Trust center
The security of Box with the ease of HubSpot
Zero-Access Architecture
Your data never leaves Box or HubSpot. SparkGrid acts as a secure bridge between your existing platforms, eliminating the risks associated with third-party data storage. We facilitate the connection, not the content.
Architecture Data Flow Diagram
OAuth 2.0 Authentication
Industry-standard OAuth 2.0 ensures your credentials are never shared. We store only encrypted API tokens to maintain your connection – never passwords, never your data.
Individual User Authentication
Each user authenticates individually with their own Box account, ensuring granular permissions are maintained. When an employee leaves or changes roles, their access automatically updates – no shared credentials, no security gaps.
Enterprise-Grade Token Security
– Tokens encrypted at rest with AES-256
– All communications over TLS 1.2+
– Automatic token rotation and refresh
– Secure storage on Heroku’s SOC 2 compliant infrastructure
Security Through Architecture
By keeping your data within Box and HubSpot’s certified environments, you maintain:
Box Certifications
Global Certifications
ISO 27001 (Information Security Management)
ISO 27017 (Cloud Security)
ISO 27018 (Cloud Privacy)
ISO 27001 (Information Security Management)
SOC 1 Type II, SOC 2 Type II, SOC 3
US Certifications
FedRAMP (Moderate Impact Level)
DoD IL2, IL4, and IL5 Provisional Authorization
FedRAMP (Moderate Impact Level)
HIPAA and HITECH
CJIS (FBI Criminal Justice Information Services)
EU/UK Certifications
GDPR Compliant
UK Cyber Essentials Plus
Industry Standards
PCI DSS (Payment Card Industry Data Security Standard)
GxP 21 CFR Part 11 (FDA Electronic Records)
HubSpot Certifications
Certifications & Attestations
SOC 2 Type II, SOC 3
HIPAA attestation
TRUSTe certified
Compliance Standards
GDPR compliant
CCPA compliant
Infrastructure Certifications (via AWS)
ISO 27001 (through cloud infrastructure providers)
SOC 2 Type 2 (AWS infrastructure)
Box Connector’s Security
Zero data storage – no file data ever touches our servers
Encrypted token management only
Individual user authentication enforced
Hosted on Heroku Enterprise infrastructure






