Figma

ConveyorSTAR L1Verified Sep 2026Unclaimed

Find Figma's trust center. The listing notes SOC 2 Type II, SOC 3, HIPAA, HITRUST, FedRAMP, GDPR, among other frameworks. Open Figma's own security page at compliance.figma.com from trustlists, an open directory of 4,000+ vendor trust centers. The listing also references CSA STAR Level 1 (AI CAIQ and CAIQ).

Figma Compliance & Certifications

SOC 2 Type IISOC 3HIPAAHITRUSTFedRAMPGDPRCCPATX-RAMPISO 27001ISO 27017ISO 27018ISO 27701ISO 42001PCI DSS

External Registries

CSA STAR RegistryLevel 1
AI CAIQ ยท CAIQListed Apr 2022

Frequently Asked Questions

Does Figma have SOC 2 Type II?

Yes. Figma holds SOC 2 Type II, SOC 3, HIPAA, HITRUST, FedRAMP, GDPR, CCPA, TX-RAMP, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, PCI DSS certifications. You can view their trust center at compliance.figma.com for full security and compliance documentation.

Where can I find Figma's security documentation?

Figma publishes their trust center on Conveyor at compliance.figma.com. It includes security policies, compliance certifications (SOC 2 Type II, SOC 3, HIPAA, HITRUST, FedRAMP, GDPR, CCPA, TX-RAMP, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, PCI DSS), and other documentation.

Does Figma have ISO 27001 certification?

Yes, Figma is ISO 27001 certified. This international standard confirms they have implemented a comprehensive information security management system (ISMS).

Is Figma HIPAA compliant?

Yes, Figma is HIPAA compliant and can support healthcare organizations that handle protected health information (PHI).