The 7 Figma security checks Black Cat runs
Black Cat SSPM evaluates 7 security policies against your Figma configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.
configuration
Point webhooks at HTTPS endpoints to protect event payloads in transit
Set a passcode on webhooks so your receiver can verify event authenticity
Point webhooks at a named, TLS-validated host rather than a raw IP literal
logging
Configure an org-scoped Enterprise token so Figma activity/audit logs are collected
Review file sharing/permission-change events captured in the activity log
Review member/role-grant events captured in the activity log
token governance
Review long-lived personal access tokens still making API calls