Dossier · Private startup · 2 independent sources
Fig Security
Last updated: Jul 31, 2026
Fig Security develops Security Operations Resilience software that helps SOC teams detect when changes break security data flows, repair broken detections, and model, test, version, and roll back planned changes across the SecOps stack. The startup targets the operational fragility created by constant changes to log sources, parsers, pipelines, detections, and response automations.
Visit WebsiteCompany Overview
Fig Security is building a control and engineering layer for security operations rather than another endpoint, network, or threat-intelligence feed. Its official product positioning focuses on two causes of SecOps failure: unplanned drift, in which an upstream change silently breaks a detection or automation, and planned change, in which teams move cautiously because a rollout can reduce coverage or disrupt production. Fig says its platform can detect a broken security flow, trace the cause, suggest a repair, test it, and deploy it after approval. It also presents a workflow for modeling a planned change, checking its impact, deploying through version control, and rolling back when needed.
The underlying customer problem is credible and expensive. Detection-as-code is useful only when the parsers, data sources, routing, schemas, and downstream automations beneath a detection continue to work. In a modern hybrid or multi-cloud SOC, those dependencies are changed by infrastructure migrations, vendor updates, new telemetry, normalization work, and AI or automation initiatives. Fig’s proposed value is therefore operational continuity: preserving detection and response coverage while security teams change the stack. This is distinct from generic security posture management because the relevant unit is the functioning security workflow, not merely a configuration snapshot or list of vulnerabilities.
The initial market is enterprise security engineering and SOC teams with complex, heterogeneous tooling. The platform is intended to work across security infrastructure, including open-source components, and its messaging emphasizes reducing data plumbing, increasing coverage, and shipping changes faster with verification. That creates a potentially attractive wedge into teams that already spend heavily on SIEM, SOAR, detection engineering, and observability but still rely on scripts, tribal knowledge, and manual regression testing. The commercial challenge is that the product must integrate deeply enough to understand real data and control dependencies while remaining safe to operate in the customer’s most sensitive systems.
Fig emerged from stealth in March 2026 and public reporting describes $38 million raised across seed and Series A rounds, led by Team8 and Ten Eleven Ventures with experienced security-industry angels. The founders’ backgrounds at Google SecOps, Siemplify, and Cymulate are relevant to the problem, but public evidence does not establish recurring revenue, customer counts, retention, production scale, or independent security certifications. Customer testimonials displayed on the company site are useful market signals, including references attributed to security leaders at BNSF Railway, Netskope, Elastic, AppLovin, and a Fortune 500 pharmaceutical company, but they should not be treated as proof of paid deployments without diligence.
Competitive pressure comes from several directions. SIEM and SOAR vendors can add reliability, content-management, and automation features; detection-as-code and security-content vendors can own the development workflow; observability and data-pipeline platforms can expose upstream failures; and internal platform teams can build bespoke testing and rollback systems. Fig’s prospective edge is a cross-stack model of security-flow health combined with approval-gated repair and deployment. That edge will be durable only if the product has broad integrations, low false positives, strong change-impact analysis, and a measurable reduction in broken coverage and engineering toil.
The dual-use case is substantive but bounded. The same operational-resilience layer can protect commercial enterprises, regulated sectors, critical infrastructure operators, and defense-adjacent networks where a broken detection or response workflow can leave a mission-critical environment blind. It is not evidence of defense procurement or a defense-exclusive capability. Strategic relevance comes from making cyber defense more dependable under change: fewer silent coverage gaps, safer modernization, and better recovery from configuration or dependency failures. Diligence should therefore prioritize verified production outcomes, integration depth, data-handling architecture, deployment isolation, customer references, and evidence that automated repair remains explainable and reversible under pressure.
Dual-Use Assessment
Fig's core technology maintains detection and response workflows through infrastructure and configuration change. That is directly useful in commercial SOCs and has credible application in critical infrastructure, government-adjacent, and defense networks where loss of cyber visibility can become a mission or continuity risk; public sources do not establish defense customers or procurement.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Fig addresses a specific and persistent enterprise problem: detection and response degrade when the systems underneath them change, while manual testing and repair do not scale. Its founders and reported investors provide credible category experience, and the reported $38M financing supports a meaningful commercialization effort. The strategic case is strongest as infrastructure for reliable cyber defense and critical-system continuity, not as a defense-only product. The principal diligence questions are paid production adoption, measurable coverage improvement, integration breadth, deployment safety, and whether larger SIEM, SOAR, data-pipeline, or observability vendors can absorb the capability. This is an internal strategic-priority signal, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Fig could improve the reliability of the cyber-defense layer itself. By identifying silent breaks in security flows and making planned changes testable, versioned, and reversible, it may reduce the time that an enterprise operates with degraded detection or response coverage. That matters for critical infrastructure and defense-adjacent environments where a monitoring gap can compound an incident or delay recovery. The strategic value remains conditional on proof that the platform works across heterogeneous customer stacks without introducing new control-plane or data-access risk.
Key Technologies
- Security-flow drift detection
- Detection and response dependency mapping
- Automated root-cause analysis and repair suggestions
- Change-impact modeling and simulation
- Version-controlled SecOps deployment
- Approval-gated rollback workflows
- Cross-stack security data-flow testing
Use Cases & Applications
- Detecting broken SIEM and detection pipelines after upstream changes
- Testing parser, schema, routing, and log-source migrations before production
- Repairing failed detections and response automations with operator approval
- Versioning and rolling back SecOps content and infrastructure changes
- Maintaining cyber coverage across hybrid and multi-cloud environments
- Reducing detection-engineering and security data-plumbing toil
- Improving operational resilience for regulated and critical-infrastructure SOCs
- Supporting defense-adjacent networks that require dependable cyber visibility
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Fig Security official website Official product positioning for Security Operations Resilience, drift detection and repair, change modeling, deployment, and rollback.
- Fig Security platform page Official description of the platform and SecOps engineering lifecycle.
- Fig Security About page Official founder backgrounds and company positioning.
- TechCrunch: Fig Security emerges from stealth with $38M Independent reporting on the March 2026 launch, founders, and $38M combined seed and Series A financing.
- SecurityWeek: Fig Security launches with $38M Independent reporting on the funding, March 2025 founding date, founders, and Israeli cyber background.
- Fig Security LinkedIn company profile Public company metadata listing 11-50 employees, New York headquarters, private ownership, and 2025 founding.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.