The Security Scorecard tool has flagged a concern on our website (upply.com). One of the Call-To-Actions (CTA) in our navigation bar appears to reference an Amazon S3 URL directly:
This direct reference to Amazon S3 negatively impacts our global security score. As a best practice, it’s generally recommended to route such assets through a branded subdomain rather than exposing the raw S3 URL (e.g., hubspot-cta-redirect-eu1-prod.s3.amazonaws.com).
This issue was last observed on May 19, 2025, and is still open. We’ve reached out to HubSpot CSMs, but they haven’t been able to provide a definitive answer.
Any insights or recommendations would be greatly appreciated!
Hey @Flaval at the momenr there’s no way to customise the redirect URLs used by CTAs as they’re a part of the HubSpot infrastructure and not managed user side.
Could you use the browser based tracking instead of the redirect based tracking instead?
Hi @TomM2 - Is there a workaround for this if you still use the legacy CTA editor? We’re experiencing the same issue on our end, but all of our CTAs are in the legacy editor because they’re customized with our own font, something the new editor doesn’t allow us to do.
My recommendation is to create a new Idea post focused on your specific use case for the product team to take note.
Finally, I want to tag a couple of community members to share more insights. Hey there @RubenBurdin and @GRajput, I hope you’re having a great week! Any additional thoughts?