Support
Email: jon@thejonmartin.com
Language: English.
Response time: we aim to reply within one business day (US Eastern time).
Common questions
Does Portal Audit change anything in my HubSpot account? No. It only reads. Every request is checked against a read-only allowlist before it is sent.
Why does HubSpot say the app can "create, edit and delete" workflows or forms? See "Why these permissions" below. In short: HubSpot has no read-only version of those permissions, Portal Audit only reads, and you can decline them.
A section of my report says "not assessed". Either a permission was not granted during install, or your HubSpot plan does not include that tool. Reinstall and keep the optional permissions checked if you want those sections.
Why these permissions
- Portal Audit only reads. Before any request goes to HubSpot, it is checked against a read-only allowlist in the app's code (
backend/src/hubspot/allowlist.ts). Anything that would create, change or delete data is blocked before it leaves our server, and the audit stops. - Four permissions have no read-only version in HubSpot. These are forms, marketing-email, automation (workflows) and content. HubSpot's install screen describes them as read and write, because that is the only version HubSpot offers. Portal Audit uses them only to read your forms, marketing emails and workflows.
- All four are optional. You can uncheck them on HubSpot's install screen (HubSpot: optional scopes). If you do, the app skips those checks and the report marks them not assessed. Everything else still runs.
How do I disconnect and delete my data? See Disconnect and uninstall. To have your data deleted right away, email us from an address on your HubSpot account.
Security questions or a vulnerability report? Email jon@thejonmartin.com with "Security" in the subject.