Use this as a generic HubSpot hardening resource. Validate settings in the target portal before making changes.
This resource covers controls visible in HubSpot account settings, security settings, connected apps, files, audit logs, data management, AI settings, approvals, and sandboxes.
It does not replace a penetration test, an ISO 27001 control mapping, an external log ingestion design, or a portal-specific access review. It gives the baseline an administrator should use before those activities.
Where the wording says to use, review, require, or restrict a setting, that is Kongo hardening guidance based on HubSpot controls. It is not quoted HubSpot product documentation.