Solution challenges
Solution challengeDelivered
Regulated or sensitive data remaining in a specialist system
HubSpot supports the process without holding the data it should not hold.
Project-level detail for this record is still being verified internally. Treat the summary below as capability and approach, not as a specific delivered claim.
- Forbidden's experience
- Forbidden designs the boundary explicitly, so the commercial process works while sensitive records stay where they belong.
- Architecture considerations
- What must never leave the specialist system
- Reference identifiers and status flags rather than full records
- Access control and audit requirements
- Process design so users are not tempted to paste data into HubSpot
- Supplier and processing obligations
- Common failure points
- Sensitive detail copied into notes and free-text fields
- Integration built before the compliance boundary is agreed
- Status data duplicated with no owner
- Workarounds created because the compliant path is slower
- Worth resolving in discovery
- What exactly is the restriction, and who owns it?
- What does the commercial team need to know rather than see?
- How is access audited today?
- What happens today when someone needs the detail?

