This document is an example of the format. It was produced by running the procedures against a sandbox portal owned by us and populated with invented records. No organisation named in it is a client, and nothing in it has been relied upon by anybody. A report issued for an actual engagement carries a named addressee and does not carry this notice.
Report of Factual Findings from Agreed-Upon Procedures
Data health check · engagement NF-DHC-2026-0002 · 2026-08-02
Addressee and subject matter
Addressee
Specimen — no addressee
System examined
HubSpot portal 246929157 (na2)
API version
2026-03
Extracted — contacts
2026-08-10T19:33:09Z to 2026-08-10T19:33:13Z
Extracted — companies
2026-08-10T19:33:13Z to 2026-08-10T19:33:15Z
Extracted — deals
2026-08-10T19:33:15Z to 2026-08-10T19:33:17Z
Purpose and basis
In a real engagement the procedures below are agreed in advance with a named addressee, and the report is prepared solely for that addressee and for the purpose agreed with them. This copy has no addressee and no engagement behind it: the procedures shown are our standard set, run against a sandbox we own so that the format can be read by someone deciding whether to commission the work.
This is not an audit and not a review. No assurance is expressed. No opinion or conclusion is expressed on the data or on the system. Only factual findings are stated. Had additional procedures been performed, other matters might have come to light.
The structure of this report is modelled on the Agreed-Upon Procedures standard (ISRS 4400 Revised). Noorflows LLC is not a firm of qualified accountants and does not represent that this is an ISRS 4400 engagement.
Redacted report. This report has been produced in redacted form. Names and email addresses have been replaced by the record identifiers held in the system examined, and the signatory's name is withheld. Every procedure was performed on the full data; no finding, count or rate in this report is affected. Each identifier can be resolved to its record within the system by the addressee. Because the signature is withheld, this copy is not the signed deliverable.
Procedure 3 · Record counts, checked two ways
Each object was extracted in full by cursor pagination. HubSpot's list endpoint returns no total, so the extraction is the count and a short page would reduce it silently. Each count was therefore measured a second time by an independent route — the search endpoint, which does report a total — and both figures are stated.
Object
Extracted
Independent count
Agreement
Requests
contacts
250
250
agree
4
companies
8
8
agree
2
deals
12
12
agree
2
contacts: 250 records extracted by full pagination. An independent count from the search endpoint returned 250. The two measures agree.
companies: 8 records extracted by full pagination. An independent count from the search endpoint returned 8. The two measures agree.
deals: 12 records extracted by full pagination. An independent count from the search endpoint returned 12. The two measures agree.
Procedure 1 · Association integrity
Health-check mode. One system was examined. Associations that may have existed in a prior system could not be compared, because no source system was provided. This procedure therefore reports counts as found. It does not state, and cannot state, that any association was preserved or lost.
Association
Found
deal to company
9
deal to contact
13
contact to company
20
3 of 12 deals (25.0%) have no associated company record.
HubSpot does not require deals to be associated with a company; that is the default behaviour. This figure is stated as a factual finding. Whether it represents an inconsistency depends on the association requirements configured on the client's own record-creation forms, which are outside the scope of this procedure. No conclusion is drawn.
Procedure 4 · Field completeness
Field
Populated
Records
Rate
email
247
250
98.8%
phone
242
250
96.8%
city
250
250
100.0%
dob
250
250
100.0%
247 of 250 contact records (98.8%) have a value in 'email'.
242 of 250 contact records (96.8%) have a value in 'phone'.
250 of 250 contact records (100.0%) have a value in 'city'.
250 of 250 contact records (100.0%) have a value in 'dob'.
Procedure 2 · Duplicate identification
Duplicate identification used probabilistic matching (Splink 4.0.16, model person-v4, file SHA-256 23321714d051c2d4...) at a match-weight threshold of 8.0. Records were compared where they shared: first name; surname; date of birth; email address; city; the username part of the email address; the first three letters of the surname; the first three letters of the forename; the year and month of birth. Pairs sharing none of these attributes were not compared and could not be identified as duplicates. The threshold was calibrated against a labelled reference set of 1,000 records containing 2,031 known duplicate pairs, reshaped so that no two records share an email address -- the constraint HubSpot itself enforces on contacts -- together with a further 400 records known to be distinct individuals but deliberately sharing forenames, surnames, employers, cities and email domains. At this threshold no false positives were observed in either population, and 29.0% of known duplicate pairs were identified. Duplicate counts in this report are therefore stated as a minimum. This is not an audit or a review. No assurance is expressed.
This extract contains 250 records. Term-frequency adjustment -- which reduces the evidential weight of common values such as a very frequent surname -- requires more data than this to be meaningful, and below 1,000 records it distorts results. It was therefore not applied. The calibration figures stated in this report were measured with term-frequency adjustment enabled on a larger reference set.
4 contact record pair(s) scored at or above the stated threshold, from 9,901 pairs compared across 250 contact records.
Each pair shows the evidence that produced its score. Bars to the right are evidence the records are the same person; bars to the left are evidence they are not. Contradicting evidence is shown, not suppressed. The bars sum to the total. The first bar, “starting point”, is the position before any evidence is considered: two records picked at random are unlikely to be the same person, so it always counts against a match.
Record 529841770207[withheld] Record 529841771210[withheld]
Record 529841770191[withheld] Record 529841771209[withheld]
Record 529841770207[withheld] Record 529841771231[withheld]
Record 529841771210[withheld] Record 529841771231[withheld]
Records grouped into entities
5 record(s) were grouped into 2 group(s) of records that the flagged pairs connect, directly or through another record in the same group. The largest group contains 3 record(s).
Where the pairs above connect three or more records, those records form one group. A group of three rests on the links shown, not on a separate comparison of every member against every other.
3 records: Record 529841770207 (529841770207); Record 529841771210 (529841771210); Record 529841771231 (529841771231)
2 records: Record 529841770191 (529841770191); Record 529841771209 (529841771209)
Pairs below the reporting threshold, listed for examination
A further 3 pair(s) scored between 5.0 and the reporting threshold of 8.0. They are listed in this report for examination and are NOT reported as duplicate records. On the reference set used to calibrate this threshold, 98.8% of pairs in this band were known duplicates. No conclusion is drawn about any pair in this band.
Record 529846589149[withheld] Record 529846589171[withheld]
Record 529846588142[withheld] Record 529846764226[withheld]
Record 529846588130[withheld] Record 529846589139[withheld]
Procedure 5 · Attachment reconciliation
0 note record(s) were examined, of which 0 reference at least one attachment. 0 distinct attachment reference(s) were found.
Attachments were enumerated by walking note records and resolving each attachment reference individually. The portal's full file library was not listed. Files stored in the portal that are not attached to a record examined here -- marketing assets, template images -- are outside the scope of this procedure and are not counted.
Procedure 6 · Exclusions from scope
Agreed in advance. These matters were not examined and no finding is made in respect of them.
Records held in the HubSpot recycling bin (archived) are excluded. This report covers live records only, as at the per-object extraction timestamps stated above. HubSpot's list endpoints document no reliable parameter for retrieving archived records, so archived data is defined out of scope explicitly rather than filtered by undocumented behaviour.
Attachments were enumerated by walking note records and resolving each attachment reference individually. The portal's full file library was not listed, and files not attached to a record examined here -- marketing assets, template images -- are outside the scope of this procedure and are not counted.
Association integrity was assessed in health-check mode only. No source system was provided, so associations present in a prior system could not be compared against those present here. Nothing in this report states that associations were preserved.
Company-name matching has not been calibrated against a labelled reference set. Duplicate identification covers contact records only.
first name; surname; date of birth; email address; city; the username part of the email address; the first three letters of the surname; the first three letters of the forename; the year and month of birth
Total API requests
11
Known duplicate pairs identified
29.0%
Known duplicates identified at entity level
43.0%
Review band
match weight 5.0 to 8.0
False positives observed at this threshold
none, against 400 records known to be distinct individuals
What the comparison rules mean for this finding. Two records were only compared if they shared at least one of the attributes listed above. A pair sharing none of them was never scored and could not be identified as a duplicate, however similar it may be. Against the calibration reference set this method identified 29.0% of known duplicate pairs. Duplicate counts in this report are therefore a minimum, not a total.
How the calibration figure was obtained. HubSpot enforces email uniqueness on contacts, so two contact records in this system can never share an address. An exact email match is the strongest single piece of evidence available to the model, and it is therefore absent by construction here. The reference set was reshaped to obey that same constraint before recall was measured, so the figures above describe performance on data shaped like this system rather than on a benchmark that permits evidence this system cannot produce.
Pairs and entities are counted differently. A pair figure counts each link separately. An entity figure counts a duplicate as found when two records end up in the same group, whether linked directly or through a third record. The same procedure at the same threshold identified 29.0% of known duplicate pairs and 43.0% at entity level. Both are stated so that neither is read as the other.
Who may rely on this report
Nobody may rely on this report. It is a specimen, produced from invented records, and no engagement stands behind it. A report issued for a real engagement names its addressee here and restricts reliance to the parties listed below it:
Nobody — this is a specimen and no party may rely on it
In a real engagement this names the addressee and any party they nominate, and no one else
No other party may rely on this report. Noorflows LLC accepts no responsibility to any party other than those named above, including any party into whose hands this report may come.
Independence
Noorflows LLC holds no financial interest in the system examined and did not design, build, migrate or operate the system or the data reported on. No fee payable under this engagement depends on the findings stated.
Procedure 7 · Sign-off
The procedures described above were performed under my supervision and the factual findings stated are those produced by them.