Refolk
PlaybookSales and go-to-market

Sourcing a Competitor's Customers Into a Ranked Displacement List

You will build, from public evidence alone, a deduplicated and verification-graded list of accounts running a named competitor's product, ranked by switch-readiness and dated to a likely renewal window.

16 min readLast reviewed September 26, 2026Read as Markdown

Key takeaways

  • A triple-confirmed detection is hard to be wrong about: three independent methods would have to produce the same false positive simultaneously, which is why source_count, not raw hit count, is the spine of a displacement list.
  • Even the best hand-checked scanner ran 86% precision on a 100-technology sample against Wappalyzer's 64%, meaning roughly 1 in 7 detections is still wrong and neither number says anything about what was missed.
  • G2 comparison views reach closed-won in an average of 63 days versus 147 for a product-profile view and 174 for a category signal, so an active head-to-head is worth 2.3 to 2.8 times a passive research hit.
  • In Refolk's index, 78,428 US professionals list Salesforce as a skill against 8,947 in the UK, an 8.77x gap that forces a different evidence threshold per geography.
  • Renewal timing is a documented lever, not a guess: a 90 to 120 day planning band plus a 60 to 120 day rollover notice window turns an inferred install date into a defensible work-by date.
  • New-logo B2B win rates fell to 19% across 655,000 opportunities while expansion and renewal motions reach 40 to 60%, which is why displacement should be tagged and forecast separately from net-new.

This is a sourcing guide, not a messaging guide. The job is narrow and comes before every displacement email ever written: find which companies actually run a named competitor's product, prove it from public evidence, strip the false positives, collapse the duplicates, and rank what remains by how ready each account is to switch and when its window opens. It is for founders selling their own product, account executives, SDR leads, and partnerships teams who are tired of guides that start after the list already exists.

Most published displacement advice spends its ink on switching-cost objections and cold-email templates. It assumes the list. That assumption is the hard part. A displacement list built on single-vector detections and duplicated subsidiaries will send your best reps to the wrong accounts at the wrong time. This guide treats the list as a sourcing problem with real evidence-grading, deduplication, and timing steps, and hands you a ranked, dated artifact at the end.

What public evidence proves that a company runs the incumbent

A company's use of a competitor's product leaks through a consistent set of public vectors, and each one proves something different. Some prove client-side presence outright; others only suggest usage and need corroboration.

The vectors fall into two families. Crawl-based methods read a company's website and detect front-end code, so a script tag or a fingerprint on the marketing site is direct evidence the tool loads in a browser. Job-posting and public-web methods read hiring signals and infer the backend and internal tools a crawler can never see. The two families cover different parts of the stack, which is why a serious list draws from both.

VectorWhat it provesHow it lies
Script tag / HTTP fingerprintClient-side presence, browser-loadablePoint-in-time; may be stale after migration
DNS record / tenant subdomainProvisioned account, often deep useCan persist after a tool is abandoned
Job posting mentioning the toolSuggests use or planned adoptionAspirational, client work, or migration in progress
Marketplace / logo wallNamed customer relationshipCan be old, or a light pilot
Review-site reviewerNamed user account, often with sentimentIndividual, not always current employer

Adoption depth matters as much as presence. A tool that appears only on the marketing site signals light use; a tool that appears across internal subdomains and APIs signals deep integration. The second is a far better displacement target, because deep integration means the incumbent is load-bearing and the switch decision reaches budget holders. When you record a hit, record where it appeared, not just that it appeared.

The important distinction to carry through the whole exercise: HTTP, DNS, and script-tag fingerprints prove client-side presence; job mentions only suggest it. A required skill in a posting can reflect a live deployment, a planned adoption, a migration in progress, client work rather than internal use, or simply an aspirational requirement. Treat the two families accordingly.

Evidence depth, outermost first

  1. Marketing site
    A script tag or logo proves the tool loads, but says nothing about internal depth
  2. Public hiring
    Job postings suggest the tool matters enough to staff for
  3. Internal subdomains and APIs
    DNS and tenant patterns prove a provisioned, integrated account
  4. Reviewer sentiment
    A named employee describing the tool in production is the richest signal
The deeper the layer a tool appears in, the stronger the proof of real internal use.

Why one detection is never enough

A single fingerprint is a heuristic, not proof. Detection results are point-in-time heuristic detections, not confirmation that a technology is present or absent, and even the best scanners are wrong often enough to matter.

The published precision numbers set the ceiling. In one hand-check of a 100-technology sample, 86% of one scanner's detections were verified genuinely present against 64% of Wappalyzer's. Read that carefully: this is precision, meaning it counts false positives and says nothing about what either tool missed. So even the stronger scanner leaves roughly one in seven detections wrong, and both are silent on coverage. A fingerprint-only list both over-includes and under-includes.

86%
Precision of the stronger scanner on a 100-technology hand-check
Against 64% for Wappalyzer on the same sample; a precision measure only, silent on what either tool missed.

This is why the spine of the whole method is source count, not raw hit count. A detection confirmed by a script tag, a DNS record, and a job posting carries far more weight than one backed by a single crawl, because three independent methods would have to produce the same false positive simultaneously. Grade every account by how many independent vectors agree, and rank on that grade before anything else.

Job mentions are the weakest single vector and deserve the most suspicion. One provider builds detections from five independent sources - job descriptions, script tags, DNS records, IP ranges, and cookies - plus a flag for tools that sit behind a firewall. That five-source design exists precisely because no one source is trustworthy alone.

The install-base signal is real but market-skewed

Skill-listing density is a cheap, public proxy for how widely a tool is deployed, but it varies so sharply by geography that a single evidence threshold will over-target one market. Use it to calibrate your bar, not to build the list.

In Refolk's index of professional profiles, 78,428 US professionals list Salesforce as a skill and 65,878 list HubSpot, while 8,947 UK professionals list Salesforce. The US-to-UK Salesforce gap is 8.77x. That gap is not a claim about market share; it is a warning about your evidence pipeline. If you set the same job-mention or profile-count threshold across both markets, you will surface a deep US list and a thin UK one for the same competitor, and conclude wrongly that the incumbent barely exists in the UK.

Market / skillProfessionals listing skillDerived index (US Salesforce = 100)
US - Salesforce78,428100
US - HubSpot65,87884
UK - Salesforce8,94711

Counts come from Refolk's index; the index column is derived. The practical rule: set your evidence threshold per geography. A UK account that clears a two-vector bar is proportionally rarer, and often more qualified, than a US account that clears the same bar in a much denser pool.

8.77x
US vs UK Salesforce skill-listing density
In Refolk's index; the same competitor needs a different evidence threshold per geography or you over-target the US.

Build the list: the procedure

Run these eight stages in order. The estimates assume one analyst with one RevOps handoff, and total roughly a working week for a single competitor. Do not reorder the grading and dedup steps; ranking dirty data produces a confident wrong list.

From named competitor to ranked displacement list

  1. Define the target and evidence bar
    Name the incumbent and list its unique fingerprints (script tags, DNS and subdomain patterns, marketplace listing, case-study URLs). Write a detection spec per vector so a second analyst could apply it. Half a day.
  2. Seed the raw list from multiple vectors
    Pull fingerprint hits, job-posting mentions, marketplace and logo-wall entries, community members, and review-site reviewers into one superset. Expect thousands of rows. One to two days.
  3. Grade each detection by source count
    Tag each account Confirmed (3+ vectors), Probable (2), or Suspected (1). Keep Confirmed and Probable, quarantine Suspected. One day.
  4. Deduplicate and resolve hierarchy
    Collapse by domain plus fuzzy name, fold subsidiaries and aliases into one parent, reassign child records, and retain every trading name as a known alias. One day.
  5. Firmographic filter to ICP
    Narrow by size, geography, and the segments where your product wins displacement deals, treating firmographics as weighted evidence rather than exact matches. Half a day.
  6. Layer switch-readiness signals and score
    Add dissatisfaction (review mining), active evaluation (comparison views), growth and hiring, and leadership change; produce a numeric score per account. One to two days.
  7. Time each account to a window
    Infer install or signup date, map notice windows, flag review clusters and price-hike events, and set an outreach date 90 to 120 days before likely renewal. One day.
  8. Rank and hand off
    Sort by evidence grade times switch-readiness times window proximity and hand the SDR lead a ranked, dated, deduplicated list. Half a day.

The one ordering choice worth naming: some teams score dissatisfaction first, then time the window; renewal-window plays time first, then score. Either works. What does not work is skipping grading or dedup because the raw list looks impressive. A raw superset in the thousands is expected and mostly noise.

How a raw superset narrows to a workable list

  1. Raw superset
    thousands

    All vectors combined, heavy duplication

  2. Graded (2+ vectors)
    hundreds

    Single-vector rows quarantined

  3. Deduplicated
    fewer

    Subsidiaries and aliases folded to one parent

  4. ICP-filtered
    workable subset

    Only segments where you win displacement

Each stage removes a specific class of noise, so the surviving accounts are both provable and rankable.

Deduplicate companies the way companies actually behave

Account deduplication breaks when you match company records the way you match people, because legal entities, subsidiaries, franchises, and firmographic fields behave nothing like a name and a date of birth. This is where inflated lists and inflated addressable markets come from.

The mechanics are specific. Cross-object deduplication identifies records as the same company through domain matching and fuzzy name algorithms, then merges into a single master record, reassigns all child records to the surviving account, and establishes the corporate hierarchy with subsidiaries. Two rules keep it honest. First, an entity should retain every name it has ever traded under as a known alias of itself, so a record matched under an old legal name still resolves to the same account. Second, use firmographic data as weighted, probabilistic supporting evidence in a confidence score, never as a required exact match. Match by domain and fuzzy name; let firmographics adjust confidence, not gate it.

Finding the person behind a deduplicated account - the actual buyer at the surviving parent entity - is its own step, and it is where a plain-English search over the professional graph saves the most time.

Refolk turns the abstract "companies running the incumbent" into named people at named employers, which is exactly the join you need after dedup: an account with a graded detection and a human to reach.

Rank by switch-readiness, then time the window

Two accounts can both run the incumbent and be worlds apart in how ready they are to move. Rank by active evaluation and demonstrated dissatisfaction first, then treat news events as probability-raisers, and finally time each account to its renewal.

Active evaluation is the strongest signal, and the timing data proves it. Comparison views convert far faster than passive research, because a head-to-head view means the shortlist is already forming.

Evidence vectorDays to closed-wonRelative speed
G2 comparison view63fastest
G2 product-profile view1472.3x slower
G2 category signal1742.8x slower

The multiples are derived from the published day counts. A comparison view is worth 2.3 to 2.8 times a passive research hit, so weight it accordingly. Below active evaluation, rank demonstrated dissatisfaction: phrases like "we switched from," "replaced," or "moved away from" indicate a company that has already changed tools once, meaning low switching friction and more openness to doing it again. A dissatisfaction hit from a serial switcher should outrank an equally negative hit from a long-tenured incumbent user.

A comparison view means the shortlist is forming; a category view might just be a student.

News events sit below both. A new VP of Revenue, a funding round, or an office expansion does not confirm a switch is coming, but each one raises the probability that a stale vendor relationship gets a second look. Score them as probability-raisers, not proof.

Then time the account. Renewal windows are a documented lever, not a guess. Contracts encode a notice window, often 30, 60, or 90 days before renewal, and auto-rollover notice windows commonly run 60 to 120 days before expiry - miss that window and the account locks into another 12-month term. Practitioner planning bands scale with deal size:

  • Enterprise contracts above $100K: plan around 180 days out.
  • Mid-market accounts ($25K to $100K): roughly 90-day lead times.
  • SMB and self-serve: 30 to 60 day cycles.

The default construction: take the inferred install or signup date, add twelve months, subtract 90 to 120 days, and set that as the account's work-by date. Corroborate with review clusters - a cluster of negative reviews in a 60-day window often correlates with a pricing change, a deprecation, or a support drop, and reaching out within 90 days catches the frustration while it is fresh.

Deciding who to work first

High switch-readinessLow switch-readiness
Nurture quietly
Low readiness, far window; hold and re-check next quarter
Watch closely
Low readiness, near window; a renewal alone can create an opening
Research now
High readiness, far window; build the account case so you are ready
Call this week
High readiness, near window; top of the ranked list
Window far offWindow opening now
Rank on the interaction of switch-readiness and window proximity, not either alone.

How this goes wrong

Most displacement lists fail in predictable ways, and every failure has a specific check. Treat this section as the QA pass before you hand anything to a rep.

  • Single-vector "confirmed" usage. A marketplace listing or one job mention gets treated as production use. Check: require source count of two or more; remember a job skill can be aspirational or client work.
  • Stale fingerprint. A scanner reports a tool the company already migrated off. Check: re-scan and confirm recency, because fingerprints are point-in-time heuristics.
  • Agency or consultancy false positive. A firm lists the tool because it implements it for clients, not internally. Check: does the tool appear on internal subdomains, or only on the marketing and services pages?
  • Subsidiary double-count. One parent shows up as three companies, inflating the list and the TAM. Check: resolve domain plus fuzzy name plus alias history before ranking.
  • Research mistaken for intent. A category or profile view may be an analyst, student, or consultant. Check: treat passive research as a prompt for account research, not proof of a deal.
  • Window guessing. An inferred renewal date is wrong and outreach lands after lock-in. Check: corroborate the install date with review clusters or news, and default to the 90 to 120 day band.
  • Precision mistaken for coverage. A high precision score counts false positives but says nothing about misses. Check: never treat a precision figure as a completeness score; corroboration is non-optional.
  • Displacement math over-trusted. The 3x conversion and 35% win-rate uplift are one vendor's unaudited claims. Check: tag deal type and report displacement separately.

That last point deserves its own numbers. What is well established is the context, not the uplift. New-logo B2B win rates fell to 19% across 655,000 opportunities, enterprise new-business typically runs 15 to 30%, and expansion and renewal motions reach 40 to 60% because of incumbent advantage.

MotionWin-rate rangeSource
New-logo (blended)19%Ebsta/Pavilion
Enterprise new-business15-30%UserIntuition
Expansion/renewal40-60%UserIntuition

Displacement generally runs lower than greenfield because of switching costs and incumbent relationships, so it behaves like neither pure net-new nor pure expansion. That is the whole reason to forecast it on its own line.

Before you call the list done

Run this checklist before the list leaves your hands. It catches the failures above in the order they usually appear.

Displacement list QA

  • Every kept account carries a source-count grade, and single-vector rows are quarantined, not shipped.
  • Fingerprint detections have been re-scanned for recency, not carried over from an old crawl.
  • Agency and consultancy false positives are removed by checking internal subdomains versus services pages.
  • Records are deduplicated by domain plus fuzzy name plus alias history, with subsidiaries folded to one parent.
  • Firmographics were used as weighted confidence, not as a hard exact-match filter.
  • Switch-readiness scores weight active evaluation and past-switching above news events.
  • Every account carries a work-by date built from an inferred install date minus a 90 to 120 day band.
  • Deal type is tagged so displacement is forecast separately from net-new.

Keeping the list current

A displacement list decays the moment you build it, because every input is time-sensitive: fingerprints go stale after migrations, renewal windows pass, and dissatisfaction fades once a vendor fixes the problem. Re-scan fingerprints on a schedule tied to your outreach cadence, and re-check any account you did not reach before its window closed.

The two inputs that move fastest are comparison-view signals and leadership changes, so wire those to alert rather than to a quarterly rebuild. Re-run your seed queries for new job postings and new reviewers monthly, regrade anything that crosses from Suspected to Probable, and push newly two-vector accounts into the ranking. The method does not change; only the rows do. A list you rebuild the grading and timing on every month stays a working document instead of a snapshot that was right once.

Questions practitioners ask

How do I find companies using a competitor's product without buying a technographics tool?

Combine free public vectors before you pay for anything. Front-end fingerprints (script tags, DNS records, tenant subdomains) prove client-side presence; job postings that mention the tool suggest internal use; marketplace logo walls, community memberships, review-site reviewers, and public case studies each add a corroborating vector. The value is not any single source but agreement across them: keep accounts where two or more independent methods point at the same company.

How many detection sources should agree before I call an account confirmed?

Require at least two, and reserve Confirmed for three or more. The math is the point: three independent methods would have to produce the same false positive simultaneously for a triple-confirmed account to be wrong. A single-vector hit, such as one job mention or one marketplace listing, is Suspected only. Even the best hand-checked scanner ran 86% precision, so roughly one in seven single-vector detections is wrong.

How do I time displacement outreach to a contract renewal I cannot see?

Infer the install or signup date, add roughly twelve months, and subtract a planning band of 90 to 120 days to get a defensible work-by date. Auto-rollover notice windows commonly fall 60 to 120 days before expiry, so landing inside that band catches the account before it re-locks. Corroborate the inferred date with review clusters or news events; if you cannot, default to the 90 to 120 day band.

What is the strongest public signal that a company is actively evaluating a switch?

A head-to-head comparison view on a review site. In one published benchmark, comparison signals reached closed-won in an average of 63 days versus 147 for a product-profile view and 174 for a category signal. A comparison view means the shortlist is forming. Rank it above passive category research, which can come from analysts, students, or consultants rather than buyers.

Why deduplicate before ranking instead of after?

Because subsidiaries, franchises, and legal-entity variants inflate both your list and your addressable market, and they distort ranking if you score duplicates as separate accounts. Collapse by domain plus fuzzy name plus alias history first, fold children into one parent, then rank the canonical rows. Company dedup is not person dedup: use firmographics as weighted supporting evidence in a confidence score, never as a required exact match.

Should I forecast displacement deals alongside net-new pipeline?

No. Tag deal type and report them separately. The widely cited 3x conversion and 35% win-rate uplift for displacement is a single vendor's claim and is not independently audited, so blending it into a net-new forecast distorts the number. What is well established is that new-logo win rates fell to 19% while expansion and renewal reach 40 to 60%, so displacement behaves differently enough to warrant its own line.

Try it on the search you came here for

Stop building boolean strings. Just describe the person.

Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.

  1. 01Describe them

    One plain sentence. Role, city, stack, stage, whatever matters to you.

  2. 02I read the web live

    GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.

  3. 03You read the shortlist

    Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.

  • No boolean, no filters, no seat to buy. One box.
  • Read at search time, so a profile updated yesterday counts today.
  • Every step visible as it runs, every name with its reason.

500 free credits on sign-up. No card, no demo call. See real searches.

Read next