper means." Improper means = theft, bribery, misrepresentation, breach of a duty of confidentiality, or espionage.
- Hiring someone away is fine; hiring their secrets isn't. A new hire can't bring a competitor's confidential material with them, and you can't put them in a role where disclosure is inevitable.
The caveats: I'm not your lawyer, this isn't legal advice, and if you're in the EU, handling GDPR data, or answering to a specific regulator, the rules shift. But this framework covers 95% of what a SaaS CI team actually runs into.
What "Improper Means" Actually Covers
The phrase to remember is improper means. It's the hinge the whole thing swings on. If you got the information through improper means — lying, hacking, bribing, breaching a contract — it doesn't matter how valuable the information is or how public it later became. You've crossed the line.
So the test isn't "is this information secret?" It's "how did I get it?" Two people can collect the exact same document — one legally, one not — and the entire difference is in the method.
The Four Ways Teams Get Themselves in Trouble
Not every legal breach looks like a heist movie. Most of them look like an ordinary Tuesday that got away from somebody.
1. Pretexting — Lying About Who You Are
The classic. You create a fake identity — a fake company, a fake title, a fake email — to get a demo, a trial, a quote, or a document a competitor wouldn't hand you if they knew who you were. Sometimes it's a "mystery shop" where you pose as a prospect. Sometimes it's a fake student "doing research," or a fake analyst, or a fake journalist.
This is the one that gets people in real trouble, because misrepresentation is textbook improper means. It also has the worst optics: when it comes out — and it comes out — "we lied to a competitor to get their pricing" doesn't read as sharp CI. It reads as the thing that happened right before the headline.
The legal version is boring and works fine: use your real identity, or actually buy the competitor's product and read the contract you signed. You'd be surprised how much you learn just from being a legitimate customer — and a legitimate customer is exactly who a competitor's pricing structure is designed to reveal.
2. Mining a New Hire's Brain
Hiring someone away from a competitor is legal. Hiring them specifically to spill their former employer's roadmap, customer list, or pricing model is not — and it's a reliable way to get sued under the Defend Trade Secrets Act even if no document ever changes hands.
The trap: you interview a candidate, and the conversation drifts to "so what was their actual win rate against us?" or "walk me through how their pricing model works." Every answer is a liability for both of you. The employee is probably violating an NDA, and you're inducing them to do it.
The fix is clean and boring: screen candidates for skills, not secrets. Tell them explicitly, in writing, not to share confidential information. And if you're the one who left a competitor — you know the drill, and so do they.
3. Buying or Soliciting Stolen Data
This should be obvious, but it happens more than people admit. A data broker offers you a competitor's customer list. A "lead gen" vendor can "get you" a competitor's pricing sheet. An intern finds an unsecured S3 bucket full of a competitor's financials.
Accessing an unsecured bucket is still unauthorized access — finding the door unlocked doesn't make it your house. And buying data you know (or should know) was obtained improperly makes you part of the chain. The broker doesn't absorb the liability; you inherit it.
Stolen data is also just bad data. You can't verify it, you can't cite it, and you can't build strategy on something you have to pretend you don't have. It's a liability you paid for.
4. The Friendly Login
Someone you know — a friend, a former colleague, an ex-coworker who moved to the competitor — offers to "just show you around" their product, or forwards an internal doc "off the record." It feels low-stakes because it's friendly. It isn't.
Accessing a competitor's systems with someone else's credentials is unauthorized access, full stop. And the person handing you the login is the one who signed the NDA — you're helping them violate it. When the competitor finds out, they don't sue your friend's goodwill. They sue you, and the friend gets fired.
The Ethics That Don't Have a Law Attached
Here's where it gets interesting, because the legal line and the ethical line are not the same line. Some things are legal and still a bad idea.
Attending a competitor's webinar under your own name and asking a pointed question in the Q&A? Legal, arguably fine, occasionally useful. Dumping fifty questions designed to bait the presenter into oversharing? Legal — and everyone in the room knows exactly what you're doing, and now your company has a reputation for it.
Scraping a competitor's public pricing page? Legal, standard practice. Scraping it every hour until the site 503s? That's a different conversation — you've moved from research to nuisance, and depending on jurisdiction you might be staring at a CFAA claim for the load alone.
Reading the LinkedIn profiles of every engineer a competitor just hired? Legal and smart. Reaching out to those engineers under false pretenses to pump them for roadmap details? Back to pretexting.
The pattern: legality is about method, ethics is about the relationship you're building — with competitors, with your own team, with the market. You can be fully legal and still be the kind of operator nobody wants to deal with.
Collect on the method, not on the identity you had to invent to collect it. If the tactic only works because someone doesn't know who you are, the tactic is the problem.
A Test You Can Defend
Forget the 47-page ethics policy nobody reads. Here's a three-question test that covers almost everything, and it fits on a sticky note:
- Would I do this the same way if the competitor knew it was me? If your behavior would change the moment your name got attached, that's your answer.
- Would I be comfortable describing this, in detail, to a customer or a reporter? If you'd dodge or soften the description, that's your answer.
- If we get sued tomorrow, can we explain the method and hold the line? If your defense starts with "well, technically...", you've already lost the deposition.
The point of the test isn't to make you paranoid. It's to make the line concrete, so your team doesn't have to guess in the moment. Ambiguity is where people drift. A clear test is what keeps the eager intern from "just checking" a competitor's staging environment.
Build the Line Into the Process
The best ethical safeguard isn't a policy document — it's a workflow that makes the legal path the easy path. When collecting the right way is more work than collecting the wrong way, the wrong way wins by default.
That's most of why this stuff matters when you're building a CI program from scratch. Decide up front what your team will and won't do, write it in one page, and make the collection workflow default to public sources. If someone wants to use a tactic outside the list, that's not a spontaneous decision — it's a sign-off, which is exactly the friction you want.
The practical payoff is that public-source CI scales. You can automate it, document it, and defend it. A metric you can't explain is worthless; a source you can't name is worse. Everything in a RivalSignal report — pricing, hiring, reviews, changelogs — comes from public sources, collected openly, the same way you'd do it if you had the time. No pretexting, no logins, no gray areas. Just the boring, legal, public stuff, turned into something you can actually act on.
There's a deeper point buried in the boredom, though. The teams that do CI ethically aren't giving anything up. They're choosing to compete on reading public signals better than the other side reads them. That's a contest of analysis, not access — and it's the only kind you can win without looking over your shoulder.
Collect everything that's out in the open. Read it harder than your competitor reads it. And when someone floats a shortcut that requires a fake email address or a borrowed login, remember the easiest test of all: if you wouldn't want your name on it, it isn't intelligence. It's just evidence.
Collect the right way, automatically — public sources only, no gray areas.
Get Your Free Sample ReportWe'll monitor your top 2 competitors for a week — pricing structure, hiring, reviews, and changelogs. Delivered as a branded report with strategic analysis. No setup, no commitment.