The 7 Figma security checks Black Cat runs
Black Cat SSPM evaluates 7 security policies against your Figma configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Figma — what access Black Cat needs, and why.
Logging & audit
3 checks · highest severity: low
Configuration hardening
3 checks · highest severity: high
Logging & audit (3)
- Account Not Org-Scoped (No Audit Visibility) severity: low
- Activity Permission Change Event severity: info
- Activity Member Role Change Event severity: info
Configuration hardening (3)
- Webhook Endpoint Not HTTPS severity: high
- Webhook Without Passcode severity: medium
- Webhook Targets Raw IP Endpoint severity: low
Other checks (1)
severity: medium Stale API Token In Use fix difficulty: easy #
Review long-lived personal access tokens still making API calls
- Open Figma settings > Personal access tokens and review active tokens
- Revoke tokens that are unused, over-scoped, or owned by departed users
- Rotate tokens on a regular schedule
Satisfies: NIS2 Directive NIS2-21.e.3 DORA (SaaS Security) DORA-9.8