Skip to content

The 7 Figma security checks Black Cat runs

Black Cat SSPM evaluates 7 security policies against your Figma configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.

configuration

highWebhook Endpoint Not HTTPS

Point webhooks at HTTPS endpoints to protect event payloads in transit

mediumWebhook Without Passcode

Set a passcode on webhooks so your receiver can verify event authenticity

lowWebhook Targets Raw IP Endpoint

Point webhooks at a named, TLS-validated host rather than a raw IP literal

logging

lowAccount Not Org-Scoped (No Audit Visibility)

Configure an org-scoped Enterprise token so Figma activity/audit logs are collected

infoActivity Permission Change Event

Review file sharing/permission-change events captured in the activity log

infoActivity Member Role Change Event

Review member/role-grant events captured in the activity log

token governance

mediumStale API Token In Use

Review long-lived personal access tokens still making API calls

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial