Trust documentation
Security
Last updated: August 23, 2026 / Version 1.1
1.0 Overview
Connecting a CRM is a significant decision. Quarterdeck is designed as a read-only intelligence layer for HubSpot pipeline review. It reads evidence, computes risk context, and produces briefing artifacts; it does not take autonomous CRM actions.
2.0 OAuth protocol
Quarterdeck requests only read scopes for deals and owners, plus the contacts read scope that the current integration uses for deal-associated note timestamps. It has no HubSpot write scopes.
crm.objects.deals.read crm.objects.owners.read crm.objects.contacts.read
3.0 Encryption
Data in transit
Quarterdeck's configured HubSpot API connections use HTTPS endpoints.
Stored tokens
HubSpot access and refresh tokens are encrypted at the application layer before storage.
4.0 Tenant isolation
Quarterdeck's database schema enables row-level security and membership-scoped policies for workspace-accessible records.
5.0 AI data handling
Anthropic narrative requests contain structured metrics and deterministic evidence. Depending on the findings, this can include company name, reporting period, at-risk deal names, HubSpot deal IDs, amounts, and risk reasons. Quarterdeck does not send contact records or note bodies in these narrative requests.
6.0 Deletion
When Quarterdeck confirms a successful disconnect, it has deleted the locally stored HubSpot connection and the CRM-derived records used by the product. If a deletion step fails, Quarterdeck reports an error instead of confirming success. Revoke the OAuth grant separately from HubSpot Connected Apps. Quarterdeck does not modify your HubSpot CRM records.
Subprocessor details are available in the Privacy Policy. The exact HubSpot data we read is documented on the Shared Data page.
Security contact
Report vulnerabilities to hello@kpappworx.com.