TECHNOLOGIES: HUBSPOT

HubSpot Security Review

Only a Super Admin can promote another user to Super Admin, and that reach spans the whole account. We test your permissions, teams, private app scopes and CMS custom code. CREST-certified testers, fixed price from £4,180 for a 3-day single-platform scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
HubSpot Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Scopes

A private app in HubSpot only holds the scopes an admin ticked on its Scopes tab, and a public app only asks for the ones its OAuth flow requests. We test which scopes each one actually has and what a leaked token would let someone do.

Why a HubSpot finding is a scope or permission setting, not a HubSpot flaw

HubSpot’s Super Admin permission set is the only one that can promote another user to Super Admin, and it reaches every tool and setting in the account. Teams then control which CRM records each user or group can see and how they appear in reports, separately from the permission set itself. We test who holds Super Admin, whether that list still matches who should, and whether team assignment actually restricts the records it is meant to.

A private app only holds the scopes an admin explicitly ticked on its Scopes tab, and its access token lives under Legacy apps in Development settings, where it can be rotated with the old token left valid for 7 days or revoked immediately. A public OAuth app’s scopes work the same way but are requested through the install flow instead, and Sensitive and Highly Sensitive Data properties, an Enterprise-only feature, need their own dedicated scopes before an app can read them at all. We test what each app in your account can actually reach with the scopes it holds.

CMS Hub serverless functions read secrets by name rather than having them hardcoded, HubL templates render your pages, and Memberships gates content behind a CRM contact login, each with its own way to get access control wrong. Webhook subscriptions carry a request signature in the X-HubSpot-Signature-V3 header, and an integration that never checks it will accept a forged payload from anyone who knows the URL. Two-factor authentication cannot be turned off for a username-and-password login, and SSO is available on Professional and Enterprise; we test whether every account in scope is actually covered by one or the other.

SCOPE

What we pen test on a HubSpot account

HS-01

Super Admin and User Permissions

Super Admin is the only permission set that can promote another user to Super Admin or customise other users’ permissions, and every other permission set sits below it. We test who holds Super Admin, whether that list is still accurate, and whether every other user’s permission set matches the access their role needs.

HS-02

Teams and Record Access

Teams control which CRM records a user or group can see and how those records appear in reports, separately from the permission set assigned to them. We test whether team assignment actually restricts record access the way your org chart assumes, including for a user who belongs to more than one team.

HS-03

Private App Scopes and Token Storage

A private app only holds the scopes an admin explicitly ticked on its Scopes tab, and the resulting access token sits under Legacy apps in Development settings, where it can be rotated with a 7-day overlap or revoked immediately. We test which scopes each private app actually has and what a leaked token would let someone do.

HS-04

OAuth App Scopes

A public OAuth app requests scopes through its install flow rather than a settings tab, and HubSpot categorises each scope as required, conditionally required or optional. We test which scopes every connected app has been granted and whether any hold more access than the integration actually uses.

HS-05

Sensitive Data Properties

Sensitive and Highly Sensitive Data properties, an Enterprise-only feature, need a dedicated scope before an app can read them through the API, on top of whatever standard CRM scopes it already holds. We test which properties are marked sensitive and whether every user and app that can reach them actually needs to.

HS-06

CMS Serverless Functions and Secrets

CMS Hub serverless functions reference secrets by name rather than hardcoding them, so a function that logs its inputs or returns them in a response can leak a secret without ever printing its value directly. We test your serverless functions for exactly that: what they log, what they return, and what a request to them can trigger.

HS-07

HubL Templates and Memberships Content

Memberships gates a page behind a CRM contact login rather than a separate user system, and a HubL template that renders member-only content without checking membership state can leak it to an anonymous visitor. We test whether gated content and the HubL logic controlling it actually hold up against a request that skips the login.

HS-08

Form and Integration Endpoints

Forms and other integration endpoints accept submissions from outside your account, and we test what each one does with data it was not expecting, from an unvalidated field to a submission replayed after the form was meant to close.

HS-09

Webhook Signature Validation

A webhook subscription carries a request signature in the X-HubSpot-Signature-V3 header, and an integration that never validates it will accept a forged payload from anyone who finds the URL. We test whether your webhook receiver actually checks that signature before acting on what it is sent.

HS-10

2FA and SSO Coverage

Two-factor authentication cannot be turned off for a username-and-password login, and single sign-on is available on the Professional and Enterprise tiers as an alternative. We test whether every account in scope is actually covered by one or the other, including any account that predates your current policy.

OUR PROCESS

HubSpot Security Review: From Scope to Attestation

01

Scope and Access

We agree the portal, an admin test account, and a regular user account for a couple of your permission sets and teams, plus which private apps, public apps and CMS templates are in scope.

02

Permission and Scope Mapping

We map user permissions, team assignment, private and OAuth app scopes, and sensitive data property access across your account before manual testing starts.

03

Manual Testing

A CREST-certified tester manually tests permission boundaries, app scopes, CMS custom code and webhook signature validation, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST HubSpot pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent HubSpot Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£4,180–£5,860
3 to 5 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,470–£11,320
7 to 9 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From HubSpot Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our HubSpot account?

We need an account with Super Admin access for scoping, plus at least one regular user account covering a couple of your permission sets and teams. If you run private or public apps we need visibility of their scopes, and if you use CMS Hub, access to the theme and template source.

Will testing touch our live data?

We test the portal you nominate. A sandbox or developer test account avoids any risk to live CRM records, and if we test your production portal, we agree exclusions such as sending real marketing emails or processing live payments before testing starts.

How long does a HubSpot security review take?

A single HubSpot account sits in our 3-day single-platform scope, with a report typically landing around 6 to 8 working days after kickoff. An account with several private and public apps, a large CMS custom-code footprint or many teams can move into a wider scope.

Do you test our CMS Hub website as well as the CRM?

Yes. If your account uses CMS Hub, we test the HubL templates, serverless functions and Memberships-gated content on your website as part of the same engagement, alongside the CRM permission and app-scope testing.

What is out of scope for a single-platform HubSpot review?

HubSpot’s own infrastructure and multi-tenant platform are never in scope. A separate system that only happens to integrate through the API or a webhook is scoped and quoted separately.

Do you need our source code?

We do not need HubSpot’s own platform code, since that belongs to HubSpot. For CMS Hub, a grey-box option where we review your HubL templates and serverless function code alongside testing is available if you want deeper coverage of specific findings.

Does HubSpot have a customer penetration-testing policy we need to follow?

HubSpot’s Trust Center lists a public vulnerability disclosure and bug bounty programme run through HackerOne, and we confirm its current scope and rules of engagement during scoping before testing your account or any connected app.

Do you test our webhook and integration endpoints?

Yes. We test what your webhook receivers do with an unsigned or forged payload, and what your form and integration endpoints do with data outside what they expect.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your HubSpot account

Only a Super Admin can promote another user to Super Admin, and that reach spans the whole account. We test your permissions, teams, private app scopes and CMS custom code. CREST-certified testers, fixed price from £4,180 for a 3-day single-platform scope, quoted within 24 hours.