Improved security for Quote sharing

We have recently implemented the use of Quoting to push out from HubSpot all of our order forms to prospective customers, and upon doing so we have noted the major security flaw the URL generation has the potential to cause.

The public nature of the quote, post submission/ approval, is a security risk, leaving pricing, customer and contract information available. Although the auto-generated slugs add a level of security in its complexity, there is still potential for public access and user sharing, of which is unacceptable for such a sensitive process in a customer’s journey.

A few suggestions to mitigate/ remove the risk here could include;

1. Introducing password protection against quotes sent out/ URL’s generated from the process, shared only via individuals with access to the quote produced.

2. Locking down (unsure as to how) URL access based on the senders/ buyers on the quote being built/ sent out.

3. Making the URL generation ‘optional’, allowing generation of a quote without public URL against it.

The first two options above are more favourable, owing to utilising the e-signature platform via linking.

For us, working in Cybersecurity, this is a must for us to properly send out quotes.

I’m currently reviewing Hubspot to determine if we can migrate to the platform, and was shocked at how unsecure the process is for sharing a quote - and the near inability to even generate a pdf of a quote without it first being published in a public manner. (unless I’m missing something)

I agree that this needs to be addressed as the current implementation probably breaks about every MSA agreement with any large organization.

The current public quote system is completely unacceptable from a security stand point.

There’s another forum that’s requesting the same thing: https://community.hubspot.com/t5/HubSpot-Ideas/Password-Protection-for-Quotes/idi-p/427220#feedback-success

Follow and like both and let’s fill this gap!

I would like to address a concern raised by our customers. It has become apparent that additional security measures for quotes are necessary, as the reasons provided by our customers are both legitimate and important. Thank you Product Team!

There’s already an email verification feature for signature so if it was used for viewing instead it would solve the issue. If Hubspot took security seriously as they always say they do, this could/should be improved rapidly.

Lack of password prohibits our company from utilizing the quotes tool, leaving is with a clunky work around.

Hi all,

I am the product manager for Commerce Hub Quotes and wanted to share that we’re starting work to provide authentication/access management to Quotes. Stay tuned for updates!

Good to know it’s being developed, but is there an ETA for this?