Deep scanSoftware business · Storefront property/Scanned 3 Sept 2026, 19:35 UTC/2 agent walks, 17 requests/Partial scan
hubspot.com
HubSpot's pricing renders only after JavaScript runs and its signup CTA points to a robots-blocked subdomain, so an agent can read about the product but cannot price or buy it.
Incomplete scan
The human side of this site could not be measured, so there is no Door Gap to report. The scores below cover only what the scan actually reached.
Three issues, in priority order
Each one is drawn from evidence recorded during the walks.
2 pieces of evidence and the recommended fix are recorded for this issue.
What a visitor actually meets
4 moments, 3 with friction, 1 blocking
We walked the funnel in a real browser and captured every step. Nothing was submitted and no account was created.
- 01
Landing page
Headline is vague marketing language: "Where go-to-market teams go to close." Takes a moment to figure out this is CRM/marketing/sales software. Two clear CTAs though: "Get a demo" and "Get started free". A chat widget pops up immediately offering to help, adding visual noise.
friction·www.hubspot.com
Landing page - 02
Pricing page
Prices only render after JavaScript executes. Once rendered: Free $0, Starter $7/mo/seat, Professional $800/mo, Enterprise $3,600/mo. Professional and Enterprise hide a mandatory one-time onboarding fee ($3,000 and $7,000) in small print, and both require "Talk to Sales" instead of self-serve checkout.
friction·/pricing/marketing
Pricing page - 03
Attempting to reach signup form
Every "Get started free" and "Get started" link points to app.hubspot.com/signup-hubspot/crm. That subdomain's robots.txt disallows automated access entirely, so an agent-based evaluator cannot even view the signup form, let alone get an API key or account without a human passing through a browser session manually.
blocked·/pricing/marketing
- 04
Developer API documentation
API reference is organized, with clear endpoint patterns like GET /crm/objects/2026-03/contacts. Sign up link points to the same robots-blocked signup path. Page text contains an embedded instruction to fetch /docs/llms.txt "before exploring further," an odd directive inside content.
friction·/docs/api-reference/latest/overview
Developer API docs
We sent a buying agent
17 requests, in order
The agent got through 11 of 17 requests, but could not find a published agent interface. It came up empty on 5 other checks too. That is enough missing for a machine to give up before it reaches a purchase.
- 01reached
www.hubspot.com
reach the site at all
- 02reached
/robots.txt
find out whether machines are welcome
- 03reached
www.hubspot.com
ask whether the door opens for requests carrying the AI crawlers' names
- 04reached
/llms.txt
read the site's own guide for language models
- 05reached
/sitemap.xml
find out what pages exist
- 06reached
/.well-known/security.txt
find a contact route for machines
- 07not found
www.hubspot.com
find a published agent interface
- 08not found
/.well-known/ai-plugin.json
find an agent plugin manifest
- 09not found
www.hubspot.com
find out whether verified agents are recognised
- 10reached
www.hubspot.com
read the homepage as data rather than as a page
- 11not found
www.hubspot.com
find a machine readable API spec
- 12reached
www.hubspot.com
read the developer documentation
- 13not found
/pricing/marketing
read the prices without running JavaScript
- 14reached
www.hubspot.com
find a comparison page worth citing
- 15reached
www.hubspot.com
walk the way a visitor would, to a signup form or a product
- 16not found
/signup/crm
check if free account signup is self-serve
- 17reached
/docs/api/private-apps
check if API key/private app can be obtained self-serve without sales
Ten dimensions
Not measured is not zero.
The agent door
41 of 100What a machine can do on your site with nobody watching.
Machine discoverability
Whether a retrieval system can find and read you at all.
Robots.txt carries 358 directives and allows every named AI crawler including GPTBot, ClaudeBot and PerplexityBot. Sitemap lists 1098 URLs, llms.txt has 293 lines, homepage carries 9 schema.org types, but pricing only appears after.
4 observations recorded.
Programmatic onboarding
Whether an agent can get working access without a human.
A free account can be created, but developer docs describe minting an API key by clicking through the dashboard by hand, with no self-serve key endpoint or OpenAPI spec, and the signup CTA itself points to a robots-blocked subdomain.
4 observations recorded.
Pricing legibility
Whether total cost can be computed from published numbers.
The pricing page returns 0 prices in raw HTML; all 16 prices from $0 to $3,600 only appear once JavaScript renders. Any client that does not run JS, human or agent, sees no price at all.
1 observation recorded.
Agent-aware instrumentation
Whether you publish anything built for machine callers.
No MCP manifest.
4 observations recorded.
Machine-fetchable trust
Whether terms, security and status are readable as text.
security.txt is published with a machine contact route and the homepage answers automated requests directly. A developer docs page also embeds an unusual instruction telling readers to fetch a specific file before continuing, which is.
2 observations recorded.
Commercial rails
Whether a purchase can complete without a sales call.
Rendered prices exist from $0 to $3,600 across tiers, but none sit in raw HTML, and Professional and Enterprise route to 'Talk to Sales' with onboarding fees of $3,000 and $7,000 disclosed only in small print.
3 observations recorded.
The human door
0 of 100What a first time visitor meets between landing and first value.
Steps to first value
How far a new visitor travels before something useful happens.
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Required fields
How much you ask for before you give anything back.
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Verification walls
How many gates stand between intent and access.
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Error recovery
What happens when someone gets it wrong.
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Show the score
The badge always shows the latest scores for this domain and links back to the report. Put it in a README or a footer.
This number moves every time you deploy
SecondDoor rescans on a schedule and tells you the day a release closes a door. Watch the trend on the dashboard, or scan another site now.