Figma security review: SOC 2, AI training & subprocessors

What Figma publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
100/100
SOC 2
SOC 2 Type II
ISO 27001
Claimed
Trains AI on your data?
See quotes
Subprocessors
58 listed

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does Figma train AI on your data?

Statements differ between pages

Figma's own words (figma.com/legal/ai-terms):

If Customer’s “Content Training” toggle is on and an administrative user later toggles it off, new Customer Content and edits added after the date the toggle was turned off will not be used to train AI models.

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Other statements we found
When “Content Training” is toggled on within Customer’s administrative user settings, Figma may use Customer Content to maintain, improve, and enhance Figma’s products and services by training machine learning and artificial intelligence algorithms and models.
figma.com/legal/ai-terms

Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.

Certifications Figma claims

Certification or reportMentioned on
SOC 2 Type IIfigma.com/security
SOC 3figma.com/security
ISO/IEC 27001figma.com/security
ISO/IEC 27017figma.com/security
ISO/IEC 27018figma.com/security
ISO/IEC 27701figma.com/security
ISO/IEC 42001figma.com
FedRAMPfigma.com
TISAXfigma.com/security

Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask Figma for the SOC 2 report or ISO certificate.

Figma subprocessors

Figma lists 58 subprocessors on figma.com/sub-processors (first 50 shown):

Security features mentioned

SSO / SAMLNot found
SCIM provisioningNot found
Multi-factor authenticationMentioned
Encryption at restMentioned
Encryption in transitNot found
Penetration testingNot found
Bug bounty / disclosure programMentioned
Audit logsNot found
Data residencyMentioned EU, United States, UK
security.txt contacthttps://hackerone.com/figma

Key documents

Trust / security centerfigma.com/security
Privacy policyfigma.com/legal/privacy
Subprocessor listfigma.com/sub-processors
Data processing agreement (DPA)figma.com/legal/dpa
AI policyfigma.com/legal/ai-terms
TermsNot found
Status pagestatus.figma.com

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15Yes
DPA available10Yes
AI training policy stated15Yes
security.txt contact5Yes
Status page10Yes

The score measures how much of a standard security review our reader could answer from Figma's public pages. It is not a rating of how secure Figma is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Productivity vendors

Airtable · Asana · Atlassian · Basecamp · Box · Calendly · ClickUp · Coda · DocuSign · Dropbox · Evernote · Fireflies.ai

Source: Figma's own public website (6 pages read on October 10, 2026). Stormap is not affiliated with Figma. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.