# Figment

**Security First | Risk Mitigation | Slashing Prevention**

Figment's multi-layered security approach encompasses continuous proactive measures and purpose-built controls to maximize the resiliency and security of its staking services.

Security is integrated throughout all aspects of Figment to reduce risk and enable the assurance, integrity and confidentiality customers expect.

[grc@figment.io](mailto:grc@figment.io)

## Compliance

SOC 2 Type II

ISO 27001:2022

SOC 1 Type I

Node Operator Risk Standard (NORS)

## Resources

### Security Program

[Information Security Policy](https://trust.figment.io/?requestAccessOpen=true&requestedResources=66a97a4a429ff960283f20f4)

[Risk Management Procedure](https://trust.figment.io/?requestAccessOpen=true&requestedResources=66a97f08cf484e7c84a80525)

[Technical Security Policy](https://trust.figment.io/?requestAccessOpen=true&requestedResources=66a979ec429ff960283f1cad)

[Annual Risk Assessment Summary](https://trust.figment.io/?requestAccessOpen=true&requestedResources=66a2ec438dbf67ff7fda54e6)

### Penetration Tests

[Figment Mutable Push Transfer Splitter Smart Contract Security Assessment Report](https://trust.figment.io/?requestAccessOpen=true&requestedResources=66a2f02e96fd6675dc4639f2)

[Figment ETH2 Depositor (0x01 Validators) Smart Contract Security Audit Report](https://trust.figment.io/?requestAccessOpen=true&requestedResources=66a2f00d775b7765aec379a5)

[Figment ETH2 Depositor (0x02 Validators) Smart Contract Security Audit Report](https://trust.figment.io/?requestAccessOpen=true&requestedResources=68efc74cfe5ff88af8bcf53d)

[Figment App, Admin, and API Pentest Report 2025](https://trust.figment.io/?requestAccessOpen=true&requestedResources=68c9c7233815d6f8cb885d0e)

### Compliance

[2025 Figment SOC 2 Type 2 Report](https://trust.figment.io/?requestAccessOpen=true&requestedResources=66fea5e6d200575542144daa)

[2025 Figment SOC 2 Bridge Letter.pdf](https://trust.figment.io/?requestAccessOpen=true&requestedResources=67ab8c0aac78ce27ec3b8625)

2025 Certificate - ISO:27001.2022.pdf

[2025 Figment SOC 1 Type 1 Report](https://trust.figment.io/?requestAccessOpen=true&requestedResources=691b534459161cf90f8588fa)

### Legal & Insurance

[Certificate of Insurance E&O - Technology](https://trust.figment.io/?requestAccessOpen=true&requestedResources=690e7a7574d9908f1ab34262)

[Certificate of Insurance - Proof Excess Liability (Slashing)](https://trust.figment.io/?requestAccessOpen=true&requestedResources=6a175f181000cbfba6f785e5)

[Certificate of Insurance - Tech EO_Cyber_Staking Policy](https://trust.figment.io/?requestAccessOpen=true&requestedResources=6a1765eb829eaadbee5bee67)

[Certificate of Insurance - D&O](https://trust.figment.io/?requestAccessOpen=true&requestedResources=6a175b5d941296b1ad6a8332)

## Controls

[**Organizational security**](https://trust.figment.io/controls#organizational-security)

- Employee Security Training
- Access Management
- Endpoint Security

[**Threat Management**](https://trust.figment.io/controls#threat-management)

- Application Security
- Bug Bounty
- Penetration Testing

[**Infrastructure security**](https://trust.figment.io/controls#infrastructure-security)

- Network Security
- Physical Access Control - Data Center
- Systems Security

[**Availability & Reliability**](https://trust.figment.io/controls#availability--reliability)

- Denial of Service (DoS) Protection
- Infrastructure Redundancy
- Key Management

[**Incident Management**](https://trust.figment.io/controls#incident-management)

- Incident Management and Response

[**Business Continuity**](https://trust.figment.io/controls#business-continuity)

- Business Continuity Plan
- Disaster Recovery Plan

## FAQ

### Does Figment have slashing event coverage?

### How does Figment safeguard against DDoS attacks on a validator node?

### How does Figment safeguard against DDoS attacks?

### What security measures does Figment take to ensure the security of its staking services?

Figment's commitment to security assurance is top priority. Figment has been examined to attest that its system and the suitability of the design of controls meets the AICPA's SOC 2 Type II requirements. Figment has received certification from an independent auditor for compliance with ISO/IEC 27001:2022, a security management standard for information security management systems (ISMS) and their requirements.
