Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with HubSpot, your compliance team needs documented proof they can be trusted. ThirdProof investigated HubSpot across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
25 sources queried. 99% confidence. Every HubSpot investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get HubSpot's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 39% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
Not found in FedRAMP marketplace
Q40
HubSpot is HIPAA compliant for specific covered services and offers a business associate agreement for entities handling Protected Health Information.
Q42
HubSpot has a Data Processing Agreement (DPA) published at legal.hubspot.com/dpa that reflects GDPR processing agreements.
+ 6 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get HubSpot's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
HubSpot is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
25
Sources Queried
25
Sources With Data
April 6, 2026
Last Assessed
AI-generated analysis for HubSpot
HubSpot (hubspot.com) is a well-established enterprise SaaS platform assessed at Tier 3 (Moderate Risk) with a 99% confidence score, reflecting a broadly positive security posture tempered by a small number of unresolved due diligence gaps material to organizations with high data access requirements. HubSpot demonstrates several meaningful strengths indicative of a mature vendor:
Independence Statement
All evidence underlying this assessment was sourced independently by ThirdProof from external registries, public threat intelligence databases, certificate transparency logs, domain analysis tools, and archived media without vendor participation or notification.
3 findings identified for HubSpot
hubspot.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.
hubspot.com has certificates from 21 different Certificate Authorities. This may indicate inconsistent certificate management practices.
2 article(s) mention "HubSpot" with risk keywords, severity reduced due to article age: "HubSpot Hacked! Customers Impacted by New Cybersecurity Attack" (CX Today) https://news.google.com/rss/articles/CBMilAFBVV95cUxQMnNudWF5emhNcDQwUDl1Wlo5b0FQNXlKb09PdC1NTGtySkRqNVRSblJ3bDMtVEQycGtfQnYzbTVPVzB0am14dldrYUNnWmp5Z25tQkVHWHBZSnJZdjRuZmZFMjRvWHg5UlZBeGxVcloyMjJtUTNxMHR2ZTQ1Q0ZmbHUyaFpsZFlDOXBQX0szZUQ1dEFm?oc=5; "HubSpot hacked: Data breach hits leading cryptocurrency companies" (SiliconANGLE) https://news.google.com/rss/articles/CBMipAFBVV95cUxNbzZEeUJkS2oyQ2VJaXg2b0FQSEJWeXJncHNybDBqYnR6TkpaUHZuRVF0Z2FneGdiWTFxdHlHSTNPNjdOSGtQc2FhSUpRZ2Yya2dMajU0aXI5Yy1feXYzMmlCNTM0eU1hZ2tsYmRGeDdrdjVkdWNzZGEya1lBbW5COWtXQWVzXzhyYjJNTGhzdURQVEFRTUh1UHFYZmZaT0plWnBwdw?oc=5
25 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Found
Adverse Media Scan →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →10 Open Ports Detected
Infrastructure Exposure →Established Domain (21+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Notable Tech Community Presence
Tech Community Sentiment →Minimal Tech Community Discussion
Tech Community Sentiment →HTTP Security Grade: B
HTTP Security Scan →Large Certificate Footprint (167 subdomains)
Certificate Transparency →Established Web Presence (20+ years)
Web Archive History →Domain in 42 Threat Intelligence Pulses
Threat Intelligence (OTX) →Low Abuse Score: 0% (2 reports)
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: ISO 27001 (Inherited)
Trust & Compliance Page Scan →Subprocessor Page Found (Placeholder)
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →HITRUST Directory Match — Manual Verification Required
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for HubSpot
Obtain HubSpot's SOC 2 Type II report and bridge letter — contact their security team directly or check [legal.hubspot.com/security](https://legal.hubspot.com/security). Request a report dated within the last 12 months and a bridge letter covering any gap to today's date. File both documents with reviewer signature as CC9.2 evidence.
Resolve the subprocessor disclosure gap within 60 days: contact HubSpot's privacy or DPA team to obtain a current subprocessor list, verify it against the public page at [trust.hubspot.com/subprocessors](https://trust.hubspot.com/subprocessors), and document the list in your vendor risk file. Run a basic sanctions check on any newly identified subprocessors handling personal data.
Request clarification on HubSpot's AI data usage policy — specifically: (1) whether customer CRM and contact data is used to train AI models, (2) what retention periods apply to data processed by AI features, and (3) which third-party AI providers (if any) access customer data. Reference the [published privacy policy](https://legal.hubspot.com/privacy-policy) as a starting point and request a written statement from the vendor's privacy team if the policy is ambiguous.
Request HubSpot's incident post-mortem or security bulletin for the June–July 2024 customer account compromise. Ask the vendor's security team for root cause, remediation steps taken, and whether your organization's account type was in scope. Document the response in your vendor risk file.
Confirm that HubSpot has automated TLS certificate renewal in place for hubspot.com. The current certificate expires June 17, 2026 (~71 days from assessment date). You can independently monitor expiry via the [SSL/TLS analysis service report](https://www.SSL/TLS analysis service.com/ssltest/analyze.html?d=hubspot.com). Flag for re-check 30 days before expiry if confirmation is not received.
Document complementary user entity controls (CUECs) if HubSpot is within your SOC 2 audit boundary. Typical CUECs for a SaaS CRM include: access provisioning/deprovisioning controls, MFA enforcement for all HubSpot user accounts, data export and deletion procedures, and API key rotation policies. Your SOC 2 auditor will expect these to be documented.
25 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you HubSpot? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is HubSpot on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is HubSpot's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is HubSpot a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has HubSpot appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is HubSpot's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are HubSpot's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does HubSpot claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does HubSpot depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has HubSpot appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
HubSpot processes marketing data, customer contact information, and sales pipeline data — making SOC 2 compliance verification essential for organizations in regulated industries. HubSpot integrates with a wide range of productivity tools, including Google Workspace, which means data flows between these platforms should be assessed holistically. Organizations that rely on both HubSpot and a productivity suite should evaluate the compliance posture of each vendor and document the data flows between them as part of their SOC 2 CC9.2 evidence package.
Seeing this in an audit? ThirdProof lets you investigate HubSpot and every other vendor in your stack — average report time: 7 minutes. Get HubSpot's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates HubSpot across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.