Skip to main content

Figma Security and Compliance

Figma empowers teams to build better products, with enterprise-grade security every step of the way. Our dedicated Security team makes sure your data is protected and your security and compliance obligations are met through continuous audits, privacy safeguards, and a robust security infrastructure.

Trusted by teams at

  • atlassian logo
  • braintree logo
  • dribbble logo
  • github logo
  • microsoft logo
  • one medical logo
  • slack logo
  • the new york times logo
  • zoom logo
  • walgreens logo
  • airbnb logo
  • asana logo
  • basic logo
  • coinbase logo
  • dropbox logo
  • herman miller logo
  • rakuten logo
  • vodafone logo

Certifications and Attestations

Figma maintains a Trust Center where you can find answers to frequently asked questions, explore our extensive security practices, and access and download our compliance documentation. Learn more about Figma’s certifications, frameworks, and compliance programs—all meticulously designed to safeguard our customers’ data and privacy.

  • SOC 2

    Figma has an SOC 2 Type 2 report that shows our commitment to protecting customer data through robust security, availability, and confidentiality controls that align with the AICPA Trust Services Criteria.

  • SOC 3

    Figma has an SOC 3 report that shows our commitment to protecting customer data through robust security, availability, and confidentiality controls that align with the AICPA Trust Services Criteria.

  • ISO 27001+

    • ISO 27017
    • ISO 27018
    • ISO 27701

    Figma has certified its product and services against ISO/IEC 27001:2022 and ISO/IEC 27018:2019.

  • ISO 42001

    Figma has certified its AI management system against ISO/IEC 42001:2023.

  • EU Cloud Code of Conduct

    The EU Cloud Code of Conduct translates GDPR requirements into practical guidelines for Cloud Service Providers, offering cloud-specific approaches, recommendations, and a roadmap that aligns with GDPR and international standards like ISO 27001 and ISO 27018.

  • C5 Cloud Computing Compliance Criteria Catalogue

    The Cloud Computing Compliance Controls Catalogue (C5) certification exists to meet rigorous, German government–backed standards for security, transparency, and operational resilience, providing independent assurance for regulated and public-sector customers, especially in Germany and the EU.

  • TISAX

    Trusted Information Security Assessment Exchange (TISAX) is a European automotive industry-standard information security assessment (ISA) catalog based on key aspects of information security and requirements from the international standard ISO 27001.

  • Cloud Security Alliance (CSA)

    At least annually, Figma completes the Consensus Assessments Initiative Questionnaire (CAIQ) based on the Cloud Controls Matrix (CCM) in order to provide customers with assurance over our security and compliance posture, including the regulations, standards, and frameworks they adhere to.

  • FedRAMP Authorized

    FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government program that standardizes security assessment, authorization, and continuous monitoring for cloud products and services, ensuring they meet federal cybersecurity requirements before agencies can use them.

Bug Bounty and Uptime

Learn more about Figma's Bug Bounty program and Uptime status

Add extra control with Governance+

For even more protection, the Governance+ add-on for Figma Enterprise gives you centralized controls like IP allowlisting, network restrictions, enforced 2FA, and extended idle session timeouts.

From the blog

How we secure Figma’s internal systems with agents

Our security team built an AI agent that triages alerts, conducts forensic investigations, queries our security data lake, writes code to fix issues—and remembers what it learns. Here's how we cut alert time-to-resolution by 71% and fundamentally changed how our on-call engineers work.

Learn more
Friendly AI workers assemble and defend a castle-like software repository, symbolizing an AI-assisted secure software development pipeline.Friendly AI workers assemble and defend a castle-like software repository, symbolizing an AI-assisted secure software development pipeline.

How Figma stays ahead of vulnerabilities with agents

For the past year, agents at Figma have guarded code as it's written, reviewed every pull request, and audited a decade-old monorepo, all on one policy.

Learn more
Abstract illustration with colorful geometric arcs and a striped butterfly-like shape, featuring bold gradients, blue cubes, soft glows, and dramatic shadows on a white background.Abstract illustration with colorful geometric arcs and a striped butterfly-like shape, featuring bold gradients, blue cubes, soft glows, and dramatic shadows on a white background.

Trust you can verify: Figma is now ISO 42001 certified

Saying you use AI responsibly is easy, but proving it to an accredited auditor is harder. We decided that was a standard worth meeting.

Learn more
Large yellow and green particles pass through a red elliptical sieve intersecting blue lanes, illustrating filtration across multiple layers.Large yellow and green particles pass through a red elliptical sieve intersecting blue lanes, illustrating filtration across multiple layers.

Visibility at scale: How Figma detects sensitive data exposure

Solving security challenges at scale requires creativity as much as rigor. To reduce the risk of sensitive data exposure, we built Response Sampling: a lightweight, real-time control that watches outbound responses, validates access, and provides an early warning system across our products.

Learn more
Abstract digital illustration with a cutaway cylinder containing green spheres on the left, and a scattered arrangement of red cubes, yellow rounded shapes, and translucent overlays on a blue background—representing a system with elements being distributed or deployed.Abstract digital illustration with a cutaway cylinder containing green spheres on the left, and a scattered arrangement of red cubes, yellow rounded shapes, and translucent overlays on a blue background—representing a system with elements being distributed or deployed.

Rolling out Santa without freezing productivity: Tips from securing Figma’s fleet

We scaled Santa, an open-source binary authorization tool, across all Figmates’ laptops to boost endpoint security while keeping workflows seamless. Here’s how we tackled the challenges and ensured a smooth rollout.

Learn more
Person getting distorted as they pass through various checkpointsPerson getting distorted as they pass through various checkpoints

Designing for security and usability: Figma's modern endpoint strategy

At Figma, security doesn’t have to slow you down. We’ve designed our corporate endpoint security with UX in mind, making it seamless and self-serve.

Learn more