Security Review Checklists: SAP vs Salesforce vs HubSpot
Security review scope differs meaningfully by platform, and buyers who use one generic checklist across all three tend to miss the questions that matter most fo…
Security review scope differs meaningfully by platform, and buyers who use one generic checklist across all three tend to miss the questions that matter most for each.
SAP: focus on interface and custom-code review
Most SAP security incidents trace back to a custom RFC or a poorly scoped interface, not the core platform. Ask specifically how custom ABAP code gets security-reviewed before it ships.
Request the change-control process for custom code specifically, separate from the general change-management process — many organizations have a rigorous general process but a much looser one for developer-authored interfaces.
Salesforce: focus on sharing rules and connected apps
Object-level sharing misconfiguration and over-permissioned connected apps are the two most common Salesforce findings in a real audit — ask for a sharing model review, not just a permissions export.
Connected apps in particular deserve a standing quarterly review, not a one-time setup check — marketing and sales teams routinely authorize new integrations without security ever being looped in.
HubSpot: focus on data retention and third-party integrations
HubSpot's biggest exposure is usually the long tail of marketing integrations with access to contact data. Inventory every connected app quarterly, not just at initial setup.
Ask specifically about data retention defaults for form submissions and marketing contacts — many HubSpot instances retain personal data well beyond what's required by the organization's own stated privacy policy, simply because nobody configured a retention window.
The one question that applies to all three
Regardless of platform, ask who owns security review as an ongoing function, not just a pre-launch gate. Platforms don't stay secure by default — a review that happens once and never recurs is a review that expires the moment the first new integration ships.
Responses
Sign in to join the conversation.
Sign in