Q39
Are you PCI DSS compliant? At what level?
HubSpot is NOT PCI DSS certified; multiple sources confirm HubSpot is not a PCI-certified platform, though it can be used in a PCI-compliant manner.
ThirdProof independently checks public intelligence sources to show what your team can verify about HubSpot before HubSpot sends a questionnaire or a security document.
HubSpot's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from HubSpot — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on HubSpot's own trust page.
⚠ HubSpot was not found in the FedRAMP Marketplace. Checked August 2026.
This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 27 returning usable evidence. The HubSpot assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest HubSpot Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 74% of a 133-question vendor security questionnaire — without waiting for HubSpot. The remaining 35 are listed as open, so the follow-up you send is short and specific.
Q39
HubSpot is NOT PCI DSS certified; multiple sources confirm HubSpot is not a PCI-certified platform, though it can be used in a PCI-compliant manner.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
Encryption at rest claim found on trust page (Vendor attested)
+ 93 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing HubSpot for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for HubSpot
HubSpot is a mature, publicly traded SaaS platform with a 21-year operational history and significant market presence in customer relationship management (CRM) and marketing automation.
The vendor demonstrates strong security fundamentals, including a dedicated security leadership team (Chief Information Security Officer Eric Richard and Chief Security Officer Chris McLellan), commitment to a 99.95% uptime SLA, redundant multi-region data centers, and vendor-attested SOC 2 Type II and ISO 27001 certifications. Positive signals include: clean domain reputation with no malware or phishing listings; TLS 1.2+ encryption in transit; AES-256 encryption at rest on cloud storage; support for SSO/MFA; a published bug bounty program via Bugcrowd; third-party penetration testing; GDPR-compliant 72-hour breach notification procedures; and published data residency options for EU and USA.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence was independently sourced from external data providers and public registries without vendor participation.
4 findings identified for HubSpot
Adverse media reporting indicates HubSpot experienced a data breach in January 2026 where a compromised employee account was exploited to access customer data. The event severity was adjusted from critical to medium due to age and the vendor's documented incident response (72-hour breach notification commitment). …
The [subprocessor page](https://trust.hubspot.com/subprocessors) exists but contains placeholder content—zero individual subprocessor entries were extracted. For a vendor with medium data access, a complete and regularly updated list of subprocessors (GDPR Article 28 Annex 3 requirement) is essential due diligence. …
Four certifications are mentioned on [HubSpot's trust page](https://trust.hubspot.com/)—SOC 2 Type II, ISO 27001 (inherited), SOC 1 Type II, and HIPAA—but independent registry verification was not possible. SOC 2 reports are confidential by design, so vendor attestation is the expected evidence pathway. …
HubSpot's domain appears in 50 threat intelligence pulses in the Open Threat Exchange (OTX). However, the domain is clean on URLhaus and malware blacklists, indicating these pulses likely reflect third-party campaigns (e.g., phishing emails impersonating HubSpot, malicious actors abusing HubSpot's infrastructure) rather than direct risk from the vendor itself. …
Evidence that positively supports HubSpot's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →HubSpot complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
HubSpot processes marketing data, customer contact information, and sales pipeline data — making SOC 2 compliance verification essential for organizations in regulated industries. HubSpot integrates with a wide range of productivity tools, including Google Workspace, which means data flows between these platforms should be assessed holistically. Organizations that rely on both HubSpot and a productivity suite should evaluate the compliance posture of each vendor and document the data flows between them as part of their SOC 2 CC9.2 evidence package.
Represent HubSpot? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The HubSpot assessment above is already written; ask for it and it lands in your inbox.