Security Advisory: Third-Party Supply-Chain Credential Exposure (Trivy) — March 2026
ABBYY Logo

Trust Center

Start your security review
View & download sensitive information
ControlK

Welcome to ABBYY's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.

  • McDonald's
  • Siemens
  • Yum! Brands
  • PepsiCo
  • Volkswagen UK
  • Deloitte
  • Fujifilm
  • Erste Group
  • Vinmar
  • Konica Minolta

Documents

REPORTSPentest Report

Trust Center Updates

Security Advisory: Third-Party Supply-Chain Credential Exposure (Trivy) — March 2026

Copy link
Incidents

We identified potential exposure of internal credentials associated with our CI/CD and artifact management tooling, arising from the known March 2026 Trivy supply chain compromise.

Based on our investigation to date, we have found no evidence of unauthorised use of the affected credentials within the systems and logs available to us, and no related alerts were raised by our security operations centre during the relevant period. The credential's access permissions were time-limited by design and had expired within approximately 60 hours of issuance, independent of any remediation action taken. As a precaution, we have also rotated the affected credentials.

We will update this notice should any new information emerge.

A message to our customers about the Klue security incident

General

ABBYY was recently informed of a security breach involving Klue, a third-party platform previously used for competitive intelligence. The breach impacted Salesforce data accessed through Klue's integration.

We want to assure you that ABBYY's network, products, and technology were not affected. Our systems remain secure.
In response, we immediately revoked the affected credentials, disabled the impacted integration, discontinued Klue's use and completed a full security review to confirm no further issues.

If you have questions, please contact our security team at infosec@abbyy.com. Thank you for your trust in ABBYY. You can also subscribe to receive automatic updates as they become available.

SOC 2 Report

Compliance

The 2026 ABBYY SOC2 Type II report has been published on TrustCenter. This report covers the period of April 1, 2025 to March 31, 2026. It also covers our Vantage, Timeline and FlexiCapture systems in one report so there's no need to download multiple reports any longer.

Built onSafeBase by Drata Logo