Addigy Logo

Security Portal

Start your security review
View & download sensitive information
Ask for information
ControlK

Overview

Welcome to Addigy's Security Portal. Our commitment to data privacy and security is embedded in every part of our business. Use this Security Portal to learn about our security posture and request access to our security documentation.

Documents

DOCUMENTSCMMC CRM Report

Policies

Available upon request.

Security Portal Updates

Security Notice: Klue / Salesforce Incident (June 2026)

Copy link
Incidents

Status: No impact to Addigy

Summary

Addigy is aware of the recently disclosed security incident involving Klue, in which attackers compromised the Klue integration and stole OAuth tokens used to connect to customers' Salesforce environments. Several organizations have confirmed unauthorized access to their Salesforce data as a result.

Addigy does not use Klue. No Addigy systems, customer data, or Salesforce data were affected.

Addigy's position

Because Addigy does not use Klue, there is no direct exposure to this incident. We have reviewed our environment and confirmed:

  • Addigy does not have, and has never had, the Klue integration connected to any Addigy system.
  • No Addigy customer data was involved in this incident.
  • Addigy's products and services were not affected and required no customer action related to this event.

Our ongoing commitment

While this specific incident does not affect us, we treat third-party integration security as an ongoing priority. We are evaluating all Addigy third-party providers to verify if they were impacted by this incident. We maintain controls and monitoring around the third-party applications connected to our systems, and we continue to review and strengthen our defenses against this class of supply-chain attack.

Questions

If you have questions about this notice or Addigy's security practices, please contact our security team at security@addigy.com.

SOC 2 Type II Reports for 2025

Compliance

We have recently completed our audit and received the finalized SOC 2 Type II and SOC 3 reports for 2025.

They are now currently available on our Security Portal for your review.

Please reach out to us if there are any questions at security@addigy.com or compliance@addigy.com.

In Response to the React2Shell Vulnerability

Vulnerabilities

Following the disclosure of React2Shell (CVE-2025-55182), Addigy immediately conducted a review of all of its libraries, third-party packages, and systems.

After the review, we have determined that none are vulnerable to React2Shell. We do not use the React framework, its server components, nor Next.js in any of our systems.

The necessary components for the React2Shell vulnerability are not present in Addigy systems.

If you have any questions or need additional information, please contact our security team directly at security@addigy.com.

In Response to the Gainsight Security Incident

Incidents

Update to Gainsight Security Incident

On Monday, December 15 2025, Addigy completed our immediate and thorough investigation, which included verification with the Salesforce security team, confirms no customer data was exposed, accessed, or exfiltrated during this incident.

To secure our environment and as a precautionary measure, we have invalidated and rotated all tokens for any related systems. Log analysis indicates the only information potentially accessed was minimal Addigy employee user data (specifically company usernames and emails), which belongs exclusively to our employees.

Your security and trust remain our highest priority. If you have any questions, please contact our security team directly at security@addigy.com.


On Saturday, November 22 2025, Addigy was notified of a incident involving unauthorized access to its Salesforce Environment. The investigation suggests this occurred via a critical vulnerability with the integration between Gainsight Software and Salesforce.

This is a broader incident affecting organizations beyond Addigy, as detailed here: Salesforce Connection Failure

Impact and Investigation

  • Addigy's Security Team is actively investigating the incident in collaboration with both Salesforce and Gainsight. Updates will be provided as the situation evolves.

  • Core Services Unaffected: Addigy’s SaaS Cloud Interface and essential services related to Device Management and MDM remain functional and were not impacted.

  • Data Exposure Status: At this time, the investigation indicates that only an internal Salesforce Environment login was attempted, and no customer data has been exposed. Further investigation is underway to affirm this conclusion.

Data Contained in Salesforce

Salesforce is used by Addigy for sales automation and account management, as part of Addigy’s subprocessors. The data stored includes Account Holder Names, Phone Numbers, and Emails.

If you have additional questions or need additional information, please contact security@addigy.com.

SOC 2 Type II Reports for 2024

Compliance

We have recently completed our audit and received the finalized SOC 2 Type II and SOC 3 reports for 2024!

They are now currently available on our Security Portal for your review.

Please reach out to us if there are any questions at security@addigy.com or compliance@addigy.com.

If you need help using this Security Portal, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo