Trust Center - Figment

Figment

Security First | Risk Mitigation | Slashing Prevention

Figment's multi-layered security approach encompasses continuous proactive measures and purpose-built controls to maximize the resiliency and security of its staking services.

Security is integrated throughout all aspects of Figment to reduce risk and enable the assurance, integrity and confidentiality customers expect.

grc@figment.io

Compliance

SOC 2 Type II

ISO 27001:2022

SOC 1 Type I

Node Operator Risk Standard (NORS)

Resources

Security Program

Information Security Policy

Risk Management Procedure

Technical Security Policy

Annual Risk Assessment Summary

Penetration Tests

Figment Mutable Push Transfer Splitter Smart Contract Security Assessment Report

Figment ETH2 Depositor (0x01 Validators) Smart Contract Security Audit Report

Figment ETH2 Depositor (0x02 Validators) Smart Contract Security Audit Report

Figment App, Admin, and API Pentest Report 2025

Compliance

2025 Figment SOC 2 Type 2 Report

2025 Figment SOC 2 Bridge Letter.pdf

2025 Certificate - ISO:27001.2022.pdf

2025 Figment SOC 1 Type 1 Report

Legal & Insurance

Certificate of Insurance E&O - Technology

Certificate of Insurance - Proof Excess Liability (Slashing)

Certificate of Insurance - Tech EO_Cyber_Staking Policy

Certificate of Insurance - D&O

Controls

Organizational security

Threat Management

Infrastructure security

Availability & Reliability

Incident Management

Business Continuity

FAQ

Does Figment have slashing event coverage?

How does Figment safeguard against DDoS attacks on a validator node?

How does Figment safeguard against DDoS attacks?

What security measures does Figment take to ensure the security of its staking services?

Figment's commitment to security assurance is top priority. Figment has been examined to attest that its system and the suitability of the design of controls meets the AICPA's SOC 2 Type II requirements. Figment has received certification from an independent auditor for compliance with ISO/IEC 27001:2022, a security management standard for information security management systems (ISMS) and their requirements.