Jul 21, 2026
Enterprise

Fig brings CI/CD workflow to SecOps with new Figaro AI agent

The Israeli security startup says Figaro lets teams design, test, deploy and roll back detection changes using software-style delivery controls.

Wei-Lin Zhao

By Wei-Lin Zhao · AI Correspondent

· 3 min read

Fig brings CI/CD workflow to SecOps with new Figaro AI agent
Photo: SiliconANGLE

Fig Security Inc. has launched Figaro, an AI agent for security operations teams that the company says applies software engineering-style CI/CD controls to detection and response infrastructure. No pricing, revenue, valuation or headcount figures were disclosed, so the significance is less about a commercial milestone and more about where SecOps tooling is headed: toward controlled change management for systems that often break quietly.

The Israeli company is pitching Figaro as part of what it calls a full engineering lifecycle for security operations. The product combines an AI agent with version control, preproduction testing, deployment and rollback capabilities, tools that are standard in software delivery but less mature across security operations centers.

Fig’s argument is that detection pipelines are now brittle enough to need the same discipline as application code. Security teams keep adding cloud services, telemetry feeds and detection logic, while upstream systems can change without notice. Fig says a small configuration shift can disrupt a detection flow without an obvious alert, leaving teams unaware that a security gap has opened.

How Figaro is supposed to work

Figaro is built on what Fig calls security data lineage, a deterministic graph that maps detection flows across a customer’s SecOps stack. According to the company, an engineer can describe a desired change in natural language, after which Figaro inspects the live environment, drafts the change, simulates its effect and runs tests before deployment.

If approved, the change can be pushed with a click, Fig said. The platform also includes version tracking and a one-step rollback function. After deployment, continuous monitoring is meant to verify that both existing and newly added detection flows still operate as intended.

That positioning puts Figaro in the broad wave of AI agents being attached to operational workflows, but Fig is making a more specific claim than generic automation. The company says the agent is constrained by a mapped view of the security data plane and detection dependencies, rather than acting only as a chatbot over logs or tickets.

Fig claims the system can shorten several common SecOps jobs. It says threat intelligence reports can be converted into functioning detections within a day, rather than being deferred for longer roadmap cycles. It also says SIEM migrations that previously took months can be completed in weeks while keeping detection coverage running. Those are company claims, and Fig did not provide comparative customer metrics beyond one named early user.

Customer and funding context

AppLovin Corp. is among the early users named by Fig. Jayme Hancock, AppLovin’s head of security operations and engineering, said the team has been able to make accurate detection changes in minutes rather than weeks and described a higher-confidence workflow for security engineers. He also said engineers have started using the term “vibe parsing,” a nod to the broader “vibe coding” language around AI-assisted development.

Fig co-founder and Chief Executive Gal Shafir said the company wants SecOps engineers to get workflows similar to those used by software developers, including the ability to design changes with context, validate them before release and keep checking system resilience as environments change.

Fig was founded in 2025 by alumni of Google LLC’s security operations group and Siemplify. The company came out publicly in March with $38 million in combined seed and Series A funding from Team8 Capital and Ten Eleven Ventures. It was also a finalist in this year’s RSAC Innovation Sandbox competition.

The company says its platform has reached dozens of Fortune 500 companies, but it did not name those customers beyond AppLovin or disclose deployment sizes. Fig operates from New York and Tel Aviv.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →