Skip to main content
Skip to main content

HubSpot Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about HubSpot before HubSpot sends a questionnaire or a security document.

HubSpot's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from HubSpot — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on HubSpot's own trust page.

HubSpot was not found in the FedRAMP Marketplace. Checked August 2026.

This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.

Risk
Tier 3Moderate Risk
Evidence confidence
100%
27 of 27 sources returned data
Questionnaire
98 / 133 answered
74% from public evidence
Last assessed
Aug 27, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 21.6 years🟢Infrastructure: 11 open ports, 0 CVEs
FedRAMP Status
HubSpot is not listed on the FedRAMP Marketplace (checked August 2026).
SOC 2 Status
HubSpot — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
HubSpot returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned HubSpot a Moderate Risk tier across 27 intelligence sources, 27 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 27 returning usable evidence. The HubSpot assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest HubSpot Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

98 questions answered before HubSpot responds.

ThirdProof used public evidence to pre-fill 74% of a 133-question vendor security questionnaire — without waiting for HubSpot. The remaining 35 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

HubSpot is NOT PCI DSS certified; multiple sources confirm HubSpot is not a PCI-certified platform, though it can be used in a PCI-compliant manner.

Public evidencehigh confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

GDPR compliance / DPA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

HIPAA compliance / BAA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

Encryption at rest claim found on trust page (Vendor attested)

Public evidencemedium confidence

+ 93 additional evidence-backed answers

Get the Complete HubSpot Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before HubSpot sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • No Sanctions Matches Found
  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered
  • Clean domain reputation
  • Clean Safe Browsing Status

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Incident Response — 7 of 10 questions need vendor input
  • Data Security — 5 of 14 questions need vendor input
  • Governance & Risk — 4 of 10 questions need vendor input
  • Access Control — 4 of 12 questions need vendor input

Reviewing HubSpot for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for HubSpot

HubSpot is a mature, publicly traded SaaS platform with a 21-year operational history and significant market presence in customer relationship management (CRM) and marketing automation.

Area Requiring Attention

The vendor demonstrates strong security fundamentals, including a dedicated security leadership team (Chief Information Security Officer Eric Richard and Chief Security Officer Chris McLellan), commitment to a 99.95% uptime SLA, redundant multi-region data centers, and vendor-attested SOC 2 Type II and ISO 27001 certifications. Positive signals include: clean domain reputation with no malware or phishing listings; TLS 1.2+ encryption in transit; AES-256 encryption at rest on cloud storage; support for SSO/MFA; a published bug bounty program via Bugcrowd; third-party penetration testing; GDPR-compliant 72-hour breach notification procedures; and published data residency options for EU and USA.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence was independently sourced from external data providers and public registries without vendor participation.

Investigation Findings

4 findings identified for HubSpot

1 medium3 low
medium

Data breach or security incident in media coverage

Adverse media reporting indicates HubSpot experienced a data breach in January 2026 where a compromised employee account was exploited to access customer data. The event severity was adjusted from critical to medium due to age and the vendor's documented incident response (72-hour breach notification commitment). …

low

Subprocessor page contains placeholder content

The [subprocessor page](https://trust.hubspot.com/subprocessors) exists but contains placeholder content—zero individual subprocessor entries were extracted. For a vendor with medium data access, a complete and regularly updated list of subprocessors (GDPR Article 28 Annex 3 requirement) is essential due diligence. …

low

4 certifications claimed but not independently verified

Four certifications are mentioned on [HubSpot's trust page](https://trust.hubspot.com/)—SOC 2 Type II, ISO 27001 (inherited), SOC 1 Type II, and HIPAA—but independent registry verification was not possible. SOC 2 reports are confidential by design, so vendor attestation is the expected evidence pathway. …

low

Threat intelligence pulses detected

HubSpot's domain appears in 50 threat intelligence pulses in the Open Threat Exchange (OTX). However, the domain is clean on URLhaus and malware blacklists, indicating these pulses likely reflect third-party campaigns (e.g., phishing emails impersonating HubSpot, malicious actors abusing HubSpot's infrastructure) rather than direct risk from the vendor itself. …

Security Strengths

Evidence that positively supports HubSpot's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

No Sanctions Matches Found

Sanctions & Watchlist Screening

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Clean Website Security Scan

Website Security Scan

Clean IP Reputation

IP Reputation

HubSpot complete vendor assessment

Tier 3
Moderate Risk
98 / 133
questionnaire answers
27
sources checked
Aug 27, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 27, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

HubSpot Compliance and Integration Context

HubSpot processes marketing data, customer contact information, and sales pipeline data — making SOC 2 compliance verification essential for organizations in regulated industries. HubSpot integrates with a wide range of productivity tools, including Google Workspace, which means data flows between these platforms should be assessed holistically. Organizations that rely on both HubSpot and a productivity suite should evaluate the compliance posture of each vendor and document the data flows between them as part of their SOC 2 CC9.2 evidence package.

Frequently asked about HubSpot

Is HubSpot FedRAMP authorized?+
HubSpot was not found in the FedRAMP Marketplace when it was checked on August 27, 2026. Absence of a public record is not evidence that the certification is absent; organisations with a hard requirement should confirm directly with the vendor.
Does HubSpot have SOC 2 Type II?+
HubSpot states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is HubSpot on the OFAC sanctions list?+
HubSpot returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is HubSpot's vendor risk tier?+
ThirdProof assigned HubSpot a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning HubSpot.
Has HubSpot had any data breaches or security incidents?+
ThirdProof's assessment as of August 2026 records 1 incident-related finding for HubSpot. The most severe concerns data breach or security incident in media coverage. Each finding states whether the incident affected HubSpot's own systems, a customer's environment, or a third party — a distinction that changes what you should ask about — and links to the source it was drawn from. The complete assessment carries all of them with their evidence.
Is HubSpot PCI DSS compliant?+
HubSpot is NOT PCI DSS certified; multiple sources confirm HubSpot is not a PCI-certified platform, though it can be used in a PCI-compliant manner. ThirdProof records this from HubSpot's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does HubSpot support HIPAA and sign BAAs?+
HIPAA compliance / BAA claim found on trust page (Vendor attested) If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a HubSpot security questionnaire?+
Yes. ThirdProof answered 98 of 133 questions (74%) about HubSpot from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 35 are listed as open, so the follow-up you send HubSpot is short and specific.

If HubSpot is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The HubSpot assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required