These Product-Specific Terms describe the components of the Fig Services and set out additional terms that apply to their use. For new platform orders, they're incorporated into the accepted Order Form, the Master Services Agreement and the applicable Customer or MSP Subscription Agreement. Capitalised terms have the meanings given there.
1. Overview
The Fig Services comprise the Fig Platform (a multi-tenant, cloud-hosted SaaS application) and the Fig Software: the Fig Endpoint Agent, the Fig Cloud Agent, the Fig Data Scanner, the Fig Vulnerability Scanner, and the Fig Security mobile app (where included).
2. Fig Platform
The Fig Platform provides framework and control management (including ISO 27001, ISO 27701, SOC 2, NIST CSF 2.0, Cyber Essentials, CMMC Level 2, HIPAA, PCI DSS, UK/EU GDPR, NIS 2, DORA and custom frameworks), policy management, risk management, asset/supplier/personnel management, evidence collection, an auditor workspace, reporting and dashboards, and integrations with common cloud, identity, HR, ticketing and scanning tools. Where the Customer is an MSP, the Platform also provides partner capabilities described in the MSP Partner Agreement. The Platform is hosted in Western Europe with disaster-recovery capability in Northern Europe, with each customer's tenant logically segregated using the tenant-isolation controls described in the Data Processing Agreement.
3. Fig Endpoint Agent
An on-device agent installed on endpoints to collect and report configuration, security posture, patch and encryption status; detect and (if enabled) remediate non-compliant configuration; and collect security telemetry. Currently supports Windows 10/11 and macOS 13+; supported platforms are listed in the Documentation and may change over time. The Customer is responsible for assessing whether the Agent's required privileges are appropriate for its environment and for obtaining any internal approvals needed. The Agent updates automatically by default.
3A. Fig Security mobile app
These provisions apply where Fig Security is included in the Customer's subscription or authorised deployment. They describe the mobile app separately from the desktop Endpoint Agent. This section does not itself grant additional licences, change agreed Fees or expand the products, framework access or usage limits recorded in the Order Form. Publication does not by itself amend an existing signed agreement; its agreed change procedure continues to apply.
Fig Security reports available device security-posture checks to the organisation's Fig service. On supported, enrolled and organisation-managed iOS devices, separately enabled network protection uses Apple's network-extension/VPN permission for local DNS threat filtering and security-event reporting. It does not provide a remote VPN service, proxy general internet traffic or decrypt website content. Supported capabilities depend on the device, operating system, permissions and organisation configuration.
The Customer, or MSP acting with the relevant End Customer's authority, is responsible for authorising deployment and monitoring, providing required user notices, and configuring access and device-management policies appropriately. Network protection requires sign-in, device enrolment, an enabled managed configuration and the applicable in-app consent and operating-system permissions. It remains dormant on unmanaged or disabled installations. Acceptance of an Order Form does not replace those notices, permissions or in-app choices.
Users are shown the network-processing notice before activation. They may close it without enabling network protection. Where the device is configured as personally owned, users can withdraw network consent in the app's Settings; changes on corporate-managed devices are administered through the organisation. Base device-posture consent is separate from network-protection consent.
The filter processes queried domains and DNS query types against its local threat feed and policy. Allowed or detect-only DNS requests are forwarded over unencrypted UDP to Cloudflare's public resolvers (1.1.1.1 and 1.0.0.1), which receive the query and network source address. This resolver processing is separate from regional Fig platform storage. The app does not inspect webpage content, messages, files, URL paths or search terms and does not maintain a complete browsing-history log.
Security detections can contain the domain or host, event identifier and time, category, severity, verdict, matched indicator and evidence, DNS query type and policy/feed version. Regional connectivity checks can report suspected interception. Events are associated with the enrolled device, account and organisation and sent over HTTPS to its configured Fig region. The device stores up to 500 pending detections and 50 recent history entries; these are local count limits, not server retention periods. Regional storage, authorised access, retention, deletion and backups remain subject to the applicable Data Processing Agreement and documented subprocessors.
This device and network-security data is used to provide DNS resolution, threat detection and blocking, security monitoring and investigation, and connectivity checks. It is not used for advertising, marketing profiles, cross-service tracking or sale. Further details, including Cloudflare's processing, are in the Privacy Policy and Sub-processor List. The privacy notice explains processing and does not replace the Data Processing Agreement.
Protection and reporting depend on enabled permissions, current configuration and threat data, operating-system support and connectivity. Detections may include false positives or miss threats; unavailable reporting is retried subject to local queue limits. Fig Security does not guarantee that every threat will be detected or blocked, and does not replace the Customer's incident-response, backup or wider security arrangements. The warranties, support commitments, liability allocation and document precedence in the applicable subscription agreement continue to apply.
4. Fig Cloud Agent
A cloud-deployed component installed within a cloud environment to enumerate assets and identities, detect misconfigurations against recognised benchmarks (CIS, AWS/Azure/GCP best practice), provide continuous compliance monitoring, and feed evidence into the Fig Platform. Currently supports AWS, Microsoft Azure and Google Cloud Platform. The Agent operates with read-only, configuration-monitoring permissions by default; enabling remediation features requires additional write permissions, which the Customer must expressly authorise.
5. Fig Data Scanner
A data-discovery and classification component that scans designated file shares, repositories, mailboxes, databases and cloud storage to identify and classify sensitive or regulated data, supporting data-mapping and breach-impact assessment obligations. The Customer must designate which data sources are scanned and must have the necessary authorisation to permit scanning of each one. Content-snippet capture is off by default; where the Customer enables it, the Customer is responsible for ensuring captured snippets are handled in line with the Data Processing Agreement, and Fig recommends minimising snippet capture and applying strict access controls.
6. Fig Vulnerability Scanner
6.1 What it does
An externally-operated attack-surface scanner. The Customer nominates Scanned Assets (domains, hostnames, IP addresses, URLs, web applications); the scanner performs scheduled or on-demand scans and reports findings with confidence and severity indicators. It's designed in alignment with NIST SP 800-115, the OWASP Web Security Testing Guide and OWASP API Security Top 10, and is enriched using public sources like the NVD, CISA KEV and FIRST EPSS. It is not a substitute for manual penetration testing, red-team engagements, or any regulatory testing requirement (including DORA Threat-Led Penetration Testing).
6.2 Scan profiles
- Passive (default) - non-intrusive checks only: DNS, certificate-transparency, TLS metadata, HTTP headers, robots/sitemap review. No state-changing requests, no fingerprinting, no fuzzing beyond public metadata.
- Standard - adds bounded web-application checks (safe endpoint discovery, public-file discovery, low-rate content checks). No destructive methods, credential brute-forcing or exploit payloads.
- Aggressive - opt-in only; requires verified ownership and explicit attestation. Adds service fingerprinting, larger fuzzing wordlists, DNS zone-transfer tests, GraphQL introspection and broader subdomain enumeration.
- Custom - build from any profile above; enabling an Aggressive-only check triggers Aggressive-level authorisation requirements.
6.3 Built-in safety guardrails
Private/internal IP ranges are automatically blocked; per-scan budgets limit requests, hosts and runtime; per-host rate limiting honours Retry-After and halts on repeated block signals; requests identify themselves via User-Agent; the scanner doesn't attempt credential brute-forcing or destructive HTTP methods by default; every scan is audit-logged.
6.4 Mandatory authorisation before scanning
The Customer must not initiate a Standard or Aggressive scan of any asset without first: (a) confirming ownership or authority over the asset and completing one of Fig's target-verification methods (DNS TXT token, HTTP well-known file, existing asset proof, allowlisting, or uploaded authorisation evidence); (b) obtaining any internal approvals its own policies require; (c) obtaining any regulatory authorisations required; (d) checking the terms of service of any third-party hosting, CDN or security provider that might be triggered by the scan; and (e) notifying its own IT/security operations teams so they can distinguish an authorised scan from a genuine attack. The Customer must maintain records of these authorisations and must not scan any asset it doesn't own or control, any government, military, healthcare or critical-infrastructure target without express lawful authorisation, or any asset in a sanctioned jurisdiction.
6.5 Risk acknowledgement
The Customer accepts that external scanning - particularly under the Aggressive profile - can generate significant network traffic, trigger third-party security controls, or (rarely) affect the availability of the asset being scanned; that findings may include false positives and false negatives; and that all operational and legal risk of using the Vulnerability Scanner sits with the Customer, save where directly caused by Fig's breach of the Master Services Agreement. Full risk allocation and the related indemnity are set out in the Master Services Agreement.
7. Documentation and support
Documentation for each component is available within the Fig Platform and at www.docs.figgroup.co.uk. Support is provided in accordance with the Support Policy.
8. What's not included
The Fig Services don't include: the Customer's own compliance programme (which remains the Customer's responsibility); legal advice, audit opinions or formal certifications; manual penetration testing or red-team services; incident-response services beyond the alerting described above; or backup/archival beyond what's described in the Data Processing Agreement.
This document is part of Fig's public legal documentation. It works alongside our Terms of Service, Master Services Agreement, MSP Partner Agreement, Data Processing Agreement, Service Level Agreement and Support Policy.