No article in the knowledge graph for Fig yet.
Who is Fig?
Fig is a private cybersecurity company that provides cloud and application security capabilities focused on finding, prioritizing, and remediating risks across modern software delivery environments.
- Cloud security posture visibility across infrastructure and managed services
- Application and software supply chain risk detection in development workflows
- Policy-based controls, misconfiguration analysis, and exposure prioritization
- Developer and security team workflows for remediation and governance
- Support for enterprise security operations across multicloud environments
Show more
More About Fig
Fig operates as a security software provider for enterprises running cloud-native applications and distributed infrastructure. Its offerings are positioned for organizations that need a unified view of risk across cloud resources, application components, and engineering workflows. In enterprise settings, this type of platform is typically used by security engineering, cloud platform, DevSecOps, and compliance teams to monitor configuration drift, identify exposed services, and route remediation tasks into existing operational processes.
The technology domain associated with Fig centers on cloud and application security. That commonly includes analysis of infrastructure deployed in public cloud environments, inspection of identities and permissions, and evaluation of configuration against internal policy or external frameworks. Enterprise buyers in this category often expect integrations with CI/CD pipelines, source code repositories, containerized workloads, infrastructure as code, and ticketing or alerting systems. In practical use, the platform fits alongside broader cloud security and DevSecOps programs, rather than replacing endpoint, network, or identity security controls.
From a solution-category perspective, Fig aligns most closely with cloud security and application security software, especially where teams want security findings tied to remediation workflows. Compared with point tools that cover only posture management or only developer scanning, platforms in this segment are generally used to reduce fragmentation between runtime cloud visibility and pre-deployment checks. That matters in enterprise environments where risk ownership is shared across infrastructure, application, and governance teams.
As a private company in the enterprise software market, Fig is best understood as competing in cybersecurity, with emphasis on securing cloud estates and software delivery pipelines. Its business relevance comes from addressing operational issues common in multicloud and cloud-native environments: misconfigurations, excessive permissions, exposed assets, policy violations, and backlog management for remediation. For directory purposes, the company fits within current security software categories tied to cloud security posture, application security, and DevSecOps-oriented risk management.
Our description of Fig. Updated September 2026.