Trust Center - Figment

Figment

Security First | Risk Mitigation | Slashing Prevention

Figment's multi-layered security approach encompasses continuous proactive measures and purpose built controls to maximize the resiliency and security of its staking services.

Security is integrated throughout all aspects of Figment to reduce risk and enable the assurance, integrity and confidentiality customers expect.

grc@figment.io

Controls

Organizational security

Control
Employee Security Training
Figment has an ongoing security awareness program employing various channels for engagement. These include content sharing, phishing simulations, and learning platform modules. New employee education and mandatory information security training is required for all team members.
Access Management
Figment manages access to its resources through a request and approval process for onboarding, transfers, and terminations. Access is evaluated based on business need and role function.
Highly restrictive, privileged access is provided through a real-time request-and-approval process monitored by the security team, reviewed on a quarterly basis, and reported through an internal audit process.
Endpoint Security
Endpoints are protected against data leakage from device loss via an endpoint (disk) encryption solution. Multi-factor authentication controls, desktop firewalls and next-gen endpoint detection and response (EDR) protections limit threat exposure.
Personnel Screening
Figment conducts appropriate team member screening prior to authorizing access. Background screening may include a review of references, identity verification, public information, criminal history, violent offender registry, and employment history. Additional background checks will be required for roles that require privileged access.
Risk Management
Figment's risk assessment program considers, and mitigates as appropriate, information security risks and vulnerabilities within critical networks, blockchain participation, staking operations, vendor services and third-party integrations.
Continuous risk reviews and annual assessments are conducted with key department leaders to discuss issues and prioritization of remediation efforts across the organization.
Security Responsibilities
All Figment team members are responsible for being vigilant, adhering to information security policies, participating in awareness campaigns, following security standards, and reporting security incidents.
Security Reviews
Security reviews are conducted across a variety of projects, technologies, vendor outsourcing arrangements and integration activities at Figment. Findings are prioritized for remediation through the risk register and governance reporting processes.
Vendor Management
Figment vendors are required to meet security standards based on their potential risk to the organization. Depending on the level of risk and vendor profile, standard terms and conditions include contractual obligations relating to information security. These clauses may include the right to audit.

Threat Management

Control
Application Security
Application security controls mitigate code-quality risks introduced from open source software. Existing controls include secure software development lifecycle (SSDLC), code reviews, web application firewalls (WAF), testing and approvals prior to code release.
Load balancers manage the quality of service rate limiting and prevent unauthenticated requests.
Source code is regularly scanned for any vulnerabilities prior to production/go-live utilizing SAST (static application security testing) solutions.
Bug Bounty
Figment utilizes Bugcrowd to field all bug submissions, escalate when required, and to patch or respond to issues found.
More details at https://www.figment.io/responsible-disclosure
Penetration Testing
Figment identifies and mitigates risks through regular network and application, external and internal security testing, conducted by a certified Red Team member.
Remediation activities for discovered vulnerabilities are performed in order of criticality rating and tracked through a risk management process to include retesting until resolution.
Responsible Disclosure
Figment welcomes reports from third-party security researchers and their help in making its services and platforms more secure.
More details at https://www.figment.io/responsible-disclosure
Vulnerability Scanning
Figment's vulnerability management framework dictates the continuous lifecycle of identifying, evaluating, remediating and validating vulnerabilities.
Vulnerabilities are identified through industry/vendor sources, internal security scanning and penetration testing.
Automated scanning tools are used for application and system security vulnerabilities on a frequent basis.
Remediation is conducted based on criticality.

Infrastructure security

Control
Network Security
Figment-managed networks are designed using a multi-cloud, multi-tiered segmented approach. Connectivity is restricted by VPNs, private links and advanced identity management solutions. Restricted networks are blocked from the public internet. Security standards are followed based on vendor hardening benchmarks and security best practices.
Physical Access Control - Data Center
Figment's private physical infrastructure is hosted in SOC 2 compliant third-party facilities. Physical and environmental controls include physical barriers, 2N power and cooling, redundant fiber, card access, fire suppression systems, control systems, security guards, biometrics, cameras, key locks, monitoring and logging, and 24/7 access.
Only restrictive authorized personnel are allowed inside these data centers and all access is logged.
Systems Security
System security is built into Figment's server platforms using automation wherever possible. Hardening measures and controls are incorporated into server builds.
- Unnecessary ports, services, system protocols, system and network utilities, programs and accounts are disabled or removed.
- Host-based firewalls are enabled.
- Logging is enabled for audit trail management.
- Patch management is reviewed and applied to assets either automatically or manually depending on the asset.
Zero-Trust Architecture
Restricted environments utilize a zero-trust architecture with tools for policy enforcement and continuous validation and monitoring.

Availability & Reliability

Control
Denial of Service (DoS) Protection
Figment uses a DNS provider and failover design that monitors for DDoS attacks and can mitigate on the global network level.
Infrastructure Redundancy
Figment's network infrastructure includes diverse paths across various cloud and data center providers supporting blockchain participation.
Key Management
Validator key management is critical to Figment’s blockchain participation and staking lifecycle. Limited privileged key custodians with a business need have access to appropriate security tiers, encrypted hardware devices and encrypted vaults to manage keys.
Service Monitoring
Figment utilizes performance and security monitoring tools. A 24/7 on-call operations and security response team is available for response and issue resolution.
Slashing Protections
Figment has a robust infrastructure strategy in place to reduce the likelihood and severity of a slashing event.
Figment has insurance policies in place that help cover slashing, downtime and/or missed rewards that may occur across its supported networks.

Incident Management

Control
Incident Management and Response
Figment's incident management procedure ensures that incidents are resolved as quickly as possible to normalize service operations and minimize any adverse operational or security impact. All incidents are triaged, escalated and reported appropriately.

Business Continuity

Control
Business Continuity Plan
Figment maintains recovery plans that document the organizational processes for triage, remediation, and recovery from catastrophic incidents or disasters that may impact critical business processes.
Disaster Recovery Plan
Figment's multi-cloud architecture design inherently provides high-availability and redundancy for disaster recovery events. However, failover requires careful attention to ensure that a slashing event is avoided. Applicable backups are in place with the consideration of safety over liveness in all cases. Controlled intervention processes are in place to confirm “safe off” of validator clients before a failover to backups.

Data Security

Control
Data Security
Figment does not store or transmit sensitive customer data or otherwise act as a custodian.
However, as part of Figment's standardized framework, encryption is utilized and enabled within supporting databases, communication channels, enforced over transmission and at rest within storage and platforms.
As part of Figment's staking services, public on-chain data is resolvable.

Privacy

Control
Privacy Policy
https://figment.io/resources/privacy-policy