Welcome to Ontrack's Trust Center.
There is no room for missteps when it comes to security.
Given the nature of our business, we are entrusted with large amounts of sensitive and confidential information by our clients and understand that security is increasingly imperative for today’s corporations. We invest significant time and money to protect your most sensitive ESI.
Documents
Corporate Security
Corporate Security
We implement internal measures and practices to maintain a high standard of security.
Risk Profile
Risk Profile
We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request.
AI
AI
We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.
Incident Response
Incident Response
We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.
Risk Management
Risk Management
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
Cisco Catalyst SD-WAN Controller Authentication Bypass CVE-2026-20127 February 2026
We do not use Cisco for SD Wan and we do not utilize Cisco hardware, therefore, KLDiscovery is not affected by this vulnerability.
KLDiscovery SOC 2 Type II Report Now Available
KLDiscovery's annual SOC 2 Type II report for 2024-2025 is now available via KLDiscovery's Trust Center at https://trust.kldiscovery.com/?product=ontrack&itemUid=fa950d02-cbb3-4010-b917-7137a7c2a982&source=click
Please reach out to your primary KLDiscovery contact if you have any questions.
Vulnerabilities and Exposures events as CVE-2025-55182
KLDiscovery does not use the React Server. Concerning this, KLDiscovery is not affected by this vulnerability.
F5 Vulnerabilities and Exposures: CVE-2025 - 53868F5, CVE – 2025 – 57780 and CVE – 2025 – 61955
KLDiscovery does not own any of the affected products from F5 Networks, therefore no action has been taken outside of validating the fact that our product stack is not affected.
We do utilize NGINX as our on-premises load balancers – this product is owned by F5 but is not affected by this vulnerability.
Vulnerabilities and Exposures events as Oracle CVE-2025-61884, Oracle CVE-2025-61882
KLDiscovery is not affected by these vulnerabilities.








