Skip to contentAbout Fig Group

Fig Product-Specific Terms.

Product-Specific Terms describing the components of the Fig Services.

Last updated: 1st July 2026

These Product-Specific Terms describe the components of the Fig Services and set out additional terms that apply to their use. They're incorporated into, and form part of, the Master Subscription Agreement. Capitalised terms have the meanings given there.

1. Overview

The Fig Services comprise the Fig Platform (a multi-tenant, cloud-hosted SaaS application) and the Fig Software: the Fig Endpoint Agent, the Fig Cloud Agent, the Fig Data Scanner, and the Fig Vulnerability Scanner.

2. Fig Platform

The Fig Platform provides framework and control management (including ISO 27001, ISO 27701, SOC 2, NIST CSF 2.0, Cyber Essentials, CMMC Level 2, HIPAA, PCI DSS, UK/EU GDPR, NIS 2, DORA and custom frameworks), policy management, risk management, asset/supplier/personnel management, evidence collection, an auditor workspace, reporting and dashboards, and integrations with common cloud, identity, HR, ticketing and scanning tools. Where the Customer is an MSP, the Platform also provides partner capabilities described in the MSP Partner Agreement. The Platform is hosted in Western Europe with disaster-recovery capability in Northern Europe, with each customer's tenant logically segregated using the tenant-isolation controls described in the Data Processing Agreement.

3. Fig Endpoint Agent

An on-device agent installed on endpoints to collect and report configuration, security posture, patch and encryption status; detect and (if enabled) remediate non-compliant configuration; and collect security telemetry. Currently supports Windows 10/11 and macOS 13+; supported platforms are listed in the Documentation and may change over time. The Customer is responsible for assessing whether the Agent's required privileges are appropriate for its environment and for obtaining any internal approvals needed. The Agent updates automatically by default.

4. Fig Cloud Agent

A cloud-deployed component installed within a cloud environment to enumerate assets and identities, detect misconfigurations against recognised benchmarks (CIS, AWS/Azure/GCP best practice), provide continuous compliance monitoring, and feed evidence into the Fig Platform. Currently supports AWS, Microsoft Azure and Google Cloud Platform. The Agent operates with read-only, configuration-monitoring permissions by default; enabling remediation features requires additional write permissions, which the Customer must expressly authorise.

5. Fig Data Scanner

A data-discovery and classification component that scans designated file shares, repositories, mailboxes, databases and cloud storage to identify and classify sensitive or regulated data, supporting data-mapping and breach-impact assessment obligations. The Customer must designate which data sources are scanned and must have the necessary authorisation to permit scanning of each one. Content-snippet capture is off by default; where the Customer enables it, the Customer is responsible for ensuring captured snippets are handled in line with the Data Processing Agreement, and Fig recommends minimising snippet capture and applying strict access controls.

6. Fig Vulnerability Scanner

6.1 What it does

An externally-operated attack-surface scanner. The Customer nominates Scanned Assets (domains, hostnames, IP addresses, URLs, web applications); the scanner performs scheduled or on-demand scans and reports findings with confidence and severity indicators. It's designed in alignment with NIST SP 800-115, the OWASP Web Security Testing Guide and OWASP API Security Top 10, and is enriched using public sources like the NVD, CISA KEV and FIRST EPSS. It is not a substitute for manual penetration testing, red-team engagements, or any regulatory testing requirement (including DORA Threat-Led Penetration Testing).

6.2 Scan profiles

  • Passive (default) - non-intrusive checks only: DNS, certificate-transparency, TLS metadata, HTTP headers, robots/sitemap review. No state-changing requests, no fingerprinting, no fuzzing beyond public metadata.
  • Standard - adds bounded web-application checks (safe endpoint discovery, public-file discovery, low-rate content checks). No destructive methods, credential brute-forcing or exploit payloads.
  • Aggressive - opt-in only; requires verified ownership and explicit attestation. Adds service fingerprinting, larger fuzzing wordlists, DNS zone-transfer tests, GraphQL introspection and broader subdomain enumeration.
  • Custom - build from any profile above; enabling an Aggressive-only check triggers Aggressive-level authorisation requirements.

6.3 Built-in safety guardrails

Private/internal IP ranges are automatically blocked; per-scan budgets limit requests, hosts and runtime; per-host rate limiting honours Retry-After and halts on repeated block signals; requests identify themselves via User-Agent; the scanner doesn't attempt credential brute-forcing or destructive HTTP methods by default; every scan is audit-logged.

6.4 Mandatory authorisation before scanning

The Customer must not initiate a Standard or Aggressive scan of any asset without first: (a) confirming ownership or authority over the asset and completing one of Fig's target-verification methods (DNS TXT token, HTTP well-known file, existing asset proof, allowlisting, or uploaded authorisation evidence); (b) obtaining any internal approvals its own policies require; (c) obtaining any regulatory authorisations required; (d) checking the terms of service of any third-party hosting, CDN or security provider that might be triggered by the scan; and (e) notifying its own IT/security operations teams so they can distinguish an authorised scan from a genuine attack. The Customer must maintain records of these authorisations and must not scan any asset it doesn't own or control, any government, military, healthcare or critical-infrastructure target without express lawful authorisation, or any asset in a sanctioned jurisdiction.

6.5 Risk acknowledgement

The Customer accepts that external scanning - particularly under the Aggressive profile - can generate significant network traffic, trigger third-party security controls, or (rarely) affect the availability of the asset being scanned; that findings may include false positives and false negatives; and that all operational and legal risk of using the Vulnerability Scanner sits with the Customer, save where directly caused by Fig's breach of the Master Subscription Agreement. Full risk allocation and the related indemnity are set out in the Master Subscription Agreement.

7. Documentation and support

Documentation for each component is available within the Fig Platform and at www.docs.figgroup.co.uk. Support is provided in accordance with the Support Policy.

8. What's not included

The Fig Services don't include: the Customer's own compliance programme (which remains the Customer's responsibility); legal advice, audit opinions or formal certifications; manual penetration testing or red-team services; incident-response services beyond the alerting described above; or backup/archival beyond what's described in the Data Processing Agreement.


This document is part of Fig's public legal documentation. It works alongside our Terms of Service, Master Subscription Agreement, MSP Partner Agreement, Data Processing Agreement, Service Level Agreement and Support Policy.