VendorScore · Comparison · Data-access posture

Salesforce vs HubSpot: which can read your CRM data?

Get the full 5-dimension PDFs — join the waitlist

Evidence dated 2026-10-06, public docs only, not legal advice.

Short answer

Both can read your CRM data by design. In the scored configurations, Salesforce (60/100) has less inherent vendor read access than HubSpot (46/100), mainly because Shield Platform Encryption supports customer key material you can revoke; HubSpot documents no customer-held key option and may train its own AI models on customer data unless you opt out.

Higher score = less inherent vendor read access in the scored configuration, not a more secure product. Each score comes from that vendor's VendorScore page.

Last reviewed: · Evidence date: Salesforce 2026-10-06, HubSpot 2026-10-06 (from each vendor page) · Sources

Side by side

Salesforce HubSpot
Overall score 60/100 46/100
Scored configuration Sales/Service Cloud on Hyperforce/core with optional Shield Platform Encryption (including BYOK / customer key material). HubSpot CRM platform (paid hubs) with published AES-256 at rest and TLS in transit, and AI/feature subprocessors as publicly listed.
Key custody option Shield Platform Encryption with customer-supplied key material (BYOK / EKM / cache-only keys). Revoking key material can make Shield-encrypted data inaccessible; while keys are active, Salesforce uses them. HubSpot/infrastructure-managed keys (AES-256 at rest, TLS 1.2/1.3 in transit). No public customer-held key (BYOK) option for CRM records.
E2EE / CSE scope None: Shield encrypts selected fields and files, and Salesforce decrypts for authorized app operations when keys are available. Not full zero-knowledge for the platform. None. HubSpot processes CRM data in plaintext on its systems.
AI training default (scored config) Not fully stated. The Einstein Trust Layer's zero data retention policy says prompts and responses are never stored or used to train third-party LLMs. No general rule for Salesforce's own models in the pages reviewed. On by default (opt-out). HubSpot may use customer data to train its own AI models unless a Super Admin switches off AI Model Training; Sensitive Data accounts are opted out by default.
EU residency For authorized products: the Hyperforce EU Operating Zone processes and stores customer data within the EU and Switzerland, with EU-based support. Yes: HubSpot can host your account in its EU (Germany) data center on AWS; staff may still access data from other regions for support and development.
DPA link Salesforce DPA HubSpot DPA

Dimension scores (key custody, plaintext access, encryption claims, subprocessors, auditability) stay in the full PDFs.

What this means

Get the full 5-dimension PDFs — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Salesforce vs HubSpot

Does Salesforce Shield or HubSpot encryption stop the vendor reading my CRM data?

No. Shield encrypts selected fields and files, but Salesforce still decrypts for authorized app operations when keys are available; revoking customer key material can make Shield-encrypted data inaccessible. HubSpot encrypts data at rest with AES-256 and in transit with TLS 1.2/1.3 using HubSpot-managed keys, and its public docs don't describe a BYOK option for CRM records.

Which can read my CRM data less, Salesforce or HubSpot?

In the scored configurations, Salesforce scores 60/100 (Sales/Service Cloud with optional Shield Platform Encryption) and HubSpot 46/100 (paid hubs with published AES-256 and TLS), so Salesforce has less inherent vendor read access. Without Shield, the report estimates Salesforce at about 50 overall.

Can Salesforce or HubSpot employees see my CRM data?

Salesforce's DPA limits its access to Personal Data to personnel performing the Services. HubSpot's DPA says a subset of employees have access to customer data via controlled interfaces, for reasons including support, product development and troubleshooting, with logged just-in-time access; VendorScore found no public customer approval gate for that access.

Do Salesforce or HubSpot train AI on my CRM data?

Salesforce says the Einstein Trust Layer's zero data retention policy means prompts and responses are never stored or used to train third-party LLMs; the pages we reviewed don't state a general rule for Salesforce's own models. HubSpot may use customer data to train its own AI models unless a Super Admin switches off AI Model Training; accounts with Sensitive Data turned on are opted out by default.

Can I keep Salesforce or HubSpot data in the EU?

Salesforce's Hyperforce EU Operating Zone processes and stores customer data within the EU and Switzerland, for authorized products only. HubSpot can host your account in its EU (Germany) data center, though HubSpot staff may still access data from other regions for support and development.

Sources

Every URL cited on this page. Scores, configurations and facts come from the linked VendorScore vendor pages and their reports; nothing here goes beyond them.

Disclaimer

This comparison restates the vendor pages for the scored configurations only; default setups usually score lower. A higher score means less inherent vendor read access in that configuration, not a safety rating. VendorScore doesn't certify compliance. Public-docs review only. Not a pen test, not legal advice, not a SOC 2 substitute.