- Knowledge Base
- Account & Setup
- Account Security
- Scan and redact Sensitive Data in HubSpot
Scan and redact Sensitive Data in HubSpot
Last updated: January 22, 2026
Available with any of the following subscriptions, except where noted:
-
Marketing Hub Enterprise
-
Sales Hub Enterprise
-
Service Hub Enterprise
-
Data Hub Enterprise
-
Content Hub Enterprise
-
Smart CRM Enterprise
-
Commerce Hub Enterprise
Scan and redact Sensitive Data to identify sensitive information stored in CRM activities such as notes, calls, tasks, emails, and meetings. Super Admins can run scans to detect flagged values and redact them when Sensitive Data is configured in the account. This reduces compliance risk associated with unintentionally stored financial or health data. If Sensitive Data isn't turned on in your account, you can review the scan results.
Before you get started
Before you begin working with this feature, make sure to fully understand what steps should be taken ahead of time, as well as the limitations of the feature and potential consequences of using it.
Understand requirements
Permissions required Super Admin permissions are required to scan and redact Sensitive Data.
- You must turn on Sensitive Data in the account to redact detected values.
- When you don't configure Sensitive Data, you can still scan and review the results, but the flagged values can't be redacted.
Understand limitations & considerations
- Sensitive Data scans analyze CRM activities from the last 60 days.
- Each account is limited to one scan every 30 days.
- Redaction replaces detected values with placeholder text.
Scan for Sensitive Data
Scan for Sensitive Data to detect sensitive values in CRM activities from the previous 60 days. Only users with Super Admin permission can run scans.
- In your HubSpot account, click the settings settings icon in the top navigation bar.
- In the left sidebar menu, navigate to Security.
- Click the Sensitive Data tab.
- In the Sensitive Data Scan section, click Start scan. If you've done a scan before, click Scan again.


- In the right panel, select the checkboxes next to the types of data you want to scan (e.g., PII or Health information).
- In the Exclude keywords from your scan section, enter any keywords you'd like to exclude. Press Enter after each keyword to add it.
- In the bottom right, click Next.
- Review the information and select the checkbox to agree.
- Click Start scan. While the scan is running, a Scan in progress banner is displayed in the Sensitive Data Scan section. An email notification is sent when scan results are available.

Review Sensitive Data scan results
Review scan results to examine detected values and determine whether action is required. Only users with Super Admin permission can review results and take action. All actions taken during review are recorded in the account’s audit logs.
- In your HubSpot account, click the settings settings icon in the top navigation bar.
- In the left sidebar menu, navigate to Security.
- Click the Sensitive Data tab.
- In the Sensitive Data Scan section, click View results.
- To filter the results, click the dropdowns at the top. To filter by record name, enter record names in tin the searchIcon search bar.
- To review an activity, hover over the activity and click View details.
- In the right panel, click View in CRM to view the full activity details. To view the specific value that was flagged, click Value #.
Mark values as non-sensitive
Mark values as non-sensitive to indicate that flagged information doesn’t require redaction. After you mark values as non-sensitive, they remain in the account.
- In the right panel, select the Mark as non-sensitive checkbox.
- Click Next.
- Click Next again.
- Click Confirm.
Redact values from an account
If you have Sensitive Data turned on in your account, you can redact values from your account. This will permanently remove values from CRM activities. The original value will be replaced with placeholder text.
- In the right panel, click Next.
- Select the checkbox next to the value you want to remove, and click Next.
- Click Confirm.
After redaction, the original value is replaced with generic placeholder text, such as REDACTED-ACCOUNT-NUMBER.
