Skip to content
Solution challenges
Solution challengeDelivered

Regulated or sensitive data remaining in a specialist system

HubSpot supports the process without holding the data it should not hold.

Project-level detail for this record is still being verified internally. Treat the summary below as capability and approach, not as a specific delivered claim.

Forbidden's experience
Forbidden designs the boundary explicitly, so the commercial process works while sensitive records stay where they belong.
Architecture considerations
  • What must never leave the specialist system
  • Reference identifiers and status flags rather than full records
  • Access control and audit requirements
  • Process design so users are not tempted to paste data into HubSpot
  • Supplier and processing obligations
Common failure points
  • Sensitive detail copied into notes and free-text fields
  • Integration built before the compliance boundary is agreed
  • Status data duplicated with no owner
  • Workarounds created because the compliant path is slower
Worth resolving in discovery
  • What exactly is the restriction, and who owns it?
  • What does the commercial team need to know rather than see?
  • How is access audited today?
  • What happens today when someone needs the detail?