<!doctype html><html lang="en" class="font-sans text-gray-800 text-body leading-[1.15] min-h-screen"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1,shrink-to-fit=no"><meta name="theme-color" content="#000000"><meta name="referrer" content="origin"><link nonce="dCtiZ1/c5YsI4PAPtj8xhg==" rel="icon" href="https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWswTjJWa1lqQTNOeTAwTkRJeExUUmhPVFl0WVRWaU55MDRNak00T1RWa056YzVZV0VHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--9e3d348b5b73f7afeea0ec4bfc044ee543f449e4/LogoHubspot.jpg"><title>HubSpot Trust Center | Powered by Conveyor</title><script nonce="dCtiZ1/c5YsI4PAPtj8xhg==">// code is lifted from https://github.com/arasatasaygin/is.js
    var windowObject = function (value) {
      return value != null && typeof value === 'object' && 'setInterval' in value;
    };
    var freeSelf = windowObject(typeof self == 'object' && self) && self;
    var navigator = freeSelf && freeSelf.navigator;
    var userAgent = (navigator && navigator.userAgent || '').toLowerCase();
    var match = userAgent.match(/(?:msie |trident.+?; rv:)(\d+)/);
    if (match !== null && match[1] <= 11) {
      window.location.href = window.location.origin + "/unsupported.html";
    }</script><script nonce="dCtiZ1/c5YsI4PAPtj8xhg==">window.VENDOR_REPORT = {"id":"1ea4ccd5-a64c-476b-866e-7589accfaf2d","created_at":"2021-11-30T19:17:46.550Z","updated_at":"2026-04-27T18:33:28.612Z","_type":"public_vendor_report","data_access":"HubSpot will store significant details about your customer base including their contact information. Depending on your use case, they will likely store intellectual property and integrate heavily with your website and email.","description":"HubSpot provides a comprehensive suite of sales, marketing, and customer success tools. This includes a CRM, content management, and customer support software.","hot_take_content":"HubSpot blazed the inbound path, and they leave nothing to the imagination when it comes to quickly finding details about their security and privacy practices. With great power comes great responsibility, so the onus is now on you as a customer (or potential customer) of HubSpot to configure it correctly and be transparent about the data you collect and store in their platform.","hot_take_source":"joe","published":true,"url_connect":"https://app.conveyor.com/datarooms/f47aa376-4d7b-406d-86f2-421aff40bb96","_embedded":{"canonical_asset":{"id":"2680cfcf-ab2c-499c-87f0-9dec420a2d5e","created_at":"2021-02-03T18:51:36.380Z","updated_at":"2025-12-15T17:38:03.006Z","_type":"canonical_asset/vendor","name":"HubSpot","type":"Vendor","trending":false,"logo_url":"https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWswTjJWa1lqQTNOeTAwTkRJeExUUmhPVFl0WVRWaU55MDRNak00T1RWa056YzVZV0VHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--9e3d348b5b73f7afeea0ec4bfc044ee543f449e4/LogoHubspot.jpg","cover_photo_url":"https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWs0T0RCaVlUQTVZeTB4TmpJNUxUUXhOVGd0WW1JNVppMDRZemN5Tm1RNFlqY3laRElHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--5399507b865b8748566d4f40656aecb674843c2d/Welcome-New.jpg","thumbnail_image_url":"https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWxoTlRjNU5UbGlOUzA1TkRNMkxUUTRZVEF0WVRRM1l5MDFObU5tWkdJM04yWmxNMllHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--1d3f2223e58e5a776df63977b8d0a8a68f531daf/Thumbnail.jpg","certifications":["soc2-type-2","soc3","hipaa","gdpr","ccpa","eu-cloud-coc","truste"],"website":"http://www.hubspot.com/","dataroom_id":"f47aa376-4d7b-406d-86f2-421aff40bb96","additional_company_details":{"founded":"2006","legal_name":"","company_size":"","physical_address":""},"has_published_report":true,"url_addressable_name":"hubspot","accent_color":"#FF4800","primary_color":null,"report_vulnerability_url":"","privacy_policy_url":"","terms_conditions_url":"","show_transparency_score_on_public_profile":false,"has_claimed_dataroom":true,"slug":"hubspot","published":true,"public_profile_published":true,"custom_font_url":null,"custom_font_name":"","custom_font_resource_url":null,"dataroom_discoverable":true},"trust_indicators":[{"id":"168bec40-4247-4f63-918f-1c9e3c2f5800","created_at":"2021-11-30T19:17:46.555Z","updated_at":"2021-12-07T22:39:39.017Z","_type":"trust_indicator","name":"sso_mfa","question_text":"Do they outline the identity management capabilities of the product?","description":"HubSpot supports [single sign-on] (https://legal.hubspot.com/security) as well 2FA.","weight":"important","score":"great","cta_link":"","weight_value":2,"score_value":3,"points":6},{"id":"4be6b0a2-984d-4579-aec7-bc9ccc8d3946","created_at":"2021-11-30T19:17:46.554Z","updated_at":"2021-11-30T19:17:46.554Z","_type":"trust_indicator","name":"soc2_report","question_text":"Do they have a current SOC 2 Type II Report to share (or proof that they support a comparable framework)?","description":"HubSpot has their SOC 2 Type II Report available for download after you sign their confidentiality agreement. This can be accessed on their [Security Page](https://legal.hubspot.com/security).","weight":"important","score":"great","cta_link":"https://legal.hubspot.com/security","weight_value":2,"score_value":3,"points":6},{"id":"e421af31-3602-4856-bb0e-4bc58f86c35b","created_at":"2021-11-30T19:17:46.557Z","updated_at":"2021-11-30T19:17:46.557Z","_type":"trust_indicator","name":"public_privacy_policy","question_text":"Do they have a public privacy policy?","description":"HubSpot has a detailed privacy statement that covers what they collect, how they use it, their security practices, and how to get in touch with them if you have questions.","weight":"important","score":"great","cta_link":"https://legal.hubspot.com/privacy-policy","weight_value":2,"score_value":3,"points":6},{"id":"21277142-d0fa-4f2d-931c-4dcf8b3b99a5","created_at":"2021-11-30T19:17:46.559Z","updated_at":"2021-11-30T19:17:46.559Z","_type":"trust_indicator","name":"public_security_policy","question_text":"Do they have a public security policy?","description":"In addition to a detailed security overview, HubSpot makes specific statements about their security practices in Annex 2 of their pre-signed DPA.","weight":"important","score":"great","cta_link":"https://legal.hubspot.com/security","weight_value":2,"score_value":3,"points":6},{"id":"8acb654d-2c5f-47a6-b535-e3e7b02e069b","created_at":"2021-11-30T19:17:46.561Z","updated_at":"2021-12-07T22:39:39.018Z","_type":"trust_indicator","name":"penetration_testing","question_text":"Do they complete regular penetration testing?","description":"HubSpot provides quick and easy access to their most recent [penetration test] (https://legal.hubspot.com/security) for their CRM platform. They indicate the report contains a summary of the methodology, findings, and remediation.","weight":"important","score":"great","cta_link":"","weight_value":2,"score_value":3,"points":6},{"id":"8d657fca-e22a-4195-adb4-90ff5c966e6c","created_at":"2021-11-30T19:17:46.562Z","updated_at":"2021-12-07T22:39:39.020Z","_type":"trust_indicator","name":"encrypt_data","question_text":"Do they share details about how they encrypt data?","description":"Encryption at-rest uses AES-256 and they [list encryption] (https://legal.hubspot.com/security) in-transit as TLS 1.2 and 1.3.","weight":"important","score":"great","cta_link":"","weight_value":2,"score_value":3,"points":6},{"id":"c2562ce9-06dd-4cbe-bd5a-abe28f5386c6","created_at":"2021-11-30T19:17:46.564Z","updated_at":"2021-12-07T22:39:39.022Z","_type":"trust_indicator","name":"public_subprocessor_list","question_text":"Do they have a public subprocessor list? Can you opt-in to receive updates?","description":"A detailed sub-processor list is included in their public [DPA] (https://legal.hubspot.com/dpa). You can subscribe to updates if you are a customer.","weight":"relevant","score":"great","cta_link":"","weight_value":1,"score_value":3,"points":3},{"id":"fe24f345-0318-43bf-a0f2-99b015ff2947","created_at":"2021-11-30T19:17:46.566Z","updated_at":"2021-12-07T22:39:39.023Z","_type":"trust_indicator","name":"disclose_hosting_location","question_text":"Do they disclose their hosting provider(s) and location(s)?","description":"Per their [DPA] (https://legal.hubspot.com/dpa), HubSpot is hosted using AWS in the USA.","weight":"relevant","score":"great","cta_link":"","weight_value":1,"score_value":3,"points":3},{"id":"9bc67fa6-5907-4d4a-ac44-7d5bbd8e713f","created_at":"2021-11-30T19:17:46.568Z","updated_at":"2021-12-07T22:39:39.025Z","_type":"trust_indicator","name":"live_status_page","question_text":"Do they have a live status page with historical reliability data?","description":"They have a status page and commitments to uptime in product-specific terms. We could not find a way to subscribe to status updates.","weight":"important","score":"good","cta_link":"https://status.hubspot.com/","weight_value":2,"score_value":2,"points":4},{"id":"76da46f6-84e9-4289-b794-b81d5211c75c","created_at":"2021-11-30T19:17:46.569Z","updated_at":"2021-12-07T22:39:39.027Z","_type":"trust_indicator","name":"bug_bounty_resp_disclosure","question_text":"Do they have a bug bounty or responsible disclosure program?","description":"They run a [bug bounty program] (https://bugcrowd.com/hubspot) on Bugcrowd.","weight":"relevant","score":"great","cta_link":"","weight_value":1,"score_value":3,"points":3},{"id":"3c81c41c-a465-42f4-bbc3-63eb154986a6","created_at":"2021-11-30T19:17:46.571Z","updated_at":"2021-12-07T22:39:39.028Z","_type":"trust_indicator","name":"self_serve_security_docs","question_text":"Do they offer customers and prospects self-serve access to up-to-date documentation and questionnaire answers?","description":"They provide a detailed trust portal that includes an FAQ, downloadable whitepapers that are kept up to date, and self-service access to security documentation.","weight":"relevant","score":"great","cta_link":"https://legal.hubspot.com/security","weight_value":1,"score_value":3,"points":3},{"id":"1d22c99f-f71a-4b1f-80be-a0dc2e3f4ab3","created_at":"2021-11-30T19:17:46.573Z","updated_at":"2021-12-07T22:39:39.030Z","_type":"trust_indicator","name":"enter_into_dpa","question_text":"Will they enter into a Data Processing Agreement (DPA), if relevant?","description":"Yes, a signed DPA for Hubspot can be downloaded from their [Security Page] (https://legal.hubspot.com/security)","weight":"important","score":"great","cta_link":"","weight_value":2,"score_value":3,"points":6},{"id":"74233677-0f0f-483f-924e-42b5faabd596","created_at":"2021-11-30T19:17:46.574Z","updated_at":"2021-12-07T22:39:39.032Z","_type":"trust_indicator","name":"publish_system_visuals","question_text":"Do they publish a system diagram/definition?","description":"On their marketing site, they provide a [basic overview] (https://www.hubspot.com/products/marketing) of how their various products work.","weight":"neutral","score":"baseline","cta_link":"","weight_value":0,"score_value":1,"points":0},{"id":"0f647c63-3ac7-452b-a738-ff1945e0040a","created_at":"2021-11-30T19:17:46.576Z","updated_at":"2021-12-07T22:39:39.034Z","_type":"trust_indicator","name":"integration_docs","question_text":"Do they have a list of available third-party integrations and good integration documentation?","description":"Detailed documentation that includes videos.","weight":"relevant","score":"great","cta_link":"https://ecosystem.hubspot.com/marketplace/apps","weight_value":1,"score_value":3,"points":3}],"announcements":[{"id":"f15a1d35-7d74-45ca-a31b-bcb97b14ce55","created_at":"2026-03-11T20:53:13.083Z","updated_at":"2026-03-12T17:56:30.932Z","_type":"vendor_announcement","content":"**March 12, 2026 Update:**\r\n\r\nOn March 12 at 1:30 PM ET, HubSpot’s security team temporarily disabled [legacy public app](https://developers.hubspot.com/docs/apps/legacy-apps/public-apps/overview) and [project-based app](https://developers.hubspot.com/docs/apps/developer-platform/build-apps/overview) creation for new portals. This increase in security measures is in response to a phishing campaign that impacted some customers. Investigation is ongoing and updates will be available at our Trust Center when they become available. \r\n\r\n**- End Update**\r\n\r\n**Advisory Notice**\r\n\r\nHubSpot is aware of an ongoing phishing campaign targeting some HubSpot customers. While our investigation is ongoing, we are sharing this information to help customers recognize and prevent these fraudulent attempts.\r\n\r\n**Summary**\r\n\r\nA subset of customers may have received fraudulent emails that appear to be from HubSpot, but were sent from non-HubSpot email addresses and domains. These emails may contain subject lines like “Your HubSpot portal has been deactivated” with fraudulent instructions to take an action, such as clicking a link to “Verify your Identity”. \r\n\r\nSome customers may have also received an erroneous email verification from noreply@hubspot.com with the subject line “Looks like you already have an account”. These emails can be safely ignored. \r\n\r\nWe have identified that bad actors have attempted to impersonate HubSpot to convince some customers to install malicious third-party app integrations to their HubSpot portals. Our Security team has blocked identified malicious apps and is investigating other potentially malicious apps.  We’re also identifying impacted customer portals and will notify them directly once impact is confirmed.\r\n\r\n**Red Flags to Watch**\r\n\r\n- **Look out for Unsolicited Emails or Calls:** Be skeptical of any unexpected email or call appearing to be from HubSpot Support or your own company IT support, especially if it is requesting to install an app. \r\n\r\n- **Do not install Apps from Email Links:** Unless you know and trust the app developer, app integrations should only be installed from the HubSpot Marketplace. When installing an app from outside the Marketplace, HubSpot will first provide you with a warning that you are installing an unverified app. \r\n\r\n- **Check Email Senders:** All legitimate communications from HubSpot, including password reset, account validation, and renewal emails, are sent from the hubspot.com domain. Please review the display name and the “sent from:” email address if you receive suspicious or unusual emails.\r\n\r\n- **Inspect Links and URLs:** Ensure that you are only entering your credentials on the official HubSpot login page. \r\n\r\nIf you receive suspicious emails from non-HubSpot email domains, please do not click any links or provide personal information, such as email addresses or passwords, to the sender or through the web pages linked within these emails. Do not install any untrusted apps. \r\n\r\n**Key Takeaways**\r\n\r\nBe vigilant for any suspicious emails from fraudulent email domains, and be mindful of any request to install new or untrusted app integrations to your HubSpot portal. Report any suspicious activity to abuse@hubspot.com.\r\n\r\nWe will provide additional updates to the HubSpot Trust Center as needed. ","title":"Security Advisory: Phishing Campaign to Install Malicious Integrations","publish_at":null,"sent_at":"2026-03-12T12:55:00.065Z","notify_subscribers":false},{"id":"bb84f493-d048-4216-8df0-a0756e74a848","created_at":"2026-01-23T18:42:52.664Z","updated_at":"2026-01-24T13:55:02.920Z","_type":"vendor_announcement","content":"HubSpot is aware of [reports](https://www.okta.com/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/) detailing sophisticated voice phishing (vishing) campaigns targeting Okta Single Sign-On (SSO) accounts. While these attacks are targeting identity providers broadly, we are proactively sharing this information to help customers recognize and prevent these social engineering attempts.\r\n\r\n**How the Attack Works**\r\n\r\nAttackers call employees and pose as IT support staff from their company or a service provider. They trick victims into visiting a fake login page designed to steal usernames and passwords. While still on the phone, the attacker uses those stolen credentials to trigger a real login. They then guide the victim through the Multi-Factor Authentication (MFA) step, such as asking for a code or telling them to approve a push notification, to gain full access to the account. Once inside, they can access sensitive data from various business tools and may attempt to extort the organization.\r\n\r\n**Red Flags to Watch For**\r\n\r\n- **Unsolicited Calls:** Be skeptical of any unexpected call from \"IT Support\" or \"Okta\" that creates a sense of urgency.\r\n- **Requests for Interaction:** Legitimate support will not ask you to visit non-standard URLs (e.g., company-internal.com) or provide MFA codes over the phone.\r\n- **MFA Mismatches:** Pay close attention if you receive an MFA push notification or other security prompts that you did not personally trigger through a verified login attempt.\r\n\r\n**Key Takeaways**\r\n\r\nHubSpot and your official service providers will never call you to request credentials or MFA codes.\r\n\r\nHubSpot customers utilizing Okta should be vigilant of unsolicited calls claiming to be IT support. If you receive a suspicious call, hang up and contact your internal IT department through official, known channels.\r\n\r\nHubSpot and [Okta recommend using phishing-resistant MFA](https://www.okta.com/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/#:~:text=each%20targeted%20service.-,Recommendations,-Thankfully%20there%20is), such as hardware keys or authenticators, which are more effective against these real-time relay attacks.\r\n","title":"Security Advisory: Vishing-Based Attacks Targeting Okta SSO Accounts","publish_at":null,"sent_at":"2026-01-24T13:55:00.052Z","notify_subscribers":true},{"id":"c9bdadec-7ec6-4c4e-9422-a1e5a889fe3b","created_at":"2025-12-19T22:58:25.270Z","updated_at":"2025-12-20T13:55:02.119Z","_type":"vendor_announcement","content":"### Threat Overview\r\n\r\nHubSpot is aware of a [threat report](https://evalian.co.uk/phishing-campaign-targets-hubspot-users/) detailing an ongoing phishing campaign targeting HubSpot customers and other SaaS platforms. The campaign deploys business email compromise (BEC) tactics and infrastructure abuse to bypass traditional email security controls.\r\n\r\n### How the Attack Works\r\n\r\nAttackers send emails impersonating HubSpot, requesting users to verify their accounts in connection with “unusual unsubscribe activity.” Notably, while email bodies do not contain typical malicious links, the phishing URL is instead embedded within the sender’s display name. If the malicious link is clicked, it redirects the user to a convincing login page that mimics the legitimate HubSpot login page and steals user passwords and multi-factor authentication (MFA) credentials.\r\n\r\n### Red Flags to Watch For\r\n\r\nAll legitimate communications from HubSpot, including password reset, account validation, and renewal emails, are sent from the hubspot.com domain. Please review the display name and the “sent from:” email address if you receive suspicious or unusual emails. Ensure that you are only entering your credentials on the official HubSpot [login page](https://app.hubspot.com/login?hubs_signup-url=knowledge.hubspot.com/account-management/log-in-to-hubspot&hubs_signup-cta=login-page). \r\n\r\nIf you receive these types of fraudulent emails from non-HubSpot email domains, directing to non-HubSpot pages, please do not click any link or provide any personal information, such as email addresses or passwords, to the sender or through the web pages linked within these emails.\r\n\r\n### How to Protect Yourself\r\n\r\nUsers are encouraged to set up and login with [Passkeys](https://knowledge.hubspot.com/account-management/set-up-and-log-in-with-passkeys). Super Admins can also [restrict the permitted login methods for their account](https://knowledge.hubspot.com/account-security/restrict-which-login-methods-users-can-use-to-access-your-account) to disable password-based logins. \r\n\r\n### Conclusion\r\n\r\nOur investigation is ongoing and we will provide updates on this page as needed. If you receive this, or any other suspicious email impersonating HubSpot, please report it to abuse@hubspot.com.","title":"Customer Advisory - Phishing Campaign Targeting HubSpot Users","publish_at":null,"sent_at":"2025-12-20T13:55:00.044Z","notify_subscribers":true},{"id":"721c02c9-aecb-4f89-9de6-783b0c1ae043","created_at":"2026-05-27T22:31:57.918Z","updated_at":"2026-06-03T21:26:10.345Z","_type":"vendor_announcement","content":"On May 25, 2026, [Composio disclosed a security incident](https://composio.dev/blog/composio-may-2026-security-incident) involving unauthorized access to certain internal Composio systems, including leaked OAuth credentials and API keys used in their [toolkits](https://composio.dev/blog/composio-may-2026-security-incident#things-we-have-done-so-far). Between May 25th and May 27th, based on Composio’s recommendation, HubSpot Security rotated OAuth tokens and API keys for apps using Composio's [managed or custom authorization options](https://docs.composio.dev/docs/custom-app-vs-managed-app) to integrate with Composio's [HubSpot toolkit](https://docs.composio.dev/toolkits/hubspot). \n\n*It is important to note that this issue did **not** stem from a vulnerability within the core HubSpot platform, but rather from a compromise of Composio’s internal systems.*\n\nCustomers and developers can [re-enable their app connections](https://docs.composio.dev/docs/composio-connect) with new credentials. Before doing so, customers are encouraged to review Composio’s [incident disclosure in detail](https://composio.dev/blog/composio-may-2026-security-incident). \n\nWe are investigating any potential impact to HubSpot customers and working with Composio to understand the full scope of the incident. **At this time, there is no evidence to suggest HubSpot or our customers’ accounts have been compromised.** \n\nComposio has contacted customers directly if their connection(s) were affected. HubSpot will also notify customers directly via email when our investigation concludes if we find any instance of account compromise. If you do not receive an email from Composio or HubSpot, you were not impacted.\n\nHubSpot will continue to monitor the situation and provide updates in our Trust Center as necessary. \n\n**Update on May 29th:** \nBased upon our continued investigation and due diligence, HubSpot continued to rotate OAuth credentials and API keys which we believe to be used in Composio [toolkits](https://composio.dev/blog/composio-may-2026-security-incident#things-we-have-done-so-far) between May 28th and May 29th.\n\n**Update on June 3rd:**\nHubSpot's investigation into the [Composio security incident](https://composio.dev/blog/composio-may-2026-security-incident) is now complete. We have found no evidence that HubSpot or any HubSpot customer accounts were compromised as a result of this incident. \n\n**Actions Recommended:**\n* Customers and developers: HubSpot users with impacted apps or keys will see a banner at the top of their [Connected Apps page](https://app.hubspot.com/l/connected-apps/). The banner will instruct super admins to [re-enable their app connections](https://docs.composio.dev/docs/custom-app-vs-managed-app) with new credentials if they wish. \n* App owners: Any apps available in the [HubSpot Marketplace](https://ecosystem.hubspot.com/marketplace/) that rely on Composio’s HubSpot toolkit may have also experienced degraded functionality or broken connections. App owners can review their Composio interface for connection failures and [re-enable their app connections](https://docs.composio.dev/docs/custom-app-vs-managed-app) with new credentials, if necessary.\n\nIf you have questions about Composio and their recent incident, we encourage you to [reach out to Composio directly](https://composio.dev/contact). For questions on using AI-native integration platforms in the future, please consult your IT or Security team.\n","title":"HubSpot Update on 2026 Composio Security Incident ","publish_at":null,"sent_at":"2026-05-28T12:55:00.285Z","notify_subscribers":false},{"id":"62cc1903-ce0d-42b5-972b-27962307829c","created_at":"2026-02-02T22:08:59.120Z","updated_at":"2026-02-03T13:55:04.033Z","_type":"vendor_announcement","content":"HubSpot has issued a patch for a critical vulnerability that allows for sandbox bypass and remote code execution that impacts Jinjava, as documented [here](https://github.com/HubSpot/jinjava/security/advisories/GHSA-gjx9-j8f8-7j74). Jinjava is a Java-based template engine used to generate dynamic web content that was developed and open-sourced by HubSpot. The vulnerability is fixed in [versions 2.8.3 and 2.7.6](https://github.com/HubSpot/jinjava/blob/master/CHANGES.md). \r\n\r\nWe completed an investigation into this vulnerability’s impact on HubSpot and found no evidence to suggest exploitation of this vulnerability. All Jinjava libraries used by HubSpot have been successfully patched as of January 30, 2026 at 5:33 PM ET. \r\n\r\n**Background**\r\n\r\nOn January 29, 2026, members of the Assetnote Security research team contacted HubSpot Security to disclose a vulnerability they discovered in HubSpot’s open-source Jinjava code. The vulnerability allows for Sandbox Escape and Remote Code Execution in unpatched versions of Jinjava. HubSpot immediately investigated, and patches were staged and ready to test with our partnering researchers the same day. \r\n\r\nOn February 2, we deployed the patch and published a Trust Center update regarding the exercise.\r\n\r\nDiscovery and disclosure of this vulnerability is credited to Shubham Shah, Adam Kues and Tomais Williamson from the Assetnote Security Research Team.\r\n\r\n**How does HubSpot use Jinjava?**\r\n\r\nJinjava is HubSpot’s open-source Java port of Python’s Jinja2 template engine, used to generate dynamic web content. The HubSpot product platform leverages Jinjava in several supporting back-end applications and is a core component of how the HubSpot CMS renders web content. HubSpot’s CMS uses the HubSpot Markup Language (HubL), which itself is HubSpot’s extension of Jinjava. Other instances of Jinjava within HubSpot’s back-end stack, which do not allow rendering of external templates, were not vulnerable.  \r\n\r\nAll vulnerable versions of Jinjava used by HubSpot internally and within the product infrastructure were patched by 5:33 PM ET on January 30, 2026. \r\n\r\n**HubSpot Customers**\r\n\r\nHubSpot has remediated any risk to HubSpot-provided tools internally. After investigating, there is no evidence to suggest this vulnerability was exploited historically or that customer data was impacted.\r\n\r\nNo action is needed by HubSpot customers. Only developers hosting custom-developed web content that utilizes Jinjava should take action to update their own Jinjava libraries to the latest version.\r\n\r\n\r\n**Actions Required for External Usage**\r\n\r\nDevelopers using Jinjava in their own projects should update Maven dependencies (com.hubspot.jinjava:jinjava) to [version 2.8.3 or 2.7.6](https://github.com/HubSpot/jinjava/blob/master/CHANGES.md).","title":"HubSpot Update on Jinjava Vulnerability","publish_at":"2026-02-03T00:00:00.000Z","sent_at":"2026-02-03T13:55:00.035Z","notify_subscribers":true},{"id":"bd5890be-16a5-4c3d-85b4-9899f4b5edcc","created_at":"2025-12-12T22:41:20.394Z","updated_at":"2025-12-13T13:55:00.499Z","_type":"vendor_announcement","content":"We’re excited to announce an upgrade coming to HubSpot’s Trust Center! \r\n\r\nOn Monday, December 15, 2025, we will be launching an all-new HubSpot Trust Center experience. Our current URL: “trust.hubspot.com” will remain as our one-stop-shop for public information, gated access, and communications on HubSpot’s security and compliance posture, but with an improved browsing experience and new features that will make it easier to find the information you are looking for. \r\n\r\n**Actions Needed From You:**\r\n\r\nAs a current HubSpot Trust Center subscriber, you will need to re-subscribe to our Trust Center again following the launch (after December 15, 2025) to continue receiving our updates and announcements. \r\n\r\nYou’ll also need to confirm your email address with our new Trust Center to gain access to our gated Trust Center content, such as our SOC 2 report. Customers with active subscriptions will be provisioned with full access to Trust Center content after confirming their email. \r\n\r\nTrust Center subscribers who are not active HubSpot customers will need to complete HubSpot’s clickwrap NDA to un-gate all content, just like how the HubSpot Trust Center works today.\r\n\r\n**What’s Coming:**\r\n\r\nWe’re excited to offer you easier access to our documentation, as well as an interactive knowledge base to answer our most commonly asked security and compliance questions. Keep a lookout for more features in the months ahead. ","title":"HubSpot is launching a new Trust Center!","publish_at":"2025-12-08T00:00:00.000Z","sent_at":"2025-12-13T13:55:00.189Z","notify_subscribers":false},{"id":"125c426a-a0d8-4fd4-96c9-2ec59d1cdca4","created_at":"2025-12-12T22:39:04.079Z","updated_at":"2025-12-13T13:55:00.215Z","_type":"vendor_announcement","content":"On December 3, 2025, a [vulnerability was announced](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components) related to popular open-source web development frameworks React Server Components (CVE-2025-55182) and Next.js (CVE-2025-66478). These open-source resources are widely used across the internet to build user interfaces. \r\n\r\n**Is HubSpot Impacted?**\r\n\r\nHubSpot utilizes React Server Components and Next.js in a limited capacity primarily for internal tools and experimental product research. We have conducted a thorough review of our Product and Corporate environments to determine the full extent of possible exposure to affected versions of React and Next.js. \r\n\r\nWe have found no evidence to suggest any attempted exploitation of CVE-2025-55182 in our environments. \r\n\r\n**Actions Taken**\r\n\r\nWe began patching procedures for vulnerable versions of React and Next.js immediately upon becoming aware of the vulnerability. Initial patches based on advisories were completed by December 3, 2025 at 5:14 PM EST. \r\n\r\nAs of December 4, 2025 at 1:00 PM EST, all vulnerable React and Next.js versions within HubSpot’s production environment were fully patched. \r\n\r\nAdditionally, HubSpot’s product platform and public APIs are protected behind our Web Application Firewall (WAF). A new ruleset to specifically protect against this vulnerability was fully implemented into our WAF on December 3, 2025 by 5:00 PM EST. All instances of the HubSpot product, as well as HubSpot’s own marketing pages, are fully protected behind our WAF.\r\nHubSpot is also monitoring any potential impact to our third-party vendors.\r\n\r\n**Next Steps** \r\n\r\nThere is no action needed for HubSpot customers to protect their HubSpot accounts or data. However, customers using React Server Components and/or Next.js in their own environments are strongly encouraged to update to the latest patched versions. \r\n\r\nWe will continue to monitor the situation and will post any additional updates to the Trust Center as needed. ","title":"HubSpot’s Response to React Vulnerability","publish_at":"2025-12-05T00:00:00.000Z","sent_at":"2025-12-13T13:55:00.189Z","notify_subscribers":false},{"id":"d24a328f-9454-4bd2-a6a2-353c376a54a8","created_at":"2025-12-12T22:39:56.550Z","updated_at":"2025-12-13T13:55:00.506Z","_type":"vendor_announcement","content":"HubSpot is excited to announce that the 2025 Corporate Network Penetration Test report is now available for review in our Trust Center. This assessment focused on our corporate network’s external attack surface and all publicly accessible corporate network assets.\r\n\r\nAdditionally, we have published an updated version of the HubSpot Network Diagram that contains new, up-to-date information around our network architecture.","title":"Updated Documents Now Available on HubSpot’s Trust Center","publish_at":"2025-12-05T00:00:00.000Z","sent_at":"2025-12-13T13:55:00.189Z","notify_subscribers":false},{"id":"7fc97710-0fd5-43e4-9b13-b2723d5ce8e1","created_at":"2025-12-01T17:52:41.056Z","updated_at":"2025-12-02T13:55:00.285Z","_type":"vendor_announcement","content":"Based on our investigation into Gainsight integration activity along with published indicators of compromise (IOCs), we have found no evidence to suggest that HubSpot or our customers were impacted.\r\nThe Gainsight integration will remain deactivated from the HubSpot app marketplace until Gainsight fully concludes their investigation to ensure all systems are secure.\r\n\r\nHubSpot will continue to follow Gainsight’s investigation updates, and customers should continue to visit Gainsight's status page and Salesforce's status page for updated information.","title":"HubSpot Update on Gainsight Integration Security Incident","publish_at":"2025-11-25T00:00:00.000Z","sent_at":"2025-12-02T13:55:00.246Z","notify_subscribers":false},{"id":"3a381a51-d834-4d9c-91fe-93e7154a7e62","created_at":"2025-12-01T17:52:04.834Z","updated_at":"2025-12-02T13:55:00.273Z","_type":"vendor_announcement","content":"On November 19, Salesforce reported unauthorized activity in their Gainsight integration. Out of an abundance of caution, we have temporarily removed the app from the HubSpot Marketplace and disabled the integration for any HubSpot accounts where it was in use.\r\n\r\nWe are investigating any potential impact to the HubSpot integration. At this time, there is no evidence to suggest HubSpot or our customers are impacted. We will continue our investigation and have contacted Gainsight to understand the full scope of the incident.\r\n\r\nNo additional action is needed from HubSpot customers at this time. Customers who did not integrate Gainsight in their HubSpot accounts were not impacted.\r\n\r\nFor updates on this issue, customers can visit Gainsight’s status page. For Salesforce-related updates, please visit Salesforce's status page.\r\n\r\nHubSpot will continue to monitor the situation and will provide updates in our Trust Center as necessary.","title":"Gainsight Integration Security Incident","publish_at":"2025-11-21T00:00:00.000Z","sent_at":"2025-12-02T13:55:00.246Z","notify_subscribers":false},{"id":"421be086-9a88-4b33-ae01-77a1327f6272","created_at":"2025-09-30T21:19:36.201Z","updated_at":"2025-11-14T22:19:04.367Z","_type":"vendor_announcement","content":"HubSpot is pleased to announce that the 2025 Application Pentest Attestation is now available for review. This report provides a summary of our latest third-party penetration test against the HubSpot web application, including the LLMs that power HubSpot’s AI features.\n\nHubSpot conducts regular third-party penetration tests to identify potential vulnerabilities and strengthen the security of our platform. The 2025 Attestation report details the scope of testing, the methods employed by independent security experts, key findings, and remediation information.","title":"HubSpot’s 2025 Application Pentest Attestation Now Available","publish_at":"2025-09-30T21:19:36.201Z","sent_at":"2025-09-30T21:19:36.201Z","notify_subscribers":false},{"id":"90ef9385-da67-4b54-947c-cd5d22ed90d7","created_at":"2025-09-09T20:18:10.355Z","updated_at":"2025-11-14T22:19:04.376Z","_type":"vendor_announcement","content":"### September 12, 2025\n\nOn September 11, HubSpot deactivated Drift's integration with HubSpot as a precautionary response to [Salesloft's latest update](https://trust.salesloft.com/?uid=Drift+Status+Update). \n\nWe have not observed any unauthorized access via the Drift integration beyond [what we have previously reported](https://trust.hubspot.com/?tcuUid=15b88d27-7a4c-4d06-b1dc-4ec1e135169a).\n\nHubSpot will continue to monitor the situation and provide updates in our Trust Center as necessary. \n\nAs a reminder, customers who did not integrate Drift in their HubSpot accounts were not impacted. HubSpot notified impacted customers on September 9, 2025. If you have not received email notice, there is no evidence of impact to your account.\n\n---\n\n### September 9, 2025\n\n### HubSpot Update on Salesloft Drift Security Incident\n\nOn August 26, HubSpot became aware of a security incident involving Drift, an AI chatbot tool by Salesloft. While HubSpot does not use Drift internally and was not directly impacted, we investigated Drift integrations in HubSpot customer portals and found evidence of unauthorized access to customer data via Drift Oauth tokens. HubSpot is also monitoring any potential impact to our third-party vendors. It is important to note that this issue did **not** stem from a vulnerability within the core HubSpot platform, but rather from a compromise of the Drift app connection.\n\n### What Happened?\n\nIn August 2025, Salesloft disclosed a [security incident](https://trust.salesloft.com/?uid=Drift%2FSalesforce+Security+Notification) involving their Drift chatbot service. Threat actors obtained OAuth tokens used to integrate Drift with other platforms, such as CRMs. These tokens were used to access and exfiltrate data in Drift chatbot support cases between August 8 and August 18, 2025. \n\nAlthough HubSpot is not a direct Salesloft/Drift customer, we took steps to understand how HubSpot and our customers might be impacted and began our investigation on August 26. In this initial investigation, we found no evidence that the OAuth tokens had been used maliciously by searching for known malicious indicators (also known as Indicators of Compromise or IOCs). \n\nHubSpot Security continued to investigate. On September 5, we found evidence of unauthorized access to customer data via Drift OAuth tokens. This access occurred via a new set of IOCs. By Monday, September 8, HubSpot identified a subset of customer portals with Drift integrations that were impacted through unauthorized access to customer data via Drift’s OAuth tokens. On September 9, 2025, HubSpot notified all impacted customers. \n\nCustomers who did **not** integrate Drift in their HubSpot accounts were **not** impacted. Not every HubSpot customer who installed the Drift integration was impacted by this incident. If you have not received email notice, there is no evidence of impact to you and we are continuing to monitor the situation. \n\n### Actions Taken and Next Steps\n\nHubSpot is investigating our customers’ Drift usage and our own third-party vendors to understand impact and next steps. \n\n1. Starting on August 26, we reviewed logs based on [Salesloft’s guidance](https://trust.salesloft.com/?uid=Drift%2FSalesforce+Security+Update), threat intelligence reports, and our own analysis. In our initial investigation, we found no evidence of the known IOCs. \n\n2. Our team conducted threat hunting which yielded new, additional IOCs, and on Friday, September 5, 2025, HubSpot discovered evidence of unauthorized access to customer data via compromised Drift OAuth tokens on August 28. We have shared these new IOCs below for your review. \n\n3. We have notified impacted customers and have shared steps they can take to review information that was likely exposed.\n\n4. We have been in communication with Salesloft while they have [secured their environment](https://trust.salesloft.com/?uid=Update+on+Mandiant+Drift+and+Salesloft+Application+Investigations). On August 29, 2025, Salesloft rotated compromised Drift tokens for their HubSpot integration. This revoked any unauthorized access to HubSpot and Drift data. On September 6, 2025 [Salesloft confirmed](https://trust.salesloft.com/?uid=Update+on+Mandiant+Drift+and+Salesloft+Application+Investigations) that the incident had been fully contained in their environment. \n\n5. HubSpot has been in communication with our vendors to understand how HubSpot may have been impacted by this event. A small number of our vendors have confirmed that they were impacted, and that some HubSpot data was in-scope. We have conducted thorough investigations and at this time, we have found: \n- no evidence of customer data being exposed through third party providers that support the product \n- no evidence of any sensitive HubSpot data being exposed through our corporate supply chain. \n\nWe will continue monitoring our vendors.  \n\nWith these actions we consider the incident closed, but we will continue to monitor the situation and provide updates in our Trust Center as necessary. \n\nOur investigation revealed a number of new Indicators of Compromise which we’ve provided in the TXT file here: https://www.hubspot.com/hubfs/Security/2025-09-09-drift-iocs.txt. Our intelligence sources indicate these IPs are operated by Oculus Proxies.","title":"HubSpot Update on Salesloft Drift Security Incident","publish_at":"2025-09-09T20:18:10.355Z","sent_at":"2025-09-09T20:18:10.355Z","notify_subscribers":false},{"id":"9202c53f-a521-4527-9c17-9e9249364679","created_at":"2025-08-13T17:57:22.329Z","updated_at":"2025-11-14T22:19:04.382Z","_type":"vendor_announcement","content":"### Threat Overview\n\nHubSpot is aware of a [threat report](https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion) detailing sophisticated voice phishing (vishing) campaigns where attackers impersonate IT support personnel to trick victims into [authorizing malicious applications](https://attack.mitre.org/techniques/T1671/) to be connected to their Salesforce instances. At this time, we have no evidence that HubSpot customers are being targeted. However, since these attacks have been successfully used against customers of SaaS products with associated app marketplaces, we believe similar techniques could pose a significant risk to HubSpot customers.\n\n### How the Attack Works\n\nAttackers begin by calling victims and posing as IT support staff from either the victim's organization or the SaaS provider itself. They manipulate employees into installing a malicious app integration in their SaaS instance using convincing telephone-based social engineering. Once authorized, the malicious app gains broad access to your data which allows attackers to extract information from the compromised environment. The malicious app remains connected and authorized until manually revoked which allows attackers to return and extract additional data over time. The stolen data is either sold on dark web markets, used for further attacks, or leveraged in extortion attempts against the victim organization.\n\n### Red Flags to Watch For\n\nBe suspicious of unsolicited calls claiming to be from IT support or HubSpot, especially those using urgency tactics. Other warning signs include requests to:\n\n- install or authorize new applications\n- visit specific websites or enter codes\n- gain credentials, MFA codes, or permissions to remotely access your computer\n\nWhen reviewing app authorization requests, watch for apps with names that mimic legitimate tools but have slight variations, apps requesting excessive permissions, authorization requests from unknown or suspicious-looking applications, and apps that don't match your organization's approved software list.\n\nHubSpot displays clear warnings when you're connecting an app that hasn't been reviewed or verified by HubSpot - pay attention to warning banners within your portal.\n\n### How to Protect Yourself\n\nBefore authorizing any connected app, pay attention to warnings displayed by HubSpot. If HubSpot shows a warning that you're connecting an unverified app, take extra caution and verify the app's legitimacy.\n\n- Only authorize apps that are officially approved by your organization, carefully examine what data access the app is requesting, and ensure the app comes from a trusted developer or is officially endorsed by HubSpot.\n- Have a super-admin user carefully [review which users have access to install Marketplace apps](https://knowledge.hubspot.com/user-management/hubspot-user-permissions-guide#:~:text=App%20Marketplace%20access%3A%20toggle%20the%20App%20Marketplace%20access%20switch%20on%20to%20let%20the%20user%20install%20apps%20from%20the%20HubSpot%20Marketplace%20and%20third%2Dparty%20websites.%20Certain%20integrations%20will%20still%20require%20specific%20permissions.%C2%A0), and revoke this access for any user unless it is necessary.\n- Never provide credentials, MFA codes, or authorize apps during unsolicited phone calls.\n- Report suspicious calls to your IT security team immediately, be skeptical of urgent requests especially those involving data access, and when in doubt, hang up and verify through official channels.\n\n### Key Takeaway\n\nRemember: HubSpot will never call you asking to install applications or provide credentials. Any such requests should be treated as potential social engineering attempts. When in doubt, verify independently through official channels before taking any action. This type of attack relies entirely on tricking users—there are no technical vulnerabilities being exploited. Your vigilance and following proper verification procedures are the best defenses against these sophisticated social engineering campaigns. If you believe you have been targeted by this attack, [report it to HubSpot support](https://www.google.com/url?q=https://knowledge.hubspot.com/help-and-resources/get-help-with-hubspot&sa=D&source=docs&ust=1755113493190076&usg=AOvVaw2DzyPClCOu1gtch-32zI7T).","title":"Security Advisory: Malicious App Vishing Campaigns","publish_at":"2025-08-13T17:57:22.329Z","sent_at":"2025-08-13T17:57:22.329Z","notify_subscribers":false},{"id":"cdf7233d-4425-46f1-8d95-8f422492a84d","created_at":"2025-07-24T13:22:06.817Z","updated_at":"2025-11-14T22:19:04.386Z","_type":"vendor_announcement","content":"HubSpot is excited to announce a new Security Contact role in all customer accounts. To access it, users with [Billing Admin](https://knowledge.hubspot.com/account/add-a-billing-admin-to-your-account) permissions can log in and navigate to Company Name (top right) > Account & Billing > Company Info. \n\nWe strongly recommend designating your Cybersecurity and Incident Response team, Chief Information Security Officer, or other individual best suited to receive Security notifications from HubSpot. Distribution lists are allowed, and this role does not have to be a user in the HubSpot portal. For more information on setting up this new role, and your Account’s other Primary Contacts, please visit our [Knowledge Base](https://knowledge.hubspot.com/account/how-can-i-update-my-company-and-billing-info).","title":"HubSpot Product Update - New Security Contact Role","publish_at":"2025-07-24T13:22:06.817Z","sent_at":"2025-07-24T13:22:06.817Z","notify_subscribers":false},{"id":"4a55a7ac-35fa-4363-8bca-7244e2a08da9","created_at":"2025-06-23T16:56:35.570Z","updated_at":"2025-11-14T22:19:04.390Z","_type":"vendor_announcement","content":"We are pleased to announce that HubSpot has obtained independent HIPAA attestation, now available for customers on the HubSpot Trust Center. This compliance achievement demonstrates the effectiveness of HubSpot’s security practices in supporting our HIPAA-regulated customers, reinforcing our ongoing commitment to safeguarding Protected Health Information (PHI) and to helping organizations meet their HIPAA obligations with confidence.\n\nAdditionally, our 2025 SOC 2 Type II report is now available for download on the Trust Center. The report covers the period of 5/1/2024 - 4/30/2025 and includes several new controls and enhancements to existing controls that strengthen our security and compliance posture. We’ve detailed these new controls and control enhancements in an updated version of our Compliance FAQs, available on the Trust Center.\n\nAll systems and features that have launched in General Availability on or before 4/30/2025 are included in the report, including [Breeze](https://www.hubspot.com/products/artificial-intelligence) and our three new Regional Data Centers.","title":"HIPAA Attestation & 2025 SOC 2 Report Now Available","publish_at":"2025-06-23T16:56:35.570Z","sent_at":"2025-06-23T16:56:35.570Z","notify_subscribers":false},{"id":"24e236f0-7573-461c-bec9-ebf7ab156ed7","created_at":"2025-03-17T21:40:37.584Z","updated_at":"2025-11-14T22:19:04.394Z","_type":"vendor_announcement","content":"HubSpot is aware of recent phishing email campaigns designed to look like HubSpot account notifications. The emails have used various subject lines such as “New Login Detected,” “Credential Reset Request,” and “Urgent: Review Your Recent Email Campaign.” The emails appear to come from a HubSpot sender, imply that certain features within a HubSpot portal have been temporarily restricted, and may contain a malicious link to review certain activity.\n\nThese emails are fraudulent and were not sent from HubSpot. Please do not click any link or provide any personal information, such as email addresses or passwords, to the sender or through the web pages linked within these emails. If you provided your username or password, or suspect your portal has been compromised, please reset your password and [review your account activity](https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history). \n\nAll legitimate communications from HubSpot, including password reset, account validation, and renewal emails, are sent from the **hubspot.com** domain. If you receive a suspicious email, be sure to check the sender’s address and exercise caution with any links or attachments. HubSpot offers the ability for Super Admins to [restrict the available login methods](https://knowledge.hubspot.com/account-security/restrict-which-login-methods-users-can-use-to-access-your-account) for users in their account, or set up [Passkeys for passwordless authentication](https://knowledge.hubspot.com/account-management/set-up-and-log-in-with-passkeys). For users with two-factor authentication (2FA) enabled, please be sure to enter 2FA verification codes on official HubSpot login pages only. \n\nWhen logging into HubSpot, ensure that you verify the domain is a legitimate HubSpot domain at **hubspot.com**. These phishing campaigns are using fake domains designed to appear similar to a HubSpot domain, but they are not legitimate. Our investigation is ongoing and we will provide updates on this page as needed. If you receive this, or any other suspicious email impersonating HubSpot, please report it to abuse@hubspot.com.","title":"Customer Advisory - Fraudulent HubSpot Account Notification Emails","publish_at":"2025-03-17T21:40:37.584Z","sent_at":"2025-03-17T21:40:37.584Z","notify_subscribers":false},{"id":"dd889d5b-e48f-4159-beec-87af85d07404","created_at":"2025-02-06T21:50:02.046Z","updated_at":"2025-11-14T22:19:04.399Z","_type":"vendor_announcement","content":"HubSpot is aware of recent phishing email campaigns designed to look like HubSpot account notifications. The emails have used various subject lines such as “HubSpot SPAM Complaint Notice” and “Account Restriction Notice.” The emails appear to come from a HubSpot sender, imply that certain features within a HubSpot portal have been temporarily restricted, and may contain a malicious link to “Review Complaint”.\n\nThese emails are fraudulent and were not sent from HubSpot. Please do not click any link or provide any personal information, such as email addresses or passwords, to the sender or through the web pages linked within these emails. If you provided your username or password, or suspect your portal has been compromised, please reset your password and [review your account activity](https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history). \n\nAll legitimate communications from HubSpot, including password reset, account validation, and renewal emails, are sent from the hubspot.com domain. If you receive a suspicious email, be sure to check the sender’s address and exercise caution with any links or attachments.\n\nOur investigation is ongoing and we will provide updates on this page as needed. If you receive this, or any other suspicious email impersonating HubSpot, please report it to [Customer Support](https://knowledge.hubspot.com/help-and-resources/get-help-with-hubspot) or your Customer Success Manager so we can investigate.","title":"Customer Advisory - Fraudulent HubSpot Account Notification Emails","publish_at":"2025-02-06T21:50:02.046Z","sent_at":"2025-02-06T21:50:02.046Z","notify_subscribers":false},{"id":"9536d71f-58b8-49dd-8798-d0bd545446f1","created_at":"2025-02-04T17:03:04.123Z","updated_at":"2025-11-14T22:19:04.402Z","_type":"vendor_announcement","content":"HubSpot is pleased to announce that an updated version of our Security & Compliance Overview is now available on the HubSpot Trust Center for review. This document serves as HubSpot’s in-depth guide to our Security, Compliance, and Privacy posture. \n\nThe Security Overview will also be available localized in all of HubSpot’s supported languages (German, Spanish, French, Japanese, and Portuguese) in the coming weeks.\n\nWe have also published a new DORA FAQ to address customer questions around the Digital Operational Resilience Act (DORA), and have updated the CAIQ pre-filled questionnaire.","title":"Updated Security Overview Now Available ","publish_at":"2025-02-04T17:03:04.123Z","sent_at":"2025-02-04T17:03:04.123Z","notify_subscribers":false},{"id":"bc7f6fc6-42ca-4163-a92a-148af940cffe","created_at":"2024-10-31T16:01:51.636Z","updated_at":"2025-11-14T22:19:04.427Z","_type":"vendor_announcement","content":"On October 30, 2024, at 6:45 pm ET, HubSpot was made aware of a vulnerability in Lottie Player, a widely-used JavaScript animation library which enables animations created in Adobe After Effects to integrate into web and mobile applications. Affected customers may have included Lottie Player on their HubSpot website independently, or may have used a Marketplace template which included Lottie Player.\n\nAffected customers would have seen an unintended pop-up on their webpage(s) directing them to “Connect Wallet” or “Get a Wallet”.\n\nThe vulnerability has been identified and Lottie Player maintainers implemented a fix at 7:30 pm ET. For more context on the supply chain attack targeting Lottie Player, [see LottieFiles’ official statement and timeline here](https://x.com/LottieFiles/status/1851848602093777273).\n\nNo additional action is needed from customers. \n\nIf you are concerned about the security of Lottie Player, please ensure you are running the latest released version (2.0.8), or you can remove associated code from your HubSpot website. This may mean removing a template or working with template creators to find alternative modules. For specific guidance, we encourage you to review this information with your IT or Security team.","title":"HubSpot Update on October 2024 Lottie Player Security Incident","publish_at":"2024-10-31T16:01:51.636Z","sent_at":"2024-10-31T16:01:51.636Z","notify_subscribers":false},{"id":"07721852-5387-4e04-ba9c-e1d76b8c4da9","created_at":"2024-10-18T15:09:57.996Z","updated_at":"2025-11-14T22:19:04.430Z","_type":"vendor_announcement","content":"HubSpot is encouraging customers to stay alert of bad actors who may be impersonating HubSpot employees. \n\nThrough recent reports, we have found that bad actors are [spoofing](https://www.fcc.gov/spoofing) HubSpot support numbers and/or impersonating HubSpot employees in an attempt to gain access to HubSpot accounts.  \n\n**Here’s how to spot a HubSpot impersonator:**\n+ Receiving an unprompted call from a HubSpot employee. HubSpot’s support team will not proactively reach out to you unless you have initiated a [call back](https://knowledge.hubspot.com/help-and-resources/get-help-with-hubspot#professional-or-enterprise) through your account. If you are unsure whether a call is from a legitimate HubSpot employee, hang up and contact us using [one of our contact methods](https://knowledge.hubspot.com/help-and-resources/get-help-with-hubspot?). \n\n+ The caller instills a sense of fear or urgency. We will never use scare tactics to convince you to share account information. We will never ask you to share your HubSpot account credentials, including your password and two-factor authentication code(s).\n\nEnsure your account is secure by: \n+ Regularly reviewing all users on your HubSpot account(s) to [ensure no unrecognized users have been added](https://knowledge.hubspot.com/user-management/deactivate-hubspot-users#remove-a-user), and remove users who no longer need access to reduce risk.\n+ Requiring [two-factor authentication](https://knowledge.hubspot.com/account-security/set-up-two-factor-authentication-for-your-hubspot-login) for all accounts and HubSpot users. \n+ Consider [IP allowlisting](https://knowledge.hubspot.com/account-security/limit-logins-to-trusted-ip-addresses?hubs_content=knowledge.hubspot.com%2Faccount-security%2Flimit-logins-to-trusted-ip-addresses&hubs_content-cta=kb-breadcrumbs__item), which allows you to limit logins to trusted IP addresses.\n+ Reviewing your [account activity](https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history) and reporting any suspicious activity with [HubSpot Support](https://knowledge.hubspot.com/help-and-resources/get-help-with-hubspot?). \n+ Visiting our [security health tool](https://knowledge.hubspot.com/account-security/manage-your-account-security-using-hubspost-security-health) to learn about more ways to improve your account security.","title":"Customer Advisory - Bad Actors Impersonating HubSpot Employees","publish_at":"2024-10-18T15:09:57.996Z","sent_at":"2024-10-18T15:09:57.996Z","notify_subscribers":false},{"id":"5c4c6605-4195-480d-aa9c-63d9a76de595","created_at":"2024-09-18T14:53:35.659Z","updated_at":"2025-11-14T22:19:04.434Z","_type":"vendor_announcement","content":"HubSpot is thrilled to announce a new product feature which allows customers to store [Sensitive Data within HubSpot](https://www.hubspot.com/products/sensitive-data). We have published a new Sensitive Data FAQ and Sensitive Data Implementation Guide to the Trust Center to help empower your understanding and use of these new product features.\n\nWe have also updated a number of other Trust Center resources, including the Compliance FAQs, and the CAIQ and SIG pre-filled questionnaires.","title":"New Sensitive Data Resources & Updated Security Documents Now Available","publish_at":"2024-09-18T14:53:35.659Z","sent_at":"2024-09-18T14:53:35.659Z","notify_subscribers":false},{"id":"620ac0a1-9460-4afe-91ee-68b3393c0c26","created_at":"2024-08-22T20:34:23.784Z","updated_at":"2025-11-14T22:19:04.437Z","_type":"vendor_announcement","content":"HubSpot is aware of recent phishing email campaigns designed to look like HubSpot account notifications. The emails have used various subject lines such as “New Login Detected/Location” and “Action Required: Validate Your Account.” The emails appear to come from a HubSpot sender, imply a potential account compromise and may contain a malicious link to \"Re-Login\" or \"Validate your account.\"\n\n**These emails are fraudulent and were not sent from HubSpot**. Please do not click any link or provide any personal information, **such as email addresses or passwords**, to the sender or through the web pages linked within these emails. \n\nAll legitimate communications from HubSpot, including password reset, account validation, and renewal emails, are sent from the **hubspot.com** domain. Please review the “sent from:” email address if you receive suspicious or unusual emails.\n\nOur investigation is ongoing and we will provide updates on this page as needed. If you receive this, or any other suspicious email impersonating HubSpot, please report it to [Customer Support](https://knowledge.hubspot.com/help-and-resources/get-help-with-hubspot) or your Customer Success Manager so we can investigate.","title":"Customer Advisory - Fraudulent HubSpot Account Notification Emails","publish_at":"2024-08-22T20:34:23.784Z","sent_at":"2024-08-22T20:34:23.784Z","notify_subscribers":false},{"id":"7b86bb97-ca64-4665-8788-82381bb7b0bf","created_at":"2024-08-12T16:33:22.165Z","updated_at":"2025-11-14T22:19:04.441Z","_type":"vendor_announcement","content":"HubSpot is excited to announce the release of our AI Trust FAQs, now available for download in the Trust Center. This new resource addresses common questions surrounding the security, privacy, compliance, and governance of AI products offered by HubSpot.\n\nIn addition, the 2024 Application Pentest Attestation is now available for download. This report provides a summary of our latest third-party penetration test against the HubSpot web application.","title":"HubSpot’s AI Trust FAQs and 2024 Application Pentest Attestation Now Available","publish_at":"2024-08-12T16:33:22.165Z","sent_at":"2024-08-12T16:33:22.165Z","notify_subscribers":false},{"id":"e322a2e1-38e5-44f9-9a3b-cceeb4680c86","created_at":"2024-06-28T22:05:51.784Z","updated_at":"2025-11-14T22:19:04.444Z","_type":"vendor_announcement","content":"### July 12, 2024\n\n**HubSpot June 2024 Security Incident Investigation Complete**\n\nAs of July 12, 2024, our investigation is complete. At the close of our investigation, we confirmed that bad actors were able to gain unauthorized access to less than 30 HubSpot customer portals. All impacted customers have been notified via email and steps have been taken to secure their accounts. \n\nThe incident began June 22, 2024 and was resolved by June 27, 2024. We have seen no new instances of unauthorized access in 14 days. \n\nIn response to this incident, our Security team: \n* Deactivated and blocked bad actor accounts as we identified them;\n* Audited login and signup activity to identify all affected customers;\n* Reset passwords of some users based on the results of the investigation;\n* Provided audits of portal activity to impacted customers.\n\nThe core tenets of HubSpot’s security program are to safeguard customer data and to maintain customer trust. HubSpot uses a defense-in-depth approach to implement layers of security throughout our organization. We’re passionate about developing new security controls and continuously refining our existing ones to protect our customers. Please see our [Security Overview document](https://trust.hubspot.com/?itemUid=382f924d-54f3-43a8-a9df-c39e6c959958&source=click) and request a copy of our [SOC 2 Type 2 Report](https://trust.hubspot.com/?itemUid=f4951085-df2e-4fac-9d43-60b796478b2e&source=click) for more information on our security program overall.\n\n---\n\n### July 1, 2024\n\n### July 1, 2024 Update: HubSpot June 2024 Security Incident\n\nHubSpot continues to investigate this incident, however as of 12pm ET on July 1, 2024, we have seen no new instances of unauthorized access in over 90 hours. We have contacted all impacted customers at this time. We will post an update at the end of the investigation.\n\n---\n\n### June 28, 2024\n\nOn June 22, 2024, HubSpot identified a security incident that involved bad actors targeting a limited number of HubSpot customers and attempting to gain unauthorized access to their HubSpot accounts.\n\nHubSpot triggered our incident response procedures, and since June 22, we have contacted impacted customers and taken necessary steps to revoke the unauthorized access to protect our customers and their data. In addition, the HubSpot Security team has been actively investigating and blocking attempts to gain access to customer accounts.\n\nWhile our investigation is still underway, we believe based on our initial assessment that the bad actors were able to gain unauthorized access to less than 50 HubSpot accounts.\n\nAs of 4:00 pm ET, June 28, we have seen no new instances of unauthorized access in the last 24 hours, and we have contacted all impacted customers at this time.\n\nThough the investigation is ongoing, based on our current assessment of the incident, we believe that the impact will be isolated to a small subset of the HubSpot customer base. We will post an update at the end of the investigation in the spirit of continued transparency. We have also posted this update to our Investor Relations page at https://ir.hubspot.com/news-releases/news-release-details/hubspots-statement-regarding-june-22-2024-security-incident.","title":"HubSpot June 2024 Security Incident","publish_at":"2024-06-28T22:05:51.784Z","sent_at":"2024-06-28T22:05:51.784Z","notify_subscribers":false},{"id":"2634cffd-2fc2-482c-a409-a48674a82056","created_at":"2024-06-24T13:58:12.894Z","updated_at":"2025-11-14T22:19:04.448Z","_type":"vendor_announcement","content":"We are proud to share that HubSpot is now certified by the EU Cloud Code of Conduct for demonstrating GDPR compliance as a cloud service provider. \n\nAchieving the Code’s Level 2 Compliance Mark reinforces our commitment to safeguarding our customer’s data and our high standards for security, privacy and compliance.\n\nThe report is available for download from the HubSpot Trust Center, and the [EU Cloud Code of Conduct public register](https://eucoc.cloud/fileadmin/cloud-coc/files/reports/202406_ReportVerificationDoA_HubSpot_2024LVL02SCOPE5419.pdf).","title":"HubSpot Achieves EU Cloud Code of Conduct Level 2 Compliance, Report Now Available","publish_at":"2024-06-24T13:58:12.894Z","sent_at":"2024-06-24T13:58:12.894Z","notify_subscribers":false},{"id":"bff4f78b-99f4-4b0d-ac61-1af2ca66e1aa","created_at":"2024-06-12T13:59:48.403Z","updated_at":"2025-11-14T22:19:04.451Z","_type":"vendor_announcement","content":"HubSpot is pleased to announce the release of our 2024 SOC 2 Type II report, now available for download in the Trust Center. The report covers the period of 5/1/2023 - 4/30/2024 and includes several new controls, as well as enhancements to existing controls, that strengthen our security and compliance posture. All systems and features that have launched in General Availability on or before 4/30/2024 are included in the report, including most AI-powered features (excluding ChatSpot).\n\nIn addition to our SOC 2, we’re excited to share the following resources as part of our  commitment to accessible & transparent information regarding our approach to security, privacy and compliance:\n\n- Sensitive Data Beta FAQs - New!\n- Compliance FAQs - New!\n- SOC 3 - Updated\n- Corporate Pentest Attestation - Updated\n- Pre-filled security questionnaires:\n    - CAIQ v4 - Updated\n    - SIG Lite - Updated\n- Clearbit SOC 2 Report - Legacy\n- Clearbit TRUSTe Certification - Legacy","title":"HubSpot’s 2024 SOC 2 and Updated Security Documents Now Available","publish_at":"2024-06-12T13:59:48.403Z","sent_at":"2024-06-12T13:59:48.403Z","notify_subscribers":false},{"id":"65faf343-fa19-4d0f-b88b-31e2e9054565","created_at":"2024-05-14T20:29:55.766Z","updated_at":"2025-11-14T22:19:04.455Z","_type":"vendor_announcement","content":"On May 2, 2024, HubSpot was notified by our service provider, Dropbox, about [a security incident involving their e-signatures service](https://sign.dropbox.com/blog/a-recent-security-incident-involving-dropbox-sign). This service is used by some HubSpot customers as part of the [quoting tool](https://knowledge.hubspot.com/quotes/use-e-signatures-with-quotes).\n\n**What Happened:** \nOn April 24, Dropbox discovered a third party gained unauthorized access to Dropbox Sign, a tool used by some HubSpot customers in Sales Hub and Commerce Hub. \n\nBased on Dropbox’s investigation, HubSpot customers’ contacts who have received or signed a quote, up to and including April 24, through our [e-signatures tool](https://knowledge.hubspot.com/quotes/use-e-signatures-with-quotes) had their email address and name exposed. Additionally, the email address and name of any countersigner on your HubSpot portal has also been exposed. However, there is no evidence to suggest unauthorized access to the contents of HubSpot customers’ quotes, or their payment information.\n\nCustomers or customer contacts **who created a Dropbox Sign account** also had information such as email addresses, usernames, phone numbers and hashed passwords exposed. In addition, general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication may have been compromised. Dropbox will be contacting these individuals directly.\n\n**Actions to Date & Next Steps:**\nHubSpot rotated any [API keys and OAuth tokens](https://developers.hellosign.com/api/reference/authentication/) that may have been exposed to re-secure our e-signature integration. Additionally, we have rotated the passwords for our Dropbox Sign user accounts and, at this time, have found no evidence of unauthorized access to HubSpot’s Dropbox Sign account. See what actions Dropbox has taken [here](https://sign.dropbox.com/blog/a-recent-security-incident-involving-dropbox-sign).\n\nAt this point, all potentially affected customers have been notified via email. We will continue to monitor the situation and provide updates to affected customers if there are any changes that impact your HubSpot account.","title":"HubSpot Update on Dropbox Sign Security Incident","publish_at":"2024-05-14T20:29:55.766Z","sent_at":"2024-05-14T20:29:55.766Z","notify_subscribers":false},{"id":"a9901376-c97d-47f8-a6c4-041c59188061","created_at":"2023-10-19T19:03:33.430Z","updated_at":"2025-11-14T22:19:04.459Z","_type":"vendor_announcement","content":"Recently two zero-day vulnerabilities were announced, one related to [HTTP/2](https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/) ([CVE-2023-44487](https://www.cve.org/CVERecord?id=CVE-2023-44487)) and the other related to the libwebp library ([CVE-2023-4863](https://nvd.nist.gov/vuln/detail/CVE-2023-4863)).\n\nHubSpot has conducted thorough investigations and is fully protected against both vulnerabilities. \n\nThere is no evidence of any exploitation, and there is no action required from HubSpot customers. We have checked with our sub-processors regarding both vulnerabilities, and are monitoring their responses.","title":"HubSpot Update on HTTP/2 and Libwebp Vulnerabilities","publish_at":"2023-10-19T19:03:33.430Z","sent_at":"2023-10-19T19:03:33.430Z","notify_subscribers":false},{"id":"35fde3ee-ea5c-4bd0-a7f0-18a28663f388","created_at":"2023-06-14T14:54:59.682Z","updated_at":"2025-11-14T22:19:04.462Z","_type":"vendor_announcement","content":"Recently two zero-day vulnerabilities were announced related to the MOVEit file transfer application. HubSpot has conducted a careful review of our Product and Corporate infrastructures and can confirm that there is no use of the MOVEit applications internally at HubSpot. Based upon our review, HubSpot is not impacted by CVE-2023-34362 or CVE-2023-35036.\n\nAdditionally, we have reached out to our 3rd party vendors and have confirmed that at this time, there is no evidence of compromise related to these CVEs to any of HubSpot's 3rd party vendors.","title":"HubSpot Not Impacted by MOVEit Vulnerabilities","publish_at":"2023-06-14T14:54:59.682Z","sent_at":"2023-06-14T14:54:59.682Z","notify_subscribers":false},{"id":"d1828bef-3c2a-497e-a39b-1312c8869a4c","created_at":"2023-06-13T14:54:35.198Z","updated_at":"2025-11-14T22:19:04.466Z","_type":"vendor_announcement","content":"HubSpot is excited to announce the release of our 2023 SOC2 Type 2 and SOC3 reports, which are now available for download in the Trust Center. The reports cover the period from 5/1/22-4/30/23. Our new reports include all Hubs in one report, including OpsHub which was in a standalone report for the previous period.","title":"HubSpot's 2023 SOC 2 Type 2 & SOC 2 Type 3 Reports Now Available","publish_at":"2023-06-13T14:54:35.198Z","sent_at":"2023-06-13T14:54:35.198Z","notify_subscribers":false},{"id":"8e89d14c-4d42-4d31-aef8-f224f4065caf","created_at":"2023-03-24T14:46:27.012Z","updated_at":"2025-11-14T22:19:04.469Z","_type":"vendor_announcement","content":"### June 16, 2022\n\n### Update to HubSpot's SOC 2 & SOC 3 Now Available\n\nFor this year’s audit, we asked for a second helping of SOC reports.  \n\nGiven the release timing and infrastructure of HubSpot’s new product, Operations Hub (Ops Hub), we elected to cover this in a separate SOC 2 Type II Report. HubSpot’s Ops Hub SOC 2 report covers a 6 month period dating from 11/1/21-4/30/22.  The CRM, Marketing Hub, Sales Hub, Service Hub, and CMS Hub are covered under the HubSpot Platform SOC 2 report. \n\n##### Report Changes\n- In our efforts to comply with the EU data localization requirements per the GDPR, HubSpot launched a new EU Data Center on 07/19/2021. SOC 2 controls were designed/implemented/validated for the EU instances of in-scope systems prior to the EU data center launch and these systems are included in our new report!\n- As of 01/15/2022, HubSpot launched a new HubSpot Payments Tool powered by Stripe. SOC 2 controls were designed/implemented/validated for Stripe prior to the public launch and are included in our new report.\n\n---\n\n### July 26, 2021\n\n### HubSpot's SOC 2 Type 2 & SOC 3 Now Available for Download!\n\nWe are delighted to announce that HubSpot now has a SOC 2 Type II report and SOC 2 report available for our customers and prospects!\nThese reports represent an independent third-party verification that HubSpot has specific controls in place governing the security and availability of our product, as well as the confidentiality of our customers' data.","title":"HubSpot's SOC 2 & SOC 3 Reports","publish_at":"2023-03-24T14:46:27.012Z","sent_at":"2023-03-24T14:46:27.012Z","notify_subscribers":false},{"id":"e5e2d996-a587-4407-8142-2bc1f2e9bf60","created_at":"2023-03-24T14:40:50.683Z","updated_at":"2025-11-14T22:19:04.473Z","_type":"vendor_announcement","content":"### January 20, 2023\n\n### HubSpot's TIA Now Available in More Languages!\n\nWe're excited to share that our TIA is now available in French, German, Portuguese, and Spanish to help support our EMEA customers.\n\n---\n\n### May 10, 2022\n\n### HubSpot's TIA Now Available for Download!\n\nWe're delighted to announce that HubSpot now makes its Transfer Impact Assessment available for customers and prospects on a self-serve basis. \n\nThe new SCCs require data exporters (i.e. customers) to document their data transfer. Our TIA includes infomation to support customers in conducting a risk assessment of transferring data outside of the EU.","title":"HubSpot's Transfer Impact Assessment (TIA)","publish_at":"2023-03-24T14:40:50.683Z","sent_at":"2023-03-24T14:40:50.683Z","notify_subscribers":false},{"id":"8a0a90b7-e53d-4446-ae53-fe7c71fcb1b0","created_at":"2023-01-30T14:54:20.443Z","updated_at":"2025-11-14T22:19:04.477Z","_type":"vendor_announcement","content":"### September 6, 2022\n\n### Update to HubSpot's Response to Log4J\n\nA vulnerable version of Log4j was discovered in HubSpot’s infrastructure by a security researcher and responsibly  disclosed to us through the HubSpot bug bounty program on August 28, 2022. \n\nHubSpot investigated the reported findings and performed the following actions:\n- Confirmed that a small legacy portion of our logging infrastructure contained the vulnerable version of Log4j\n- Patched and fixed the affected service to remove the vulnerability\n- Inspected multiple log sources to confirm that no malicious attempts to exploit the vulnerability had been found \n\nAt this time, no action is required by HubSpot customers. HubSpot Security will continue to monitor for any potential exposure to this vulnerability and assess additional safeguards to help prevent future exploitation. We will update this page as needed.\n\n---\n\n### December 14, 2021\n\n### HubSpot's Response to Log4J\n\nHubSpot is aware of ongoing security issues related to open-source Apache “Log4j2”. We know that the security of your HubSpot tools is especially important given the uncertainty around these events. HubSpot customer-facing tools do not use Log4j2 as a logging tool, and are not susceptible to the vulnerabilities that have been discovered thus far.\n\nWe are committed to continued monitoring of the situation, thorough review of the HubSpot tools as new information becomes available, and to do our best to provide you with the information you need to feel secure for your business.\n\n#### Log4J Vulnerability Background\nLog4j2 is an open-source Java-based logging tool maintained by the Apache Software Foundation, and used by many services.\n\n#### HubSpot Response & Actions Taken\nWe have performed a thorough investigation and found no HubSpot customer-facing tools that use Log4j2. \n\nSince we became aware of the vulnerability, HubSpot has taken a number of steps to identify and mitigate any risk to our products and our customers. \nWe have implemented:\n- Full scans of all production services to confirm that they don't have a dependency on the Log4j2 library. Precautions to prevent use of the vulnerable version of Log4j2 in future systems. \n- Updated Web Application Firewall rules to avert exploitation attempts.\n- We will continue regular vulnerability scans on all HubSpot systems as outlined in our security resources.\n- We have requested details of any potential vulnerabilities from all sub-processors of the HubSpot product, and are monitoring their responses. HubSpot’s most important sub-processors, including Amazon Web Services, Google Cloud, Cloudflare, and Snowflake were either not vulnerable or have already begun patching the vulnerability across their networks.\n\n#### Conclusion & Update \nHubSpot Corporate Security, which monitors the internal tools that HubSpot employees use, is systematically reviewing each HubSpot Corporate internal system. If any system is found to be vulnerable, we will rapidly patch the instance, or apply other mitigation tactics as advised by the vendors we use.\n\nWe will continue to investigate any potential exposure to this vulnerability and alert our customers as required. At this time, HubSpot customers do not need to take any action related to their use of HubSpot software.\n\n If you have specific questions related to this event, please contact HubSpot Support.","title":"HubSpot's Response to Log4J","publish_at":"2023-01-30T14:54:20.443Z","sent_at":"2023-01-30T14:54:20.443Z","notify_subscribers":false}],"subprocessors":[],"products":[{"id":"1cf14fb8-570c-4547-b85c-03d1a18fa138","created_at":"2025-11-14T15:27:16.132Z","updated_at":"2025-11-15T02:56:23.118Z","_type":"vendor_product","name":"AI Model Cards","description":"Check out HubSpot's AI Model Cards [here](https://trust.hubspot.com/ai).\r\n\r\nAt HubSpot, we leverage both proprietary AI models and those from third-party service providers. These include generative AI models for text and image processing, generation, and content moderation. The models detailed on the model cards page power HubSpot's generative AI capabilities and are categorized by product, use case, and function.","data_access":"","certifications":[]},{"id":"248cf2f6-05dd-44f8-ac5e-5613f8f66ea7","created_at":"2025-11-14T17:03:27.234Z","updated_at":"2026-01-06T15:48:24.326Z","_type":"vendor_product","name":"Other AI Trust Resources","description":"**AI Security**\r\nReview our [AI Trust FAQs](https://trust.hubspot.com/d/hub-spot-ai-trust-fa-qs/dncFvX) for detailed information on AI security controls, privacy & data use, and legal compliance.\r\n\r\n**AI Trust and Safety**\r\nAt HubSpot, we are committed to doing the right thing. Our approach to AI is rooted in trust, transparency, and accountability. Check out our AI Trust & Safety [here](https://www.hubspot.com/products/artificial-intelligence/ai-trust).","data_access":"","certifications":[]}],"pvr_translations":[],"canonical_assets":[]},"report_type":"full","points":61,"max_points":63,"score":96,"top_percentile":10,"philosophy":"[HubSpot](www.hubspot.com) is the customer platform that helps businesses grow better with AI-powered engagement hubs, a Smart CRM, and a wide-ranging, connected ecosystem.\r\n\r\nHubSpot’s primary security focus is to safeguard our customers’ data. To this end, HubSpot has implemented a comprehensive security program, with teams dedicated to Corporate, Product, Infrastructure, and Physical Security that partner with Compliance, Legal, and Privacy to own the governance process. Our Chief Information Security Officer oversees the implementation of security safeguards across the HubSpot enterprise.","key_people":[{"name":"","title":""}],"products":[],"roadmap":"We’ve updated our Trust Center!\r\n\r\nOur goal is to provide a simple, fast, and efficient way for our customers to learn about HubSpot’s Security and Compliance posture. As part of our commitment to transparency and Customer Trust, we want to make it as easy as possible to find security documents, compliance reports, and answers to your security-specific questions. \r\n\r\nAs part of our new Trust Center experience, you’ll find new features such as a Knowledge Base of frequently asked questions & answers as well as improved organization of our Security and Compliance documentation available for download. \r\n\r\nStay tuned for additional new features, and be sure to subscribe to Trust Center updates for our latest news and announcements! ","third_party_vendors":[],"summary_indicators":[{"enabled":true,"link_url":"","indicator":"annual_third_party_audits"},{"enabled":true,"link_url":"https://status.hubspot.com/","indicator":"has_status_page"},{"enabled":true,"link_url":"","indicator":"has_drp"},{"enabled":true,"link_url":"https://developers.hubspot.com/docs","indicator":"has_api"},{"enabled":true,"link_url":"http://legal.hubspot.com/privacy-policy","indicator":"has_privacy_policy"},{"enabled":true,"link_url":"http://hackerone.com/hubspot","indicator":"has_bug_bounty"},{"enabled":false,"link_url":"https://legal.hubspot.com/dpa","indicator":"enter_into_dpa"},{"enabled":false,"link_url":"","indicator":"has_mdm_program"},{"enabled":false,"link_url":"","indicator":"has_iam"},{"enabled":false,"link_url":"","indicator":"deletes_cust_data"},{"enabled":true,"link_url":"https://legal.hubspot.com/sub-processors-page","indicator":"subproccessor_list"},{"enabled":true,"link_url":"https://trust.hubspot.com/d/hub-spot-certificate-of-liability-insurance/GKG6ZZ","indicator":"has_cyber_insurance"},{"enabled":true,"link_url":"https://trust.hubspot.com/d/hub-spot-application-pen-test-report-2025/8TfzQW","indicator":"annual_penetration_testing"}],"trusted_by":[],"host_url":"https://trust.hubspot.com","host_embed_parent_url":"","content_order":[{"id":"intro","name":"Just for You","hidden":false,"custom_name":""},{"id":"access","name":"Access Request Button","hidden":false,"custom_name":""},{"id":"badges","name":"Badges","hidden":false,"custom_name":""},{"id":"philosophy","name":"Our Philosophy / Coming Soon","hidden":true,"custom_name":"Our Company / Welcome to HubSpot's New Trust Center"},{"id":"summary","name":"Quick Summary","hidden":false,"custom_name":""},{"id":"documents","name":"Featured Documents","hidden":true,"custom_name":""},{"id":"search","name":"Documents & Knowledge Base FAQs","hidden":false,"custom_name":""},{"id":"products","name":"What we offer","hidden":false,"custom_name":"AI Trust at HubSpot"},{"id":"announcements","name":"Announcements","hidden":false,"custom_name":""},{"id":"videoResources","name":"Video Resources","hidden":true,"custom_name":""},{"id":"subprocessors","name":"Subprocessors","hidden":true,"custom_name":""},{"id":"customers","name":"Trusted by","hidden":true,"custom_name":""}],"gated_public_view":false,"subprocessor_updated_at":null,"tagline":"Trust Center","summary":"Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.","quick_links":[{"icon":"link","url_link":"http://www.hubspot.com/","display_text":"Website URL"}],"featured_documents":{}};
    window.CANONICAL_ASSET = {"id":"2680cfcf-ab2c-499c-87f0-9dec420a2d5e","created_at":"2021-02-03T18:51:36.380Z","updated_at":"2025-12-15T17:38:03.006Z","_type":"canonical_asset/vendor","name":"HubSpot","type":"Vendor","trending":false,"logo_url":"https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWswTjJWa1lqQTNOeTAwTkRJeExUUmhPVFl0WVRWaU55MDRNak00T1RWa056YzVZV0VHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--9e3d348b5b73f7afeea0ec4bfc044ee543f449e4/LogoHubspot.jpg","cover_photo_url":"https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWs0T0RCaVlUQTVZeTB4TmpJNUxUUXhOVGd0WW1JNVppMDRZemN5Tm1RNFlqY3laRElHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--5399507b865b8748566d4f40656aecb674843c2d/Welcome-New.jpg","thumbnail_image_url":"https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWxoTlRjNU5UbGlOUzA1TkRNMkxUUTRZVEF0WVRRM1l5MDFObU5tWkdJM04yWmxNMllHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--1d3f2223e58e5a776df63977b8d0a8a68f531daf/Thumbnail.jpg","certifications":["soc2-type-2","soc3","hipaa","gdpr","ccpa","eu-cloud-coc","truste"],"website":"http://www.hubspot.com/","dataroom_id":"f47aa376-4d7b-406d-86f2-421aff40bb96","additional_company_details":{"founded":"2006","legal_name":"","company_size":"","physical_address":""},"has_published_report":true,"url_addressable_name":"hubspot","accent_color":"#FF4800","primary_color":null,"report_vulnerability_url":"","privacy_policy_url":"","terms_conditions_url":"","show_transparency_score_on_public_profile":false,"has_claimed_dataroom":true,"slug":"hubspot","published":true,"public_profile_published":true,"custom_font_url":null,"custom_font_name":"","custom_font_resource_url":null,"dataroom_discoverable":true};
    window.USE_ALTERNATE_PRODUCT_NAME = false;
    window.IS_CUSTOMER_HOSTED = true;</script>   <script nonce="dCtiZ1/c5YsI4PAPtj8xhg==">(function (a, p, t) {
      a.conveyor = a.conveyor || { _q: [] };
      f = "event,identify".split(",");
      l = function (n) {
        return function () {
          a.conveyor._q.push([n, Array.prototype.slice.call(arguments)]);
        };
      };
      for (e = 0; e < f.length; e++) {
        a.conveyor[f[e]] = l(f[e]);
      }
      i = p.createElement(t);
      i.type = "text/javascript";
      i.async = 1;
      i.nonce = "dCtiZ1/c5YsI4PAPtj8xhg==";
      i.src = "https://static.conveyor.com/js/webflow-react-component/conveyor.com.js";
      b = p.getElementsByTagName(t)[0];
      b.parentNode.insertBefore(i, b);
    })(window, document, "script");</script><script nonce="dCtiZ1/c5YsI4PAPtj8xhg==">// If the page is intended to be rendered in an iframe (has parent_url)
    // and is not in an iframe + the standard host url was used, redirect to parent_url
    if (window.VENDOR_REPORT && window.VENDOR_REPORT.host_embed_parent_url) {
      var inIframe = window.self !== window.top;
      if (!inIframe && !window.location.href.includes(window.VENDOR_REPORT.host_embed_parent_url) && window.location.href.includes(window.VENDOR_REPORT.host_url)) {
        window.location.href = window.VENDOR_REPORT.host_embed_parent_url;
      }
    }</script><meta name="description" content="See how HubSpot manages their security and compliance program with Conveyor. Access and download any security certification and get instant answers to your questions"/><meta property="og:title" content="HubSpot Trust Center | Powered by Conveyor"/><meta property="og:url" content="https://trust.hubspot.com"/><meta property="og:description" content="See how HubSpot manages their security and compliance program with Conveyor. Access and download any security certification and get instant answers to your questions"/><meta property="og:image" content="https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWxoTlRjNU5UbGlOUzA1TkRNMkxUUTRZVEF0WVRRM1l5MDFObU5tWkdJM04yWmxNMllHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--1d3f2223e58e5a776df63977b8d0a8a68f531daf/Thumbnail.jpg"/><meta property="og:logo" content="https://api.conveyor.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaEpJaWswTjJWa1lqQTNOeTAwTkRJeExUUmhPVFl0WVRWaU55MDRNak00T1RWa056YzVZV0VHT2daRlZBPT0iLCJleHAiOm51bGwsInB1ciI6ImJsb2JfaWQifX0=--9e3d348b5b73f7afeea0ec4bfc044ee543f449e4/LogoHubspot.jpg"/><meta property="og:type" content="website"/><script nonce="dCtiZ1/c5YsI4PAPtj8xhg==" defer="defer" src="/static/vendors~main.a3435e.bundle.js"></script><script nonce="dCtiZ1/c5YsI4PAPtj8xhg==" defer="defer" src="/static/main.039969.bundle.js"></script><link nonce="dCtiZ1/c5YsI4PAPtj8xhg==" href="/static/vendors~main.87e35f.css" rel="stylesheet"><link nonce="dCtiZ1/c5YsI4PAPtj8xhg==" href="/static/main.807671.css" rel="stylesheet"></head><body class="bg-gray-100 min-h-screen overflow-hidden"><div id="app" class="flex flex-col min-h-screen"></div><script nonce="dCtiZ1/c5YsI4PAPtj8xhg==" integrity="sha384-WhU5M4wjkBNzKad/seVynclBH8Fh2CQOoYVhhvz9jp8ASZm6dvRb/Gp5YAJdSWfr" crossorigin="anonymous" src="https://status.conveyor.com/embed/script.js"></script></body></html>