# Figment

**Security First | Risk Mitigation | Slashing Prevention**

Figment's multi-layered security approach encompasses continuous proactive measures and purpose built controls to maximize the resiliency and security of its staking services.

Security is integrated throughout all aspects of Figment to reduce risk and enable the assurance, integrity and confidentiality customers expect.

## Resources

[Bulk download](https://trust.figment.io/doc/trust-zip?r=mcypaja55g34jd85e07bzf)

### Security Program

|   |   |
|---|---|
| **Information Security Policy** | Copy link for Information Security Policy  
2026 Information Security Policy  
Request access Information Security Policy |
| **Risk Management Procedure** | Copy link for Risk Management Procedure  
2024 Risk Management Procedure  
Request access Risk Management Procedure |
| **Technical Security Policy** | Copy link for Technical Security Policy  
2026 Technical Security Policy, v2.2  
Request access Technical Security Policy |
| **Annual Risk Assessment Summary** | Copy link for Annual Risk Assessment Summary  
2025 Annual Risk Assessment Summary Report  
Request access Annual Risk Assessment Summary |
| **Figment Incident Management Summary** | Copy link for Figment Incident Management Summary  
2025 Incident Management Summary  
Request access Figment Incident Management Summary |
| **BCP/DR Statement and Plan Excerpt** | Copy link for BCP/DR Statement and Plan Excerpt  
2024 BCP/DR Statement and excerpt of first two pages of the BCP/DR Plan.  
Request access BCP/DR Statement and Plan Excerpt |
| **2025 Vendor Management Procedure** | Copy link for 2025 Vendor Management Procedure  
Vendor Management Procedure  
Request access 2025 Vendor Management Procedure |

### Penetration Tests

|   |   |
|---|---|
| **Figment Mutable Push Transfer Splitter Smart Contract Security Assessment Report** | Copy link for Figment Mutable Push Transfer Splitter Smart Contract Security Assessment Report  
Request access Figment Mutable Push Transfer Splitter Smart Contract Security Assessment Report |
| **Figment ETH2 Depositor (0x01 Validators) Smart Contract Security Audit Report** | Copy link for Figment ETH2 Depositor (0x01 Validators) Smart Contract Security Audit Report  
Request access Figment ETH2 Depositor (0x01 Validators) Smart Contract Security Audit Report |
| **Figment ETH2 Depositor (0x02 Validators) Smart Contract Security Audit Report** | Copy link for Figment ETH2 Depositor (0x02 Validators) Smart Contract Security Audit Report  
Request access Figment ETH2 Depositor (0x02 Validators) Smart Contract Security Audit Report |
| **Figment App, Admin, and API Pentest Report 2025** | Copy link for Figment App, Admin, and API Pentest Report 2025  
Request access Figment App, Admin, and API Pentest Report 2025 |
| **Figment API Pentest Report 2024** | Copy link for Figment API Pentest Report 2024  
Request access Figment API Pentest Report 2024 |
| **Figment App and Admin Pentest Report 2024** | Copy link for Figment App and Admin Pentest Report 2024  
Request access Figment App and Admin Pentest Report 2024 |
| **Figment Staking Gen 2 (SG2) Environment Pentest Report 2024** | Copy link for Figment Staking Gen 2 (SG2) Environment Pentest Report 2024  
Request access Figment Staking Gen 2 (SG2) Environment Pentest Report 2024 |

### Compliance

|   |   |
|---|---|
| **2025 Figment SOC 2 Type 2 Report** | Copy link for 2025 Figment SOC 2 Type 2 Report  
Request access 2025 Figment SOC 2 Type 2 Report |
| **2025 Figment SOC 2 Bridge Letter.pdf** | Copy link for 2025 Figment SOC 2 Bridge Letter.pdf  
Request access 2025 Figment SOC 2 Bridge Letter.pdf |
| **2025 Certificate - ISO:27001.2022.pdf** | Copy link for 2025 Certificate - ISO:27001.2022.pdf  
View 2025 Certificate - ISO:27001.2022.pdf |
| **2025 Figment SOC 1 Type 1 Report** | Copy link for 2025 Figment SOC 1 Type 1 Report  
Figment 2025 SOC 1 Type 1 Audit Report  
Request access 2025 Figment SOC 1 Type 1 Report |
| **FIGMENT 2025 CSAE 3000 NORS Assurance Report** | Copy link for FIGMENT 2025 CSAE 3000 NORS Assurance Report  
Request access FIGMENT 2025 CSAE 3000 NORS Assurance Report |
| **SOC 1 Type 1 Bridge Letter** | Copy link for SOC 1 Type 1 Bridge Letter  
Request access SOC 1 Type 1 Bridge Letter |
| **2026 SOC 2 Type 2 Bridge Letter** | Copy link for 2026 SOC 2 Type 2 Bridge Letter  
2026 SOC 2 Type 2 Bridge Letter  
Request access 2026 SOC 2 Type 2 Bridge Letter |

### Legal & Insurance

|   |   |
|---|---|
| **Certificate of Insurance E&O - Technology** | Copy link for Certificate of Insurance E&O - Technology  
Request access Certificate of Insurance E&O - Technology |
| **Certificate of Insurance - Proof Excess Liability (Slashing)** | Copy link for Certificate of Insurance - Proof Excess Liability (Slashing)  
Policy Type: Excess Cyber Liability.  
Request access Certificate of Insurance - Proof Excess Liability (Slashing) |
| **Certificate of Insurance - Tech EO_Cyber_Staking Policy** | Copy link for Certificate of Insurance - Tech EO_Cyber_Staking Policy  
Cyber & Tech E&O/Slashing Coverage Binder (Policy No. RUSPTEOCY3752025) for Figment USA, Inc  
Request access Certificate of Insurance - Tech EO_Cyber_Staking Policy |
| **Certificate of Insurance - D&O** | Copy link for Certificate of Insurance - D&O  
Directors & Officers (D&O) Certificate of Insurance (N° 25-001) for Figment Inc.  
Request access Certificate of Insurance - D&O |
| **Certificate of Insurance - CGL** | Copy link for Certificate of Insurance - CGL  
This document is a Certificate of Insurance for Figment Inc. provided for evidence purposes.  
Request access Certificate of Insurance - CGL |

Bulk download will only work on resources that are accessible and not view only.
