Trust
Security
Last updated: 8 October 2026
Connecting a company CRM to a new tool is a fair thing to be careful about. This page sets out exactly what Pipeline SLA reads, what it never touches, and how the data is looked after, so you can decide with the facts in front of you.
Read-only, by design
Pipeline SLA never creates, edits, moves, closes or deletes anything in HubSpot. It doesn't create tasks or update properties. It reads your deals, checks them against the rules you set, and sends alerts by email. Everything it writes goes to its own database, not to your CRM.
The exact HubSpot permissions it asks for
These three read-only permissions are the full list. HubSpot shows them to you before you connect.
| crm.objects.deals.read | Read deals in your pipelines |
| crm.schemas.deals.read | Read your pipeline and stage names |
| crm.objects.owners.read | Read deal owners, so alerts reach the right person |
What it reads from each deal
- Deal name
- Amount and currency
- Pipeline and stage
- When the deal entered its current stage
- Last modified and last activity dates
- Next activity date
- Close date
- Deal owner (HubSpot owner ID and email)
If HubSpot doesn't say when a deal entered its current stage, Pipeline SLA reads that deal's stage history to work it out.
What it never touches
It has no permission to read contacts, companies, tickets, emails, call recordings, notes, attachments or files. It cannot see anything outside deals, pipelines and deal owners, because HubSpot won't give it access beyond the three permissions above.
How data is protected
- HubSpot access keys are encrypted with AES-256-GCM before they are stored, so even a copy of the database would not give anyone access to your HubSpot.
- Each organisation's data is kept separate in the database by row-level security. Your login can only reach your own organisation's data.
- All traffic is encrypted in transit (HTTPS, with HSTS). The site sends strict security headers, including a content security policy.
- A web application firewall blocks known attack patterns, and DDoS protection is provided by our hosting.
- Incoming webhooks from HubSpot and Stripe are checked against their signatures before they are acted on.
- Passwords are handled by our authentication provider and only ever stored hashed.
- Every account with access to our infrastructure is protected by two-factor authentication.
- Card details are handled entirely by Stripe. We never see or store a card number.
Where data is stored
The database and authentication run on Supabase in the European Union (Ireland). The app is hosted on Vercel. Alerts and account emails are sent through Resend. The full list of providers, and how data leaving the UK is safeguarded, is in the Privacy Policy.
One optional feature uses AI: if you ask for a suggested re-engagement message for a stale deal, the deal name, stage and time in stage are sent to Anthropic (Claude) to write it. Nothing is sent unless you ask for a suggestion.
Disconnecting and deleting
An owner or admin can disconnect HubSpot from the Connections page at any time. Scanning stops straight away and the stored refresh key is deleted, so access can never be renewed. The short-lived access key left behind is encrypted and expires within the hour. You can also remove the app from inside HubSpot under Settings, Integrations, Connected apps.
Deleting your account from the Account page permanently deletes your organisation's data from our database straight away. If a free trial ends without a paid plan, account data is kept for 90 days so you can come back, after which it may be permanently deleted. The details, including the few copies held outside our database, are in the Privacy Policy.
Questions, or found a problem?
If your IT or security team needs anything not covered here, or you think you've found a security issue, email founder@argutix.com. Security reports are answered first.