Trust Center - Figment
Figment
Security First | Risk Mitigation | Slashing Prevention
Figment's multi-layered security approach encompasses continuous proactive measures and purpose built controls to maximize the resiliency and security of its staking services.
Security is integrated throughout all aspects of Figment to reduce risk and enable the assurance, integrity and confidentiality customers expect.
Controls
Organizational security
| Control |
|---|
| Employee Security Training Figment has an ongoing security awareness program employing various channels for engagement. These include content sharing, phishing simulations, and learning platform modules. New employee education and mandatory information security training is required for all team members. |
| Access Management Figment manages access to its resources through a request and approval process for onboarding, transfers, and terminations. Access is evaluated based on business need and role function. Highly restrictive, privileged access is provided through a real-time request-and-approval process monitored by the security team, reviewed on a quarterly basis, and reported through an internal audit process. |
| Endpoint Security Endpoints are protected against data leakage from device loss via an endpoint (disk) encryption solution. Multi-factor authentication controls, desktop firewalls and next-gen endpoint detection and response (EDR) protections limit threat exposure. |
| Personnel Screening Figment conducts appropriate team member screening prior to authorizing access. Background screening may include a review of references, identity verification, public information, criminal history, violent offender registry, and employment history. Additional background checks will be required for roles that require privileged access. |
| Risk Management Figment's risk assessment program considers, and mitigates as appropriate, information security risks and vulnerabilities within critical networks, blockchain participation, staking operations, vendor services and third-party integrations. Continuous risk reviews and annual assessments are conducted with key department leaders to discuss issues and prioritization of remediation efforts across the organization. |
| Security Responsibilities All Figment team members are responsible for being vigilant, adhering to information security policies, participating in awareness campaigns, following security standards, and reporting security incidents. |
| Security Reviews Security reviews are conducted across a variety of projects, technologies, vendor outsourcing arrangements and integration activities at Figment. Findings are prioritized for remediation through the risk register and governance reporting processes. |
| Vendor Management Figment vendors are required to meet security standards based on their potential risk to the organization. Depending on the level of risk and vendor profile, standard terms and conditions include contractual obligations relating to information security. These clauses may include the right to audit. |
Threat Management
| Control |
|---|
| Application Security Application security controls mitigate code-quality risks introduced from open source software. Existing controls include secure software development lifecycle (SSDLC), code reviews, web application firewalls (WAF), testing and approvals prior to code release. Load balancers manage the quality of service rate limiting and prevent unauthenticated requests. Source code is regularly scanned for any vulnerabilities prior to production/go-live utilizing SAST (static application security testing) solutions. |
| Bug Bounty Figment utilizes Bugcrowd to field all bug submissions, escalate when required, and to patch or respond to issues found. More details at https://www.figment.io/responsible-disclosure |
| Penetration Testing Figment identifies and mitigates risks through regular network and application, external and internal security testing, conducted by a certified Red Team member. Remediation activities for discovered vulnerabilities are performed in order of criticality rating and tracked through a risk management process to include retesting until resolution. |
| Responsible Disclosure Figment welcomes reports from third-party security researchers and their help in making its services and platforms more secure. More details at https://www.figment.io/responsible-disclosure |
| Vulnerability Scanning Figment's vulnerability management framework dictates the continuous lifecycle of identifying, evaluating, remediating and validating vulnerabilities. Vulnerabilities are identified through industry/vendor sources, internal security scanning and penetration testing. Automated scanning tools are used for application and system security vulnerabilities on a frequent basis. Remediation is conducted based on criticality. |
Infrastructure security
| Control |
|---|
| Network Security Figment-managed networks are designed using a multi-cloud, multi-tiered segmented approach. Connectivity is restricted by VPNs, private links and advanced identity management solutions. Restricted networks are blocked from the public internet. Security standards are followed based on vendor hardening benchmarks and security best practices. |
| Physical Access Control - Data Center Figment's private physical infrastructure is hosted in SOC 2 compliant third-party facilities. Physical and environmental controls include physical barriers, 2N power and cooling, redundant fiber, card access, fire suppression systems, control systems, security guards, biometrics, cameras, key locks, monitoring and logging, and 24/7 access. Only restrictive authorized personnel are allowed inside these data centers and all access is logged. |
| Systems Security System security is built into Figment's server platforms using automation wherever possible. Hardening measures and controls are incorporated into server builds. - Unnecessary ports, services, system protocols, system and network utilities, programs and accounts are disabled or removed. - Host-based firewalls are enabled. - Logging is enabled for audit trail management. - Patch management is reviewed and applied to assets either automatically or manually depending on the asset. |
| Zero-Trust Architecture Restricted environments utilize a zero-trust architecture with tools for policy enforcement and continuous validation and monitoring. |
Availability & Reliability
| Control |
|---|
| Denial of Service (DoS) Protection Figment uses a DNS provider and failover design that monitors for DDoS attacks and can mitigate on the global network level. |
| Infrastructure Redundancy Figment's network infrastructure includes diverse paths across various cloud and data center providers supporting blockchain participation. |
| Key Management Validator key management is critical to Figment’s blockchain participation and staking lifecycle. Limited privileged key custodians with a business need have access to appropriate security tiers, encrypted hardware devices and encrypted vaults to manage keys. |
| Service Monitoring Figment utilizes performance and security monitoring tools. A 24/7 on-call operations and security response team is available for response and issue resolution. |
| Slashing Protections Figment has a robust infrastructure strategy in place to reduce the likelihood and severity of a slashing event. Figment has insurance policies in place that help cover slashing, downtime and/or missed rewards that may occur across its supported networks. |
Incident Management
| Control |
|---|
| Incident Management and Response Figment's incident management procedure ensures that incidents are resolved as quickly as possible to normalize service operations and minimize any adverse operational or security impact. All incidents are triaged, escalated and reported appropriately. |
Business Continuity
| Control |
|---|
| Business Continuity Plan Figment maintains recovery plans that document the organizational processes for triage, remediation, and recovery from catastrophic incidents or disasters that may impact critical business processes. |
| Disaster Recovery Plan Figment's multi-cloud architecture design inherently provides high-availability and redundancy for disaster recovery events. However, failover requires careful attention to ensure that a slashing event is avoided. Applicable backups are in place with the consideration of safety over liveness in all cases. Controlled intervention processes are in place to confirm “safe off” of validator clients before a failover to backups. |
Data Security
| Control |
|---|
| Data Security Figment does not store or transmit sensitive customer data or otherwise act as a custodian. However, as part of Figment's standardized framework, encryption is utilized and enabled within supporting databases, communication channels, enforced over transmission and at rest within storage and platforms. As part of Figment's staking services, public on-chain data is resolvable. |
Privacy
| Control |
|---|
| Privacy Policy https://figment.io/resources/privacy-policy |