Policies
Available upon request.
Security Portal Updates
Security Notice: Klue / Salesforce Incident (June 2026)
Status: No impact to Addigy
Summary
Addigy is aware of the recently disclosed security incident involving Klue, in which attackers compromised the Klue integration and stole OAuth tokens used to connect to customers' Salesforce environments. Several organizations have confirmed unauthorized access to their Salesforce data as a result.
Addigy does not use Klue. No Addigy systems, customer data, or Salesforce data were affected.
Addigy's position
Because Addigy does not use Klue, there is no direct exposure to this incident. We have reviewed our environment and confirmed:
- Addigy does not have, and has never had, the Klue integration connected to any Addigy system.
- No Addigy customer data was involved in this incident.
- Addigy's products and services were not affected and required no customer action related to this event.
Our ongoing commitment
While this specific incident does not affect us, we treat third-party integration security as an ongoing priority. We are evaluating all Addigy third-party providers to verify if they were impacted by this incident. We maintain controls and monitoring around the third-party applications connected to our systems, and we continue to review and strengthen our defenses against this class of supply-chain attack.
Questions
If you have questions about this notice or Addigy's security practices, please contact our security team at security@addigy.com.
SOC 2 Type II Reports for 2025
We have recently completed our audit and received the finalized SOC 2 Type II and SOC 3 reports for 2025.
They are now currently available on our Security Portal for your review.
Please reach out to us if there are any questions at security@addigy.com or compliance@addigy.com.
In Response to the React2Shell Vulnerability
Following the disclosure of React2Shell (CVE-2025-55182), Addigy immediately conducted a review of all of its libraries, third-party packages, and systems.
After the review, we have determined that none are vulnerable to React2Shell. We do not use the React framework, its server components, nor Next.js in any of our systems.
The necessary components for the React2Shell vulnerability are not present in Addigy systems.
If you have any questions or need additional information, please contact our security team directly at security@addigy.com.
In Response to the Gainsight Security Incident
Update to Gainsight Security Incident
On Monday, December 15 2025, Addigy completed our immediate and thorough investigation, which included verification with the Salesforce security team, confirms no customer data was exposed, accessed, or exfiltrated during this incident.
To secure our environment and as a precautionary measure, we have invalidated and rotated all tokens for any related systems. Log analysis indicates the only information potentially accessed was minimal Addigy employee user data (specifically company usernames and emails), which belongs exclusively to our employees.
Your security and trust remain our highest priority. If you have any questions, please contact our security team directly at security@addigy.com.
On Saturday, November 22 2025, Addigy was notified of a incident involving unauthorized access to its Salesforce Environment. The investigation suggests this occurred via a critical vulnerability with the integration between Gainsight Software and Salesforce.
This is a broader incident affecting organizations beyond Addigy, as detailed here: Salesforce Connection Failure
Impact and Investigation
-
Addigy's Security Team is actively investigating the incident in collaboration with both Salesforce and Gainsight. Updates will be provided as the situation evolves.
-
Core Services Unaffected: Addigy’s SaaS Cloud Interface and essential services related to Device Management and MDM remain functional and were not impacted.
-
Data Exposure Status: At this time, the investigation indicates that only an internal Salesforce Environment login was attempted, and no customer data has been exposed. Further investigation is underway to affirm this conclusion.
Data Contained in Salesforce
Salesforce is used by Addigy for sales automation and account management, as part of Addigy’s subprocessors. The data stored includes Account Holder Names, Phone Numbers, and Emails.
If you have additional questions or need additional information, please contact security@addigy.com.
SOC 2 Type II Reports for 2024
We have recently completed our audit and received the finalized SOC 2 Type II and SOC 3 reports for 2024!
They are now currently available on our Security Portal for your review.
Please reach out to us if there are any questions at security@addigy.com or compliance@addigy.com.




