Ogham Works - Trust & Security

Access to what we need. Nothing more.

 Enrollem is a focused, single-purpose HubSpot app. Here's exactly what it touches, what it doesn't, and how it's protected. 

Enrollem - HubSpot Certified App
RISING_Orange
Overview

Overview

 Jump to a section, or read straight through. 

Data & infrastructure

What we store, and what we don't

  • Enrollem runs as a HubSpot Marketplace app. Enrollment requests are processed by our own API, hosted on Render (EU). HubSpot workflows call it to enroll or unenroll contacts.
  • We store account-level usage data in a Supabase-hosted database: your HubSpot portal ID, account contact email, enrollment counts, and plan tier.
  • For the contacts you enroll, we only ever handle record IDs. We never receive their email addresses or any other personal detail about them or their enrollments.
  • To determine who a sequence sends as, Enrollem also processes the email address of the sequence's sender/owner: a member of your own team, never the enrolled contact. This isn't stored in our database; it appears only in Render's own operational logs, which roll off automatically after 14 days.
  • Everything that moves between HubSpot, our Render-hosted API, and Supabase travels over TLS-encrypted connections. Nothing goes over the wire in plain text.
Access controls

Limited access

  • Enrollem is installed through HubSpot's own OAuth flow. We never see or store your HubSpot login credentials.
  • It requests only the access it needs to know who to enroll and update enrollment status, not broad, standing access to your CRM.
  • Uninstalling Enrollem from HubSpot immediately revokes its access to your account.
Compliance

What we're certified for, and what we're not

 Enrollem is a HubSpot Technology Partner, and Enrollem itself carries HubSpot's Certified App badge: the only certified app for sequence enrollment automation on the Marketplace. Certification isn't automatic. HubSpot requires an app to clear three bars, and to keep clearing them afterward.

  • Technical excellence: a 95%+ success rate on HubSpot's own technical review, sustained over a set period of time. Enrollem exceeded this bar to earn certification.
  • Trust: at least 6 months listed on the Marketplace, at least 60 real installs, and every scope the app uses clearly disclosed. Enrollem passed this well past 2,000 installs.
  • Customer service: a demo video, a getting-started guide, dedicated knowledge base articles, and a real support channel, all of which we maintain.
  • This is a real, ongoing technical bar set and enforced by HubSpot, but it is not the same as an independent SOC 2 or ISO 27001 audit. We do not hold either today.
Subprocessors

Who else touches your data

  • HubSpot (US): CRM platform of record; Enrollem operates within your existing HubSpot account.
  • Render (EU): hosts Enrollem's core enrollment engine/API.
  • Supabase (EU): hosts Enrollem's usage and plan data.
  • Make.com (EU): schedules Enrollem's automated usage-sync jobs.
  • Stripe (US): processes payment data for Enrollem subscriptions.
Availability

What keeps Enrollem running

  • Enrollment requests are triggered from your HubSpot workflows and processed by our own API, hosted on Render. We're responsible for keeping that layer available, alongside Render's own infrastructure uptime.
  • Our own usage/plan data is backed up on our database provider's standard backup schedule.
Incident response

If something goes wrong

  • If we ever confirm a data breach affecting your data, we will notify affected customers promptly.
  • Found a security issue? Email support@oghamworks.com. We take reports seriously and respond quickly.

Have a security question we didn't answer?

Get in touch