HublytixBack to the app

Security & Trust

Last updated: 15 June 2026

Connecting an analytics tool to your CRM is an act of trust. Hublytix is built so that trust is easy to give: we use read-only access, we store findings rather than your customer records, and you can cut off access at any time. This page explains exactly how.

Read-only by design

Hublytix connects to HubSpot using OAuth with a small set of read-only scopes. We do not request write access and are technically unable to create, edit, or delete anything in your portal. Every fix we recommend is applied by you, in HubSpot, under your control.

Findings, not your data

We do not replicate your CRM. When an audit runs, we read your portal transiently to compute results, and we persist only what is needed to show and track those results:

  • issue counts, health scores, and audit history;
  • property and workflow definitions (the structure of your portal), not the contents of every record;
  • record identifiers so we can deep-link you straight to the item that needs attention in HubSpot.

We do not copy your full contact, company, or deal records into our database, we do not sell your data, and we do not use it to train machine-learning models.

Encryption

  • In transit: all traffic is served over HTTPS/TLS, with HSTS enforced.
  • At rest: HubSpot access and refresh tokens are encrypted with AES-256-GCM before storage; our database provider encrypts data at rest.

Tenant isolation

Customer data is separated at the database layer using PostgreSQL Row-Level Security (RLS). Access is scoped per account, so one customer’s data is not reachable from another’s session.

You are always in control

You can revoke Hublytix’s access at any time — from within HubSpot’s connected-apps settings, or with one click from the Settings page in the app. When you disconnect a portal, we revoke the associated access tokens and permanently delete that portal’s stored findings.

Application security

The app is hardened with current web-security controls, including a strict Content-Security-Policy with per-request nonces, protection against cross-site request forgery on state-changing requests, HSTS, and a full set of security response headers. Secrets are held in managed environment configuration and are never committed to source control, and we rotate them when needed.

Monitoring

We use error monitoring to detect and diagnose problems quickly. We log access and key events to support security and troubleshooting.

Infrastructure and sub-processors

Hublytix runs on established cloud providers for hosting, database, authentication, email, payments, and monitoring. The full list of sub-processors, what each one handles, and where they operate is on our Sub-processors page.

Compliance posture

We designed Hublytix to align with the EU/UK GDPR and to meet India’s Digital Personal Data Protection Act, 2023 as its requirements come into force. A Data Processing Agreement is available for customers who need one — contact privacy@hublytix.ai. We describe how we handle personal data in our Privacy Policy.

We do not currently hold formal third-party certifications such as SOC 2 or ISO 27001; we will say so plainly here if and when that changes.

Reporting a vulnerability

If you believe you have found a security issue, please email security@hublytix.ai. We welcome responsible disclosure and will work with you to investigate and resolve valid reports. Please do not publicly disclose an issue until we have had a reasonable opportunity to address it.

Privacy PolicyTerms of ServiceCookie PolicySecuritySub-processors

© 2026 Hublytix LLP. All rights reserved.