Access to what we need. Nothing more.
Enrollem is a focused, single-purpose HubSpot app. Here's exactly what it touches, what it doesn't, and how it's protected.
Overview
Jump to a section, or read straight through.
Data & infrastructure
What Enrollem stores, and what it never touches.
Learn More →Access controls
Check out our apps such as Enrollem that save you time and make processes simpler.
Learn More →Compliance
Our HubSpot certification, and our honest compliance posture today.
Learn More →Subprocessors
The third parties Enrollem relies on.
Learn More →Availability
What keeps Enrollem running.
Learn More →Incident Response
What happens if something goes wrong.
Learn More →What we store, and what we don't
- Enrollem runs as a HubSpot Marketplace app. Enrollment requests are processed by our own API, hosted on Render (EU). HubSpot workflows call it to enroll or unenroll contacts.
- We store account-level usage data in a Supabase-hosted database: your HubSpot portal ID, account contact email, enrollment counts, and plan tier.
- For the contacts you enroll, we only ever handle record IDs. We never receive their email addresses or any other personal detail about them or their enrollments.
- To determine who a sequence sends as, Enrollem also processes the email address of the sequence's sender/owner: a member of your own team, never the enrolled contact. This isn't stored in our database; it appears only in Render's own operational logs, which roll off automatically after 14 days.
- Everything that moves between HubSpot, our Render-hosted API, and Supabase travels over TLS-encrypted connections. Nothing goes over the wire in plain text.
Limited access
- Enrollem is installed through HubSpot's own OAuth flow. We never see or store your HubSpot login credentials.
- It requests only the access it needs to know who to enroll and update enrollment status, not broad, standing access to your CRM.
- Uninstalling Enrollem from HubSpot immediately revokes its access to your account.
What we're certified for, and what we're not
Enrollem is a HubSpot Technology Partner, and Enrollem itself carries HubSpot's Certified App badge: the only certified app for sequence enrollment automation on the Marketplace. Certification isn't automatic. HubSpot requires an app to clear three bars, and to keep clearing them afterward.
- Technical excellence: a 95%+ success rate on HubSpot's own technical review, sustained over a set period of time. Enrollem exceeded this bar to earn certification.
- Trust: at least 6 months listed on the Marketplace, at least 60 real installs, and every scope the app uses clearly disclosed. Enrollem passed this well past 2,000 installs.
- Customer service: a demo video, a getting-started guide, dedicated knowledge base articles, and a real support channel, all of which we maintain.
- This is a real, ongoing technical bar set and enforced by HubSpot, but it is not the same as an independent SOC 2 or ISO 27001 audit. We do not hold either today.
Who else touches your data
- HubSpot (US): CRM platform of record; Enrollem operates within your existing HubSpot account.
- Render (EU): hosts Enrollem's core enrollment engine/API.
- Supabase (EU): hosts Enrollem's usage and plan data.
- Make.com (EU): schedules Enrollem's automated usage-sync jobs.
- Stripe (US): processes payment data for Enrollem subscriptions.
What keeps Enrollem running
- Enrollment requests are triggered from your HubSpot workflows and processed by our own API, hosted on Render. We're responsible for keeping that layer available, alongside Render's own infrastructure uptime.
- Our own usage/plan data is backed up on our database provider's standard backup schedule.
If something goes wrong
- If we ever confirm a data breach affecting your data, we will notify affected customers promptly.
- Found a security issue? Email support@oghamworks.com. We take reports seriously and respond quickly.