Q39
Are you PCI DSS compliant? At what level?
HubSpot is NOT PCI DSS certified; multiple sources confirm HubSpot is not a PCI-certified platform, though it can be used in a PCI-compliant manner.
ThirdProof independently checks public intelligence sources to show what your team can verify about HubSpot before HubSpot sends a questionnaire or a security document.
HubSpot's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from HubSpot — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on HubSpot's own trust page.
⚠ HubSpot was not found in the FedRAMP Marketplace. Checked August 2026.
This matters if you place federal workloads with this vendor: agencies may only use cloud services holding a FedRAMP certification. It carries no weight for a purely commercial deployment.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 27 returning usable evidence. The HubSpot assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest HubSpot Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 74% of a 133-question vendor security questionnaire — without waiting for HubSpot. The remaining 35 are listed as open, so the follow-up you send is short and specific.
Q39
HubSpot is NOT PCI DSS certified; multiple sources confirm HubSpot is not a PCI-certified platform, though it can be used in a PCI-compliant manner.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
Encryption at rest claim found on trust page (Vendor attested)
+ 93 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Narrative analysis for HubSpot
HubSpot is a mature, publicly traded SaaS platform with a 21-year operational history and significant market presence in customer relationship management (CRM) and marketing automation.
The vendor demonstrates strong security fundamentals, including a dedicated security leadership team (Chief Information Security Officer Eric Richard and Chief Security Officer Chris McLellan), commitment to a 99.95% uptime SLA, redundant multi-region data centers, and vendor-attested SOC 2 Type II and ISO 27001 certifications. Positive signals include: clean domain reputation with no malware or phishing listings; TLS 1.2+ encryption in transit; AES-256 encryption at rest on cloud storage; support for SSO/MFA; a published bug bounty program via Bugcrowd; third-party penetration testing; GDPR-compliant 72-hour breach notification procedures; and published data residency options for EU and USA.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence was independently sourced from external data providers and public registries without vendor participation.
4 findings identified for HubSpot
Adverse media reporting indicates HubSpot experienced a data breach in January 2026 where a compromised employee account was exploited to access customer data. The event severity was adjusted from critical to medium due to age and the vendor's documented incident response (72-hour breach notification commitment). …
The [subprocessor page](https://trust.hubspot.com/subprocessors) exists but contains placeholder content—zero individual subprocessor entries were extracted. For a vendor with medium data access, a complete and regularly updated list of subprocessors (GDPR Article 28 Annex 3 requirement) is essential due diligence. …
Four certifications are mentioned on [HubSpot's trust page](https://trust.hubspot.com/)—SOC 2 Type II, ISO 27001 (inherited), SOC 1 Type II, and HIPAA—but independent registry verification was not possible. SOC 2 reports are confidential by design, so vendor attestation is the expected evidence pathway. …
HubSpot's domain appears in 50 threat intelligence pulses in the Open Threat Exchange (OTX). However, the domain is clean on URLhaus and malware blacklists, indicating these pulses likely reflect third-party campaigns (e.g., phishing emails impersonating HubSpot, malicious actors abusing HubSpot's infrastructure) rather than direct risk from the vendor itself. …
Evidence that positively supports HubSpot's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →HubSpot complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
HubSpot processes marketing data, customer contact information, and sales pipeline data — making SOC 2 compliance verification essential for organizations in regulated industries. HubSpot integrates with a wide range of productivity tools, including Google Workspace, which means data flows between these platforms should be assessed holistically. Organizations that rely on both HubSpot and a productivity suite should evaluate the compliance posture of each vendor and document the data flows between them as part of their SOC 2 CC9.2 evidence package.
Represent HubSpot? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The HubSpot assessment above is already written; ask for it and it lands in your inbox.