Trust Center - Figment
Figment
Security First | Risk Mitigation | Slashing Prevention
Figment's multi-layered security approach encompasses continuous proactive measures and purpose built controls to maximize the resiliency and security of its staking services.
Security is integrated throughout all aspects of Figment to reduce risk and enable the assurance, integrity and confidentiality customers expect.
FAQ
Compliance
How can I get a copy of Figment's most recent audit attestations?
Figment's SOC 2 Type 2 Audit Report and ISO 27001:2013 Certificate can be requested under "Resources" or in the Compliance section of the Overview page.
Security
Does Figment have slashing event coverage?
For slashing and downtime penalties, Figment's off-the-shelf coverage generally covers up to 6-months worth of fees earned from the customer and 3-months worth of fees earned for missed rewards, annually.
How does Figment safeguard against DDoS attack at the Protocol level?
The PoS network protocol itself provides security against DDoS attacks. Being a decentralized network means that there is no single point-of-failure that can be attacked. However, if necessary Figment will add more relay nodes until the attack is over.
How does Figment safeguard against DDoS attacks on a validator node?
Figment has designed its networks to be dynamic and scalable. If a node is under attack, that node will be migrated elsewhere. Taking advantage of the distributed nature of blockchain data will not be lost and the migration will be seamless.
How does Figment safeguard against DDoS attacks?
Figment uses a DNS provider and failover design that monitors for DDoS attacks and can mitigate on the global network level.
How does Figment secure keys?
Key management capabilities are dependent on blockchain and either generated directly onto an encrypted FIPS 140-2 physical device restricted to custodians, or stored in a zero-trust vault solution.
What are Figment's security measures against validator nodes?
Figment utilizes a threat management approach and works closely with the PoS network protocol developers to get first-hand information about security threats, Red Team pre-emptive attack scenarios, enforcement of industry standard hardening practices and security and performance monitoring.
What happens if one validator node is compromised and what is the exposure for the others?
Each node runs completely independent of each other, at a bare minimum in a different private network. In the unlikely event that a node is compromised, the other nodes will not be affected.
What is monitored on the validator node and blockchain?
At the node level we monitor:
- VM monitoring
- CPU Disk
- Memory Disk Usage
- Network Line speed
At the blockchain level we monitor:
- Block Height
- Peer Count
- Number of transactions sent to a node
- Number of transactions pending in txpool
- Number of queued transactions in txpool
What security measures does Figment take to ensure the security of its staking services?
Figment utilizes a proactive zero-trust architecture approach that enforces the following high-level controls:
- Access authentication, MFA and privileged monitoring
- Vendor and industry hardening
- Perimeter protections
- End-point protections and host checking
- Strong encryption methods
- Strict key custodian management
- Secure development
- Continuous vulnerability management
- Security 24/7 monitoring and alerting
- ISO 27001 and SOC 2 audit frameworks
Additionally, Figment has a dedicated security team that manages threats and enforces controls utilizing a risk-approached model.