Compliance frameworks, security audits, and quality certifications this company maintains.
HubSpot maintains SOC 2 Type II certification across its CRM platform, providing enterprise customers independent assurance that security, availability, and confidentiality controls protect their marketing and sales data.
HubSpot is ISO 27001 certified, demonstrating that its information security management system follows internationally recognized controls for protecting the customer CRM and marketing automation data it processes.
HubSpot is GDPR compliant and provides European customers with data residency options, a Data Processing Agreement, and built-in consent management tools to support lawful processing of EU personal data through its CRM platform.
HubSpot supports CCPA compliance for California-based customers by providing tools to manage consumer data rights requests, opt-out workflows, and data deletion directly within the HubSpot CRM platform.
HubSpot offers HIPAA-eligible configuration for Enterprise-tier Service Hub customers in healthcare, allowing covered entities to use HubSpot ticketing and contact management under a signed Business Associate Agreement.
HubSpot Commerce Hub operates in a PCI DSS compliant environment, ensuring that payment data processed through HubSpot quotes and payment links meets card industry security standards.
HubSpot holds ISO 27018 certification for cloud-based PII processing, giving marketing and sales customers confidence that personal contact data stored in HubSpot CRM is handled under internationally recognized privacy controls.
HubSpot participates in the CSA STAR self-assessment program, publishing its cloud security posture to give enterprise security teams transparency into the controls protecting HubSpot CRM infrastructure.
HubSpot achieves CSA STAR Level 2 certification with independent third-party assessment, validating the cloud security controls protecting customer CRM, marketing, and sales data hosted across HubSpot's multi-tenant SaaS platform.
HubSpot holds ISO 27017 certification for cloud-specific security controls, confirming that the infrastructure hosting HubSpot's CRM, Marketing Hub, and Service Hub meets international standards for protecting customer data in shared cloud environments.