Compliance
SOC 2 evidence your auditor can read, straight from your HubSpot estate
FlowSentinel reviews access across every connected portal each quarter, records a named reviewer's decisions and exports the evidence CSV, so the access-control and monitoring criteria are documented before the audit window opens.
Mapped criteria
SOC 2 criteria FlowSentinel helps you evidence
Access control
CC6.1 and CC6.2 expect access to be granted on need and reviewed regularly. FlowSentinel discovers every user, role and team membership across connected portals and records the current state.
Privileged access oversight
Super admin and export permissions are flagged automatically, including missing two-step verification on privileged HubSpot accounts, with a built-in reminder workflow.
Deprovisioning
CC6.3 expects access to be removed when it is no longer needed. Offboarding hands over every record before removal, and revoke decisions from recertification feed straight into it.
Monitoring and anomaly alerts
CC7 expects monitoring for suspicious activity. Drift detection, anomaly rules, data-export and export-volume alerts create a timestamped record of changes and risks.
Audit trail
Every FlowSentinel action, from a baseline capture to a remediation step, is written to the audit trail with actor, portal and timestamp, and can be exported as a CSV.
Reviewer sign-off
Named reviewers sign off quarterly recertification campaigns, producing a decision record and exportable evidence for each portal.
Recertification
Quarterly recertification decisions
SOC 2 access criteria expect user access to be reviewed at defined intervals and the review to be documented. FlowSentinel runs a quarterly recertification campaign for every connected portal.
- Open a campaign. On the first day of each quarter the system creates a campaign per portal and populates it with the current users, roles and team memberships that need review.
- Assign a named reviewer. Each campaign has one reviewer who is responsible for checking every item. Reviewers can be reassigned by an administrator at any time.
- Make keep, change or revoke decisions. For each user and access path the reviewer records whether access should stay the same, be changed or be removed.
- Sign off. When every item has been reviewed the reviewer signs the campaign. The signed statement, timestamp and full decision log are stored as evidence.
- Export the evidence CSV. The campaign detail page exports the full decision record, ready for an auditor.
If a revoke decision is recorded, the reviewer can hand the user over to the existing offboarding or move-user workflows so the decision is actioned and logged.
Evidence CSV
What the export contains
Each signed campaign exports a CSV covering every review item in that portal and quarter. It is designed to drop straight into an auditor's evidence request.
- One row per person and access path reviewed, with their role and teams.
- The keep, change or revoke decision recorded for each item.
- The named reviewer and the time each decision was made.
- The sign-off statement, reviewer and timestamp for the campaign as a whole.
- The portal and quarter the evidence covers.
Open Access recertification in the console, pick a signed campaign and select Export evidence CSV.
Example evidence rows
portal,period,person,access,decision,decided_by,decided_at Acme UK,Q3 2026,jane@example.com,"Sales role, Deals team",keep,A Reviewer,2026-07-03T09:14Z Acme UK,Q3 2026,mark@example.com,Super admin,change,A Reviewer,2026-07-03T09:21Z Acme UK,Q3 2026,lea@example.com,Service user,revoke,A Reviewer,2026-07-03T09:30Z
Illustrative format. The real export uses your portal, people and decisions.
Evidence
Reports you can produce for an auditor
Quarterly recertification evidence
Signed campaign exports with reviewer name, decisions, timestamps and portal coverage.
Audit-trail export
A complete CSV of actions taken inside FlowSentinel, filterable by date, actor and portal.
Security alert history
Records of multi-team members, shared contacts, missing two-factor verification and data-export events.
Pen-test findings and coverage
Automated nightly platform penetration testing results and coverage reports from the system console.
What FlowSentinel is not
FlowSentinel is software that supports your SOC 2 programme. It is not itself SOC 2 attested, and it does not grant attestation to your organisation. Attestation remains your own responsibility with your chosen auditor; FlowSentinel makes the access-review, monitoring and logging evidence easier to produce and maintain.