HubSpot Security Review
Only a Super Admin can promote another user to Super Admin, and that reach spans the whole account. We test your permissions, teams, private app scopes and CMS custom code. CREST-certified testers, fixed price from £4,180 for a 3-day single-platform scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
A private app in HubSpot only holds the scopes an admin ticked on its Scopes tab, and a public app only asks for the ones its OAuth flow requests. We test which scopes each one actually has and what a leaked token would let someone do.
Why a HubSpot finding is a scope or permission setting, not a HubSpot flaw
HubSpot’s Super Admin permission set is the only one that can promote another user to Super Admin, and it reaches every tool and setting in the account. Teams then control which CRM records each user or group can see and how they appear in reports, separately from the permission set itself. We test who holds Super Admin, whether that list still matches who should, and whether team assignment actually restricts the records it is meant to.
A private app only holds the scopes an admin explicitly ticked on its Scopes tab, and its access token lives under Legacy apps in Development settings, where it can be rotated with the old token left valid for 7 days or revoked immediately. A public OAuth app’s scopes work the same way but are requested through the install flow instead, and Sensitive and Highly Sensitive Data properties, an Enterprise-only feature, need their own dedicated scopes before an app can read them at all. We test what each app in your account can actually reach with the scopes it holds.
CMS Hub serverless functions read secrets by name rather than having them hardcoded, HubL templates render your pages, and Memberships gates content behind a CRM contact login, each with its own way to get access control wrong. Webhook subscriptions carry a request signature in the X-HubSpot-Signature-V3 header, and an integration that never checks it will accept a forged payload from anyone who knows the URL. Two-factor authentication cannot be turned off for a username-and-password login, and SSO is available on Professional and Enterprise; we test whether every account in scope is actually covered by one or the other.
SCOPE
What we pen test on a HubSpot account
Super Admin and User Permissions
Super Admin is the only permission set that can promote another user to Super Admin or customise other users’ permissions, and every other permission set sits below it. We test who holds Super Admin, whether that list is still accurate, and whether every other user’s permission set matches the access their role needs.
Teams and Record Access
Teams control which CRM records a user or group can see and how those records appear in reports, separately from the permission set assigned to them. We test whether team assignment actually restricts record access the way your org chart assumes, including for a user who belongs to more than one team.
Private App Scopes and Token Storage
A private app only holds the scopes an admin explicitly ticked on its Scopes tab, and the resulting access token sits under Legacy apps in Development settings, where it can be rotated with a 7-day overlap or revoked immediately. We test which scopes each private app actually has and what a leaked token would let someone do.
OAuth App Scopes
A public OAuth app requests scopes through its install flow rather than a settings tab, and HubSpot categorises each scope as required, conditionally required or optional. We test which scopes every connected app has been granted and whether any hold more access than the integration actually uses.
Sensitive Data Properties
Sensitive and Highly Sensitive Data properties, an Enterprise-only feature, need a dedicated scope before an app can read them through the API, on top of whatever standard CRM scopes it already holds. We test which properties are marked sensitive and whether every user and app that can reach them actually needs to.
CMS Serverless Functions and Secrets
CMS Hub serverless functions reference secrets by name rather than hardcoding them, so a function that logs its inputs or returns them in a response can leak a secret without ever printing its value directly. We test your serverless functions for exactly that: what they log, what they return, and what a request to them can trigger.
HubL Templates and Memberships Content
Memberships gates a page behind a CRM contact login rather than a separate user system, and a HubL template that renders member-only content without checking membership state can leak it to an anonymous visitor. We test whether gated content and the HubL logic controlling it actually hold up against a request that skips the login.
Form and Integration Endpoints
Forms and other integration endpoints accept submissions from outside your account, and we test what each one does with data it was not expecting, from an unvalidated field to a submission replayed after the form was meant to close.
Webhook Signature Validation
A webhook subscription carries a request signature in the X-HubSpot-Signature-V3 header, and an integration that never validates it will accept a forged payload from anyone who finds the URL. We test whether your webhook receiver actually checks that signature before acting on what it is sent.
2FA and SSO Coverage
Two-factor authentication cannot be turned off for a username-and-password login, and single sign-on is available on the Professional and Enterprise tiers as an alternative. We test whether every account in scope is actually covered by one or the other, including any account that predates your current policy.
OUR PROCESS
HubSpot Security Review: From Scope to Attestation
Scope and Access
We agree the portal, an admin test account, and a regular user account for a couple of your permission sets and teams, plus which private apps, public apps and CMS templates are in scope.
Permission and Scope Mapping
We map user permissions, team assignment, private and OAuth app scopes, and sensitive data property access across your account before manual testing starts.
Manual Testing
A CREST-certified tester manually tests permission boundaries, app scopes, CMS custom code and webhook signature validation, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST HubSpot pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent HubSpot Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
3 to 5 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote7 to 9 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test HubSpot For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From HubSpot Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our HubSpot account?
We need an account with Super Admin access for scoping, plus at least one regular user account covering a couple of your permission sets and teams. If you run private or public apps we need visibility of their scopes, and if you use CMS Hub, access to the theme and template source.
Will testing touch our live data?
We test the portal you nominate. A sandbox or developer test account avoids any risk to live CRM records, and if we test your production portal, we agree exclusions such as sending real marketing emails or processing live payments before testing starts.
How long does a HubSpot security review take?
A single HubSpot account sits in our 3-day single-platform scope, with a report typically landing around 6 to 8 working days after kickoff. An account with several private and public apps, a large CMS custom-code footprint or many teams can move into a wider scope.
Do you test our CMS Hub website as well as the CRM?
Yes. If your account uses CMS Hub, we test the HubL templates, serverless functions and Memberships-gated content on your website as part of the same engagement, alongside the CRM permission and app-scope testing.
What is out of scope for a single-platform HubSpot review?
HubSpot’s own infrastructure and multi-tenant platform are never in scope. A separate system that only happens to integrate through the API or a webhook is scoped and quoted separately.
Do you need our source code?
We do not need HubSpot’s own platform code, since that belongs to HubSpot. For CMS Hub, a grey-box option where we review your HubL templates and serverless function code alongside testing is available if you want deeper coverage of specific findings.
Does HubSpot have a customer penetration-testing policy we need to follow?
HubSpot’s Trust Center lists a public vulnerability disclosure and bug bounty programme run through HackerOne, and we confirm its current scope and rules of engagement during scoping before testing your account or any connected app.
Do you test our webhook and integration endpoints?
Yes. We test what your webhook receivers do with an unsigned or forged payload, and what your form and integration endpoints do with data outside what they expect.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your HubSpot account
Only a Super Admin can promote another user to Super Admin, and that reach spans the whole account. We test your permissions, teams, private app scopes and CMS custom code. CREST-certified testers, fixed price from £4,180 for a 3-day single-platform scope, quoted within 24 hours.



