Fig launches AI-assisted CI/CD workflow for security operations

Fig Security launched an AI-assisted engineering workflow for security operations on July 21, combining plain-language change creation with simulation, version control, one-click deployment and rollback. The company says its security data lineage graph lets teams test detections and configuration changes against a live environment before production, then continuously verify that detection flows still work; independent reporting identifies the agent as Figaro.
Fig Security on July 21 introduced what it calls a full engineering lifecycle for security operations: a workflow for building, testing, shipping and monitoring detection and configuration changes. The launch combines an AI-assisted builder with simulation, version control, rollback and continuous verification.
What Fig launched
According to Fig's announcement, an engineer can describe a needed detection or configuration in plain language. The system models the change against the organization's data infrastructure, schemas, fields and sources, then simulates and checks it before production. Approved changes can be deployed in one click, with each version tracked and reversible.
SiliconANGLE's independent report identifies the AI agent as Figaro. Fig's own launch post describes the AI-assisted workflow but does not use that product name, so the naming remains attributed to the reporting rather than presented as an independently documented specification.
Security data lineage is the foundation
Fig says the workflow is built on a deterministic security data lineage graph covering detections, data sources and pipelines in the customer's environment. That graph supplies the context for proposed changes and supports post-deployment checks intended to confirm that both existing and new detection flows continue to operate.
The company describes this as the first true CI/CD workflow for SecOps. That is a vendor positioning claim, not an independently measured category finding. SiliconANGLE also reports that AppLovin's security operations team can now ship detection changes in minutes rather than weeks, but the statement is a customer testimonial included with the launch, not a published benchmark.
Why it matters for security teams
The practical idea is familiar from software delivery: treat security logic as versioned production code and require evidence before a change ships. If the lineage and simulations accurately represent the live environment, that could reduce the risk that a parser update, data-source change or detection edit silently opens a monitoring gap.
For security engineering teams evaluating the platform, the important questions are how completely it maps their specific stack, how simulation results are validated, which actions require approval and whether rollback and audit records cover every supported integration. The launch establishes the workflow and product direction, while independent operational evidence beyond selected customer claims is still limited.
Key Points
- 1Fig's new workflow uses AI to draft SecOps changes, then simulates and checks them against the customer's environment before deployment.
- 2Version control, one-click rollback and continuous post-deployment verification bring software-style change controls to detection engineering.
- 3The product architecture and speed claims come from Fig and a selected customer; independent benchmark evidence has not been published.
Scoring Rationale
The launch gives SecOps engineers a concrete AI-assisted build, test, deployment and rollback workflow tied to live security-data lineage. It is operationally relevant, but its performance and category-leadership claims remain vendor-reported and supported mainly by selected customer testimony rather than independent benchmarks.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
