Better to Embed ChatGBT and/or Claude in Hubspot for Security reasons?

I am always excited for the new advancements in Hubspot, but I noticed no one is discussing the security concerns around Hubspot and Chat GBT or Claude integration especially with customer data being used.

My thoughts are;

  • Wouldnt it be better to embed Chat GBT and/or Claude inside Hubspot, much like the old days of intranets having their search powered by Google? Instead of launching queries outside of Hubspot? This example would also conflict with Co-Pilot/Breeze functionality to a degree?

  • Certain companies that do business with larger customers like the Fed or State Govs may need to have strict policies around Trust and Security. Hence my concern.

Full disclosure. I dont have the integration set up but I was hoping Hubspot and or the community would chime in on this.

Appreciate any perspectives on this.

Hi @BillX,

I absolutely love this question. I believe that’s the direction Breeze is heading in the long run. But for now, making AI integration optional is the best option. Customers who trust the integration can connect right away, while others can wait. Developing a GPT-4.1-level AI into HubSpot would be a long and costly journey.

Additionally, each AI model offers its own advantages; for example, relying only on GPT could limit users who prefer Claude, and vice versa.

Really glad someone raised this – it’s the question that should come before any “here’s what you can do with it” post.

The embedding idea makes a lot of sense intuitively: keep the queries inside a controlled environment rather than routing them through an external endpoint. That’s essentially what we ended up building at MAI Group. We already ran an internal AI environment on EU servers (GDPR), so we connected HubSpot to that instead of using the default Anthropic endpoint. Same natural language experience, but the data path stays within infrastructure we control and can audit.

It doesn’t solve every concern – if your data residency requirements are strict enough (federal/state gov level as you mention), you’d need to go further. But it’s a meaningful step up from the standard setup where you genuinely don’t know what path your CRM data is taking.

GiantFocal is right that model flexibility matters too – but I’d argue the architecture question (where does the query go?) comes before the model question (which AI do I use?).

Hi @BillX,

This is a great question, especially as more organizations are evaluating AI adoption alongside their data governance requirements.

From what I’ve observed, HubSpot has been placing increasing emphasis on trust, privacy, permissions, and transparency with how AI-powered features are introduced. So features such as enrichment, automation, and AI assistants can provide significant operational value, though they also require organizations to be intentional about what data is being used, what permissions are enabled, and which of their processes are appropriate for AI assistance.

I don’t have visibility into HubSpot’s internal AI architecture or every regulatory consideration they account for, but I think the broader point is important: the conversation is shifting from - Can AI do this? to Should AI do this with this specific data and workflow?

Organizations with stricter requirements such as those regulated industries or government-related customers. A recommendation would be: evaluating the available security documentation, data processing terms, and internal governance policies before enabling any AI integration.

In practice, I think in the near future there will likely be a balance between embedded AI experiences inside platforms and giving customers control over which AI services they connect based on their security and operational needs.