EN
Back to the archive

The archive · Developer & Business Tools · Product decision · 2025–2026

Fig Security's SecOps bet: $38M to catch silent failures

Fig's bet: security stacks silently break as tools change, so it traces detection flows end-to-end; $38M raise and Fortune 100 customers within months.

Fig Security

The betThat security's blind spot is silent breakage of existing detections: back-trace each detection's data flow, alert on inconsistencies, simulate changes before rollout.Live

What the business is

Sells SecOps 'resilience' software that maps an enterprise's detection and response flows across the whole security stack, traces data lineage from sources through SIEMs and data lakes to SOAR platforms and SOC agents, and alerts teams when a change would silently break detection or response.

Starting capital$38M announced March 2026, across seed and Series A rounds, with Team8 and Ten Eleven Ventures among the investors, plus security leaders including former Splunk CEO Doug Merritt and former Palo Alto Networks CMO Rene Bonvanie.

How it started

Gal Shafir led Google Cloud Security's global architecture team before founding Fig Security in 2025 with CTO Roy Haimof and CPO Nir Loya Dahan, veterans of Israel's Unit 8200 and Mamram. While pitching Google's AI products to CISOs, Shafir kept hearing the same doubt: 'I don't know if I trust my detections right now' — meaning AI that promises safety tomorrow is worthless if the data feeding existing detections is already broken. The founders concluded that constant tool and environment change silently skews security operations, and that no vendor was solving that trust problem, so they left to build Fig.

What happened

Fig's platform autonomously discovers and maps an organization's complete detection and response flows, samples data as it moves through pipelines, and builds a data lineage that shows how an upstream change could break downstream detection in real time. It connects to data links and SIEM systems, alerts security teams to inconsistencies, and lets them simulate fixes before deployment. The company ran in stealth with offices in New York and Tel Aviv, and by March 2026 had raised $38M across seed and Series A rounds from Team8, Ten Eleven Ventures and a group of security-industry angels, with plans to triple headcount and expand in North America.

No ending yet — it is still running.

Background

Fig Security, founded in 2025 by Gal Shafir, Roy Haimof and Nir Loya Dahan — veterans of Israel's Unit 8200 and Mamram, with Shafir formerly leading Google Cloud Security's global architecture team — came out of stealth on March 3, 2026 with $38 million across seed and Series A rounds. Its premise: enterprise security stacks are so dense and change so often that detections silently break, and an alarm that has not fired in months may simply be broken rather than proof that nothing is wrong.

The product is a SecOps resilience platform that treats each detection as the source of truth and works backward. It autonomously maps the organization's detection and response flows, traces data lineage end-to-end — from sources through pipelines, data lakes and SIEMs to SOAR platforms and SOC agents — and alerts teams in real time when an upstream change threatens detection or response. Teams can also simulate how a new fix, patch or configuration would ripple through the stack before deploying it to production.

The idea came from customer conversations while Shafir was at Google Cloud Security: CISOs told him they could not trust AI recommendations about tomorrow's security posture when they did not trust the data feeding today's detections. The founding bet was that the market's need was confidence in existing security operations, not another point tool. Team8 and Ten Eleven Ventures backed the rounds, joined by security leaders including former Splunk CEO Doug Merritt and former Palo Alto Networks CMO Rene Bonvanie.

Roughly eight months after launching, Fig counted large enterprises among its customers, including Fortune 100 companies, in the low double digits, and planned to reach 50–100 customers by the end of 2026 while tripling headcount and expanding in North America. As of the announcement, the company had not disclosed revenue or pricing, and its impact rests on whether CISOs treat 'resilience of the security stack itself' as a budget line separate from detection tooling.

What has to be true

  • A detection that has not fired for months is indistinguishable from a detection that is broken, so trust in the security stack decays silently as tools change.
  • CISOs said they could not trust AI advice on future posture while unsure the data under today's detections still flowed correctly.
  • Back-tracing from each detection as the source of truth converts an unmanageable sprawl of tools into one auditable data lineage.
  • Simulating changes before rollout sells a workflow enterprises already want — safe innovation in the SOC — rather than a new alert source.
  • Founders with Google Cloud Security, Unit 8200 and Mamram backgrounds gave enterprise buyers reason to trust a brand-new category.

What can be applied

The most dangerous failure is the one nobody sees: sell certainty about existing detections — back-trace flows, alert on silent breaks, simulate before rollout.

Aftermath

As of the March 3, 2026 announcement, Fig Security runs from New York and Tel Aviv with the platform live at low double-digit large-enterprise customers, including Fortune 100 companies. The $38M across seed and Series A funds tripling engineering and go-to-market headcount and North American expansion, with a stated goal of 50–100 customers by end-2026; investors Team8 and Ten Eleven Ventures are joined by security angels such as ex-Splunk CEO Doug Merritt, while pricing, revenue and retention figures remain unpublished.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases