For security operations teams, change has become a constant. New cloud services, data sources, detections, and automations are added continuously, while upstream systems evolve without notice. The result is an environment where even routine updates can unintentionally disrupt detection pipelines, reducing visibility into potential threats.
Fig believes those challenges require a different approach. The company has unveiled what it calls the first true continuous integration and continuous delivery (CI/CD) workflow for Security Operations (SecOps), expanding its platform to cover the entire engineering lifecycle for security operations. The release is designed to help SecOps Engineers build, deploy, and continuously observe infrastructure changes while maintaining confidence that detection pipelines continue to function as expected.
Applying Software Engineering Principles to Security Operations
At its core, Fig is giving SecOps something it has never had: A complete engineering lifecycle for detections and configurations. Rather than requiring engineers to manually navigate complex security infrastructure, Fig allows them to describe the detection or configuration they want to create. The platform then analyzes the live environment and generates a proposed implementation based on its understanding of the existing infrastructure.
Before any change reaches production, Fig says it is simulated and tested to demonstrate its expected impact. Engineers can then deploy approved changes with version control and rollback capabilities, while continuous observability verifies that detection flows remain operational after deployment.
The workflow mirrors practices commonly found in software development, where testing and validation occur before code reaches production environments.
A Data Lineage Model Designed for Security Infrastructure
Underlying the platform is what Fig describes as a deterministic graph representing security data lineage. The model maps detections, data sources, and every connection between them into a single operational view of the SecOps environment.
According to the company, this foundation enables Fig to understand how proposed changes affect the broader detection pipeline. By maintaining visibility across the entire infrastructure, the platform is intended to preserve operational resilience even when upstream or downstream systems change.
The company says this continuous verification allows security teams to identify issues before they affect detection coverage.
Supporting Everyday SecOps Challenges
Fig says the expanded platform is intended to streamline several tasks that frequently consume security engineering resources.
Threat intelligence can be translated into detections and queries much sooner, allowing organizations to implement protections without lengthy development cycles. The platform is also designed to simplify SIEM migrations by enabling organizations to remain fully operational while completing projects in weeks instead of months.
In addition, teams can manage data ingestion and storage costs through greater control over the data plane without disrupting existing detections.
The overall objective is to reduce the operational effort required to maintain modern security infrastructure while allowing engineers to focus on security logic rather than implementation details.
Early Customer Experience
Jayme Hancock, Head of Security Operations and Engineering at AppLovin, said the platform has changed how his team approaches detection engineering.
"With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing," said Hancock. "My team builds with a confidence we've never had, and yeah, we've even started 'vibe parsing.'"
The feedback highlights the company's emphasis on shortening engineering timelines without sacrificing confidence in production deployments.
Continuing the Company's Focus on Security Operations Resilience
The product expansion builds on Fig's broader strategy around Security Operations Resilience. Since launching publicly, the company has announced $38 million in funding from Team8, Ten Eleven Ventures, and Crosspoint Capital, earned recognition as an RSAC Innovation Sandbox finalist, and said its technology has been deployed across dozens of Fortune 500 companies.
The founders, who previously worked on Google SecOps and Siemplify, developed the platform after seeing how infrastructure changes could silently affect large-scale security operations. Their goal, according to the company, is to give security teams a workflow where every change is evaluated before deployment and continuously monitored afterward.
"Security teams shouldn't have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure," said Gal Shafir, Co-Founder and CEO of Fig. "Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve."
This article was written in cooperation with Tom White