HubSpot Vendor Due Diligence Memorandum (Regulation S-P)
Last Updated: September 2026
Goodwood provides this memorandum as a template for your firm's own vendor file. "The Adviser" refers to your firm. Review it against your policies and HubSpot's current documentation before adopting it.
1. Purpose of This Document
This document is intended to support the Adviser's service provider oversight and vendor due diligence obligations under the Securities and Exchange Commission's amended Regulation S-P. It documents the Adviser's evaluation of HubSpot, Inc. as a third-party service provider that processes customer information on the Adviser's behalf.
This memorandum is not an internal incident response policy. Rather, it is designed to evidence reasonable due diligence and oversight of HubSpot consistent with Regulation S-P requirements applicable to registered investment advisers.
2. Regulatory Context
Regulation S-P requires covered institutions to establish, maintain, and enforce written policies and procedures reasonably designed to provide oversight of service providers. Such oversight must ensure that service providers:
- take appropriate measures to protect against unauthorized access to or use of customer information; and
- notify the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider.
Larger entities were required to comply with these requirements by December 3, 2025, and smaller entities by June 3, 2026.
3. Description of the Vendor
HubSpot, Inc. provides customer relationship management (CRM), marketing, sales, and service software platforms. In the course of providing these services, HubSpot may process or store nonpublic personal information and other customer information on behalf of the Adviser.
4. Scope of Customer Information
Customer information processed by HubSpot may include nonpublic personal information relating to clients and prospects, account-related identifiers, communications, and documents uploaded by authorized Adviser personnel.
For purposes of Regulation S-P, such information constitutes customer information handled or maintained by a service provider on the Adviser's behalf.
5. HubSpot Data Protection and Security Framework
HubSpot publicly represents that it maintains a formal information security program, including:
- an internal, written information security policy;
- documented technical and organizational safeguards;
- third-party assurance reports, including SOC 2 Type II and SOC 3 reports; and
- ongoing penetration testing and security assessments.
HubSpot makes security and compliance documentation available through its Trust Center, which is accessible to HubSpot customers and supports vendor due diligence and monitoring.
6. Breach Definition and Notification Practices
HubSpot's Data Processing Agreement defines a customer personal data breach as unauthorized access to or disclosure of customer personal data processed by HubSpot or its subprocessors.
The Adviser relies on HubSpot's contractual commitments, security documentation, and incident response representations to support compliance with Regulation S-P's requirement that service providers notify the Adviser as soon as possible, but no later than 72 hours after becoming aware of a qualifying security incident.
7. Ongoing Monitoring and Review
The Adviser conducts ongoing monitoring of HubSpot as a service provider through periodic review of publicly available legal, privacy, and security documentation, including updates to HubSpot's Data Processing Agreement and Trust Center materials.
This document may be updated as part of the Adviser's periodic vendor review cycle or in response to material changes in HubSpot's services, security posture, or applicable regulatory requirements.
8. Conclusion
Based on the Adviser's review of HubSpot's publicly available legal and security documentation, contractual commitments, and customer-restricted Trust Center materials, the Adviser has determined that HubSpot maintains controls reasonably designed to safeguard customer information and to support timely breach notification consistent with Regulation S-P service provider oversight requirements.