What exactly is the end goal or problem you are trying to solve here?
By default the FusionHub from Customer A and B will advertise any routes they know about to your HQ FusionHub, that in turn would pass routes that it learns from Customer B to Customer A and so on.
Configuring route / peer isolation on the HQ hub should drop the route advertisments from OSPF between your HQ and the Customers.
However that does not stop traffic flowing if the route could be learned by some other means, so firewall rules should be configured to isolate the customer networks - that may be easier said than done if these customers all manage their own address spaces without any coordination.
Using multiple VRFs on the HQ FusionHub is probably the correct way forward here, you would end up with a routing table per customer, which would solve the isolation problem without complex or unweildy firewall rules on the HQ FusionHub.
Have a look at this post and see if it would do what you want: