Is my data safe with SurroundR?
The plain-English answer: what SurroundR asks HubSpot for, what it keeps, what it writes back, and what happens when you delete a contact.
Written By Philip Poppe
Last updated 28 days ago
The short version
SurroundR does not replicate your CRM. Your contacts, companies and deals stay in HubSpot.
We never see your HubSpot password. You sign in with HubSpot itself.
We ask for the permissions the product needs, and you approve them on HubSpot's own screen.
We do not ask for your email, your calendar or your deals.
Everything is encrypted, in storage and in transit.
Delete a contact in HubSpot and our related records go too.
All of it is on by default. There is nothing for you to configure. Keep reading for the detail, or send the technical article to whoever asks for it.
Signing in works like a wristband
When you sign in, SurroundR issues you a token, effectively a digital wristband. Every action checks the wristband. If it is missing, expired or revoked, you are bounced.
Change your password or have an administrator revoke your access, and every existing wristband stops working immediately.
We never see your HubSpot password
You log in with HubSpot, not with us. HubSpot then hands SurroundR a permission slip listing what you agreed to. We cannot do anything that is not on the slip.
There are two SurroundR apps, and they ask for different things:
The SurroundR Connect app, which is how you sign in, asks to read and write contacts and companies, to read and edit their properties, and to read your owners list so records and tasks can be assigned to the right person.
The SurroundR app, which is optional, asks to read contacts, to write timeline events so SurroundR activity shows on the contact record, and, if you want sequence enrolment from LinkedIn, to read your sequences and enrol contacts in them.
We do not ask for your inbox, your calendar or your deals pipeline. If your portal has granted deals access for another reason, SurroundR will show deals it can already see, but it never asks for that permission itself.
That permission slip lives in a safe
The token HubSpot gives us is valuable, so it is encrypted with AES-256-GCM, the standard banks use, with a fresh salt for every operation. We decrypt it only at the moment a request needs it, and never write it to a log or return it to the browser.
What we actually keep
This is the part worth reading properly, because "we store nothing" would be a comfortable thing to say and it would not be true.
SurroundR keeps a directory so it can recognise people across LinkedIn and your CRM. That includes CRM record identifiers, and hashed values for matching on email and company domain. Without it, the extension could not tell you that the person whose profile you are reading is already in your CRM and owned by a colleague.
We also keep the things you create in SurroundR: your field mapping and settings, message templates, Chirps and their view figures, and your activity totals for streaks and leaderboards.
What we do not do is take a copy of your CRM. We do not pull your deals, your pipelines, your email or your reporting. When you press sync, data flows into HubSpot; the reading we do back out of it is the index that makes matching work.
What we write into HubSpot
Only what you ask for, but that is more than contacts and companies now, so here is the list: contact and company records and their properties, LinkedIn profile photos where you have enabled that, notes and tasks you create, LinkedIn message threads if you turn on conversation sync, and timeline events such as a prospect watching your Chirp.
Each of those is a feature you can turn off. See What can I change in Settings?
Everything travels through a locked tunnel
Every conversation between your browser, the extension and our servers goes over HTTPS, and our database connections are encrypted too.
We check the messenger's badge
HubSpot sometimes sends us notifications, for example "this contact was deleted, clean up". Before acting on any of them we verify the cryptographic signature HubSpot attaches. Unsigned or tampered messages are thrown out.
When a contact is deleted, our records go too
A HubSpot privacy deletion for a contact triggers a cleanup on our side: the directory entry is marked deleted and its personal fields scrubbed, and the index rows, the LinkedIn-to-CRM mapping and the conversation sync records for that contact are deleted outright.
The boring but important part
Managed, encrypted database hosting with automatic backups.
Services run in isolated containers. We do not share space with other companies' applications.
Sign-ins and important actions are logged for audit.
Sensitive values are filtered out of error reports.
Filling in a security questionnaire?
Email support@surroundr.io and we will work through it with you, including our sub-processors and retention periods. For the architecture in full, see How does SurroundR handle security and data privacy?
Was this helpful?
Still need help? Ask the team