We have recently implemented the use of Quoting to push out from HubSpot all of our order forms to prospective customers, and upon doing so we have noted the major security flaw the URL generation has the potential to cause.
The public nature of the quote, post submission/ approval, is a security risk, leaving pricing, customer and contract information available. Although the auto-generated slugs add a level of security in its complexity, there is still potential for public access and user sharing, of which is unacceptable for such a sensitive process in a customer’s journey.
A few suggestions to mitigate/ remove the risk here could include;
1. Introducing password protection against quotes sent out/ URL’s generated from the process, shared only via individuals with access to the quote produced.
2. Locking down (unsure as to how) URL access based on the senders/ buyers on the quote being built/ sent out.
3. Making the URL generation ‘optional’, allowing generation of a quote without public URL against it.
The first two options above are more favourable, owing to utilising the e-signature platform via linking.
I’m currently reviewing Hubspot to determine if we can migrate to the platform, and was shocked at how unsecure the process is for sharing a quote - and the near inability to even generate a pdf of a quote without it first being published in a public manner. (unless I’m missing something)
I agree that this needs to be addressed as the current implementation probably breaks about every MSA agreement with any large organization.
I would like to address a concern raised by our customers. It has become apparent that additional security measures for quotes are necessary, as the reasons provided by our customers are both legitimate and important. Thank you Product Team!
There’s already an email verification feature for signature so if it was used for viewing instead it would solve the issue. If Hubspot took security seriously as they always say they do, this could/should be improved rapidly.
I am the product manager for Commerce Hub Quotes and wanted to share that we’re starting work to provide authentication/access management to Quotes. Stay tuned for updates!