Find Figma's trust center. The listing notes SOC 2 Type II, SOC 3, HIPAA, HITRUST, FedRAMP, GDPR, among other frameworks. Open Figma's own security page at compliance.figma.com from trustlists, an open directory of 4,000+ vendor trust centers. The listing also references CSA STAR Level 1 (AI CAIQ and CAIQ).
Figma Compliance & Certifications
External Registries
Frequently Asked Questions
Does Figma have SOC 2 Type II?
Yes. Figma holds SOC 2 Type II, SOC 3, HIPAA, HITRUST, FedRAMP, GDPR, CCPA, TX-RAMP, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, PCI DSS certifications. You can view their trust center at compliance.figma.com for full security and compliance documentation.
Where can I find Figma's security documentation?
Figma publishes their trust center on Conveyor at compliance.figma.com. It includes security policies, compliance certifications (SOC 2 Type II, SOC 3, HIPAA, HITRUST, FedRAMP, GDPR, CCPA, TX-RAMP, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, PCI DSS), and other documentation.
Does Figma have ISO 27001 certification?
Yes, Figma is ISO 27001 certified. This international standard confirms they have implemented a comprehensive information security management system (ISMS).
Is Figma HIPAA compliant?
Yes, Figma is HIPAA compliant and can support healthcare organizations that handle protected health information (PHI).