
Fig announced today that Security Operations engineers can now build, ship, and observe every change to their detection and response infrastructure through a single workflow, delivering what the company describes as the first true CI/CD for security operations. The result is a shift in tempo. Detections and configurations that once took weeks can now be built in minutes and shipped with accuracy and confidence.
The Problem Fig Is Solving
Security operations environments rarely sit still. New data sources, detections, automations, and cloud services arrive daily, while upstream systems shift without warning. A minor update in one place can quietly break a detection pipeline somewhere else. When that happens, coverage gaps open, and teams lose the ability to detect and respond to threats they assumed they were watching.
That fragility is the gap Fig is built to close. The company positions itself as the pioneer of Security Operations Resilience, a category focused on keeping detection and response working through constant change rather than treating each change as a fresh risk.
How the Workflow Runs
The platform is rooted in security data lineage, which Fig describes as a deterministic graph of every detection flow across the entire SecOps stack. An engineer describes the change they need. Fig analyzes the live environment and proposes it. Every proposed change is simulated and tested to prove its impact before it reaches production, then deployed in a single click, with full version control and rollback available. Continuous observability then confirms that every detection flow, both current and new, works as intended.
Underneath sits the lineage itself, a deterministic, ground-truth graph of the SecOps infrastructure. Every detection and data source is mapped into a single flow. Fig says this is why it knows the infrastructure down to the inch, and why pipelines keep running as intended through any change upstream or downstream.
What Changes for Teams
The new capabilities target work security teams already do. Threat reports become detections and queries that protect the environment today rather than next quarter. SIEM migrations finish in weeks instead of months and stay fully operational throughout. Full control over the data plane lets teams dictate ingest and storage spend without touching live detections.
Jayme Hancock, Head of Security Operations and Engineering at AppLovin, pointed to the speed and the confidence. “With Fig, we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing,” he said. “My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.’”
Backing and Traction
Today’s announcement builds on the promise Fig launched with a few months ago. The company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named an RSAC Innovation Sandbox finalist, and has deployed across dozens of Fortune 500 companies. Its founders are veterans of Google SecOps and Siemplify who modernized some of the world’s largest and most complex SOCs, and who saw firsthand what silently breaks inside them.
Gal Shafir, Co-Founder and CEO of Fig, framed the release as a way to remove a long-standing trade-off. “Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,” he said. “Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.”
The Bigger Picture
As threats accelerate, the SOC functions as the last line of defense, and its resilience has never mattered more. Fig’s argument is that resilience should be a default state rather than something teams scramble to restore after a change breaks something. The founders describe the outcome as a SOC where every change is designed with context, proven before production, and continuously verified after. Agile by design, resilient by default.
The engineering lifecycle Fig now offers borrows a familiar idea from software development and applies it where it has been absent. Developers have long relied on build, ship, and observe cycles backed by testing and rollback. Fig’s position is that security operations deserve the same discipline, and that closing this gap is what lets teams move quickly without trading away the confidence that their detections still hold.