# Vet every new HubSpot company before anyone works the record

> The moment a company is created in HubSpot, we check how established their website is and attach a plain-language profile to the record.

- Workflow type: agent
- Services: SecurityTrails, HubSpot, Slack Bot
- Categories: Sales, Operations
- Published: 2026-08-09

## What it does

- Starts the moment a new company record is created in your CRM, before a rep or a reviewer has opened it
- Looks up how long the business's website has been registered, who it was registered through, and which country it is registered in
- Checks how large their web presence is, who runs their email and hosting, and whether the site carries a proper security certificate
- Writes a short plain-language profile onto the company record and posts a two line version to your Slack channel
- Flags anything that looks off, such as a website registered only weeks ago, a missing certificate, or a footprint of one single page

## What you'll need

- A HubSpot account where new companies are created, with the website field filled in
- A SecurityTrails account for the website research
- A Slack workspace and a channel where the summaries should land

## Prompt

Whenever a new company is created in HubSpot, research that company's web presence and attach a plain-language profile to the record before a sales rep or a security reviewer ever touches it. Use a webhook trigger that fires on HubSpot company creation.

Start with HubSpot Get Company to read the company name and the website domain from the newly created record. If the company has no domain filled in, skip the research entirely, post nothing to Slack, and leave a short note on the record saying the profile was skipped because no website was set. Never guess a domain from the company name.

When there is a domain, run these SecurityTrails lookups against it. Use Get WHOIS to establish how long the business has been registered, who the registrar is, and which country the registrant sits in. Use Get Domain for the current DNS records, including which email provider the MX records point at and who hosts the site. Use List Subdomains to gauge how large their web footprint is. Use Get Domain SSL Certificates to see whether the site is properly certified and which brands appear on their certificates.

Turn the findings into a short written brief. Cover company maturity based on how long the domain has been registered, rough technical size based on how many subdomains exist, and the email and hosting stack in named terms such as Google Workspace, Microsoft 365, Cloudflare or AWS.

Call out anything that looks off, explicitly and in one place: a domain registered only weeks ago, no valid certificate, a footprint of one single page, a registrant country that does not match where the company claims to operate, or certificates issued to brand names unrelated to this company. If nothing looks unusual, say so plainly rather than manufacturing concerns.

Write the full brief onto the company record using HubSpot Create Note, associated with that company. Then post a two line version to a Slack channel using Send a Message so the record owner sees it in context. The first line names the company and the headline judgement, the second carries the single most useful detail or the main warning sign. Include a link back to the HubSpot record.

Keep the writing non-technical throughout. The readers are sales reps and security reviewers, not engineers, so write that their email runs on Google Workspace rather than naming record types. Never invent data the lookups did not return. If a lookup comes back empty or fails, say that the information was not available and continue with the rest of the brief.

## How to customize

- Change which Slack channel gets the summary, or send it as a direct message to the person who owns the record
- Adjust what counts as a warning sign, such as how new a website has to be before it gets called out
- Point the same research at new deals instead of new companies, so every opportunity arrives pre-checked
- Change the tone and length of the written profile to match how your team likes to read briefs

## FAQ

### Is this research intrusive in any way?

No. Everything comes from public registration records that anyone is free to look up, the same way you can see who owns a website address. Nothing is scanned, probed, or accessed on the other company's systems, and the company is never contacted.

### What happens if the company has no website filled in?

The workflow stops cleanly and leaves a short note on the record explaining that it skipped the research because no website was set. It will not guess a website address from the company name, so you never get a profile built on the wrong business.

### Can I use this for vendor and supplier checks as well as sales?

Yes, that is the point of writing it in plain language. The same profile answers a sales question, meaning how established and how big is this company, and a security review question, meaning does anything about this business look unusual before we take it further.

### Will this work on my HubSpot plan?

It needs a HubSpot plan that can notify other tools when a new company is created. If yours cannot do that, the same research can be set to run on a schedule instead and pick up companies added since the last run.

### Does it overwrite anything on the company record?

No. It only adds a note to the record, so nothing your team has already typed in gets changed or replaced. If you would rather it filled in specific fields as well, that is a straightforward change.

Use this prompt in General Input: https://www.generalinput.com/prompts/vet-every-new-hubspot-company-before-anyone-works-the-record