Verified User in Computer & Network Security
GC
Small-Business (50 or fewer emp.)
"Valuable for Audits, Needs Better Security Features"
4/5
What do you like best about Hubleto?

What I appreciate most about Hubleto is its fully modular open‑source architecture, which makes it extremely practical for my security consulting work at SecurIT GmbH when evaluating combined ERP‑CRM setups for German small‑and‑mid‑size enterprises. Unlike many closed‑source all‑in‑one business platforms, I can spin‑up isolated local test instances without heavy vendor‑locked restrictions. Since every SME customer configures their modules differently, I can enable or disable individual components one by one to mirror each client’s actual production setup. Not long ago I replicated the exact module stack for a regional wholesale client who ran sales, order processing and accounting modules while keeping HR features disabled. Being able to recreate their exact environment in‑house let me reproduce their cross‑module permission leak locally, instead of trying to troubleshoot blind on their live production system. I also value that Hubleto supports both cloud‑hosted and self‑hosted deployment modes. Plenty of our German local businesses insist on self‑hosting to keep personal customer data on‑premises for GDPR reasons, so I can test both deployment variants and compare their unique attack surfaces side‑by‑side. Another small but meaningful plus is its transparent role‑creation workflow. Building custom user roles is fairly intuitive, so I can demonstrate proper privilege‑separation practices directly to client system administrators during on‑site audit sessions. I once walked a part‑time IT admin through building restricted sales roles live inside Hubleto, showing him exactly how to lock sales staff out of sensitive financial tables. That said, the out‑of‑the‑box configurations are far from security‑ready, and I always warn clients not to go live with default settings. Even with those caveats, this flexible open‑source foundation gives my consulting team a realistic lab environment. It saves us from maintaining two separate test systems for ERP and CRM like we had to do back when we relied purely on SuiteCRM for simulation work, and helps me deliver practical, field‑tested security advice for our 11‑50‑person German SME clients. Review collected by and hosted on G2.com.

What do you dislike about Hubleto?

First off, its native audit logging is very limited for cross‑module activities. When users jump between CRM contact records and ERP order or finance modules, many critical actions such as bulk data exports, permission modifications, and mass record edits do not generate complete, immutable log entries. During one recent audit for that same local wholesale client, we needed to trace who had downloaded a large batch of customer personal data after a suspected internal data spill. Hubleto’s logs only captured basic user login timestamps. We could not track the actual export event, forcing the client to cross‑check separate web server access logs. That wasted almost a full day of audit work and created compliance uncertainty for their GDPR documentation that they had to resolve with their external legal counsel. Default permission hardening is another major weak spot. Out‑of‑the‑box role inheritance bleeds access rights across interconnected modules. Sales‑level users can inadvertently gain partial visibility into financial ERP datasets, just like the vulnerability I uncovered on that wholesale engagement. There is no built‑in permission sanity check or risk warning flag when admins assign new roles. System administrators without a deep security background will easily introduce over‑privileged accounts without realizing the risk. I would also love to see more granular controls for bulk‑action restrictions. Right now, there are no dedicated guardrails to limit mass exports or mass record deletions per user role. On another client review for a regional retail business, a junior sales employee mistakenly triggered a full export of thousands of customer contact records simply by clicking the wrong menu option. There was no confirmation prompt, no rate‑limiting, and no role‑based toggle to block bulk‑export functions for lower‑privilege staff. Fortunately the employee stored the file on local disk and did not share it further, but this incident represented a very real GDPR breach risk. Adding configurable role‑level toggles to block bulk exports and mass‑delete operations would stop these kinds of careless human errors before they happen. Review collected by and hosted on G2.com.

See what 2 reviewers think of Hubleto

4.3 out of 5 · Verified reviews from real users

Read all reviews