Compliance

Evidence ISO 27001 access controls without starting from a spreadsheet

FlowSentinel continuously maps who has access to your HubSpot estate, flags risks and records every decision, so your access-review evidence is ready when the auditor arrives.

Mapped controls

ISO 27001 requirements FlowSentinel helps you evidence

Access control and review

A.9.1 and A.9.2 require regular review of user access. FlowSentinel discovers every user, role and team membership across connected portals and records the current state.

Privileged access oversight

Super admin and export permissions are flagged automatically, including missing two-step verification on privileged HubSpot accounts.

Anomaly and event logging

A.12.4 expects logs of security events. Drift detection, data-export alerts and security alerts create a timestamped record of changes and risks.

Audit trail

Every FlowSentinel action, from a baseline capture to a remediation step, is written to the audit trail with actor, portal and timestamp.

Technical testing

Automated regular penetration testing runs against the platform, with findings triaged, recorded and available for review.

Reviewer sign-off

Named reviewers sign off quarterly recertification campaigns, producing a decision record and exportable evidence for each portal.

Recertification

Quarterly access recertification

ISO 27001 expects access rights to be reviewed at planned intervals. FlowSentinel runs a quarterly recertification campaign for every connected portal.

  1. Open a campaign. On the first day of each quarter the system creates a campaign per portal and populates it with the current users, roles and team memberships that need review.
  2. Assign a named reviewer. Each campaign has one reviewer who is responsible for checking every item. Reviewers can be reassigned by an administrator at any time.
  3. Make keep, change or revoke decisions. For each user and access path the reviewer records whether access should stay the same, be changed or be removed.
  4. Sign off. When every item has been reviewed the reviewer signs the campaign. The signed statement, timestamp and full decision log are stored as evidence.
  5. Export evidence. The campaign detail page exports a CSV containing decisions, reviewer name and sign-off time, ready for an auditor.

If a revoke decision is recorded, the reviewer can hand the user over to the existing offboarding or move-user workflows so the decision is actioned and logged.

Penetration testing

Automated regular technical testing

Technical testing is a core part of ISO 27001. FlowSentinel runs automated penetration tests against the platform on a nightly basis, covering authentication, authorisation, tenant isolation, API endpoints and common web vulnerabilities.

  • Findings are triaged and stored with severity, affected area and remediation status.
  • Coverage reports show which controls and routes have been tested over time.
  • Administrators can view the current finding set and coverage from the system console.

The results support your own ISO 27001 technical-testing evidence. They do not replace a third-party penetration test if your programme or certification body requires one.

Evidence

Reports you can produce for an auditor

Quarterly recertification evidence

Signed campaign exports with reviewer name, decision timestamps and portal coverage.

Audit-trail export

A complete CSV of actions taken inside FlowSentinel, filterable by date, actor and portal.

Security alert history

Records of multi-team members, shared contacts, missing two-factor verification and data-export events.

Pen-test findings and coverage

Platform-level test results and coverage reports from the system console.

What FlowSentinel is not

FlowSentinel is software that supports your ISO 27001 programme. It is not itself ISO 27001 certified, and it does not grant certification to your organisation. Certification remains your own responsibility; FlowSentinel makes the access-review, logging and technical-testing evidence easier to produce and maintain.