Security operations environments are constantly evolving. New cloud services, data sources, automations and detections are introduced regularly, while upstream systems can change without notice. Although these updates are intended to improve security, they can also create unintended consequences by disrupting detection pipes and leave organizations with visibility gaps.
Fig He believes the problem has less to do with creating more detections and more to do with managing change safely. To address that challenge, the company has introduced what it describes as the industry’s first full SecOps engineering lifecycle, providing a CI/CD style workflow security operations (SecOps) engineers so they can create, deploy, and continually observe changes in their environments.
Bringing software engineering principles to SOC
In essence, Fig gives SecOps something it has never had before: a complete engineering lifecycle for detections and configurations. Instead of requiring engineers to manually create detections and configurations, the platform allows them to describe the outcome they want. Fig analyzes the living environment, proposes necessary changes, and evaluates their potential impact before something reaches production.
Each proposed update is simulated and tested before implementation, according to the company. Once approved, changes can be deployed with version control and rollback capabilities, while continuous observability verifies that new and existing discovery flows continue to function as expected.
Rather than introducing another standalone security tool, Fig is applying practices familiar to software developers, including testing, validation, and controlled deployment, to the daily work of security operations teams.
A foundation built on security data lineage
Supporting the workflow is what Fig describes as a deterministic graph of your security data lineage. The platform maps every detection, data source, and connection across the entire SecOps infrastructure into a single operational view.
This detailed understanding of the environment allows Fig to evaluate proposed changes against context, helping to determine how updates may impact the broader detection process. According to the company, continuous verification ensures that these pipelines continue to operate correctly even when changes occur in upstream or downstream infrastructure.
The goal is to reduce the risk of silent failures that can occur when security environments become increasingly complex.
Accelerate daily security engineering
The expanded platform is designed to accelerate several routine but time-consuming security engineering tasks.
Fig claims that security teams can transform threat reports into detections and queries much faster than traditional workflows allow, allowing organizations to respond more quickly to emerging threats. The platform also aims to simplify SIEM migrations by allowing organizations to remain fully operational during the transition, reducing projects that typically take months to weeks.
Additionally, organizations can gain greater control over the data plane, making it easier to manage data ingestion and storage costs without impacting live detections or disrupting existing workflows.
Customer experience
Jayme Hancock, head of security engineering and operations at AppLovin, said the platform has significantly changed the way her team approaches detection engineering. “With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless pipeline,” he said. “My team is built with a trust we’ve never had before and, yes, we’ve even started ‘analyzing the vibe.'”
The experience reflects Fig’s broader goal of reducing engineering overhead while giving teams greater confidence that changes will work as expected once implemented.
Expand the view of security operations resilience
The latest announcement builds on Fig’s broader focus on security operations resilience. Since coming out of stealth, the company has raised $38 million from Team8, Ten Eleven Ventures and Crosspoint Capital, was named an RSAC Innovation Sandbox finalist, and says its platform has been adopted by dozens of Fortune 500 organizations.
Founded by Google SecOps and Siemplify veterans, Fig built the platform around the idea that every infrastructure change should be designed with full context, validated before deployment, and continuously monitored afterward.
As co-founder and CEO Gal Shafir explained, “Security teams should not have to choose between moving quickly and maintaining confidence in their SecOps infrastructure. Fig gives SecOps engineers the same modern engineering workflow that software developers have long relied on. They can design changes with full context, demonstrate that those changes work before deployment, and continually verify that their security operations remain resilient as their environments evolve.”
By bringing modern engineering workflows to the SOC, Fig is positioning its platform to help security teams manage more and more dynamic environments maintaining confidence that critical detection and response capabilities remain intact with every change.






