HubSpot security and compliance.
The answer your security review is waiting for. For regulated industries the first question about any system is not what it does. It is who can see the data, where it lives, how long it is kept and what happens when somebody asks for it to be deleted.
The deal stalled in procurement.
The buyer sent a security questionnaire and nobody can answer the HubSpot sections. Meanwhile your own portal has dormant admins, no enforced two-factor, consent that is captured and never read, and no retention position anyone has written down.
Nobody wrote the position down.
Security — the questionnaireWhat a review actually examines.
Platform certifications, correctly stated
What HubSpot itself certifies against, what that does and does not cover, and which obligations remain yours as the data controller. Most questionnaire failures are misstatements, not gaps.
Access control
SSO against your directory, enforced two-factor, permission sets by role, dormant account review and a documented joiner and leaver process.
Consent and lawful basis
Consent captured per region and actually read by sending logic and tracking. A banner nothing else obeys is worse than no banner, because it documents the failure.
Retention and deletion
A written retention position and a deletion process that reaches HubSpot, the warehouse and the integrations. Subject requests run on a clock.
Where sensitive data should not be
For health, defence and financial clients the important design decision is what never enters the CRM. Drawing that boundary is cheaper than defending it later.
Audit trail
Login history, change logs and integration activity retained and reviewable, so an incident question has an answer.
Audit, architect, build, hand over.
Audit
The portal read end to end — objects, properties, automation, permissions, integrations and the reports leadership actually opens.
Architect
The model written down before it is built: objects, lifecycle, ownership and the definitions every report has to agree on.
Build
Configuration, automation and integration built to that model, in a sequence that leaves the team working throughout.
Hand over
Documentation, enablement for the people who run it daily, and a period operating alongside your team until it is genuinely theirs.
Compliance as a document.
A policy that says consent is honoured, sitting beside a workflow that emails everyone regardless, is worse than no policy. The only compliance that survives scrutiny is enforced by the configuration. We build the enforcement and then the document describes something true.
What people ask before they commit.
Is HubSpot SOC 2 compliant?
HubSpot maintains the certifications you would expect of a platform at its scale, and publishes them. The part that matters for your review is which obligations remain yours as the controller, and that is a configuration question about your portal.
Can HubSpot be used for regulated data?
It depends entirely on the regime and the data. For health data in the US it is a question of what is in scope and what agreements are in place. Our usual advice is to design so that the most sensitive data never enters the CRM at all.
Can you complete our security questionnaire?
The HubSpot-specific sections, yes, and we do it regularly. We can also advise on the configuration changes that turn a weak answer into a strong one.
How do we handle deletion requests?
With a documented process covering HubSpot, any warehouse copy, integrated systems and backups. Deleting a contact in the CRM alone is not compliance, it is the appearance of it.
What about data residency?
HubSpot offers EU data hosting, with conditions. Whether that satisfies your requirement depends on the requirement, and we will read it with you rather than guess.
Where people go from here.










Answer the questionnaire.
Tell us what you are running
What the system does today, where it breaks, and when it has to work. An engineer reads it — you get an answer inside one business day, not a sequence.