Tag Management
7 martech vendors in Tag Management, part of Data, Analytics & Measurement. Each record carries the date we last verified it, so you can see how current it is before you rely on it.
Last verified:
Procurement-readiness profiles — SOC 2, ISO 27001, GDPR and DPA posture, data residency, AI-training policies — are available when you sign in.
Tag management software deploys the tracking pixels and scripts other marketing tools need, from one shared container instead of code scattered across a site. Marketing and web teams use it to launch new tracking without an engineering ticket each time. IT security needs it audited because it controls what outside code runs in every visitor's browser.
Who it is for
- Marketing operations and web teams shortlisting a container to manage tags across a site or app without touching a deploy pipeline for every change.
- IT security reviewers assessing what third-party JavaScript is allowed to run on a page, and how tag-publishing permissions are controlled.
- Legal and privacy teams confirming that tags load consent-appropriately and don't fire before a visitor has made a choice.
What your No-Committee will ask
- IT security
- Is the tag container protected by role-based publishing permissions and MFA, so a compromised account can't push malicious code to every page at once? Publishing-permission and MFA support are each recorded as an evidenced claim, marked verified, self-attested, or not found.
- Data governance
- Which third-party tags are pre-approved in the container's template library, and is that list published anywhere a customer can review it? Template-library disclosure is pulled from the vendor's own documentation, with a source link on the claim.
- Privacy / consent
- Does the platform natively hold tags until a visitor's consent choice is recorded, rather than firing everything on page load? Consent-gating support is tracked as a single evidenced claim, separate from a general privacy-policy mention.
- AI governance
- If the platform recommends or auto-generates tag configurations using AI, is that disclosed, and does it train on the site data flowing through the container? AI-feature disclosure and the training-data question are captured together, not folded into a general feature list.
- Architecture
- Is there a version history and rollback for container changes, so a bad tag push can be undone without a new deploy? Version-history support is recorded wherever the vendor documents it publicly.
How we verify
Every claim above comes from the vendor's own documentation — trust center, privacy policy, or public help pages — never inferred from what a tag container is capable of in general. The methodology page walks through what verified, self-attested, and not-found each actually require as evidence.
Frequently asked questions
How is tag management different from a customer data platform?
Tag management controls which third-party scripts run on a page and when they fire. A customer data platform focuses on unifying the visitor and customer data those tags, and other sources, collect into one profile. Many teams run both — the container delivers the data, the CDP organizes it.
Do tag management vendors typically publish SOC 2 or ISO 27001 certification?
Larger, enterprise-focused tag management platforms usually publish a SOC 2 report, since the container sits in a security-sensitive position on every page. Smaller or free-tier tools more often rely on a general security page without independent certification, which our audits mark as self-attested rather than verified.
Is pricing usually public for tag management platforms?
Entry-level and free tiers are common and typically listed with clear limits on tag or container count. Enterprise tiers with server-side tagging, advanced governance controls, or dedicated support are more often quote-only, which we note rather than estimate from a published starting price.
What should I check beyond the tag library before shortlisting a platform?
Confirm how publishing permissions are controlled, whether tags can be held until consent is recorded, and whether there's a rollback path if a bad configuration goes live. Those checks catch the incidents a review board hears about after the fact, not before one happens.