Security posture.
Written for the security reviewer. Where client data lives, how sub-processors are handled, and how we complete your questionnaire.
Where does client data live?
Client CRM data lives in the client's own HubSpot portal. Our products install into that portal and operate under its authentication and permission model. We do not maintain a separate database of client CRM records.
Access during service engagements runs through named user accounts in the client's portal, granted and revocable by the client. When an engagement ends, the client removes the access. There is no residual copy to request deletion of, because the architecture never created one.
How are sub-processors handled?
Sub-processor additions and changes are announced 14 days in advance to DPA holders.
Statements on this page are updated when the underlying facts change, with the reviewed date below as the record.
How do we complete your security questionnaire?
We complete questionnaires directly rather than pointing reviewers at a portal. Standing answers for common frameworks exist and shorten the turnaround.
For questions this page and the standing documents don't cover, the contact page reaches the people who can answer in writing.

