Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Figma, your compliance team needs documented proof they can be trusted. ThirdProof investigated Figma across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
25 sources queried. 100% confidence. Every Figma investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Figma's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 36% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
Not found in FedRAMP marketplace
Q40
Figma's SSA document addresses security measures and training but no explicit BAA agreement or HIPAA compliance statement is confirmed in provided evidence.
Q42
Figma has a Data Protection Addendum (DPA) that forms part of agreements with customers covering GDPR compliance and data protection laws.
+ 6 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Figma's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Figma is not listed on the FedRAMP Marketplace.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
25
Sources Queried
25
Sources With Data
April 5, 2026
Last Assessed
AI-generated analysis for Figma
Figma, Inc. (figma.com) is a publicly traded, enterprise-grade collaborative design SaaS platform assessed at Tier 3 (Moderate Risk), reflecting a broadly sound security posture offset by an active class action lawsuit and unresolved ambiguity around AI data handling practices. Figma presents several meaningful positive signals. The domain has been registered since 1999 and carries a fully clean reputation across all blacklist and malware databases. Infrastructure exposure is minimal — only 1 open port detected, 0 known CVEs, and a Cloudflare CDN providing an additional defensive perimeter, representing a well-controlled footprint significantly below the SaaS industry average of 8–12 open ports. The HTTP security grade is B (75/100), indicating strong baseline security header configuration. Malware detection service, IP reputation, and website security scans all return clean results. Figma publishes a comprehensive subprocessor list at figma.com/sub-processors (36 subprocessors identified), with none flagged across sanctions or safety databases. The vendor claims a strong compliance posture on its security page (https://figma.com/security), including:
Independence Statement
All evidence underpinning this report was independently sourced from external data providers, public registries, and open-source intelligence without participation or prior notification to the vendor under investigation.
6 findings identified for Figma
Article from www.reuters.com: "Figma sued for allegedly misusing customer data for AI training | Reuters"
figma.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.
figma.com has certificates from 31 different Certificate Authorities. This may indicate inconsistent certificate management practices.
figma.com first appeared less than 1 year ago (2026-03-06). This indicates a relatively new web presence.
figma.com has an AI-related policy page but does not clearly state whether customer data is used for AI model training.
FIGMA, INC. was first registered approximately 14 months ago.
28 positive signals verified
Legal Entity Actively Registered
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →1 Open Port Detected
Infrastructure Exposure →Established Domain (26+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: legal
Tech Community Sentiment →Tech Community Discussion: trust
Tech Community Sentiment →Tech Community Discussion: financial
Tech Community Sentiment →HTTP Security Grade: B
HTTP Security Scan →Large Certificate Footprint (57 subdomains)
Certificate Transparency →Domain in 20 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: ISO 27001
Trust & Compliance Page Scan →Certification Claimed: ISO 27017
Trust & Compliance Page Scan →Certification Claimed: ISO 27018
Trust & Compliance Page Scan →Certification Claimed: FedRAMP
Trust & Compliance Page Scan →36 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →AI Data Retention Policy Not Specified
AI Data Usage Policy →Steps to address findings for Figma
Activate Figma's AI opt-out mechanism for your account immediately and request written confirmation from Figma (security@figma.com or your account manager) that your organization's content is excluded from AI model training — this directly addresses both rf-1 and rf-5 and should be completed within 14 days.
Request Figma's current SOC 2 Type II report and bridge letter — contact their security team or visit https://figma.com/security where many enterprise vendors offer NDA-gated report downloads. This is the only reliable path to verify SOC 2 compliance given that no public registry exists for SOC 2.
Independently verify FedRAMP Authorized status by searching 'Figma' at https://marketplace.fedramp.gov — this takes under 5 minutes and provides definitive confirmation or refutation of the vendor's claim without requiring vendor contact.
Request Figma's ISO 27001:2022 certificate (with certificate number, issuing body, and expiry date) and cross-reference it at https://www.iafcertsearch.org to confirm active certification status.
Obtain a signed Data Processing Addendum (DPA) from Figma that explicitly prohibits use of customer-uploaded design content for AI model training or improvement, and ensures downstream AI subprocessors (Anthropic, OpenAI, Google Vertex, et al.) are contractually bound by the same restriction — review the current subprocessor list at https://figma.com/sub-processors.
Monitor the class action litigation (California federal court, filed November 2025) for material developments — set a 90-day review checkpoint to reassess whether any settlement terms, court orders, or changes to Figma's AI data practices affect your risk posture.
25 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Figma? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Figma on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Figma's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Figma a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Figma appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Figma's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Figma's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Figma claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Figma depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Figma appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Figma claims SOC 2, ISO 27001, ISO 27017, ISO 27018, FedRAMP, GDPR, and CCPA compliance — one of the broadest certification profiles among design tools. Organizations should verify these certifications directly given the Adobe acquisition, which may affect certification scope and renewal timelines. For design teams using Figma alongside project management tools, see the Linear security review for an example of assessing connected vendor risk.
ThirdProof investigated Figma across 27 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 86% confidence. Domain reputation is clean across 94 security engines with a 26-year domain history and A+ SSL/TLS grade. Sanctions screening is clear with no matches. No malware, phishing indicators, or adverse media were detected. The B (75/100) HTTP security grade reflects standard enterprise web application configuration.
Seeing this in an audit? ThirdProof lets you investigate Figma and every other vendor in your stack — average report time: 7 minutes. Get Figma's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Figma across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.