Fig Security
Detects silent breaks in security data pipelines -- from log sources through SIEM and SOAR -- so teams don't lose detection coverage without knowing it, founded by ex-Siemplify and Google Cloud Security veterans.
Visit Website ↗ + Add to CompareOverview
Fig Security addresses a specific, often-overlooked failure mode in security operations: detection and response capability quietly breaking without anyone noticing. The platform traces data flows through the entire security stack — from log sources, through data pipelines and data lakes, into SIEM and SOAR platforms — and alerts security teams when an upstream change (a misconfigured log source, a broken pipeline, a schema change) silently degrades detection or response coverage. It also lets teams simulate how a proposed change, patch, or new integration would affect the pipeline before deploying it, rather than discovering the break after an incident goes undetected.
Founded in March 2025 by Gal Shafir (CEO), Nir Loya Dahan (CPO), and Roy Haimof (CTO) — veterans of Israeli intelligence unit 8200 and Mamram who previously worked at Siemplify, Google Cloud Security, and Cymulate — Fig Security emerged from stealth in 2026 with $38 million raised across seed and Series A rounds, led by Team8 and Ten Eleven Ventures with participation from former Splunk and Palo Alto Networks executives as angel investors. The company operates out of New York and Tel Aviv and has said it plans to roughly triple headcount.
The problem Fig Security targets is real and underappreciated: security teams routinely assume their detection pipeline is working simply because no alerts are firing, when in fact a silent break upstream means nothing is being monitored at all. Its differentiation from broader observability or data-pipeline tools is a security-specific focus on detection and response reliability rather than general infrastructure monitoring — though as a company barely a year old, its actual detection of real-world pipeline failures at scale is not yet independently documented.
Innovation Matrix Assessment
Went from founding in March 2025 to a $38M stealth launch within about a year, and announced plans to roughly triple headcount, indicating a fast build-out pace typical of a well-capitalized early-stage company.
Covers pipeline tracing from log source through SIEM/SOAR plus pre-deployment change simulation, a reasonably complete scope for its specific niche, though as a pre-scale company its coverage across the full range of enterprise data-source types is not yet independently documented.
A $38 million seed-plus-Series-A raise led by Team8 and Ten Eleven Ventures, with participation from former Splunk and Palo Alto Networks executives, is a strong signal of investor conviction for a company only a year old.
Targets a genuinely underserved problem -- silent detection-pipeline decay that most SOCs have no dedicated way to catch -- rather than competing head-on in an already crowded category, which gives it real differentiation potential.
As a company that only emerged from stealth in 2026, there are no public customer case studies, named enterprise deployments, or independent evaluations yet of how well the platform catches real pipeline failures in production.
Detection engineering and pipeline reliability have become recognized pain points as SOC data volumes and tool sprawl grow, making a dedicated tool for catching silent coverage gaps directly relevant to modern security operations teams.
Why CISOs Should Care
Addresses the uncomfortable reality that a quiet SOC can mean either good security or a broken detection pipeline, giving teams a way to tell the difference before an incident exposes the gap.
What Makes It Different
Focuses specifically on the reliability of the security detection and response pipeline itself, rather than general data-pipeline observability or another detection-content vendor.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A well-funded, well-pedigreed early-stage company solving a real and specific SOC reliability problem; promising thesis and strong backers, but genuinely unproven at scale given it is barely a year past founding.
Editorial Note: Claims vs. Verified Findings
Nearly all available information on Fig Security -- its technical capabilities, market positioning, and growth plans -- comes from its own stealth-launch announcement and founder interviews with trade press; no independent customer case study or third-party evaluation exists yet given the company's age.
Sources
Alternatives to Fig Security
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Lumu Technologies
Network detection and response vendor using Continuous Compromise Assessment to show where compromise has actually happened, integrating with…
Edge Delta
A telemetry pipeline and AI-agent observability platform that processes logs, metrics, and security data at the edge to…